This document is available in English only. The English version is the legally binding one.

Privacy Policy

Last updated: 1 September 2026

This policy explains what personal data Clarity collects, why, and what rights you
have. Clarity is the quality-management workspace at
clarityqms.com, operated by Eventya (“we”, “us”), a
company registered in Romania.

We keep this short and specific. If something here does not answer your question,
write to privacy@clarityqms.com.


1. Two different roles

Clarity is a business tool sold to organisations, and that splits our
responsibilities in two:

We are the controller for the data we need in order to run the business: the
account and billing record of a subscribing organisation, the login identity of the
people who use it, security and service logs, and our correspondence with you.

We are a processor for everything inside a workspace — documents, procedures,
records, audits, non-conformities, projects, parties, contacts, uploaded files,
comments. That content belongs to the organisation whose workspace it is; that
organisation decides what goes in and why, and is the controller of any personal
data it contains. We process it on their instructions, which are given through
their use of the product and through our agreement with them. A data processing
agreement under Article 28 GDPR is available on request.

If you are an employee of a customer and want to know why your employer put
something about you into Clarity, ask your employer — we cannot answer that for
them, and in most cases we cannot act on your request without their instruction.

2. What we collect

Account and billing data. Organisation name, workspace address (slug), country,
the identity of the administrator, plan and subscription status, invoices, and the
billing contact. Card details are entered directly with Stripe and never reach our
servers; we store only the last four digits, card brand and expiry as returned by
Stripe.

User profile data. First and last name, work email address, job title, role in
the workspace, interface language, avatar if you upload one, and the timestamp of
your last activity.

Authentication data. Clarity signs you in with one-time codes sent to your email
address — there is no stored password. We keep the code (short-lived), the session
record, and the fact and time of sign-in.

Workspace content. Whatever your organisation puts in: document text and
revisions, approvals and acknowledgements with the name and timestamp of the person
who gave them, comments, audit findings and corrective actions, party and contact
records, offers and contracts, and any files uploaded as attachments.

Activity and audit trail. Clarity is a quality-management tool, so it keeps a
record of who changed what and when across the entities it manages. This is a core
feature, not analytics — it exists so that a document’s history is defensible in an
audit.

Technical logs. Server logs of requests, including IP address, user agent,
timestamp and the URL requested, and error reports. These are used for security,
abuse prevention and debugging.

We do not run advertising trackers, analytics scripts, session recording, or
third-party marketing pixels in the application.

Purpose Data Legal basis (GDPR Art. 6)
Providing the Service to a subscribing organisation account, profile, workspace content performance of a contract (b), or legitimate interest for the customer’s employees (f)
Signing you in and keeping the session secure authentication data contract (b)
Billing, invoicing, dunning account, billing data contract (b) and legal obligation (c)
Transactional email — invitations, approval requests, reminders, notifications name, email, related record contract (b)
Security, abuse prevention, debugging, backups technical logs, account data legitimate interest (f)
Keeping accounting records invoices, billing data legal obligation (c)
Answering support requests your message and contact details contract (b) / legitimate interest (f)

We do not use your data for automated decision-making that produces legal effects,
and we do not profile you.

4. Cookies and local storage

Clarity uses the minimum a logged-in application needs:

There are no advertising or analytics cookies, so there is no consent banner to
click through.

One note of transparency: the public marketing page loads a web font from Google
Fonts, which means Google receives the IP address of visitors to that page. Signed-in
application pages do not depend on it.

5. Who we share data with

We do not sell personal data and we do not share it for advertising. We use a small
set of subprocessors to run the Service:

Subprocessor Purpose Location
DigitalOcean Application and database hosting, backups Frankfurt, Germany (EU)
Twilio SendGrid Transactional email delivery United States
Stripe Subscription billing and payment processing United States / Ireland

We may also disclose data to professional advisers under confidentiality, to a
successor in the event of a merger or sale of the business (you would be told
beforehand), and to authorities where we are legally required to — in which case, if
the request concerns a customer’s workspace and the law allows it, we will notify the
customer first.

We will give notice before adding or replacing a subprocessor, so that customers can
object.

6. Where data is stored, and transfers

Application data and database backups are hosted in the European Union
(Frankfurt)
.

Email delivery and payment processing involve transfers to the United States. Those
transfers are covered by the European Commission’s Standard Contractual Clauses and,
where the provider is certified, the EU–US Data Privacy Framework. Only what those
services need crosses the border: an email address and message content for delivery,
and billing identifiers for payments. Workspace documents and files do not.

7. How long we keep it

8. Security

No system is perfectly secure. If we become aware of a personal data breach
affecting you, we will notify the supervisory authority within 72 hours where
required, and notify affected customers without undue delay.

9. Your rights

Under the GDPR you have the right to access your personal data, to have it
corrected, to have it erased, to restrict or object to processing, to receive it in
a portable format, and to withdraw consent where processing is based on consent.

For data where we are the controller (your account, your login identity, billing,
our correspondence), write to privacy@clarityqms.com. We reply within one month and
may ask for information to verify who you are.

For data inside a workspace, the controller is the organisation that owns it.
Send your request to them; if you send it to us, we will forward it and assist them,
but we will not act on their data without instruction.

You can also complain to a supervisory authority. In Romania that is ANSPDCP
dataprotection.ro, Bd. G-ral. Gheorghe Magheru
28-30, Bucharest.

10. Children

Clarity is a workplace tool. It is not directed at children and we do not knowingly
collect data from anyone under 16. If you believe a child’s data has reached us,
write to privacy@clarityqms.com and we will delete it.

11. Changes to this policy

We will update this page when our processing changes. Material changes are announced
by email to Account Administrators or in the application at least 30 days before they
take effect. The date at the top always reflects the current version.

12. Contact

Eventyaeventya.net

To complete before publishing: registered office address, trade register
number (J…), VAT/CUI, and — if one has been appointed — the contact details of the
data protection officer.