ClearStateNetwork.com is operated by:
VND Scandinavia AB
STYRMANSGATAN 2, 2 TR
114 54 Stockholm
Sweden
Company registration number: 556703-0381
Contact: [email protected]
In this Privacy Policy, “ClearState”, “we”, “us” or “our” means VND Scandinavia AB.
This Privacy Policy explains how we process personal data when you use ClearStateNetwork.com, RuleState, account pages, dashboards, evaluation services and related communications.
ClearState is a B2B service. It is intended for business and organisational use, not consumer use.
ClearState provides policy analysis and evaluation support.
When you run a check, your document or policy text is processed on ClearState’s servers so the service can read it. The original file is not stored.
If you create an account and save a review in progress, we save the text extracted from your document and the working information needed to continue — not the file. Frozen rulebooks and saved work are stored in the EU.
Your content is never used to train AI models.
We may process the following categories of personal data:
Account and user data
Business and policy content
You may submit documents, policy text, approval policies, operational rules, business descriptions or similar content.
This content may contain personal data if you or your organisation include names, email addresses, roles, employee identifiers, customer identifiers or other information relating to individuals.
Service usage data
We may process technical and usage information such as:
Communication data
If you contact us, we may process:
When you run a check, your document or policy text is sent to ClearState’s servers to be read so the service can be provided. The original file is not stored.
If you create an account and save a review in progress, ClearState saves the text extracted from your document and the working information needed to continue. The original document is not saved; you upload it again to continue.
When you freeze a rulebook, ClearState saves the frozen rulebook: the confirmed rules, the passages they came from, who confirmed and when.
Frozen rulebooks and saved work are stored in the EU.
The purpose of frozen records is to support later review, consistency and traceability.
We process personal data to:
Depending on the situation, we process personal data based on:
For account data, usage data, support data and service administration, VND Scandinavia AB normally acts as data controller.
For personal data included in policy text or business content submitted by a customer, the customer may be the controller and VND Scandinavia AB may act as processor, depending on the circumstances and the customer’s use of the service.
A separate data processing agreement may be required for certain customer use cases.
ClearState may use automated processing to analyse policy text and provide the service.
Your content is never used to train AI models.
We do not use customer content to build public AI models or train third-party AI models.
ClearState may use necessary cookies or similar technologies for login, security and service operation.
Marketing pages may use privacy-conscious analytics to understand website usage.
We do not place third-party marketing or analytics scripts on policy paste pages unless this is expressly changed and disclosed.
We may use email to provide login codes, account messages, support replies, service notices, security notifications and operational communications.
Authentication may use one-time passcodes or similar login methods.
Frozen rulebooks and saved work are stored in the EU.
Some service providers, infrastructure providers or processing activities may operate outside the EU/EEA. We do not promise that all processing happens only in the EU.
Where personal data is transferred internationally, we use appropriate safeguards where required by applicable data protection law.
We keep personal data only for as long as needed for the purposes described in this Privacy Policy, unless a longer period is required or permitted by law.
Current retention principles:
We use reasonable technical and organisational measures to protect personal data against unauthorised access, loss, misuse and alteration.
No system is completely secure. You are responsible for using the service responsibly, controlling who can access your organisation, and avoiding submission of unnecessary sensitive data.
We may share personal data with:
We do not sell personal data.
Depending on applicable law and your location, you may have rights to:
Requests can be sent to: [email protected]
If you are in Sweden or the EU, you may also contact the Swedish Authority for Privacy Protection, IMY.
Because ClearState is a B2B service, customers may submit policy text or business content that contains personal data about their own employees, customers, suppliers or other individuals.
The customer is responsible for ensuring that it has the right and legal basis to submit that information to ClearState.
Customers should avoid submitting unnecessary personal data, special category data, secrets, passwords, private keys or payment card data.
If self-service deletion or export is not available in the product, requests can be sent to: [email protected]
We will handle requests in accordance with applicable law, technical feasibility, account ownership, security requirements and retention obligations.
Some records may need to be retained where required for legal claims, auditability, security, contractual obligations or the purpose for which the record was created.
ClearState is not intended for children or consumer use.
We do not knowingly provide the service to children.
We may update this Privacy Policy from time to time. The updated version will be published on ClearStateNetwork.com or otherwise made available through the service.
If a change is material, we will take reasonable steps to notify affected users.
Questions, privacy requests or data protection requests can be sent to: