Privacy Policy of ClearPath Journey Solutions Ltd
This Privacy Policy explains how ClearPath Journey Solutions Ltd (“we”, “us”, “our”) collects, uses, shares, stores, and protects personal data in connection with our customer-journey services and related business activities.
ClearPath Journey Solutions Ltd
ClearPath Journey, 2 Exchange Quay, Salford, Manchester M5 3EF, United Kingdom
Email: [email protected]
Phone: +44 161 927 4836
1. Introduction and company information
ClearPath Journey Solutions Ltd is the data controller for the personal data described in this Privacy Policy, unless we expressly state otherwise. We are committed to processing personal data fairly, transparently, and securely, and to respecting your privacy rights.
This Privacy Policy applies to personal data we collect when you:
- visit our website or interact with our online content;
- contact us by email, telephone, or other communication channels;
- request information about our services;
- engage with our customer-journey and related operational services;
- receive services, support, or communications from us;
- otherwise interact with ClearPath Journey Solutions Ltd in a business or customer context.
2. Data collection and processing
We may collect and process the following categories of personal data, depending on how you interact with us:
- Identity data: name, title, job title, company name, and similar identifiers.
- Contact data: email address, telephone number, postal address, and correspondence details.
- Communication data: messages, enquiries, feedback, call records, and interaction history.
- Technical data: IP address, device information, browser type, operating system, log data, and usage information.
- Transaction and service data: service requests, account or project information, payment-related details where applicable, and records of services provided.
- Preference data: communication preferences, service interests, and marketing choices.
- Customer-journey data: data relating to interactions across touchpoints, service pathways, experience mapping, support journeys, and related operational analytics.
We generally collect personal data directly from you, but we may also receive data from:
- our business partners and service providers;
- publicly available sources;
- website analytics and cookie tools;
- third parties authorised by you to share information with us.
We only process personal data where necessary for the purposes described in this Policy and in accordance with applicable law.
3. Purpose of data processing
We process personal data for the following purposes:
- to provide, manage, and improve our services;
- to respond to enquiries and communicate with you;
- to perform contractual obligations and service administration;
- to manage customer relationships and service journeys;
- to analyse service performance, customer needs, and operational efficiency;
- to personalise communications and service experiences where appropriate;
- to send administrative, transactional, and service-related communications;
- to maintain records, accounting, and internal reporting;
- to detect, investigate, and prevent fraud, misuse, or security incidents;
- to comply with legal and regulatory obligations;
- to establish, exercise, or defend legal claims;
- to send marketing communications where permitted by law and where you have not opted out.
4. Legal basis for processing
We process personal data only where we have a lawful basis to do so. Depending on the circumstances, our legal bases may include:
- Contract: where processing is necessary to enter into or perform a contract with you or to take steps at your request before entering into a contract.
- Legitimate interests: where processing is necessary for our legitimate business interests, such as service delivery, customer support, fraud prevention, business administration, and improvement of our services, provided those interests are not overridden by your rights and interests.
- Consent: where you have given clear consent for specific processing activities, such as certain marketing communications or optional cookies, where required.
- Legal obligation: where processing is necessary to comply with applicable law, regulation, court orders, or lawful requests from authorities.
- Vital interests: in rare cases, where processing is necessary to protect someone’s life or physical safety.
- Public interest: where applicable and permitted by law.
Where we rely on legitimate interests, we balance our interests against your rights and freedoms and only proceed where appropriate.
5. Data sharing and third parties
We may share personal data with trusted third parties when necessary for the purposes described in this Privacy Policy. These may include:
- IT hosting, cloud, and software service providers;
- customer relationship, communication, and analytics platforms;
- professional advisers, auditors, insurers, and legal counsel;
- payment processors and financial service providers, where relevant;
- business partners, subcontractors, and service fulfilment providers;
- government bodies, regulators, law enforcement agencies, or courts where required by law;
- other parties in connection with a merger, acquisition, reorganisation, or sale of assets, subject to appropriate safeguards.
We require third parties to process personal data securely, lawfully, and only in accordance with our instructions or their independent legal obligations.
6. Data transfer to third countries
Where personal data is transferred outside the United Kingdom or outside other jurisdictions that provide an adequate level of data protection, we will take appropriate safeguards to protect that data. These safeguards may include:
- reliance on adequacy regulations or decisions where available;
- standard contractual clauses or equivalent transfer mechanisms;
- binding corporate rules or other approved safeguards;
- supplementary technical and organisational measures where necessary.
We will only transfer personal data where such transfer is lawful and where suitable protections are in place.
7. Storage duration
We keep personal data only for as long as necessary for the purposes for which it was collected, including to satisfy legal, accounting, reporting, and operational requirements.
The retention period depends on factors such as:
- the nature of the data and the purpose of processing;
- the existence of contractual or customer relationships;
- legal, tax, or regulatory retention obligations;
- the need to resolve disputes, enforce agreements, or establish legal claims;
- whether you have objected to or withdrawn consent for certain processing.
When personal data is no longer required, we will delete, anonymise, or securely archive it in accordance with applicable law and our retention practices.
8. User rights
Subject to applicable law, you may have the following rights in relation to your personal data:
- Access: to request confirmation as to whether we process your personal data and to obtain a copy of it.
- Rectification: to request correction of inaccurate or incomplete data.
- Erasure: to request deletion of your personal data in certain circumstances.
- Restriction: to request that we limit the processing of your personal data in certain cases.
- Data portability: to request receipt of certain data in a structured, commonly used, machine-readable format and to transmit it to another controller where technically feasible.
- Objection: to object to processing based on legitimate interests, including profiling where applicable, and to object at any time to direct marketing.
To exercise any of these rights, please contact us using the details below. We may need to verify your identity before responding to your request. We will respond within the timeframe required by applicable law.
9. Withdrawal of consent
Where we rely on your consent to process personal data, you have the right to withdraw that consent at any time. Withdrawal of consent will not affect the lawfulness of processing carried out before the withdrawal.
If you withdraw consent, we may no longer be able to provide certain optional features or communications that depend on it. You may withdraw consent by contacting us at [email protected] or by using any available opt-out mechanism we provide.
10. Right to complain
If you have concerns about how we process your personal data, we encourage you to contact us first so that we can try to resolve the issue.
You may also have the right to lodge a complaint with a relevant supervisory authority, especially in the country where you live, work, or believe an infringement has occurred. If you are in the United Kingdom, you may be able to contact the Information Commissioner’s Office (ICO).
11. Data security
We implement appropriate technical and organisational measures to protect personal data against unauthorised access, accidental loss, destruction, alteration, disclosure, or misuse. These measures may include:
- access controls and authentication;
- encryption where appropriate;
- secure storage and transmission practices;
- staff confidentiality obligations and training;
- regular monitoring, testing, and review of safeguards;
- incident response and breach management procedures.
While we take reasonable steps to protect personal data, no system can be guaranteed to be completely secure.
12. Contact information
If you have questions about this Privacy Policy or wish to exercise your rights, please contact:
ClearPath Journey Solutions Ltd
ClearPath Journey, 2 Exchange Quay, Salford, Manchester M5 3EF, United Kingdom
Email: [email protected]
Phone: +44 161 927 4836
13. Changes to privacy policy
We may update this Privacy Policy from time to time to reflect changes in our practices, services, legal requirements, or operational needs. Any updated version will be posted on our website or otherwise made available to you, and the revised policy will take effect from the date stated or, if no date is stated, upon publication.
We encourage you to review this Privacy Policy periodically to stay informed about how ClearPath Journey Solutions Ltd protects your personal data.