Privacy policy

How CARDO handles personal data, what we keep, for how long, and what you can ask us to do with it.

Effective TODO_EFFECTIVE_DATE

Draft, not for publication. The legal entity, registered address, contact addresses and effective date are still placeholders in content/site.ts. This document also needs review by a solicitor before it goes live.

CARDO is supplied to organisations, not to individuals. Your employer holds the account and decides who may use it. In data protection terms they are the controller for the risk data held in the system and TODO_LEGAL_ENTITY is the processor acting on their instructions. For the account and security data described below, we are the controller.

1. What we collect

Data you give us

  • Authentication data. Email address and a password, which is hashed and never stored in readable form.
  • Profile data. Name and the organisation you belong to.
  • Communication data. Correspondence about account activity and security.

Data collected automatically

  • Session data. A session token, used only to keep you signed in.
  • Usage data. Which endpoints an account calls and how often.
  • Technical data. IP address, browser and device type.
  • Error data. Application errors and crashes.

Risk data you upload

Risk records and their descriptions, classifications, owners and dates; comments and annotations; and the audit trail recording who changed what and when. This is your organisation’s data. We process it to run the service and for no other purpose.

2. How we use it

  • To authenticate you and run the service you asked for.
  • To find and fix faults, and to monitor performance.
  • To prevent fraud and abuse, and to meet legal obligations.
  • To send service messages: security alerts, scheduled downtime, and changes to your account.

We do not sell personal data, and we do not use it to train machine learning models.

Under UK and EU GDPR we rely on the following:

PurposeBasisKept for
Account authenticationContractAccount active, plus 30 days
Fraud preventionLegitimate interest2 years
Legal and audit complianceLegal obligation7 years
Error trackingLegitimate interest90 days

For California residents: we do not sell personal information, and we do not share it for cross-context behavioural advertising. We do not currently respond to Do Not Track signals, because we run no third-party tracking for them to disable.

4. Your rights

You can ask us to give you a copy of your data, correct it, delete it, restrict how we use it, export it in a machine-readable format, or object to a particular use. California residents additionally have the right to know what is collected and the right to correct it.

Because your employer is the controller for risk data, a request about that data may need to go to them. Ask us either way and we will tell you which applies. Email TODO_PRIVACY_EMAIL with your account email address and what you want done. We respond within 30 days.

5. Retention

DataKept whileThen
User accountMembership is activePurged after 30 days
Risk recordsYour organisation keeps themDeleted when they delete them
Session tokensYou are signed inRevoked on sign-out
Audit logsActive, plus 6 monthsPurged after 7 years
Error reportsUnder investigationPurged after 90 days
IP addressesRecent activityAnonymised after 90 days

On an account deletion request, the account and its sessions go immediately, organisational membership within 24 hours, audit log attribution is anonymised within 7 days, and backups are purged within 90 days. Audit logs, transaction records and anything subject to an active dispute are retained where the law requires it.

6. Sharing and processors

WhoWhat they seeWhy
Members of your organisationRisk records and audit logs, subject to their roleTo do their job
Google CloudAll data at restDatabase, storage and hosting
Google (Gemini)Text you submit to an AI featureTo generate the requested assessment
SentryApplication errorsFault diagnosis
Law enforcementOnly what a valid legal request compelsLegal obligation

The current list, with locations, is kept at sub-processors. We have data processing agreements with each of them.

7. International transfers

Some processing takes place outside the UK and EEA, principally in the United States. Where it does, we rely on the UK International Data Transfer Addendum and the EU Standard Contractual Clauses. Contact us if you need the detail for a transfer risk assessment.

8. Security

Data is encrypted at rest and in transit. Access is role-based with per-organisation isolation enforced on the server, not in the browser. Session cookies are HttpOnly, Secure and SameSite. Requests are rate limited, and every change to a risk record is written to an append-only audit log. A fuller description is on the security overview.

If we suffer a breach affecting personal data, we will notify the ICO within 72 hours of becoming aware of it, and notify you without undue delay where the risk to you is high.

9. Cookies

We use two cookies, both strictly necessary. We run no analytics, advertising or third-party tracking cookies, which is why you are not asked to consent to any.

CookiePurposeLifetime
cardo_sessionKeeps you signed in14 days
cardo_csrfProtects against cross-site request forgerySession

10. Children’s privacy

CARDO is a workplace tool and is not intended for anyone under 16. We do not knowingly collect their data, and will delete any account we find.

11. Changes

We will post any change here and update the effective date. Where a change materially affects your rights we will tell account holders in advance rather than relying on you to check.

12. Contact

Privacy questions and rights requests: TODO_PRIVACY_EMAIL. General enquiries: TODO_CONTACT_EMAIL. Post: TODO_LEGAL_ENTITY, TODO_REGISTERED_ADDRESS.

If you are unhappy with our response you can complain to the Information Commissioner’s Office at ico.org.uk, or to your local supervisory authority in the EEA.