Clear State’s full legal entity name, registered office, company number, ICO registration details and approved retention schedule must be confirmed before this notice is published.
Clear State handles information connected with sensitive workplace matters. We use it only where there is a clear purpose and lawful basis, limit access to those who need it, and apply safeguards proportionate to the information involved.
This notice should be read alongside any case-specific privacy information or data-processing terms provided during an engagement.
Who we are
Clear State is a UK-based independent workplace investigations consultancy. In this notice, “Clear State”, “we”, “us” and “our” refer to the Clear State legal entity responsible for the relevant processing.
For questions about this notice or our use of personal information, email enquiries@clearstate.co.uk.
Scope and our data-protection role
This notice applies when you visit our website, contact us, work with us as a client or supplier, or participate in a matter that we have been appointed to investigate.
Our role under data-protection law depends on the circumstances. We act as a controller for our website, enquiries, business administration and professional obligations. For an investigation, we may act as an independent controller, a joint controller or a processor acting on a client’s documented instructions. The engagement documents and any case-specific notice will identify the applicable arrangement.
Information we collect
Depending on how you interact with us, we may process:
- identity and contact details, including your name, role, organisation, email address and telephone number;
- enquiry, correspondence, appointment and client relationship records;
- contract, billing and payment information;
- technical and security information, such as IP address, browser information and essential session data;
- investigation material, including allegations, terms of reference, policies, correspondence, documents, interview records, witness accounts, analysis and reports;
- employment and professional information relevant to the agreed scope; and
- information about other people contained in evidence or supplied by a client, participant or authorised third party.
Please do not send detailed allegations, evidence or special-category information through the initial website enquiry form. We will provide an appropriate secure channel where material is required.
Where information comes from
We collect information directly from you when you contact us, provide documents or participate in an interview. We may also receive information from the commissioning organisation, its staff and representatives, witnesses, advisers, authorised third parties, public records, workplace systems and other sources relevant to the agreed terms of reference.
Where information is obtained from another source, we will provide appropriate privacy information within the period required by law unless an applicable exemption or restriction applies.
How and why we use information
Responding to enquiries
To assess what support may be appropriate, arrange an initial conversation and communicate with you.
Legitimate interests and steps requested before a contractDelivering engagements
To scope and carry out investigation work, communicate with participants, analyse evidence and produce agreed outputs.
Contract, legitimate interests and, where applicable, legal obligation or public taskFair and defensible process
To maintain records, manage conflicts, protect procedural integrity and establish, exercise or defend legal claims.
Legitimate interests, legal obligation and legal claimsOperating the consultancy
To administer contracts, invoices, suppliers, information security, insurance and professional advice.
Contract, legal obligation and legitimate interestsWebsite security
To deliver the site, prevent misuse, diagnose faults and protect our systems.
Legitimate interests and strictly necessary technologiesWhere we rely on legitimate interests, those interests include providing independent professional services, managing relationships, protecting confidential information, ensuring quality and security, and responding to or defending claims. We balance those interests against the rights and reasonable expectations of the people affected.
We do not use investigation information for advertising, and we do not make decisions about people based solely on automated processing.
Special-category and criminal-offence information
Workplace matters can involve information about health, disability, race or ethnicity, religion or belief, trade-union membership, sexual orientation or sex life, and alleged or proven criminal conduct.
We process this information only where necessary, proportionate and supported by both an Article 6 lawful basis and an additional condition under Article 9 or Article 10 of the UK GDPR and, where required, Schedule 1 to the Data Protection Act 2018, each as amended. Depending on the facts, relevant conditions may include employment law, substantial public interest, safeguarding, preventing or detecting unlawful acts, or legal claims.
Who we share information with
We share personal information only where necessary and with appropriate controls. Recipients may include:
- the commissioning client and authorised recipient identified for the matter;
- investigators, associates and carefully selected secure service providers;
- professional advisers, auditors and insurers subject to confidentiality duties;
- courts, tribunals, regulators, law-enforcement bodies or public authorities where disclosure is required or permitted by law; and
- other parties where you have authorised disclosure or it is necessary to protect vital interests.
We do not sell personal information. Investigation reports and evidence are not shared for publicity or marketing.
International transfers
We aim to use UK-hosted services for case material where practicable. If information is processed outside the UK, we will use a lawful transfer mechanism, such as UK adequacy regulations or approved contractual safeguards, and assess whether additional protections are required.
Retention and security
We keep information only for as long as necessary for the purpose for which it was collected and to meet legal, contractual, insurance and professional requirements. The period depends on the sensitivity of the information, engagement terms, lawful client instructions, limitation periods and whether a complaint, claim or preservation obligation is ongoing.
Unconverted enquiry information will ordinarily be reviewed for deletion within 24 months of the last meaningful contact. Contract, billing and core business records are retained for the period required by applicable tax, accounting and limitation rules. Case-specific retention will be confirmed in engagement documents or case privacy information.
We use proportionate safeguards, which may include access controls, encryption in transit, secure storage, multi-factor authentication, confidentiality obligations, supplier due diligence, data minimisation and secure deletion.
Your rights
Depending on the circumstances and lawful basis, you may have rights to:
- be informed about how your information is used;
- request access to your personal information;
- ask us to correct, erase or restrict the use of information;
- receive certain information in a portable format;
- withdraw consent where consent is the basis for processing; and
- raise a concern about our handling of your information.
Your right to object
You may object to processing based on legitimate interests or public task. You also have an absolute right to object to direct marketing. We do not currently use personal information for direct marketing.
These rights are not absolute. Access or disclosure may be limited where it would adversely affect another person’s rights, reveal privileged material, prejudice negotiations, or where another statutory exemption applies.
Contact, complaints and changes
Contact enquiries@clearstate.co.uk if you have a privacy question, wish to exercise a right or are concerned about how information has been handled.
You may also complain to the Information Commissioner’s Office through its data-protection complaints service. This does not affect your right to contact the ICO at any time.
We review this notice when our services, systems or legal obligations change. Material changes will be highlighted on this page and, where appropriate, brought directly to the attention of affected individuals.