Service: ClueCheck privacy governance and responsible operations
Effective date: 26 August 2026
Applies to: website visitors, Clients, Shoppers, applicants, authorised portal users, Staff and suppliers
1. Purpose and accountability
This page explains the operational controls that support our Privacy Policy. For each Client project, ClueCheck records whether it acts as a controller, processor, joint controller or independent controller for each relevant data flow. The project record should identify the purpose, lawful basis, approved suppliers, retention period, deletion instruction and incident contacts.
2. Requests and concerns
Use the contact route in your portal or email contact@cluecheck.co.uk. Use the subject line Data Protection Request for access, correction, deletion, restriction, objection or portability requests. We may verify identity before responding. Operational complaints and data protection requests are recorded and assessed separately.
- Report or evidence appeal: request correction of inaccurate profile information, report content or evidence attribution.
- Safety or discrimination concern: report unsafe instructions, discriminatory criteria, retaliation, coercion or inappropriate evidence requests.
- Security incident: report unauthorised access, misdirected files, exposed links or lost devices promptly. Do not include passwords in the first message.
3. Data lifecycle controls
| Stage | Control |
|---|---|
| Collection | Collect only information needed for the stated assignment, account, payment, safety or support purpose. Optional marketing is separate from service communications. |
| Location | Explain why location and accuracy are requested before check-in, minimise precision and provide a reasonable manual alternative where appropriate. |
| Evidence | Restrict access by role, avoid unnecessary third-party data, redact irrelevant personal information and document purpose and retention for photos, receipts, recordings and reports. |
| Retention | Delete or anonymise data when the documented purpose and lawful retention period end. Legal, accounting, fraud-prevention or dispute holds must be limited and explained. |
| Access | Use individual accounts, role-based access and MFA where available. Review material access, export, approval and deletion events. |
4. Suppliers, transfers and higher-risk processing
Payment, email, communications, geolocation, storage and other specialist suppliers may be used for particular features. The applicable notice or Client documentation should identify the supplier category, purpose, processing location, transfer safeguard and deletion setting. Before routine use of precise location, systematic monitoring, extensive evidence processing, matching or sensitive assignments, the responsible team should assess necessity, proportionality, alternatives and impact; a Data Protection Impact Assessment may be required.
5. Matching, monitoring and human review
Where profiles, quality records, assignment history or other information affect access to opportunities, payment or reputation, ClueCheck should explain the relevant factors and provide a route to correct inaccurate information or challenge a decision. Material decisions should receive appropriate human review and should not rely solely on an opaque automated result.
6. Incident response and continuous review
Suspected incidents are contained, logged, investigated and assessed for notification obligations. Governance controls, supplier arrangements, access permissions, retention schedules and public notices are reviewed when the service or processing changes. This page describes operational commitments; it does not replace a project-specific notice, contract, DPA, DPIA or professional legal advice.
Related information: Governance Centre · Privacy Policy · Cookie Policy · Terms & Conditions · Contact ClueCheck