Privacy notice
This notice covers two different relationships, and the difference matters. When you browse this site or ask for early access, we decide what happens to your data — we are the controller. When your organisation uses ClauseMap and puts records into it, your organisation decides — you are the controller and we are your processor.
Who we are. ClauseMap is built and run by Vasilis Rapanakis — one developer, not a company. Where this notice says "we", it means me.
It exists because organising accreditation evidence, and proving it on demand, is harder than it should be: which document answers which clause, whether it is still current, and where it went. I built it for the people doing that work.
Mail reaches me directly rather than a queue, so the person reading it is the one who can change the code. Questions, or any request about your data: [email protected].
1. When we are the controller
Asking for early access
If you submit the early-access form we store your name, organisation, work email, any standards you tell us you hold, your IP address and browser user-agent, and the date. We use it to reply to you and to set your organisation up.
Our lawful basis is legitimate interests — you asked us to get in touch, and replying is the obvious consequence. The IP address and user-agent are kept for a narrower interest: they are how we tell a real enquiry from automated form spam.
If you also ticked the box for product updates, that separate mailing rests on your consent, and you can withdraw it at any time by replying to any message or emailing us. Withdrawing it does not affect our reply to your original request.
The public demo
The demo at /demo signs you into a shared, read-only account holding invented data for a fictional organisation. You are not asked for anything and no account is created for you. A session cookie is set so the demo works, and a rate-limit counter is kept against your IP address for a short period so that one visitor cannot exhaust the demo for everyone.
This website
We use no analytics, no advertising trackers and no third-party cookies. The only cookies are the ones that make the site function: a session cookie and a CSRF token, both strictly necessary and therefore not requiring consent under PECR.
Fonts are loaded from Google Fonts, which means your browser makes a request to a Google server and Google receives your IP address. If you would rather that did not happen, blocking fonts.googleapis.com changes only the typeface.
Our servers sit behind Cloudflare, which processes connection data (including your IP address) to route traffic and to protect the service from attack.
Server logs
Our hosting keeps standard web-server logs — IP address, time, URL, response code — for security and troubleshooting. We do not use them to build any profile of you.
2. When we are the processor
Everything your organisation enters into ClauseMap — controls, evidence records, uploaded documents, findings, tasks, the names and email addresses of your colleagues — belongs to your organisation. Your organisation decides what goes in and what it is used for. We process it only to provide the service, on your instructions, and we do not use it to train anything, sell it, or look at it except where we have to in order to support or secure the service.
If you are a customer and need a written data processing agreement covering these terms, email [email protected] and we will put one in place before you upload anything.
Each organisation's data is isolated at the database layer, not merely filtered in application code, and uploaded documents are readable only through an authenticated request scoped to the organisation that owns them.
3. Who else sees it
We share personal data only with the suppliers that make the service run. Each acts under contract and none may use it for their own purposes.
| Supplier | What for | Where |
|---|---|---|
| Cloudflare | DNS, TLS and protection from attack | Global edge network |
| Our hosting provider | Application servers and database | United Kingdom / EEA |
| Backblaze B2 | Documents your organisation uploads as evidence | EU (Amsterdam) |
| Our email provider | Sending service email such as password resets and invitations | See supplier terms |
We do not sell personal data, and we do not pass it to anyone for their own marketing. Where a supplier is outside the UK, transfers are covered by the UK International Data Transfer Addendum or an adequacy decision.
4. How long we keep it
- Early-access enquiries — up to 24 months from your last contact with us, then deleted. Sooner if you ask.
- Customer account data — for as long as the organisation has an account, and for 30 days after it closes, after which it is deleted from live systems.
- Backups — a deletion from live systems works through to backups as they expire, within 35 days.
- The activity log — ClauseMap keeps a tamper-evident record of changes made inside an account, because that record is part of what the product is for. It is retained for the life of the account and cannot be edited, by us or by anyone.
- Server logs — up to 90 days.
5. Your rights
Under UK GDPR you can ask us to give you a copy of your personal data, correct it, delete it, restrict or object to how we use it, or provide it in a portable form. Where we rely on consent, you can withdraw it at any time.
Email [email protected] and we will respond within one month. There is no charge.
If your request concerns data your employer holds in ClauseMap, we will pass it to them, because in that case they are the controller and the decision is theirs.
If you think we have handled your data badly, please tell us first so we can put it right. You also have the right to complain to the Information Commissioner's Office.
6. Security
Traffic is encrypted in transit. Passwords are stored hashed with bcrypt and are not recoverable by us. Each organisation's records are separated at the database layer by row-level security, and uploaded documents are stored outside the public web root and served only to an authenticated member of the organisation that owns them. Changes inside an account are written to an append-only, hash-chained log that rejects edits and deletions at the database level.
No system is perfectly secure. If you believe you have found a vulnerability, please email [email protected] and give us a reasonable chance to fix it before disclosing it. We will not pursue anyone who reports in good faith.
7. Children
ClauseMap is a tool for accredited laboratories and proficiency testing providers. It is not intended for anyone under 18 and we do not knowingly collect their data.
8. Changes
If we change this notice we will update the date at the top. If a change materially affects how we handle your data, we will tell affected customers by email rather than relying on you to re-read this page.