How we handle your personal data
This policy covers personal data we hold as a data controller: about visitors to this site, prospects who request a Data Health Score, and our clients' contacts. Candidate data we process on a client's behalf is covered separately by our Data Processing Agreement (section 04), where the client is the controller and we act as processor.
What we collect
- Details you submit through the diagnostic form: your name, agency, work email, ATS, and database size band.
- Correspondence when you email or reply to us.
- Basic technical logs (IP address, browser, timestamps) kept for security and to run the site.
Why we hold it, and our lawful basis
- Legitimate interests: to respond to your enquiry, produce and send your Data Health Score, and keep the site secure.
- Contract: to deliver services once you become a client.
- Consent: for any optional marketing, which you can withdraw at any time.
- Legal obligation: for accounting and tax records.
Who we share it with
We do not sell, rent, or broker your data. We share it only with vetted service providers that help us operate (hosting, email, and analytics) under written contracts, and where the law requires. Our current sub-processors are listed in section 04.
Where it's processed & how long we keep it
Processing takes place in the UK. Where a provider processes data outside the UK, we rely on an approved transfer mechanism (UK adequacy or the International Data Transfer Agreement). We keep enquiry data for up to 24 months after last contact, client records for the duration of the engagement plus 6 years for legal and accounting purposes, then delete or anonymise it.
Your rights
Under UK GDPR you can ask us to give you a copy of your data, correct it, delete it, restrict or object to its use, or receive it in a portable form. Email hello@clearsystemsiq.co.uk and we'll respond within one month. If you're unhappy with how we've handled your data, you can complain to the Information Commissioner's Office (ICO) at ico.org.uk, though we'd appreciate the chance to put it right first.
Terms of using this website
These terms govern your use of this website. They are not the contract for our services; paid engagements are governed by a separate services agreement signed with each client.
- Ownership. The site, its content, and the ClearSystemsIQ name and marks are owned by ClearSystems IQ Ltd. You may view and share pages, but not copy or reuse content commercially without permission.
- Acceptable use. Don't attempt to disrupt, probe, or gain unauthorised access to the site, and don't submit false information through our forms.
- The free Data Health Score. It is provided in good faith as an assessment tool. It's an estimate based on the data you supply, not a warranty, audit certificate, or guarantee of any outcome.
- No warranty. Site content is provided "as is". We work to keep it accurate and available but don't guarantee it will be error-free or uninterrupted.
- Liability. To the extent the law allows, we're not liable for indirect or consequential loss arising from use of the website. Nothing here limits liability that cannot be limited by law.
- Changes. We may update these terms; the current version always lives on this page.
These terms and any dispute relating to them are governed by the law of England & Wales, subject to the exclusive jurisdiction of its courts.
When we process candidate data for you
This is a plain-language summary. A full DPA meeting Article 28 of the UK GDPR is executed with every client before we touch any live data. In it:
- Roles. You are the data controller; ClearSystems IQ Ltd is your processor. We process candidate data only on your documented instructions, never as a data broker for our own ends.
- Scope. Subject matter is CRM data cleaning and enrichment; data subjects are your candidates and contacts; categories are contact details, CV/employment history, and derived fields such as normalised title, seniority, and location.
- Our obligations. Confidentiality, appropriate security (section 05), assisting you with data subject requests and breach reporting, and deleting or returning all data on termination.
- Sub-processors. We use them only with your authorisation, under equivalent terms, and we keep a current list. Present sub-processors: website hosting Netlify · US/EU, form processing and email delivery Formspree · US, and bot protection Google reCAPTCHA · US. We give notice before adding or replacing any of them.
- Audit. You may audit our compliance on reasonable notice, and we'll provide the information you need to demonstrate it.
Request the full DPA at hello@clearsystemsiq.co.uk.
How we keep your data safe
- UK processing. Data is processed and stored in the UK. Any exception is disclosed and covered by an approved transfer mechanism.
- Encryption. Data is encrypted in transit (TLS) and at rest.
- Least-privilege access. Only the engineer working your account has access, on credentials you control and can revoke at any time. Nothing leaves your instance without your authorisation.
- No training on your data. Your data is never used to train models, and is not reused across clients.
- Retention & exit. We hold data only as long as needed for the work. On exit you receive a full export and we delete our copies to schedule.
- Breach response. If a personal-data breach occurs, we notify affected clients without undue delay and support any ICO reporting within the statutory 72 hours.
- Backups & testing. Backups are encrypted and access-controlled; we review our controls regularly.
To report a security concern, email hello@clearsystemsiq.co.uk.
Who you're dealing with
Complaints
Email us first and we'll acknowledge within 5 working days. For data-protection complaints you may also contact the ICO at ico.org.uk or 0303 123 1113.
Accessibility
We aim to meet WCAG 2.1 AA. If any part of this site is hard to use, tell us at hello@clearsystemsiq.co.uk and we'll help and fix it.