Privacy Policy
Short version: Clause5 uses data to operate welding tools, protect the service, send requested messages, maintain compliance evidence, and improve product reliability. We do not sell personal data.
This policy covers account and contact data, welder-linked PII, vision uploads, analytics and session telemetry, first-party /api/events telemetry, lawful basis, retention period, access, correct, erase, and port rights, anonymization limits, Privacy choices, processor categories, and change procedure.
1. Data categories
- account and contact data, including email address, organization details, waitlist details, invitation state, billing state, and support messages.
- welder-linked PII, including welder name, stamp ID, email, phone, certification number, qualification details, expiry or scope, and linkable pseudonymous references when a welding workflow needs them.
- vision uploads, including Uploaded drawings, images, and related review context submitted for analysis.
- Product inputs and outputs, including Flux questions, calculator context, project metadata, WPS or WPQ workflow state, and generated compliance-support output.
- analytics and session telemetry, including page path, rough interaction events, browser metadata, consent state, first-party /api/events telemetry, and session usability analytics that may replay clicks, scrolls, and page interactions.
- Security and operations data, including abuse-prevention signals, rate-limit records, error logs, and consent-safe debug records. Abuse-prevention signals are keyed, non-reversible references, never raw values: a keyed network (IP-range) reference, a keyed per-browser device reference, and a keyed welding-context reference recorded when you save or restore a session; and, only with your opt-in at the save prompt, keyed references derived from your browser's canvas and WebGL rendering, your connection (TLS) and browser signature, and an approximate city-scale (0.1-degree) location. Comparison records are kept for 72 hours; resulting review flags are kept for 30 days and are visible only to our operations service, never to other users.
2. Lawful basis
We process data to provide requested services, take pre-contract steps, perform contracts with customers, meet legal or compliance obligations, protect the service, and improve product reliability where analytics consent controls or a legitimate operational basis applies.
3. Welder consent and employer attestation
welder-linked PII requires a consent decision before it is used in qualification workflows. Direct welder consent is preferred where a deliverable welder contact exists. Employer attestation is provisional, reason-coded, time-limited, and not treated as permanent direct welder consent.
4. Analytics, cookies, and first-party events
Analytics is off by default. Non-essential analytics run only after you turn analytics on in Privacy choices, and you can turn them off again at any time. Keeping analytics off does not block calculators, Flux, SaveGate, share links, authentication, or app pages. Without your consent, first-party /api/events telemetry, session usability tools, and marketing/product analytics do not run, except for essential security or operational telemetry with no marketing payload.
5. Retention period
Contact and account records are kept while the relationship or requested communication remains active. Consent records, non-PII compliance trace evidence, and security logs may be kept longer where needed to prove workflow integrity, prevent abuse, or preserve lawful compliance history. Raw uploads, prompts, and telemetry are retained only as long as needed for product, security, support, or legal purposes. Keyed abuse-prevention comparison records are deleted after 72 hours and their review flags after 30 days, on an automated schedule.
6. Your rights
You can ask to access, correct, erase, and port your personal data. You can also object, restrict processing, withdraw consent, or ask for a copy of consent evidence. Email privacy requests to flux@clause5.io.
7. Deletion and anonymization limits
When consent is withdrawn, Clause5 redacts or anonymizes PII that is no longer lawful to retain, severs or rotates linkable references where possible, and preserves non-PII qualification and compliance audit history. Some audit evidence cannot be deleted without breaking compliance trace integrity, but it must not contain raw welder PII.
8. Processor categories
We use category-based service providers: edge infrastructure provider, database provider, email delivery provider, payment processor, AI processing provider, security provider, and analytics or consent-management provider. Exact processor details are maintained in an internal registry with owner, update cadence, and change procedure.
9. Updates
This policy is reviewed when processors, data categories, purposes, retention periods, or consent mechanics change. The current change procedure updates the internal processor registry, shared policy metadata, public policy copy, and automated privacy tests before deployment.
10. Contact
Privacy questions, deletion requests, and DPO-style requests can be sent to flux@clause5.io. Security reports can be sent to security@clause5.io.