Privacy Policy
Version 14 August 2026 · effective and last updated 14 August 2026 · last reviewed 14 August 2026
Who we are
Sacred Logic™ A.I. ("Sacred Logic™", "we") is operated by Sacred Logic Ltd., Kilkeedy, Tubber, Co. Clare, Ireland. We have not appointed a statutory Data Protection Officer (we are not currently required to); for any privacy or data-protection matter, contact us at [email protected].Our role. For most of the site — accounts, the self-assessment tool, the consumer portal, our own business records, and the certificate/ registry information we publish — we are the data controller: we decide the purposes and methods of that processing. For an organisation customer's certification application materials specifically (“Application Data”), we act as a processor: we process that data, including in the course of assessing it against the Human Values Framework and reaching a certification outcome, solely on the customer's documented instructions, as set out in our Data Processing Agreement for organisation customers.
What this policy covers
This policy covers the whole Sacred Logic™ site: the free self-assessment tool, the Charter Mark Registry, Charter Mark certification and payment (Organisations section), and the free consumer supplier-search portal. The consumer portal has an additional, more detailed notice at /consumers/consent covering the specific purpose of sharing searcher details with AI suppliers as leads — that notice is the authoritative one for that particular processing activity; this page is the general policy for everything else.
What we collect
Depending on how you use the site: account details if you sign up (name, email, via Clerk); self-assessment answers (Part A risk questions, Part B documentation-readiness answers) — these aren't linked to a personal account unless you're signed in when you submit; organisation registration details if you register for Charter Mark pricing (organisation name, sector, size, postal address, company phone and email, plus the registering person's name, salutation, direct email, and phone number); payment details if you purchase a Charter Mark subscription (payment card details are handled directly by Stripe — we never see or store full card numbers); and, if you use the consumer portal, the lead data described in the consumer consent notice linked above.
Assessment follow-up (optional)
After completing the free self-assessment, you can choose to leave your contact details — your email address (required to send you a copy) and, optionally, your name and phone number — so we can send you a personalised copy of your results and follow up about certification. If you do, we store those details together with that assessment's result (risk level, readiness score, and tier recommendation) on the legal basis of your consent (GDPR Article 6(1)(a)) given via the checkbox on that form. Your results copy is sent to you by email, and a notification containing the details you provided is also sent to the Sacred Logic™ certification team at [email protected]. We use the information only to follow up with you about certification, and you can withdraw consent at any time by contacting us — the assessment itself never requires this and stays anonymous unless you opt in.
Electronic marketing (email, phone, SMS)
Sending direct marketing by email, phone, or SMS to individuals in Ireland/the EU is separately regulated by Ireland's ePrivacy Regulations (S.I. No. 336 of 2011, Regulation 13), on top of the GDPR. Here's how that applies to each contact point on the site:Assessment follow-up emails (above) are the only direct marketing we currently send ourselves, and only with your prior opt-in consent given via that form's checkbox — never bundled with anything else. Every such email includes a clear way to unsubscribe, and doing so (or withdrawing consent through us) stops future emails without affecting anything else.Organisation registration contacts. Emails about an active certification — renewal reminders, expiry or suspension notices, required evidence updates — are service communications tied to an existing contract, not marketing, so Regulation 13 consent doesn't apply to them. If we ever want to send this contact promotional content beyond that (for example about a new tier or feature), we'll either ask for consent first or rely on the "existing customer" exception in Regulation 13(11) — similar products/services only, with a clear opt-out offered both when we first collected the contact details and in every message — and every such message will include an unsubscribe option.Phone and SMS. We do not currently use any phone number you give us (on registration or in the consumer portal) for marketing calls or texts — only as an optional contact method you've provided.Consumer portal lead-sharing. If an AI solution provider contacts you directly after a lead is shared, that supplier is responsible for its own compliance with Regulation 13 (and the equivalent rules wherever you're located) for that contact — see the consumer consent notice for what we require of suppliers before any sharing happens.
Why we collect it and our legal basis
To provide the service you've asked for (contract, GDPR Article 6(1)(b)) — running your account, processing self-assessments, fulfilling Charter Mark subscriptions; to meet legal obligations such as tax and accounting records (Article 6(1)(c)); and, for the consumer portal's lead-sharing specifically, your explicit consent (Article 6(1)(a) — see the consumer consent notice).
Who we share it with
Service providers who help us run the site: Clerk (accounts and sign-in), Convex (application database), and Vercel (hosting) — each processes data on our behalf, under our instructions, as our processor, not for their own purposes. If you use the AI chat assistant, your messages are sent to Google (Gemini API) to generate a reply — see "AI assistant (chatbot)" below. For the consumer portal specifically, AI solution providers as described in the consumer consent notice. We don't sell personal data.Transactional e-mail. If we send you an automated e-mail (for example a renewal reminder), it's sent via Resend, our transactional e-mail provider, on the same processor basis as our other service providers above. This feature is optional and only sends mail when configured; where it isn't, we contact you directly instead (e.g. a mailto link).Stripe is different. Stripe processes your payment details as our processor for the transaction itself, but Stripe also acts as an independent controller for its own regulatory, fraud-prevention, and financial-compliance purposes (for example, know-your-customer and anti-money-laundering checks) under Stripe's own privacy policy. We don't control, and this policy doesn't cover, that separate use.
International transfers
Our service providers process data outside the European Economic Area, including in the United States, as follows: Clerk (US) and Vercel (US, and other locations where Vercel or its sub-processors operate) rely on the European Commission's Standard Contractual Clauses (and the UK Addendum); Stripe processes data outside the EEA (it does not offer EEA data residency) under the EU–US Data Privacy Framework and Standard Contractual Clauses; Convex publishes its own GDPR and data-processing terms, and Google (Gemini API, for the chat assistant) processes data as described above. Where you use the consumer portal, AI solution provider recipients are described in the consumer consent notice.We are in the process of confirming current executed transfer terms directly with each provider and will update this section when that review is complete.
Cookies
We use only cookies that are strictly necessary for the site to function: Clerk's sign-in session cookie, Stripe's checkout session cookie (set only when you reach payment), and a Convex functional cookie for the application connection. For usage measurement we use Vercel Web Analytics and Speed Insights, which are privacy-friendly and cookieless — they set no cookies and do not track you across sites. Because we set no advertising or non-essential tracking cookies, no cookie-consent banner is required under the ePrivacy rules. Full detail is in our Cookie Policy; if we ever add non-essential cookies, we will request consent first.
Public registry publication
When a Charter Mark is issued, a limited set of information is published on the public registry and certificate: the organisation name, certification tier, certificate ID, scope, the framework version applied, and the issue and validity dates (and, for a Compliance Fast Track mark, the declared conformity basis). The underlying application data is never published. A listing is created in connection with the organisation's certification; an organisation can request a correction, or removal on expiry or revocation, by contacting us.
Automated decision-making
The free self-assessment scores your answers automatically to give an instant, provisional risk classification, readiness score, and tier suggestion. This is informational only. We do not make any decision that produces a legal or similarly significant effect about you solely by automated means: a Charter Mark is issued only after a human validation step by Sacred Logic™. The provisional score itself isn't a decision and can't be appealed, but the resulting certification decision can be, under the Certification Rules' complaints and appeals procedure.
AI assistant (chatbot)
The site has an optional AI chat assistant. If you use it, your messages (and the assistant's replies) are sent to Google, via the Gemini API, to generate a response, and may be logged by us (associated with a salted, non-reversible identifier derived from your IP address, not your account) to monitor abuse and improve the assistant's answers.We currently use Gemini's free tier. Under Google's terms, content submitted to free-tier use can be used by Google to improve its own products, and may be read by human reviewers for quality purposes (Google states this data is disconnected from your Google account before review) — except that Google applies its paid-tier, non-training data terms to all users located in the EEA, Switzerland, and the UK, even on the free tier. Please don't share sensitive personal information with the chat assistant.
Security
Authentication is handled by Clerk; access to privileged data and admin functions is enforced on the server against a cryptographically-verified identity, never a client-supplied value. Payment card data is handled directly by Stripe and never reaches our systems. Data is transmitted over encrypted connections (TLS). We apply appropriate technical and organisational measures, keep an append-only audit log of administrative actions, and restrict access on a need-to-know basis. No system is perfectly secure, but we work to protect your data and to respond promptly to any incident.
How long we keep it
We keep personal data only as long as needed for the purpose it was collected, on the following documented retention schedule:Account and organisation records — for as long as the account is active, plus 24 months afterwards.Certification application data (Application Data, incl. uploaded evidence) — for the life of the certification plus 24 months, or 24 months from a declined application, whichever applies — enough to support a renewal, appeal, or complaint, per Terms of Service § 6.Financial and tax records — the period required by the law of the Republic of Ireland (generally six years).Self-assessment follow-up and consumer-portal leads — until you ask us to delete them, or 24 months of inactivity, whichever is sooner.Chat assistant logs — 90 days, kept only for abuse-monitoring and quality purposes.Administrative audit-log entries — retained indefinitely as a permanent record of scheme governance (decisions, suspensions, revocations).Registry and certificate records — retained indefinitely as the public record of certification history, including after expiry, non-renewal, or revocation (the entry is marked accordingly rather than deleted), consistent with the audit-trail function of the register.Support and contact communications (e-mails to our contact address) — kept for up to 24 months from the last message in a thread, or longer if they form part of an Application Data, complaint, or audit record covered elsewhere in this schedule.Backups. Routine service backups may retain a copy of data for a limited period after it is deleted from the live system (typically no more than 30–90 days, depending on the provider), purely for disaster recovery, and are not used for any other purpose.Complaints, appeals and misconduct reports — kept for 24 months after the matter is closed, as our record of how it was handled, except where a longer period is needed for an active dispute, audit, or legal claim.Consumer portal consent records are kept as described in the consumer consent notice.
Retention at a glance
- Accounts / organisations
- Active + 24 months
- Application Data (certification)
- Cert. life + 24 months (or 24 months from decline)
- Financial / tax records
- 6 years
- Assessment & consumer leads
- 24 months of inactivity
- Chat assistant logs
- 90 days
- Admin audit log
- Indefinite
- Registry / certificate records
- Indefinite (marked, not deleted)
- Support e-mails
- 24 months from last message
- Complaints / appeals / misconduct
- 24 months after closed
- Deleted accounts (personal data)
- Removed immediately from the live system on request
- Backups
- 30–90 days post-deletion
Your rights
Under the GDPR / UK GDPR you can: access the data we hold about you; correct it; ask us to delete it; restrict or object to processing; ask for a copy in a portable format; and withdraw consent at any time (where consent is the legal basis). To exercise any of these, contact us at [email protected]. You also have the right to lodge a complaint with a data protection authority — in Ireland, the Data Protection Commission (dataprotection.ie); in the UK, the Information Commissioner's Office (ico.org.uk); or your local authority in another EU/EEA country. We'd appreciate the chance to resolve it with you first.
Children
The site and its services are intended for organisations and for individuals aged 18 or over, and are not directed at children. We do not knowingly collect personal data from anyone under 18.
Changes to this policy
If we make material changes, we'll update the "Last updated" date above. Continued use of the site after a change means you accept the updated policy.
Questions about our data practices? Contact [email protected].