Privacy notice
Privacy notice
Clarity-OO Ltd — Privacy notice — version 2026-10-07.2
This notice explains what personal information Clarity-OO Ltd ("Clarity", "we", "us") holds about people who use a Clarity account, why, who else handles it, and your rights.
Who we are. Clarity-OO Ltd, registered in England and Wales, company number 17484245. Registered office: 2b Henry Street, Blackburn, BB1 4JJ, United Kingdom. Contact: support@clarity-oo.com. Clarity-OO Ltd is registered with the Information Commissioner's Office (ICO), registration number ZC267390.
1. Our two roles
- Clarity accounts. We decide what is collected and why, so we are the controller. Most of this notice is about that information.
- What our customers put into a product (for example, the people on a resource plan or a programme). The customer decides what goes in and why, and we process it for them as their processor under our terms (Schedule 1). If your details are in a customer's plan, please ask that customer first. We will help them answer you.
2. Where we get information
- From you, when you sign up, sign in or contact us.
- From your organisation's account administrator, when they add you: your name, email address and role, and which products you may use.
- From Stripe, about whether payments have been made.
- Automatically, when you use the site: your IP address, your browser, and the pages you requested.
To have an account we need your name, email address, password and two-step sign-in. Without them we cannot provide one. For a paid subscription, we also need billing details.
3. What we hold, why, and on what basis
| Information | Why | Legal basis |
|---|---|---|
| Name and email address | To run your account and sign you in | Contract, where you hold the account yourself (for example, as a sole trader). Legitimate interests where your organisation added you: providing the service it has contracted for |
| Password (as a one-way hash), two-step secret, hashed recovery codes | To make sure it is you signing in | As above, plus legitimate interests in keeping accounts secure |
| Your organisation, the people in its account and their roles | To manage licences and who can do what | Legitimate interests of your organisation and of us in running the account |
| Subscriptions, invoices, payment status and Stripe customer reference. We never see or store card details: Stripe holds them | Billing | Contract with the paying organisation, and legal obligation to keep accounting records |
| Emails about your account: set-up, password resets, changes to terms and prices | To run the service | Legitimate interests (and contract, where applicable) |
| A record of who did what in an account (for example, licence changes) | Security, and resolving disputes | Legitimate interests |
| Failed sign-ins (email address and IP address) | Stopping password guessing | Legitimate interests |
| Refused automated sign-ups (IP address and the email's domain only) | Keeping out spam sign-ups | Legitimate interests |
| Web server logs (IP address, browser, pages requested) | Security and fixing faults | Legitimate interests |
| Messages you send to support@clarity-oo.com | Answering you | Legitimate interests |
Where we rely on legitimate interests, we have weighed them against your interests and rights. You can ask us about that balance.
We do not sell personal information, use it for advertising, or make decisions about you by automated means alone.
4. Cookies
We use only the cookies needed to keep you signed in. They are strictly necessary, so we do not ask for consent.
There are no analytics, advertising or tracking cookies.
Some products save working copies of your files in your own browser's storage, on your own device. We cannot read them.
5. Who else handles it
| Organisation | What it does | Its role | Where |
|---|---|---|---|
| Heart Internet Ltd | Hosts our servers | Processor | United Kingdom (Leeds) |
| Amazon Web Services (Simple Email Service) | Sends Clarity's emails | Processor | United Kingdom (London region, our choice). AWS's UK GDPR Addendum, including the UK international data transfer addendum, applies automatically to any transfer |
| Microsoft (Microsoft 365) | Our support mailbox, and storage (SharePoint) for a daily copy of our databases | Processor | United Kingdom (Microsoft's committed data location for our account) |
| Stripe | Takes payments and emails receipts and billing notices | Processor for our payments. Independent controller for its own purposes, such as fraud prevention and its legal obligations. See stripe.com/privacy | UK, EU and US |
Each processor works under a contract that requires it to protect the information. We tell business customers before we add or change a processor, as our terms set out.
Copies on our own equipment. A daily copy of our databases is kept on a company computer in the UK, on a drive with its own hardware encryption and password, and synced to our Microsoft 365 storage.
6. Transfers outside the UK
Our servers are in the UK. Some suppliers may process information, or reach it for support, from outside the UK. Stripe, in particular, processes in the United States. Where that happens, the transfer is protected by UK adequacy regulations (including the UK Extension to the EU–US Data Privacy Framework) or by the UK International Data Transfer Addendum or Agreement. Email us for details of the safeguards.
7. How long we keep it
- Account information: while your account is open. Deleted within 90 days after it closes, except billing records.
- Billing records: 6 years, as the law requires.
- Failed sign-ins: no more than a day.
- Web server logs: 10 days.
- Support emails: 2 years after the conversation ends.
- Backups: on our servers, deleted within 8 weeks (14 daily and 8 weekly copies). The daily copy on our own computer is also deleted within 8 weeks, but its Microsoft 365 copy stays recoverable for up to 93 days after that. So every copy is gone within about 5 months.
- What customers put into products: as our terms say. Read-only for 90 days after a subscription ends, or 30 days after a free trial ends without one, then deleted.
8. Keeping it safe
- Everything travels encrypted (HTTPS).
- Passwords and recovery codes are stored only as one-way hashes.
- Two-step sign-in is required for everyone.
- Our servers are in the UK, kept up to date, and backed up nightly to a second UK server.
- Our terms (Schedule 1, Annex A) give more detail.
9. Your rights
Under UK data protection law you can ask us to:
- access: give you a copy of your information;
- rectification: correct it;
- erasure: delete it;
- restriction: limit how we use it;
- objection: stop using it, where we rely on legitimate interests. We will stop unless we have compelling grounds to continue;
- portability: give it to you, or to someone else, in a common format. This applies to information you gave us, where we rely on contract.
Not every right applies in every case. For example, we must keep billing records even if you ask us to delete them, and we will explain if a right does not apply.
To ask, email support@clarity-oo.com. We answer within one month. This can be extended by up to two more months for complex requests, and we will tell you if it is. We do not normally charge.
10. Complaints
If you are unhappy with how we have handled your information, please tell us at support@clarity-oo.com. We will:
- acknowledge your complaint within 30 days;
- look into it properly;
- tell you the outcome without undue delay.
You can also complain to the Information Commissioner's Office: ico.org.uk, 0303 123 1113. The ICO may ask whether you have complained to us first.
11. Changes
If we change this notice in a way that matters, we will tell account holders by email before the change takes effect. The version date is at the top.