CLRD is operated by CLRD Technologies Ltd, a company registered in England and Wales (company number 16970508) with its registered office at 6B Wyndham Road, Poole, BH14 8SH, United Kingdom. We are the data controller for personal data we hold about you in connection with your CLRD account.
This policy explains how we collect, use, and protect your personal data when you use our service at clrd.app. To contact us about privacy, please use our contact form.
We collect the following information:
We use your data to:
We do not sell your data or use it for advertising.
We process your data under the following legal bases (UK GDPR):
We share data with the following service providers, who act as our data processors under written contracts no less protective than this policy and our Data Processing Agreement:
We do not share your data with any other third parties unless required by law (for example, to respond to a lawful request from a regulator or court).
We retain your account and job data for as long as your account is active. Generated documents, the associated audit trail, and DNO correspondence associated with a job are immutable once a job is audit-locked and are retained indefinitely as evidence of regulatory compliance, even after your account is closed, unless deletion is required by law.
If you close your account (or ask us to close it), we will remove personal data not subject to the compliance-record exception within 30 days. Backup copies are overwritten in the ordinary course of operation within 90 days.
Personal data is stored and processed within the United Kingdom and the European Economic Area. Some of our service providers (for example Google and Stripe) may process limited data outside the UK/EEA; where they do, the transfer is protected by safeguards recognised under Chapter V UK GDPR, such as the UK Extension to the EU–US Data Privacy Framework or the ICO's International Data Transfer Agreement/Addendum.
We protect your data with encryption in transit, encrypted backups, server-side session management, and access controls. Authentication uses secure password hashing.
We do not make decisions about you based solely on automated processing that produce legal or similarly significant effects. The Service applies a deterministic compliance rules engine to data you enter to generate documentation, but the resulting documents are reviewed and submitted by you, and any decision about regulatory submission rests with you. New accounts are checked automatically against the MCS installer register to enable job creation; where no match is found, the account is reviewed by a person rather than refused automatically.
The Service is intended for use by professional installers and is not directed at children. We do not knowingly collect personal data from anyone under the age of 16.
Under UK GDPR, you have the right to:
To exercise these rights, please use our contact form.
We use a single cookie to maintain your logged-in session. No personal information is stored in the cookie itself — it contains only an opaque session identifier. We do not use tracking, analytics, or third-party advertising cookies.
When you interact with billing (provided by Stripe), choose to sign in with Google, or open the Site Boundary Map editor (which loads Google Maps), those providers may set their own cookies or receive requests from your browser to complete those flows. Stripe and Google act as independent data controllers for any such cookies — please refer to their respective privacy policies for details.
If you use the Service to process personal data of your own customers, our Data Processing Agreement applies and forms part of your agreement with us. Under the DPA, you are the data controller for that data and CLRD is the data processor.
We may update this policy from time to time. We will notify you of significant changes by email or through the Service.
For privacy-related questions or to exercise your data rights, please use our contact form.