ClearStateNetwork.com is operated by:
VND Scandinavia AB
STYRMANSGATAN 2, 2 TR
114 54 Stockholm
Sweden
Company registration number: 556703-0381
Contact: [email protected]
In this Privacy Policy, “ClearState”, “we”, “us” or “our” means VND Scandinavia AB.
This Privacy Policy explains how we process personal data when you use ClearStateNetwork.com, RuleState, account pages, dashboards, evaluation services and related communications.
ClearState is a B2B service. It is intended for business and organisational use, not consumer use.
ClearState provides policy analysis and evaluation support.
Policy text stays in your browser until you choose to validate or extract it. When you validate or extract policy text, it may be sent to ClearState’s servers to provide the service.
Nothing is saved before you sign in and freeze a decision. Saved records are stored in the EU.
Your content is never used to train AI models.
We may process the following categories of personal data:
Account and user data
Business and policy content
You may submit policy text, approval policies, operational rules, business descriptions or similar content.
This content may contain personal data if you or your organisation include names, email addresses, roles, employee identifiers, customer identifiers or other information relating to individuals.
Service usage data
We may process technical and usage information such as:
Communication data
If you contact us, we may process:
Before validation or extraction, policy text stays in your browser.
When you choose to validate or extract policy text, it may be sent to ClearState’s servers to provide the service.
Before sign-in and freeze, policy text is not saved as a record.
When you sign in and freeze a decision, ClearState may save records connected to that decision. Saved records are stored in the EU.
The purpose of frozen records is to support later review, consistency and traceability.
We process personal data to:
Depending on the situation, we process personal data based on:
For account data, usage data, support data and service administration, VND Scandinavia AB normally acts as data controller.
For personal data included in policy text or business content submitted by a customer, the customer may be the controller and VND Scandinavia AB may act as processor, depending on the circumstances and the customer’s use of the service.
A separate data processing agreement may be required for certain customer use cases.
ClearState may use automated processing to analyse policy text and provide the service.
Your content is never used to train AI models.
We do not use customer content to build public AI models or train third-party AI models.
ClearState may use necessary cookies or similar technologies for login, security and service operation.
Marketing pages may use privacy-conscious analytics to understand website usage.
We do not place third-party marketing or analytics scripts on policy paste pages unless this is expressly changed and disclosed.
We may use email to provide login codes, account messages, support replies, service notices, security notifications and operational communications.
Authentication may use one-time passcodes or similar login methods.
Saved records are stored in the EU.
Some service providers, infrastructure providers or processing activities may operate outside the EU/EEA. We do not promise that all processing happens only in the EU.
Where personal data is transferred internationally, we use appropriate safeguards where required by applicable data protection law.
We keep personal data only for as long as needed for the purposes described in this Privacy Policy, unless a longer period is required or permitted by law.
Current retention principles:
We use reasonable technical and organisational measures to protect personal data against unauthorised access, loss, misuse and alteration.
No system is completely secure. You are responsible for using the service responsibly, controlling who can access your organisation, and avoiding submission of unnecessary sensitive data.
We may share personal data with:
We do not sell personal data.
Depending on applicable law and your location, you may have rights to:
Requests can be sent to: [email protected]
If you are in Sweden or the EU, you may also contact the Swedish Authority for Privacy Protection, IMY.
Because ClearState is a B2B service, customers may submit policy text or business content that contains personal data about their own employees, customers, suppliers or other individuals.
The customer is responsible for ensuring that it has the right and legal basis to submit that information to ClearState.
Customers should avoid submitting unnecessary personal data, special category data, secrets, passwords, private keys or payment card data.
If self-service deletion or export is not available in the product, requests can be sent to: [email protected]
We will handle requests in accordance with applicable law, technical feasibility, account ownership, security requirements and retention obligations.
Some records may need to be retained where required for legal claims, auditability, security, contractual obligations or the purpose for which the record was created.
ClearState is not intended for children or consumer use.
We do not knowingly provide the service to children.
We may update this Privacy Policy from time to time. The updated version will be published on ClearStateNetwork.com or otherwise made available through the service.
If a change is material, we will take reasonable steps to notify affected users.
Questions, privacy requests or data protection requests can be sent to: