Skip to content
CLARITY

Privacy notice

Last updated 8 August 2026 · version 2026-08-launch-v1

This notice explains what personal data Clarity Transaction Intelligence Ltd collects, why we collect it, and what you can do about it. It is written to be read, not to be impenetrable — if anything here is unclear, email us and we will explain it plainly.

Who we are

Clarity Intelligence is operated by Clarity Transaction Intelligence Ltd, company number 17397299, registered in England and Wales. Registered office: 71–75 Shelton Street, Covent Garden, London, WC2H 9JQ. This company is not registered for VAT, so no VAT is charged.

Clarity Transaction Intelligence Ltd is the data controller for the personal data described in this notice.

What we collect, and why

We collect the following:

  • Scorecard answers. Your responses to the free Exit-Ready Scorecard, including your role, turnover band and timeline. Used to calculate and show your result.
  • Contact details. Your email address, and optionally your name and company, when you ask us to send you your result. Used to send that result and, with your consent, our follow-up series.
  • Account and sign-in information. If you create a Clarity Intelligence account: your email, authentication identifiers, and security information such as whether two-factor authentication is enabled and when you signed in.
  • Business records. The business you are associated with, its name and sector, and which people are authorised to see it. Used to keep one business’s information separate from another’s.
  • Assessment answers. Your answers to the Exit-Readiness Review or the Business Health Review, including any free-text notes, the scores calculated from them, the findings triggered, and the report produced. Kept so you can return to them and compare later assessments.
  • Order records. What you bought, when, and for how much, together with the payment references. Card details are handled entirely by Stripe and never reach our systems.
  • Referral attribution. If a professional organisation introduced you, which organisation that was. This is used only to measure where customers come from. It gives that organisation no access to your account, answers or report.
  • Security and audit records. Sign-in events, errors and records of privileged administrative access, kept to secure the service and investigate incidents.
  • Engagement records. If you become a client, the information you share with us during the engagement.

Our lawful basis

  • Consent — for marketing emails. You give it by ticking the box; you can withdraw it at any time and we act on that immediately.
  • Contract — for delivering anything you have paid for, and for the records that go with it.
  • Legal obligation — for keeping financial records for the period the law requires.
  • Legitimate interests — for running and securing the site, and for responding to you when you contact us directly. We have weighed this against your rights and consider it proportionate.

Marketing emails

If you consent, we send you your scorecard result followed by a short series about what buyers test in diligence, and then an occasional monthly note. Every message carries a one-click unsubscribe link.

When you unsubscribe, your address goes onto a suppression list which is checked before every send. That is deliberate: it means we cannot accidentally email you again even if you later fill in another form.

Who we share it with

We do not sell your data, and we do not share it for anyone else’s marketing. We use a small number of processors to run the service:

  • Supabase — database and authentication hosting
  • Vercel — website hosting
  • Stripe — payment processing
  • Resend — sending email

Each acts only on our instructions. Some of these providers may process personal data outside the UK. Where that happens, we will use appropriate safeguards where required by applicable data protection law.

How long we keep it

  • Scorecard submissions and leads — kept only for as long as reasonably necessary for the purposes described above, taking account of legal, accounting, regulatory and dispute-resolution requirements.
  • Suppression list entries — kept indefinitely. This is the only way to guarantee we never email you again.
  • Assessments, reports, client and engagement records — kept only for as long as reasonably necessary for the purposes described above, taking account of legal, accounting, regulatory and dispute-resolution requirements.
  • Financial records — six years, as required by HMRC.

Your rights

Under UK GDPR you have the right to:

  • ask for a copy of the personal data we hold about you
  • have inaccurate data corrected
  • have your data deleted, where no legal obligation requires us to keep it
  • restrict or object to how we use it
  • receive your data in a portable format
  • withdraw consent at any time

Email louis@clarityadvisorypartners.com and we will respond within one month. If you are unhappy with how we have handled it, you can complain to the Information Commissioner’s Office at ico.org.uk.

Security

Data is encrypted in transit and at rest. Access is restricted to the people who need it, internal accounts support multi-factor authentication, and administrative actions are logged. Payment card details never touch our servers — Stripe handles them directly.

No system is perfect. If we ever suffer a breach that puts your rights at risk, we will tell you and the ICO within the timescales the law requires.

Changes to this notice

If we change this notice materially we will update the date at the top and, where the change affects how we use data you have already given us, tell you directly.