Privacy Policy
Last updated: 1 September 2026
This policy explains what personal data Clarity collects, why, and what rights you
have. Clarity is the quality-management workspace at
clarityqms.com, operated by Eventya (“we”, “us”), a
company registered in Romania.
We keep this short and specific. If something here does not answer your question,
write to privacy@clarityqms.com.
1. Two different roles
Clarity is a business tool sold to organisations, and that splits our
responsibilities in two:
We are the controller for the data we need in order to run the business: the
account and billing record of a subscribing organisation, the login identity of the
people who use it, security and service logs, and our correspondence with you.
We are a processor for everything inside a workspace — documents, procedures,
records, audits, non-conformities, projects, parties, contacts, uploaded files,
comments. That content belongs to the organisation whose workspace it is; that
organisation decides what goes in and why, and is the controller of any personal
data it contains. We process it on their instructions, which are given through
their use of the product and through our agreement with them. A data processing
agreement under Article 28 GDPR is available on request.
If you are an employee of a customer and want to know why your employer put
something about you into Clarity, ask your employer — we cannot answer that for
them, and in most cases we cannot act on your request without their instruction.
2. What we collect
Account and billing data. Organisation name, workspace address (slug), country,
the identity of the administrator, plan and subscription status, invoices, and the
billing contact. Card details are entered directly with Stripe and never reach our
servers; we store only the last four digits, card brand and expiry as returned by
Stripe.
User profile data. First and last name, work email address, job title, role in
the workspace, interface language, avatar if you upload one, and the timestamp of
your last activity.
Authentication data. Clarity signs you in with one-time codes sent to your email
address — there is no stored password. We keep the code (short-lived), the session
record, and the fact and time of sign-in.
Workspace content. Whatever your organisation puts in: document text and
revisions, approvals and acknowledgements with the name and timestamp of the person
who gave them, comments, audit findings and corrective actions, party and contact
records, offers and contracts, and any files uploaded as attachments.
Activity and audit trail. Clarity is a quality-management tool, so it keeps a
record of who changed what and when across the entities it manages. This is a core
feature, not analytics — it exists so that a document’s history is defensible in an
audit.
Technical logs. Server logs of requests, including IP address, user agent,
timestamp and the URL requested, and error reports. These are used for security,
abuse prevention and debugging.
We do not run advertising trackers, analytics scripts, session recording, or
third-party marketing pixels in the application.
3. Why we process it, and on what legal basis
| Purpose | Data | Legal basis (GDPR Art. 6) |
|---|---|---|
| Providing the Service to a subscribing organisation | account, profile, workspace content | performance of a contract (b), or legitimate interest for the customer’s employees (f) |
| Signing you in and keeping the session secure | authentication data | contract (b) |
| Billing, invoicing, dunning | account, billing data | contract (b) and legal obligation (c) |
| Transactional email — invitations, approval requests, reminders, notifications | name, email, related record | contract (b) |
| Security, abuse prevention, debugging, backups | technical logs, account data | legitimate interest (f) |
| Keeping accounting records | invoices, billing data | legal obligation (c) |
| Answering support requests | your message and contact details | contract (b) / legitimate interest (f) |
We do not use your data for automated decision-making that produces legal effects,
and we do not profile you.
4. Cookies and local storage
Clarity uses the minimum a logged-in application needs:
- Session cookie — strictly necessary, keeps you signed in. HTTP-only, secure,
same-site. - CSRF token — strictly necessary, protects forms against cross-site request
forgery. - Local storage — remembers your theme (light/dark) and a few interface
preferences such as list vs. board view. This never leaves your browser.
There are no advertising or analytics cookies, so there is no consent banner to
click through.
One note of transparency: the public marketing page loads a web font from Google
Fonts, which means Google receives the IP address of visitors to that page. Signed-in
application pages do not depend on it.
5. Who we share data with
We do not sell personal data and we do not share it for advertising. We use a small
set of subprocessors to run the Service:
| Subprocessor | Purpose | Location |
|---|---|---|
| DigitalOcean | Application and database hosting, backups | Frankfurt, Germany (EU) |
| Twilio SendGrid | Transactional email delivery | United States |
| Stripe | Subscription billing and payment processing | United States / Ireland |
We may also disclose data to professional advisers under confidentiality, to a
successor in the event of a merger or sale of the business (you would be told
beforehand), and to authorities where we are legally required to — in which case, if
the request concerns a customer’s workspace and the law allows it, we will notify the
customer first.
We will give notice before adding or replacing a subprocessor, so that customers can
object.
6. Where data is stored, and transfers
Application data and database backups are hosted in the European Union
(Frankfurt).
Email delivery and payment processing involve transfers to the United States. Those
transfers are covered by the European Commission’s Standard Contractual Clauses and,
where the provider is certified, the EU–US Data Privacy Framework. Only what those
services need crosses the border: an email address and message content for delivery,
and billing identifiers for payments. Workspace documents and files do not.
7. How long we keep it
- Workspace content — for as long as the Account is active. After an Account is
closed, it stays available for export for 30 days, then is deleted from active
systems. - Encrypted backups — rolling retention of up to 35 days, after which
deleted data disappears from backups too. - User profile — until the User is removed from the workspace or the Account is
closed. Audit-trail entries keep the name of the person who acted, because
removing it would break the integrity of the quality record. - Authentication codes — minutes; sessions expire after a period of inactivity.
- Technical logs — up to 90 days, unless retained longer for an
investigation. - Invoices and accounting records — 10 years, as Romanian accounting law
requires.
8. Security
- All traffic is served over TLS; the certificate is renewed automatically.
- Data at rest sits on encrypted volumes; backups are encrypted.
- Passwordless sign-in removes the largest single source of credential compromise.
- Every Account is isolated: queries are scoped to the workspace, and permissions
are enforced by role on the server, not just hidden in the interface. - Access to production by our staff is limited to the people who need it to operate
the Service, and is logged. - We patch dependencies and the runtime on a regular cycle.
No system is perfectly secure. If we become aware of a personal data breach
affecting you, we will notify the supervisory authority within 72 hours where
required, and notify affected customers without undue delay.
9. Your rights
Under the GDPR you have the right to access your personal data, to have it
corrected, to have it erased, to restrict or object to processing, to receive it in
a portable format, and to withdraw consent where processing is based on consent.
For data where we are the controller (your account, your login identity, billing,
our correspondence), write to privacy@clarityqms.com. We reply within one month and
may ask for information to verify who you are.
For data inside a workspace, the controller is the organisation that owns it.
Send your request to them; if you send it to us, we will forward it and assist them,
but we will not act on their data without instruction.
You can also complain to a supervisory authority. In Romania that is ANSPDCP —
dataprotection.ro, Bd. G-ral. Gheorghe Magheru
28-30, Bucharest.
10. Children
Clarity is a workplace tool. It is not directed at children and we do not knowingly
collect data from anyone under 16. If you believe a child’s data has reached us,
write to privacy@clarityqms.com and we will delete it.
11. Changes to this policy
We will update this page when our processing changes. Material changes are announced
by email to Account Administrators or in the application at least 30 days before they
take effect. The date at the top always reflects the current version.
12. Contact
Eventya — eventya.net
- Privacy and data protection: privacy@clarityqms.com
- Security reports: security@clarityqms.com
- General support: support@clarityqms.com
To complete before publishing: registered office address, trade register
number (J…), VAT/CUI, and — if one has been appointed — the contact details of the
data protection officer.