Last updated: 12 July 2026
Version: 1.1
This Privacy Policy explains how GAMSOL, a Swiss nonprofit association operating StayClear, collects, uses, shares, stores and protects personal data in connection with StayClear.
StayClear is a decision-engine reminder service for gambling-harm prevention. It allows users to create intervention profiles with goals, risk moments, action plans, wording preferences, feedback and optional transaction context, then receive reminders before selected gambling-pressure moments. The service may involve sensitive information, including information about gambling pressure, financial stress, mental health, debt, vulnerability, support needs, behavioural patterns or other personal circumstances.
Please read this policy carefully. It should be read together with our Terms of Service, Disclaimer, Cookie Notice and any plan, checkout or institution-funded access notice shown to you.
1. Who we are
1.1 Controller: The controller responsible for personal data processed through StayClear is GAMSOL, a Swiss nonprofit association operating StayClear.
Postal address: Postfach, 8008 Zurich, Switzerland.
1.2 Privacy contact: Privacy requests, data-protection complaints and account-specific requests should be sent through the StayClear contact page. We may ask you to use a verified email session or account login so that we can verify identity and protect user privacy.
1.3 Data Protection Officer: We have not appointed a statutory Data Protection Officer. Privacy requests are handled by our privacy lead through the StayClear contact page.
1.4 In this policy, “StayClear”, “we”, “us” and “our” mean GAMSOL trading as StayClear.
2. Scope of this policy
2.1 This policy applies when you:
(a) visit stayclear.org;
(b) create a StayClear account;
(c) start, manage or cancel a subscription;
(d) configure a reminder or intervention profile;
(e) receive email or SMS reminders;
(f) contact support;
(g) use optional AI-assisted decision-engine or reminder-wording features;
(h) receive institution-funded access;
(i) submit an institution, press, research, procurement or partnership enquiry;
(j) participate in a pilot, trial, evaluation or funded deployment; or
(k) otherwise interact with StayClear.
2.2 This policy applies to individual users, subscribers, website visitors, institutional contacts, public-health bodies, gambling operators, banks, employers, charities, support organisations, researchers and other business contacts.
2.3 Some institution-funded deployments may have an additional privacy notice, data sharing notice or participant information sheet. If there is any inconsistency, the more specific notice will apply to the specific deployment, but this policy will continue to apply unless stated otherwise.
3. Important privacy summary
3.1 StayClear may process sensitive information because the service is designed to help users manage gambling-pressure moments with decision-engine reminders.
3.2 You choose what reminder information you enter. You should not include details that you would not want to appear in an email, SMS, phone notification, lock screen, shared device, inbox, support message, provider log or institutional audit context.
3.3 We do not sell personal data.
3.4 We do not provide gambling operators, banks, employers or public-health bodies with your personal trigger notes, reminder wording, support messages or full intervention profile unless this is clearly disclosed to you, lawful, necessary and covered by appropriate data arrangements.
3.5 StayClear reminders are not emergency communications. Support messages, SMS replies and intervention profiles are not monitored as a crisis service.
3.6 We do not use optional AI-assisted decision-engine or wording features to make treatment, credit, employment, banking, gambling-account, legal, eligibility or safeguarding decisions about you.
3.7 We may keep limited records after cancellation or account closure where needed for legal, accounting, security, fraud-prevention, audit, dispute-resolution, safeguarding, safety or compliance reasons.
4. Personal data we collect
We may collect and process the following categories of personal data.
4.1 Account and identity data
(a) email address;
(b) account ID;
(c) name, if provided;
(d) login status;
(e) authentication records;
(f) single-use link or magic-link events;
(g) account creation date;
(h) account status;
(i) account support history.
4.2 Contact and communication data
(a) email address;
(b) verified mobile number;
(c) delivery country;
(d) support messages;
(e) institution enquiry messages;
(f) press, research, procurement or partnership messages;
(g) message metadata, including date, time, sender, recipient, message status and thread history.
4.3 Subscription and payment data
(a) plan selected;
(b) billing currency;
(c) subscription status;
(d) renewal date;
(e) cancellation date;
(f) Stripe customer ID or subscription ID;
(g) payment event records;
(h) invoice or receipt records;
(i) refund records;
(j) chargeback or dispute records;
(k) partial payment method details provided by Stripe, such as card brand, expiry month/year or last four digits where made available to us.
We do not normally receive or store your full card number or card security code.
4.4 Reminder and intervention profile data
(a) reminder preferences;
(b) Risk Windows;
(c) dates and times selected by you;
(d) recurring reminders;
(e) timezone;
(f) trigger notes;
(g) reminder wording;
(h) channel preferences;
(i) message priority or urgency settings;
(j) profile completion status;
(k) profile update history;
(l) user-selected reasons, goals or protective prompts;
(m) action plans;
(n) weekly-review and reminder-feedback entries;
(o) transaction notes or upload summaries where provided.
4.5 Sensitive reminder information
Your intervention profile, trigger notes, support messages or AI-assisted wording prompts may reveal or imply:
(a) gambling behaviour or gambling harm;
(b) addiction or compulsive behaviour;
(c) mental health or emotional distress;
(d) debt or financial difficulty;
(e) relationship stress;
(f) alcohol use or other contextual triggers;
(g) vulnerability;
(h) disability or health information;
(i) family, employment, housing or safeguarding concerns.
This may include special category data under UK data protection law where it relates to health or other protected categories.
4.6 Reminder delivery data
(a) reminder ID;
(b) scheduled date and time;
(c) queued status;
(d) sent status;
(e) failed status;
(f) cancelled status;
(g) delivery provider message ID;
(h) bounce or failure reason;
(i) SMS opt-out or “STOP” status;
(j) carrier or provider delivery status;
(k) delivery country;
(l) retry records.
A delivery record does not prove that you saw, read, understood or acted on a reminder.
4.7 Technical, security and device data
(a) IP address;
(b) device type;
(c) browser type;
(d) operating system;
(e) approximate location derived from IP address;
(f) server logs;
(g) access times;
(h) page views;
(i) referring URL;
(j) error logs;
(k) fraud-prevention logs;
(l) security audit logs;
(m) cookie or similar technology identifiers where used.
4.8 Optional AI-assisted decision-engine and wording data
Where enabled and consented to, we may process:
(a) user-provided prompt, goal, risk and action-plan information;
(b) reminder, feedback and transaction context selected by the user;
(c) AI-generated draft wording;
(d) user edits;
(e) consent records;
(f) logs needed to operate, secure, audit and improve the feature.
4.9 Institution-funded access and referral data
Where access is funded or made available by an institution, we may process:
(a) access code;
(b) voucher code;
(c) institution name;
(d) cohort or campaign identifier;
(e) referral route;
(f) eligibility status;
(g) activation status;
(h) profile completion status;
(i) aggregate usage metrics;
(j) support volumes;
(k) delivery reliability information.
Unless clearly disclosed and lawful, we do not share personal trigger notes, reminder wording, support messages or full profiles with the funding institution.
4.10 Institutional contact data
If you contact us on behalf of an organisation, we may process:
(a) name;
(b) job title;
(c) organisation;
(d) work email;
(e) work phone number;
(f) country;
(g) organisation type;
(h) enquiry content;
(i) procurement information;
(j) pilot requirements;
(k) due diligence materials;
(l) contract records;
(m) meeting notes.
4.11 Optional Open Banking data
Where you choose to connect an eligible account through Plaid, we may process:
(a) a Plaid item identifier and encrypted access token;
(b) institution and account display details needed to show and manage the connection;
(c) transaction identifiers, dates, times, amounts, currency and category signals;
(d) gambling-related classification and timing signals used by the StayClear decision engine;
(e) connection, synchronisation, permission, error and webhook status;
(f) records of your connection, disconnection and history-deletion choices.
We do not receive your online-banking password. Merchant descriptions may be used transiently to classify a transaction but are not retained on new or updated StayClear transaction records. Open Banking data is not shown to a funding institution, council, employer, bank partner or gambling operator as individual-level data.
4.12 Research, evaluation and analytics data
We may create or process:
(a) aggregate activation rates;
(b) profile completion rates;
(c) reminder scheduling volumes;
(d) reminder delivery reliability;
(e) failed delivery rates;
(f) cancellation volumes;
(g) high-level support categories;
(h) anonymised or statistical data;
(i) survey responses where provided;
(j) research-consent records where required.
4.12 Optional geography, demographic, assessment and outcome data
Where you provide it, or where it is derived from a source you have connected, we may process:
(a) an encrypted home address and, for UK addresses, derived local-authority, ward, LSOA, MSOA, region and integrated-care-board codes;
(b) age band, sex, gender identity, ethnicity, disability or long-term-condition status, employment, income band, education, housing, relationship and household information;
(c) caring responsibilities, dependants, preferred language, accessibility needs and digital access;
(d) fixed, versioned gambling-risk or harm assessment answers and scores;
(e) gambling frequency, financial-pressure, borrowing, essential-spending and affected-other indicators;
(f) whether an intervention was noticed, relevant or well timed;
(g) actions taken after an intervention, including whether a deposit was avoided, postponed or reduced and any approximate amount protected;
(h) support-pathway events, including whether support was offered, attempted, accessed, declined or unavailable;
(i) service experience, trust, accessibility and reminder-fatigue responses;
(j) confirmations or corrections of transaction classifications; and
(k) source, confidence, data-freshness, instrument-version and model-version metadata needed to interpret these records properly.
Stripe may collect a billing address during checkout. StayClear stores the address in encrypted form and asks you to confirm or update it during profile setup. UK postcodes are matched to administrative geography for area-level service reporting.
Optional demographic, assessment and evaluation questions are presented progressively. You may skip them. We record a separate consent where optional answers are used for service evaluation and aggregated public-health insights.
5. Where we get personal data from
We may receive personal data from:
(a) you directly;
(b) your StayClear account;
(c) subscription checkout;
(d) Stripe or another payment provider;
(d.1) Plaid or another bank-data provider that you choose to connect;
(e) Twilio or another SMS provider;
(f) email delivery providers;
(g) hosting, security or analytics providers;
(h) an institution funding or referring access;
(i) a support, research, press, procurement or enquiry form;
(j) your device or browser;
(k) public professional sources, where relevant to institutional contacts;
(l) legal, regulatory, payment, fraud-prevention or dispute records.
(m) Plaid or another Open Banking provider, only after you choose to connect an eligible account;
(n) official postcode and administrative-geography lookup data published by UK statistical authorities.
6. Purposes and lawful bases
We use personal data only where we have a lawful basis. Depending on the context, we may rely on contract, consent, explicit consent, legitimate interests, legal obligation, vital interests, public task or another lawful basis available under applicable law.
| Purpose |
Personal data used |
Lawful basis |
| Create and manage your account |
Account, contact, login and technical data |
Contract; legitimate interests |
| Provide subscriptions and plan access |
Account, subscription, payment and plan data |
Contract; legal obligation; legitimate interests |
| Process payments and refunds |
Payment, billing, Stripe and account data |
Contract; legal obligation; legitimate interests |
| Configure reminder and intervention profiles |
Account, intervention profile, goals, action plans, preferences, Risk Windows |
Contract; explicit consent where special-category data is involved |
| Send email reminders |
Email, reminder wording, schedule, delivery data |
Contract; explicit consent where special-category data is involved |
| Send SMS reminders |
Mobile number, verified number, reminder wording, delivery country, provider data |
Contract; explicit consent where special-category data is involved |
| Provide support |
Account, contact, support messages, technical data |
Contract; legitimate interests; legal obligation where applicable |
| Optional AI-assisted decision-engine features |
User prompts, goals, action plans, reminder context, generated wording, consent records |
Consent; explicit consent where special-category data is involved; contract where used as part of the service |
| Optional Open Banking features |
Connected-account identifiers, transaction timing and amount/category signals, classifications, connection status |
Consent; explicit consent where special-category data is involved; contract where used as part of the service |
| Security, fraud prevention and abuse prevention |
Account, technical, payment, security and audit data |
Legitimate interests; legal obligation |
| Service administration and audit trail |
Account, subscription, reminder, delivery, support and audit records |
Legitimate interests; legal obligation |
| Legal claims and dispute handling |
Relevant account, payment, reminder, support, delivery and audit records |
Legitimate interests; legal obligation; Article 9 legal-claims condition where special-category data is involved |
| Institutional funded access |
Access code, institution, activation status, aggregate metrics |
Contract; legitimate interests; legal obligation; explicit consent where needed |
| Aggregate reporting to institutions |
Aggregated or anonymised usage and delivery metrics |
Legitimate interests; contract with institution; public task where applicable |
| Research, evaluation and service improvement |
Operational, aggregate, anonymised, progressive-question, assessment, outcome and evaluation data |
Legitimate interests; consent; public task; research/statistics condition where applicable |
| Website analytics and performance |
Cookie, device, browser, page and usage data |
Consent where required; legitimate interests where lawful; legal exemptions where applicable |
| Marketing to institutional contacts |
Business contact data and enquiry records |
Legitimate interests where lawful; consent where required |
| Direct marketing to individual users |
Email, SMS or communication preferences |
Consent or lawful soft opt-in where available; legitimate interests for non-electronic marketing where lawful |
| Emergency or serious safety situations |
Relevant account, contact, support and profile data |
Vital interests; legitimate interests; legal obligation where applicable |
| Compliance with law and lawful requests |
Relevant personal data |
Legal obligation; legitimate interests; public task where applicable |
7. Special-category data
7.1 Intervention profiles, trigger notes, support messages and AI prompts may contain special-category data, especially health-related information.
7.2 Where we process special-category data, we rely on an Article 9 condition where required. This may include:
(a) explicit consent, where you choose to provide sensitive reminder-profile information;
(b) vital interests, where processing is necessary to protect life or safety and you cannot give consent;
(c) legal claims, where processing is necessary to establish, exercise or defend legal claims;
(d) substantial public interest, where applicable and supported by law;
(e) research, archiving or statistics, where lawful and subject to safeguards;
(f) another Article 9 condition available under applicable law.
7.3 If we rely on explicit consent, you may withdraw that consent at any time. If you withdraw consent, we may be unable to provide some or all reminder features. Withdrawal does not make previous lawful processing unlawful.
7.4 We may retain limited sensitive records after withdrawal where legally permitted or required, including for legal claims, safety, fraud prevention, accounting, audit, dispute resolution or compliance.
8. Optional AI-assisted decision-engine and reminder wording
8.1 StayClear may offer optional AI-assisted decision-engine and wording features to help interpret profile context, improve timing and draft concise reminder wording from information you provide.
8.2 AI assistance is optional. We will use it only where enabled and where any required consent has been obtained.
8.3 AI-generated wording and decision-engine outputs are not advice, therapy, diagnosis, treatment, crisis support, financial advice, debt advice, legal advice or safeguarding assessment.
8.4 You must review and approve any AI-assisted wording before using it.
8.5 Do not include third-party personal data, confidential information, emergency information or information you are not comfortable being processed by relevant providers.
8.6 We do not use optional AI-assisted decision-engine or wording features to make eligibility, credit, banking, gambling-account, employment, treatment, safeguarding, legal or similarly significant decisions.
8.7 We will use appropriate contractual, technical and organisational controls with AI service providers where required by law and commercially available.
9. Email and SMS privacy
9.1 Email and SMS are not fully private channels.
9.2 Your reminders may be visible to anyone who can access your:
(a) email inbox;
(b) SMS messages;
(c) phone lock screen;
(d) shared device;
(e) family device;
(f) employer device;
(g) email provider account;
(h) mobile provider records;
(i) cloud backup;
(j) notification history.
9.3 You are responsible for choosing reminder wording and channels that are appropriate for your privacy and safety needs.
9.4 SMS delivery data may be processed by mobile carriers, SMS providers and telecommunications infrastructure.
9.5 Email delivery data may be processed by email providers and related infrastructure.
10. Institution-funded access
10.1 Some users may receive StayClear through an institution, such as a public health body, local authority, gambling operator, bank, employer, charity, support provider or other organisation.
10.2 Unless clearly disclosed and lawful, institutions do not receive:
(a) your personal trigger notes;
(b) your reminder wording;
(c) your full intervention profile;
(d) your SMS content;
(e) your email reminder content;
(f) your support messages;
(g) user-level sensitive information;
(h) behavioural conclusions about you;
(i) individual connected-account details or transaction signals.
10.3 We may provide institutions with aggregate or operational information, such as:
(a) number of funded places;
(b) number of codes issued;
(c) number of codes redeemed;
(d) activation rates;
(e) profile completion rates;
(f) reminders scheduled;
(g) reminders sent;
(h) failed delivery rates;
(i) support volumes;
(j) cancellation or continuation rates;
(k) high-level delivery reliability.
10.4 Individual-level sharing with an institution will occur only where:
(a) it is clearly disclosed to you;
(b) there is a lawful basis;
(c) any required consent has been obtained;
(d) it is necessary and proportionate;
(e) appropriate data-sharing or data-processing documents are in place;
(f) applicable law is complied with.
11. Gambling operators, banks, employers and public health bodies
11.1 A gambling operator, bank, employer, public authority, charity or other institution is separately responsible for its own use of your personal data, including any decision to refer you to StayClear or fund your access.
11.2 Unless expressly agreed in a written arrangement and explained to you, StayClear is not an institution’s employee-monitoring tool, gambling-operator CRM tool, bank risk-scoring tool, affordability tool, credit-decision tool, safer-gambling compliance tool, public-health surveillance tool, debt-advice tool or safeguarding system.
11.3 We do not allow StayClear intervention profiles to be used for gambling marketing, reactivation, bonus offers, free bets, spins, odds, inducements or CRM messaging.
11.4 If an institution gives you access to StayClear, you should also read that institution’s own privacy information explaining how it decided to offer or fund access and what it does with its own records.
12. Cookies and similar technologies
12.1 We use cookies, pixels, local storage, tags, scripts, device identifiers and similar technologies.
12.2 Strictly necessary technologies may be used without consent where they are needed for security, login, checkout, forms, fraud prevention, session continuity, load balancing, remembering your cookie choice and providing the service you requested.
12.3 Optional analytics technologies are used only where you allow them through the cookie controls. These help us understand page use, acquisition channels and service performance.
12.4 Optional advertising measurement technologies are used only where you allow them through the cookie controls. These help us measure campaign and Google Ads conversion performance where configured. Where analytics consent is recorded for a checkout, we may also send a server-side purchase confirmation to our analytics provider if the browser-side purchase event is not acknowledged.
12.5 Rejecting optional cookies will not prevent you from using the website or StayClear service, although some measurement, attribution or preference features may be unavailable.
12.6 You can change your choice at any time using the Cookie settings link in the website footer. You can also manage or delete cookies through your browser settings.
12.7 If you reject optional cookies, we will not intentionally load Google Analytics, Google Ads conversion tags, StayClear analytics page-view tracking or tracking-link attribution for your visit.
13. Marketing
13.1 StayClear reminders are service messages, not gambling marketing.
13.2 We will not include gambling offers, odds, bonuses, free bets, spins, inducements, reactivation language or gambling promotional material in StayClear reminders.
13.3 We may send service messages about your account, reminders, payments, subscription, cancellation, support, security, legal terms and privacy matters.
13.4 We will send direct marketing to individual users only where we have a lawful basis and comply with applicable electronic marketing law.
13.5 You can object to direct marketing at any time.
13.6 If we send optional newsletters, product updates, research updates or institutional updates, we will provide appropriate unsubscribe or preference controls.
13.7 We may contact institutional or business contacts about relevant StayClear services, pilots, procurement, research or partnerships where lawful.
14. Automated decision-making and profiling
14.1 We do not use StayClear to make solely automated decisions that produce legal or similarly significant effects for users.
14.2 We do not use reminder-profile data to make treatment, credit, lending, employment, gambling-account, legal, eligibility, affordability, vulnerability or safeguarding decisions.
14.3 We may use automated or semi-automated systems for:
(a) login security;
(b) fraud detection;
(c) spam prevention;
(d) delivery queueing;
(e) reminder scheduling;
(f) payment status updates;
(g) abuse detection;
(h) technical monitoring.
14.4 If an automated security or abuse process restricts your account, you may contact us to request review.
15. Research, evaluation and statistics
15.1 We may use data to evaluate and improve StayClear.
15.2 We may produce aggregate or anonymised reports for internal analysis, institutions, funders, public health bodies, researchers, investors, procurement processes or service improvement.
15.3 We will not intentionally include personal trigger notes, reminder wording or support messages in aggregate reports.
15.3A Public-health or local-authority reporting is designed around aggregated area-level patterns. Councils do not receive a resident's home address, postcode, individual demographic answers, assessment responses, transaction records, goals, prompt wording or intervention history through standard aggregate reporting.
15.4 Where research requires consent, ethical approval, public-sector governance, data-sharing terms or a separate participant notice, we will use appropriate processes.
15.5 Anonymised data is not personal data where individuals cannot reasonably be identified.
16. Who we share personal data with
We may share personal data with:
(a) hosting providers;
(b) email delivery providers;
(c) SMS delivery providers;
(d) payment providers, including Stripe;
(e) customer support and operations providers;
(f) AI service providers where optional AI wording is enabled;
(g) database and workflow providers, including Airtable where used;
(h) analytics providers where lawful;
(i) fraud-prevention and security providers;
(j) professional advisers, including lawyers, accountants, auditors and insurers;
(k) banks and payment processors;
(l) regulators, courts, law enforcement or public authorities where lawful;
(m) emergency services or safeguarding bodies where necessary to protect life or safety;
(n) institutions funding access, but only as described in this policy and any deployment notice;
(o) potential acquirers, investors or restructuring parties, subject to appropriate confidentiality and legal safeguards.
(p) Open Banking providers, including Plaid, where you choose to connect an eligible account.
17. International transfers
17.1 Some providers may process personal data outside the United Kingdom.
17.2 Where we make a restricted international transfer, we will use an appropriate transfer mechanism where required, such as:
(a) UK adequacy regulations;
(b) the UK International Data Transfer Agreement;
(c) the UK Addendum to EU Standard Contractual Clauses;
(d) another lawful safeguard;
(e) a lawful derogation where appropriate.
17.3 We may also carry out transfer risk assessments where required.
17.4 International transfer arrangements may vary by provider and service configuration.
18. How long we keep personal data
We keep personal data only for as long as reasonably necessary for the purposes described in this policy, unless a longer period is required or permitted by law.
| Data type |
Typical retention approach |
| Account data |
Whilst the account is active, then for up to 6 years after closure or last activity where needed for legal, audit, fraud-prevention or dispute reasons |
| Intervention profile data |
Whilst needed to provide reminders; after cancellation or closure, normally deleted, minimised or anonymised within a reasonable period unless needed for legal, audit, safety, fraud-prevention or dispute reasons |
| Trigger notes and reminder wording |
Whilst active and needed for the service; may be retained in limited form where needed for audit, delivery history, safety, dispute or legal reasons; otherwise deleted, minimised or anonymised |
| Delivery records |
Up to 6 years where needed to prove service operation, resolve disputes, investigate failures or maintain audit records |
| Billing, invoices and tax records |
Usually 6 to 7 years, depending on tax, accounting and legal requirements |
| Payment provider IDs and subscription status |
For the subscription period and up to 6 years afterwards where needed for audit, dispute or accounting reasons |
| Optional Open Banking data |
Whilst the connection is active and needed for StayClear; access tokens are removed after confirmed disconnection, stored history can be deleted after disconnection, and non-required transaction signals are removed when the account is closed |
| Support messages |
Up to 6 years after last contact or account closure, unless a shorter or longer period is appropriate |
| Institution enquiries and business contacts |
Up to 6 years after last meaningful contact, or longer where connected with a contract, procurement, dispute or legal obligation |
| Security logs |
Usually 12 to 24 months, unless needed for security investigation, fraud prevention, legal claims or compliance |
| Consent and terms-acceptance records |
Up to 6 years after last use or account closure, or longer where needed for disputes or legal compliance |
| Cookie consent records |
For the period required to evidence preferences and comply with law |
| Research and evaluation data |
Personal data only as long as needed; anonymised or aggregate data may be kept indefinitely |
| Home address and derived geography |
Whilst needed to provide and evaluate the service; the encrypted address is deleted, minimised or anonymised after closure in line with the account and intervention-profile retention approach |
| Optional demographics and assessments |
Whilst needed for the service or consented evaluation; then deleted, minimised or anonymised unless a lawful audit, research or dispute reason requires limited retention |
| Observation, outcome and model-feedback data |
Whilst needed to operate, evaluate and improve interventions; source-linked personal records are deleted, minimised or anonymised when no longer necessary, whilst aggregate statistics may be retained |
| Legal, regulatory or dispute files |
As long as needed for the relevant matter and any limitation period |
We may retain anonymised data indefinitely.
19. Security
19.1 We use appropriate technical and organisational measures designed to protect personal data.
19.2 Measures may include encryption in transit, access controls, authentication controls, audit logs, provider due diligence, staff or contractor access restrictions, data minimisation, backup controls and security monitoring.
19.3 No online service, email system, SMS system, internet transmission or provider system is completely secure.
19.4 You are responsible for keeping your email account, phone, device, account access and login links secure.
19.5 If you suspect unauthorised access, contact us promptly.
20. Your privacy rights
Depending on your location and the circumstances, you may have rights to:
(a) be informed about how your personal data is used;
(b) access your personal data;
(c) correct inaccurate personal data;
(d) complete incomplete personal data;
(e) erase personal data in certain circumstances;
(f) restrict processing in certain circumstances;
(g) object to processing in certain circumstances;
(h) object to direct marketing at any time;
(i) request data portability in certain circumstances;
(j) withdraw consent where processing is based on consent;
(k) challenge solely automated decisions with legal or similarly significant effects;
(l) complain to a data protection regulator.
21. Exercising your rights
21.1 To exercise your rights, contact us using the privacy contact details in clause 1.
21.2 We may ask you to verify your identity.
21.3 We may refuse or limit a request where permitted by law, including where the request is manifestly unfounded or excessive, where we must retain records, where disclosure would affect another person’s rights, or where an exemption applies.
21.4 We will respond within the time required by law.
21.5 If your request concerns data also held by an institution, you may need to contact that institution separately.
22. Data protection complaints
22.1 You may complain to us if you believe we have mishandled your personal data.
22.2 Send privacy complaints through the StayClear contact page.
22.3 We will acknowledge and respond to complaints in accordance with applicable law.
22.4 You may also complain to the relevant data-protection authority where applicable.
23. Children
23.1 StayClear is intended for users aged 18 or over.
23.2 We do not knowingly provide individual StayClear accounts to children.
23.3 If we believe an account has been created by a child, we may suspend it, delete it or ask for further information.
23.4 If we ever provide a safeguarded youth deployment, we will use a separate privacy notice, age-appropriate design, safeguarding controls, consent arrangements and institutional governance.
24. Third-party websites and services
24.1 StayClear may link to third-party websites or support services.
24.2 We are not responsible for the privacy practices, content or security of third-party websites.
24.3 You should read the privacy information of any third-party service you use.
25. Changes to this policy
25.1 We may update this policy.
25.2 We will post the updated version on the website.
25.3 If changes are material, we will take reasonable steps to notify active users where required.
25.4 The “last updated” date shows when the policy was most recently changed.