Privacy Policy
Short version: Clause5 uses data to operate welding tools, protect the service, send requested messages, maintain compliance evidence, and improve product reliability. We do not sell personal data.
This policy covers account and contact data, welder-linked PII, vision uploads, analytics and session telemetry, first-party /api/events telemetry, lawful basis, retention period, access, correct, erase, and port rights, anonymization limits, Privacy choices, processor categories, and change procedure.
1. Data categories
- account and contact data, including email address, organization details, waitlist details, invitation state, billing state, and support messages.
- welder-linked PII, including welder name, stamp ID, email, phone, certification number, qualification details, expiry or scope, and linkable pseudonymous references when a welding workflow needs them.
- vision uploads, including Uploaded drawings, images, and related review context submitted for analysis.
- Product inputs and outputs, including Flux questions, calculator context, project metadata, WPS or WPQ workflow state, and generated compliance-support output.
- analytics and session telemetry, including page path, rough interaction events, browser metadata, consent state, first-party /api/events telemetry, and session usability analytics that may replay clicks, scrolls, and page interactions.
- Security and operations data, including abuse-prevention signals, rate-limit records, error logs, and consent-safe debug records. Abuse-prevention signals are keyed, non-reversible references, never raw values: a keyed network (IP-range) reference, a keyed per-browser device reference, and a keyed welding-context reference recorded when you save or restore a session; and, only with your opt-in at the save prompt, keyed references derived from your browser's canvas and WebGL rendering, your connection (TLS) and browser signature, and an approximate city-scale (0.1-degree) location. Comparison records are kept for 72 hours; resulting review flags are kept for 30 days and are visible only to our operations service, never to other users.
2. Lawful basis
We process data to provide requested services, take pre-contract steps, perform contracts with customers, meet legal or compliance obligations, protect the service, and improve product reliability where analytics consent controls or a legitimate operational basis applies.
3. Welder consent and employer attestation
welder-linked PII requires a consent decision before it is used in qualification workflows. Direct welder consent is preferred where a deliverable welder contact exists. Employer attestation is provisional, reason-coded, time-limited, and not treated as permanent direct welder consent.
4. Analytics, cookies, and first-party events
For visitors in the European Union, the European Economic Area (Iceland, Liechtenstein, Norway), and wherever your location cannot be determined, analytics is off by default. On your first visit we show a banner with two equally weighted choices, Accept analytics and Essentials only. Until you choose, only essential storage is used. Your choice is stored in your browser, the banner does not return once you have chosen, and you can change your choice at any time in Privacy choices. Non-essential analytics run only after you accept.
For visitors our edge network locates anywhere else, analytics is on by default. Until you opt out, these run: first-party /api/events telemetry without marketing payload; a third-party web analytics beacon; a third-party session analytics tool that may replay clicks, scrolls, and page interactions; and first-touch campaign parameters from the link you arrived on, kept in your browser for that tab's session, plus any advertising click identifier in that link, kept in your browser for up to 30 days. Advertising storage in the session analytics tool stays off. You can opt out at any time in Privacy choices. A Global Privacy Control signal from your browser is treated as an opt-out unless you have saved analytics on in Privacy choices. To apply these defaults we check your region group on each page you open, and analytics stays off on that page until the check confirms it; we also set a first-party cookie that holds only the resulting region group, not your location, for up to 24 hours.
Keeping analytics off does not block calculators, Flux, SaveGate, share links, authentication, or app pages. While analytics is off, whether by default or because you opted out, first-party /api/events telemetry, session usability tools, and marketing/product analytics do not run, except for essential security or operational telemetry with no marketing payload. While analytics is off we still record identifier-free aggregate counts of practice quiz starts, completions and abandons, calculator starts and results, assistant starts, symbol reference views, clicks, prints and download requests, and email sign-up prompt views and submissions, stored only as the day and the event name, with no cookie sent and no identifier stored. The same kind of count records how often the privacy banner is shown and which choice is made.
- Cloudflare Zaraz loads and routes analytics tools when analytics is allowed. It processes page and browser information, consent decisions, event data and first-party tool identifiers. Zaraz's separate retention period and tool-cookie lifetimes have not yet been confirmed.
- Google Analytics 4 receives page views, interaction events, browser and device information, campaign information and pseudonymous visitor identifiers through Zaraz. Our configured retention is 2 months for event data and 14 months for user data. New activity renews the user-data retention period. These settings do not set a deletion deadline for aggregated reports.
- Microsoft Clarity collects page-rendering and interaction data, including clicks, scrolls and mouse movements, plus pseudonymous browser and session identifiers, for heatmaps and session replay. Microsoft states that recordings are retained for 30 days, with favorites and sampled recordings retained for up to 9 months. Our project's settings have not yet been independently confirmed. See Clarity retention information.
- Cloudflare Web Analytics receives page-view and browser performance information, including load timings and page paths, through a beacon. Its configured retention period has not yet been confirmed.
Reject analytics stops these analytics sends for the current page, including pending session-replay and navigation flushes, and clears accessible first-party analytics cookies for Google Analytics, Clarity and Zaraz. It also requests server-side removal of analytics cookies, including the HttpOnly Zaraz client cookie that page scripts cannot remove. If that request fails, a notice asks you to retry through Privacy choices; analytics stays off and the dialog stays closed until you open it. It also clears campaign attribution stored by this site. Essential privacy-choice storage remains so we can honor your decision on later visits. Withdrawal prevents new collection; it does not erase data already received by a processor. Cookie lifetimes and server-side data retention are separate.
5. Retention period
Contact and account records are kept while the relationship or requested communication remains active. Consent records, non-PII compliance trace evidence, and security logs may be kept longer where needed to prove workflow integrity, prevent abuse, or preserve lawful compliance history. Raw uploads, prompts, and telemetry are retained only as long as needed for product, security, support, or legal purposes. Keyed abuse-prevention comparison records are deleted after 72 hours and their review flags after 30 days, on an automated schedule.
6. Your rights
You can ask to access, correct, erase, and port your personal data. You can also object, restrict processing, withdraw consent, or ask for a copy of consent evidence. Email privacy requests to flux@clause5.io.
7. Deletion and anonymization limits
When consent is withdrawn, Clause5 redacts or anonymizes PII that is no longer lawful to retain, severs or rotates linkable references where possible, and preserves non-PII qualification and compliance audit history. Some audit evidence cannot be deleted without breaking compliance trace integrity, but it must not contain raw welder PII.
8. Processor categories
The analytics processors are named above. We also use category-based service providers: edge infrastructure provider, database provider, email delivery provider, payment processor, AI processing provider, security provider, and analytics or consent-management provider. Exact processor details are maintained in an internal registry with owner, update cadence, and change procedure.
9. Updates
This policy is reviewed when processors, data categories, purposes, retention periods, or consent mechanics change. The current change procedure updates the internal processor registry, shared policy metadata, public policy copy, and automated privacy tests before deployment.
10. Contact
Privacy questions, deletion requests, and DPO-style requests can be sent to flux@clause5.io. Security reports can be sent to security@clause5.io.