Privacy policy
How CARDO handles personal data, what we keep, for how long, and what you can ask us to do with it.
Effective TODO_EFFECTIVE_DATE
Draft, not for publication. The legal entity, registered address, contact addresses and effective date are still placeholders in content/site.ts. This document also needs review by a solicitor before it goes live.
CARDO is supplied to organisations, not to individuals. Your employer holds the account and decides who may use it. In data protection terms they are the controller for the risk data held in the system and TODO_LEGAL_ENTITY is the processor acting on their instructions. For the account and security data described below, we are the controller.
1. What we collect
Data you give us
- Authentication data. Email address and a password, which is hashed and never stored in readable form.
- Profile data. Name and the organisation you belong to.
- Communication data. Correspondence about account activity and security.
Data collected automatically
- Session data. A session token, used only to keep you signed in.
- Usage data. Which endpoints an account calls and how often.
- Technical data. IP address, browser and device type.
- Error data. Application errors and crashes.
Risk data you upload
Risk records and their descriptions, classifications, owners and dates; comments and annotations; and the audit trail recording who changed what and when. This is your organisation’s data. We process it to run the service and for no other purpose.
2. How we use it
- To authenticate you and run the service you asked for.
- To find and fix faults, and to monitor performance.
- To prevent fraud and abuse, and to meet legal obligations.
- To send service messages: security alerts, scheduled downtime, and changes to your account.
We do not sell personal data, and we do not use it to train machine learning models.
3. Legal basis
Under UK and EU GDPR we rely on the following:
| Purpose | Basis | Kept for |
|---|---|---|
| Account authentication | Contract | Account active, plus 30 days |
| Fraud prevention | Legitimate interest | 2 years |
| Legal and audit compliance | Legal obligation | 7 years |
| Error tracking | Legitimate interest | 90 days |
For California residents: we do not sell personal information, and we do not share it for cross-context behavioural advertising. We do not currently respond to Do Not Track signals, because we run no third-party tracking for them to disable.
4. Your rights
You can ask us to give you a copy of your data, correct it, delete it, restrict how we use it, export it in a machine-readable format, or object to a particular use. California residents additionally have the right to know what is collected and the right to correct it.
Because your employer is the controller for risk data, a request about that data may need to go to them. Ask us either way and we will tell you which applies. Email TODO_PRIVACY_EMAIL with your account email address and what you want done. We respond within 30 days.
5. Retention
| Data | Kept while | Then |
|---|---|---|
| User account | Membership is active | Purged after 30 days |
| Risk records | Your organisation keeps them | Deleted when they delete them |
| Session tokens | You are signed in | Revoked on sign-out |
| Audit logs | Active, plus 6 months | Purged after 7 years |
| Error reports | Under investigation | Purged after 90 days |
| IP addresses | Recent activity | Anonymised after 90 days |
On an account deletion request, the account and its sessions go immediately, organisational membership within 24 hours, audit log attribution is anonymised within 7 days, and backups are purged within 90 days. Audit logs, transaction records and anything subject to an active dispute are retained where the law requires it.
6. Sharing and processors
| Who | What they see | Why |
|---|---|---|
| Members of your organisation | Risk records and audit logs, subject to their role | To do their job |
| Google Cloud | All data at rest | Database, storage and hosting |
| Google (Gemini) | Text you submit to an AI feature | To generate the requested assessment |
| Sentry | Application errors | Fault diagnosis |
| Law enforcement | Only what a valid legal request compels | Legal obligation |
The current list, with locations, is kept at sub-processors. We have data processing agreements with each of them.
7. International transfers
Some processing takes place outside the UK and EEA, principally in the United States. Where it does, we rely on the UK International Data Transfer Addendum and the EU Standard Contractual Clauses. Contact us if you need the detail for a transfer risk assessment.
8. Security
Data is encrypted at rest and in transit. Access is role-based with per-organisation isolation enforced on the server, not in the browser. Session cookies are HttpOnly, Secure and SameSite. Requests are rate limited, and every change to a risk record is written to an append-only audit log. A fuller description is on the security overview.
If we suffer a breach affecting personal data, we will notify the ICO within 72 hours of becoming aware of it, and notify you without undue delay where the risk to you is high.
9. Cookies
We use two cookies, both strictly necessary. We run no analytics, advertising or third-party tracking cookies, which is why you are not asked to consent to any.
| Cookie | Purpose | Lifetime |
|---|---|---|
cardo_session | Keeps you signed in | 14 days |
cardo_csrf | Protects against cross-site request forgery | Session |
10. Children’s privacy
CARDO is a workplace tool and is not intended for anyone under 16. We do not knowingly collect their data, and will delete any account we find.
11. Changes
We will post any change here and update the effective date. Where a change materially affects your rights we will tell account holders in advance rather than relying on you to check.
12. Contact
Privacy questions and rights requests: TODO_PRIVACY_EMAIL. General enquiries: TODO_CONTACT_EMAIL. Post: TODO_LEGAL_ENTITY, TODO_REGISTERED_ADDRESS.
If you are unhappy with our response you can complain to the Information Commissioner’s Office at ico.org.uk, or to your local supervisory authority in the EEA.