← Back to site

Privacy Policy

Last updated: 12 June 2026
Starting point. This is a template privacy policy, not legal advice. Have a qualified data-protection lawyer review and adapt it before you publish or collect personal data.

CleanDesk (“CleanDesk”, “we”, “us”) helps financial firms build and validate their DORA Register of Information. This policy explains what personal data we process and your rights under the EU General Data Protection Regulation (GDPR).

1. Who we are

The data controller is CleanDesk. For any privacy question or to exercise your rights, contact [email protected].

2. Information we collect

3. How and why we use it

We process this data to provide and improve the service, respond to your enquiries, and meet our legal obligations. Our legal bases are the performance of a contract with you, our legitimate interests in operating and improving CleanDesk, and your consent where required (e.g. marketing email).

4. Sub-processors

The website is served as static files via Cloudflare (content delivery and edge security). The validator runs in your browser, so your register data is not sent to any processor. If you email us, that correspondence is handled by our email provider. Any email you submit to receive your gap report is stored by Cloudflare (our hosting provider) on our behalf. We do not use advertising or analytics processors, and we never sell your data.

Acting as your data processor (managed service)

The "processed only in your browser" statements above describe our free, self-serve validator. If you engage our managed or pilot service and send us your register or vendor data (for example by email) so we can review, fix or file it for you, we process that data on your behalf, as your data processor, only to provide the service. We keep it only as long as needed, apply appropriate security, never sell it or use it for anything else, and return or delete it when the work is done. That processing is governed by a Data Processing Agreement, which we will sign with you on request.

5. International transfers

Your register data stays in your browser and is not transferred anywhere. For the limited contact data above, where any processing occurs outside the EEA it is protected by appropriate safeguards such as Standard Contractual Clauses.

6. How long we keep it

We keep the contact data you send us only for as long as needed to respond to you and keep reasonable business records, unless a longer period is required by law. Register data is never stored by us — it lives only in your browser until you clear it. You can request deletion of your contact data at any time.

7. Your rights

Under the GDPR you may access, correct, delete, restrict, or port your personal data, and object to certain processing. You can also withdraw consent and lodge a complaint with your local data protection authority. To exercise any right, email [email protected].

8. Security

Data is encrypted in transit and at rest, access is restricted on a need-to-know basis, and our in-browser validator processes data locally on your device. No method is perfectly secure, but we work to protect your data using appropriate technical and organisational measures.

9. Cookies

CleanDesk uses no cookies, trackers or analytics. The validator may keep your working register in your browser's local storage so you don't lose it — that stays on your device, and you can clear it at any time.

10. Children

CleanDesk is a business service and is not directed at anyone under 18.

11. Changes

We may update this policy and will post the new version here with a revised date. Material changes will be notified to account holders.

12. Contact

Questions or requests: [email protected].