CDClariDuty365← Back to website

Privacy notice

How ClariDuty 365 handles personal information

Last updated: 25 July 2026. This notice applies to the ClariDuty 365 website, customer workspaces and subscription service operated by Don Reynolds in the United Kingdom.

Information collected

We may process account identity and contact details, organisation and billing details, enquiry records, user roles, authentication identifiers, audit logs, device and security information, and workplace compliance records. Workplace records may include incident descriptions, action ownership, training information, risk assessments, COSHH details, evidence and uploaded documents.

Why it is used

Information is used to provide and secure the service, separate customer workspaces, maintain defensible audit histories, process subscriptions, respond to enquiries, prevent misuse, support customers and meet legal or accounting obligations.

Lawful basis

Depending on the activity, processing may rely on contract, legitimate interests, consent or legal obligation. For customer-uploaded workforce information, the customer determines the lawful basis and normally acts as data controller; ClariDuty 365 processes that information to provide the service.

Customer responsibilities

Customers must ensure they have authority and an appropriate lawful basis to upload personal information, provide required workforce privacy notices, keep records accurate, manage user permissions and avoid entering unnecessary special-category information.

Subprocessors and sharing

Information is not sold. Essential subprocessors may include OpenAI/ChatGPT Sites and underlying hosting infrastructure for application delivery, authentication, databases and storage; Stripe for subscription billing and fraud prevention; and service providers used for security, support or lawful professional advice. Each provider receives only the information reasonably required for its function.

Retention and deletion

Enquiries are retained for reasonable commercial follow-up and record-keeping. Active customer records are retained while the service is provided. Following account termination, access may be restricted while an export is arranged, after which records may be deleted or anonymised subject to statutory, dispute, fraud-prevention, security-log and backup-retention requirements.

International processing and security

Technology providers may process information outside the United Kingdom. Where required, recognised safeguards are used. ClariDuty 365 applies organisation-level separation, authenticated access, role controls, audit logging and secure hosted infrastructure; no online service can guarantee absolute security.

Data export and account termination

Organisation administrators may request an export of their organisation data before termination. Requests are subject to identity, authority and tenant-membership verification so that one organisation cannot obtain another organisation’s records.

Your rights

UK data-protection rights may include access, correction, deletion, restriction, objection and data portability. You may also complain to the Information Commissioner’s Office.

Contact

Use the website’s contact form to submit a privacy request. Identity may need to be verified before information is disclosed or changed.

This is an interim pilot notice and should be reviewed by a qualified UK data-protection professional before large-scale commercial processing.