Privacy Policy
Effective date: 8 August 2026
This Privacy Policy describes how FieldClear Ltd (“we”, “us”, “our”) collects, uses, discloses and safeguards information when you use FieldClear websites, applications and related services (the “Service”). By using the Service, you acknowledge this Policy. If you do not agree, do not use the Service.
1. Who we are
FieldClear Ltd operates fieldclear.co.uk. For questions about this Policy or personal data we hold, contact hello@fieldclear.co.uk.
2. Roles and scope
For account, billing, marketing (where permitted) and platform operation data, we act as a controller under UK GDPR. For workforce records, certificate files, requirement assignments and other materials you or your organisation upload or generate through the Service (“Customer Content”), we generally act as a processor on your instructions. You are the controller of Customer Content and are responsible for providing any required notices and obtaining any required consents from your workers, employees, subcontractors and other individuals whose data you submit.
The Service is designed for business customers. Organisation administrators control much of the data in a workspace.
3. Information we collect
- Account and profile data: name, work email, authentication credentials (stored hashed), organisation name, role assignments and preferences you provide.
- Customer Content: worker names and identifiers you enter, roles, employment types, qualifications, expiry dates, certificate and evidence files, notes, audit events and related workflow records.
- Billing data: subscription status, plan selections and payment-related identifiers processed by our payment provider. We do not store full payment card numbers on our servers.
- Technical and usage data: IP address, device and browser type, log files, timestamps, pages viewed, feature usage, error reports and security signals.
- Marketing attribution: UTM tags and similar click identifiers, where configured, so we can understand which marketing works.
- Communications: support requests, feedback and messages you send to us.
- Information from third parties: identity and fraud prevention, email delivery, analytics, hosting and integration partners, as configured for the Service.
4. How we use information
We use information to:
- provide, operate, maintain, secure and improve the Service (contract / legitimate interests);
- authenticate users, enforce access controls and prevent abuse (contract / legitimate interests);
- process transactions and manage subscriptions (contract / legal obligation);
- send transactional, security and service-related communications (contract / legitimate interests);
- generate logs, audit trails and operational metrics (legitimate interests);
- create anonymised or aggregated statistics that we may retain and use for lawful product and commercial purposes (legitimate interests);
- send product updates and marketing to business contacts where permitted (legitimate interests or consent where required);
- comply with law, respond to lawful requests and protect rights and safety (legal obligation / legitimate interests).
We do not sell personal information. We do not use Customer Content to train generalised public machine-learning models unless you separately opt in to a feature that expressly states otherwise.
5. How we share information
We may share information with:
- Service providers and subprocessors that host infrastructure, deliver email, process payments, provide analytics or otherwise support the Service under contractual confidentiality and security obligations;
- Your organisation and authorised users according to your workspace permissions;
- Professional advisers, auditors and potential transaction parties under confidentiality obligations;
- Law enforcement or regulators when required by law or when we believe disclosure is necessary to protect rights, safety or the integrity of the Service.
We may also share aggregated or de-identified information that cannot reasonably identify you. We may disclose information to defend legal claims.
6. International transfers
We aim to host Customer Content in the UK and/or EEA where practicable. Personal data may nonetheless be processed in other countries where our providers operate. Where required, we implement appropriate safeguards for restricted transfers (such as UK International Data Transfer Agreements or equivalent mechanisms).
7. Retention
We retain account data for the life of the account and thereafter as needed for billing disputes, tax, fraud prevention and legal claims — typically up to seven (7) years for transactional records, longer where required by law. After cancellation, Customer Content is retained for a limited period so you can export or reactivate, then deleted from live systems subject to backups and legal holds. Backups may persist for a limited period after deletion from live systems. Anonymised and aggregated datasets are retained indefinitely and are not subject to erasure.
8. Security
We implement administrative, technical and organisational measures designed to protect information, including encryption in transit and at rest, organisation isolation, and access controls. However, no method of transmission or storage is completely secure. You are responsible for safeguarding credentials and configuring access within your organisation appropriately. You use the Service at your own risk regarding residual security risk.
We describe our practices rather than claiming certifications we do not hold. If we obtain a formal certification, we will name it here when it is verifiable.
9. Your rights and choices
Where UK GDPR applies, you may have rights to access, rectify, erase, restrict or object to certain processing, to data portability, and to withdraw consent where processing is consent-based. You may complain to the Information Commissioner's Office (ICO) at ico.org.uk. These rights are not absolute and may be refused or limited where exemptions apply (including legal claims, and where we cannot verify identity or authority). Organisation administrators may need to action requests that relate to Customer Content we process on your organisation's behalf.
10. How to request deletion
Deletion requests must be sent by email to hello@fieldclear.co.uk with the subject line exactly: Data deletion request.
Your email must include all of the following or it may be rejected as incomplete:
- Full legal name of the individual making the request;
- Account email address;
- Organisation / company name on the account;
- Account or organisation ID if known;
- Clear statement of what you want deleted;
- Proof of identity and, for company accounts, written authority confirming you may act for the organisation;
- Confirmation you understand that account deletion does not entitle you to any refund of fees paid.
We will verify identity and authority before acting. Incomplete, unverifiable or frivolous requests may be refused. Where UK GDPR requires a response, we aim to respond within the applicable statutory period after we have received a complete, verified request (time spent clarifying or verifying does not count as undue delay). We may extend time where requests are complex.
We may refuse or limit erasure where we need to retain data for:
- Legal, tax, accounting or regulatory obligations;
- Billing, chargeback and fraud prevention;
- Establishing, exercising or defending legal claims;
- Security logs for a proportionate period;
- Anonymised or aggregated data that is no longer personal data;
- Backups until they naturally rotate off;
- Customer Content we process solely as processor, where your organisation remains the controller and must instruct deletion through the product or as controller.
11. Cookies and similar technologies
We use cookies, local storage and similar technologies as described in our Cookie Policy. Disabling some cookies may impair login or core functionality.
12. Children
The Service is not directed to individuals under 18, and we do not knowingly collect personal information from children. If you believe a child has provided information, contact us and we will take appropriate steps.
13. Third-party sites and integrations
The Service may link to or integrate with third-party services. Their privacy practices are governed by their own policies. We are not responsible for third-party practices.
14. Changes to this Policy
We may update this Policy from time to time. Material changes will be posted on this page with an updated effective date and may also be notified to account holders by email where appropriate. Continued use after changes become effective constitutes acceptance of the revised Policy.
15. Related documents
Use of the Service is also governed by our Terms of Service and Refund Policy.
16. Contact
Privacy questions or requests: hello@fieldclear.co.uk.
This Policy is provided for operational transparency. It is not legal advice. Consider independent counsel review for your jurisdiction and use case.