Skip to main content
CDClariDuty365← Back to website

Privacy notice

How ClariDuty 365 handles personal information

Last updated: 3 August 2026. This notice applies to the ClariDuty 365 website, customer workspaces and subscription service operated by Don Reynolds in the United Kingdom.

Information collected

We may process account identity and contact details, organisation and billing details, enquiry records, user roles, authentication identifiers, audit logs, device and security information, and workplace compliance records. Workplace records may include incident descriptions, action ownership, training information, risk assessments, COSHH details, evidence and uploaded documents.

Why it is used

Information is used to provide and secure the service, separate customer workspaces, maintain defensible audit histories, process subscriptions, respond to enquiries, prevent misuse, support customers and meet legal or accounting obligations.

Lawful basis

Depending on the activity, processing may rely on contract, legitimate interests, consent or legal obligation. For customer-uploaded workforce information, the customer determines the lawful basis and normally acts as data controller; ClariDuty 365 processes that information to provide the service.

Customer responsibilities

Customers must ensure they have authority and an appropriate lawful basis to upload personal information, provide required workforce privacy notices, keep records accurate, manage user permissions and avoid entering unnecessary special-category information.

Subprocessors and sharing

Information is not sold. Essential subprocessors may include OpenAI and its managed cloud infrastructure for application delivery, authentication, databases and storage; Stripe for subscription billing and fraud prevention; and service providers used for security, support or lawful professional advice. Each provider receives only the information reasonably required for its function.

Retention and deletion

Enquiries are retained for reasonable commercial follow-up and record-keeping. Active customer records are retained while the service is provided. When a founding 30-day trial ends without subscription, the workspace moves to export-only access and organisation administrators have a further 30 days to export their organisation data. After that, access is restricted for an authorised retention review. The current platform does not claim unattended automatic deletion. Deletion or anonymisation requires a verified administrative process and remains subject to statutory, dispute, fraud-prevention, security-log and backup-retention requirements.

International processing and security

Technology providers may process information outside the United Kingdom. Where required, recognised safeguards are used. ClariDuty 365 applies organisation-level separation, authenticated access, role controls, audit logging and secure hosted infrastructure; no online service can guarantee absolute security.

Data export and account termination

Organisation administrators may request an export of their organisation data before termination. Requests are subject to identity, authority and tenant-membership verification so that one organisation cannot obtain another organisation’s records.

Your rights

UK data-protection rights may include access, correction, deletion, restriction, objection and data portability. You may also complain to the Information Commissioner’s Office.

Contact

Use the website’s contact form to submit a privacy request. Identity may need to be verified before information is disclosed or changed.

This notice describes the current service position and should be reviewed by a qualified data-protection professional before large-scale or high-risk processing.