CLEAR·OCEAN← Back to home

Privacy Policy

Effective date: [DATE] · Version 1.0

This Privacy Policy explains how [COMPANY LEGAL NAME] ("ClearOcean", "we", "us") collects, uses, discloses, and protects personal information when you use our websites, applications, and email services (the "Service"), and the rights you have. It applies to information we control as a data controller / business.

⚠ DRAFT FOR LEGAL REVIEW. Professional template, not legal advice. Must be reviewed and tailored to your actual data practices, vendors, and jurisdictions (incl. GDPR/UK GDPR, CCPA/CPRA, and any others) by qualified counsel before use.

Contents

  1. Who we are
  2. Information we collect
  3. How we use information
  4. Legal bases (EEA/UK)
  5. Cookies & tracking
  6. How we share information
  7. Email & marketing
  8. Data retention
  9. Security
  10. International transfers
  11. Your rights (EEA/UK)
  12. Your rights (California)
  13. Children's privacy
  14. Third-party links
  15. Changes
  16. Contact

01 Who we are

The data controller / business responsible for your personal information is [COMPANY LEGAL NAME], [registered address]. For privacy questions or to exercise your rights, contact privacy@DOMAIN. [If applicable, our EU/UK representative or Data Protection Officer is: [NAME / CONTACT].]

02 Information we collect

(a) Information you provide

Account and contact details (name, email, password), billing information (processed by our payment processor — we do not store full card numbers), communications you send us, and any preferences you set.

(b) Information collected automatically

Device and usage data such as IP address, browser and device type, pages viewed, links clicked, referring pages, timestamps, and approximate location derived from IP, collected via cookies and similar technologies.

(c) Information from third parties

Limited information from service providers such as our payment processor (payment status), email-delivery provider (delivery/open events), and analytics providers. We do not purchase personal information to build marketing profiles.

We do not knowingly collect sensitive categories of data, and we ask that you not send them to us.

03 How we use information

We do not sell your personal information for money.

04 Legal bases (EEA / UK)

Where the GDPR or UK GDPR applies, we rely on: performance of a contract (to provide the Service); legitimate interests (to secure, analyse, and improve the Service and for non-intrusive marketing), balanced against your rights; consent (e.g., certain cookies and marketing, which you can withdraw at any time); and legal obligation (e.g., tax, accounting, responding to lawful requests).

05 Cookies & tracking

We use strictly necessary cookies to operate the Service and, where you consent, analytics and preference cookies. You can manage cookies through your browser and, where provided, our cookie banner/preferences tool. We honour Global Privacy Control (GPC) signals where required. [Insert cookie table / link to a Cookie Policy if used.]

06 How we share information

We share personal information only as follows:

RecipientPurpose
Service providers / processorsHosting, payment processing, email delivery, analytics, customer support — under contract and only as instructed.
Legal & safetyTo comply with law, lawful requests, or to protect rights, safety, and property.
Business transfersIn connection with a merger, acquisition, financing, or sale of assets (with notice where required).
With your directionWhen you ask us to share information.

We do not sell personal information for money, and we do not "share" it for cross-context behavioural advertising as those terms are defined under California law, except as you may consent to.

07 Email & marketing

We use your email to deliver the alerts you subscribe to and essential account/transactional messages, which you cannot opt out of while you hold an account. For non-essential marketing emails, you can unsubscribe at any time via the link in the email or by contacting us.

08 Data retention

We keep personal information only as long as necessary for the purposes described above, to provide the Service, to comply with legal, tax, and accounting obligations, to resolve disputes, and to enforce our agreements, after which we delete or anonymise it.

09 Security

We use reasonable technical and organisational measures (such as encryption in transit, access controls, and limited access on a need-to-know basis) to protect personal information. No method of transmission or storage is completely secure, and we cannot guarantee absolute security.

10 International transfers

We may process and store information in the United States and other countries that may have different data-protection laws than yours. Where required, we use appropriate safeguards (such as the EU Standard Contractual Clauses and the UK Addendum) for transfers out of the EEA/UK.

11 Your rights (EEA / UK)

Subject to applicable law, you may have the right to: access your personal information; correct inaccurate data; delete data; restrict or object to processing; data portability; and withdraw consent at any time. You may also lodge a complaint with your supervisory authority. To exercise your rights, contact privacy@DOMAIN. We will respond within the timeframes required by law and may need to verify your identity.

12 Your rights (California — CCPA/CPRA)

California residents may have the right to: know/access the categories and specific pieces of personal information collected; delete personal information; correct inaccurate information; and opt out of "sale" or "sharing" (we do not sell or share as defined). We will not discriminate against you for exercising your rights. To exercise them, contact privacy@DOMAIN [or use our "Do Not Sell or Share My Personal Information" link]. You may use an authorised agent, and we may verify your request.

13 Children's privacy

The Service is not directed to, and we do not knowingly collect personal information from, individuals under 18. If you believe a minor has provided us information, contact us and we will delete it.

14 Third-party links

The Service may link to third-party websites or services we do not control. Their privacy practices are governed by their own policies; we are not responsible for them.

15 Changes to this Policy

We may update this Policy from time to time. We will post the updated version with a new effective date and, where required, provide additional notice. Your continued use after changes take effect constitutes acceptance.

16 Contact

[COMPANY LEGAL NAME]
[Registered address]
Email: privacy@DOMAIN