Service: ClueCheck governance centre
Effective date: 26 August 2026
Applies to: Clients, Shoppers, applicants, authorised portal users, Staff and suppliers

Purpose: This centre explains the controls ClueCheck uses to turn privacy, safety and accountability commitments into repeatable operational steps. Project-specific notices, contracts, DPAs and DPIAs take priority where they apply.

1. Governance framework

Every new Client project should record the purpose and lawful basis for each material data flow, the parties' controller or processor roles, the approved suppliers, the retention instruction, the responsible owner and the incident contact. A project should not collect additional staff, customer, health, identity or location data merely because a portal field exists.

DecisionRequired record
RoleController, processor, joint controller or independent controller, with named parties and written instructions.
PurposeSpecific business purpose, data categories, lawful basis, recipients and whether fields are mandatory or optional.
RiskNecessity, proportionality, alternatives, access controls, retention and DPIA decision.
OwnershipAccountable owner, review date, deletion owner, incident contact and escalation route.

2. Data rights and appeals

People may request access, correction, deletion, restriction, objection or portability through the route described in the Privacy Policy. Shoppers and Clients may also challenge inaccurate profile information, report content, evidence attribution, rejection, payment holds or unsafe instructions. Each request should receive an acknowledgement, an owner, a target response date and an escalation route.

3. Retention and deletion

ClueCheck maintains a working retention schedule by data category rather than a single blanket period. Data should be deleted or anonymised when the purpose and approved retention period end, unless a documented legal, accounting, fraud-prevention, security or dispute hold applies. See the Retention & Records Standard.

4. Suppliers and higher-risk processing

Supplier categories, processing locations, international-transfer safeguards and deletion settings should be recorded before a feature is used in a Client project. Precise location, systematic monitoring, extensive evidence processing, matching or sensitive assignments should receive a documented risk assessment and, where required, a DPIA. See Suppliers & Transfers and Risk Assessments & DPIA.

5. Incidents and continuous review

Suspected personal-data or security incidents should be reported promptly, contained, logged, investigated and assessed for notification obligations. Access permissions, suppliers, retention schedules, notices and portal workflows should be reviewed when processing changes. See the Incident Response Standard.

Related information: Privacy Governance · Privacy Policy · Terms & Conditions · Contact ClueCheck