Privacy Policy
Last updated 24 July 2026
Who we are
Sacred Logic™ A.I. ("Sacred Logic™", "we") is operated by Sacred Logic Ltd., Kilkeedy, Tubber, Co. Clare, Ireland, which is the data controller for the site. We have not appointed a statutory Data Protection Officer (we are not currently required to); for any privacy or data-protection matter, contact us at burren.art.gallery@gmail.com.
What this policy covers
This policy covers the whole Sacred Logic™ site: the free self-assessment tool, the Charter Mark Registry, Charter Mark certification and payment (Organisations section), and the free consumer supplier-search portal. The consumer portal has an additional, more detailed notice at /consumers/consent covering the specific purpose of sharing searcher details with AI suppliers as leads — that notice is the authoritative one for that particular processing activity; this page is the general policy for everything else.
What we collect
Depending on how you use the site: account details if you sign up (name, email, via Clerk); self-assessment answers (Part A risk questions, Part B documentation-readiness answers) — these aren't linked to a personal account unless you're signed in when you submit; organisation registration details if you register for Charter Mark pricing (organisation name, sector, size, postal address, company phone and email, plus the registering person's name, salutation, direct email, and phone number); payment details if you purchase a Charter Mark subscription (payment card details are handled directly by Stripe — we never see or store full card numbers); and, if you use the consumer portal, the lead data described in the consumer consent notice linked above.
Assessment follow-up (optional)
After completing the free self-assessment, you can choose to leave your email address so we can follow up with a copy of your result and next steps. If you do, we store your email together with that assessment's result (risk level, readiness score, and tier recommendation), on the legal basis of your consent (GDPR Article 6(1)(a)) given via the checkbox on that form. We use it only to follow up with you about certification, and you can withdraw consent at any time by contacting us — the assessment itself never requires this and stays anonymous unless you opt in.
Why we collect it and our legal basis
To provide the service you've asked for (contract, GDPR Article 6(1)(b)) — running your account, processing self-assessments, fulfilling Charter Mark subscriptions; to meet legal obligations such as tax and accounting records (Article 6(1)(c)); and, for the consumer portal's lead-sharing specifically, your explicit consent (Article 6(1)(a) — see the consumer consent notice).
Who we share it with
Service providers who help us run the site: Clerk (accounts and sign-in), Stripe (payment processing), and Convex (application database) — each processes data on our behalf under their own data processing terms, not for their own purposes. For the consumer portal specifically, AI solution providers as described in the consumer consent notice. We don't sell personal data.[Confirm and document each sub-processor's data location and transfer mechanism before real launch — see caveat block in this file.]
International transfers
Our service providers (Clerk, Stripe, Convex, and Vercel, which hosts the site) may process data outside the European Economic Area, including in the United States. Where they do, transfers are made under an appropriate safeguard — an EU adequacy decision (such as the EU–US Data Privacy Framework where the provider is certified) or the European Commission's Standard Contractual Clauses.[Confirm the exact transfer mechanism relied on for each provider with counsel before real launch — see caveat block in this file.]
Cookies
We use only cookies that are strictly necessaryfor the site to function: Clerk's sign-in session cookie, Stripe's checkout session cookie (set only when you reach payment), and a Convex functional cookie for the application connection. For usage measurement we use Vercel Web Analytics and Speed Insights, which are privacy-friendly and cookieless — they set no cookies and do not track you across sites. Because we set no advertising or non-essential tracking cookies, no cookie-consent banner is required under the ePrivacy rules. Full detail is in our Cookie Policy; if we ever add non-essential cookies, we will request consent first.
Public registry publication
When a Charter Mark is issued, a limited set of information is published on the public registry and certificate: the organisation name, certification tier, certificate ID, scope, the framework version applied, and the issue and validity dates (and, for a Compliance Fast Track mark, the declared conformity basis). The underlying application data is never published. A listing is created in connection with the organisation's certification; an organisation can request a correction, or removal on expiry or revocation, by contacting us.
Automated decision-making
The free self-assessment scores your answers automatically to give an instant, provisional risk classification, readiness score, and tier suggestion. This is informational only. We do not make any decision that produces a legal or similarly significant effect about you solely by automated means: a Charter Mark is issued only after a human validation step by Sacred Logic™.
Security
Authentication is handled by Clerk; access to privileged data and admin functions is enforced on the server against a cryptographically-verified identity, never a client-supplied value. Payment card data is handled directly by Stripe and never reaches our systems. Data is transmitted over encrypted connections (TLS). We apply appropriate technical and organisational measures, keep an append-only audit log of administrative actions, and restrict access on a need-to-know basis. No system is perfectly secure, but we work to protect your data and to respond promptly to any incident.
How long we keep it
We keep personal data only as long as needed for the purpose it was collected: account and organisation records for as long as your account is active and for a reasonable period afterwards; financial and tax records for the period required by Irish law (generally six years); assessment follow-up and consumer-portal leads until you ask us to delete them or they are no longer needed; and administrative audit-log entries as a retained record of scheme governance. Consumer portal consent records are kept as described in the consumer consent notice.[Finalise a documented retention schedule with counsel before real launch — see caveat block in this file.]
Your rights
Under the GDPR / UK GDPR you can: access the data we hold about you; correct it; ask us to delete it; restrict or object to processing; ask for a copy in a portable format; and withdraw consent at any time (where consent is the legal basis). To exercise any of these, contact us at burren.art.gallery@gmail.com. You also have the right to lodge a complaint with a data protection authority — in Ireland, the Data Protection Commission (dataprotection.ie); in the UK, the Information Commissioner's Office (ico.org.uk); or your local authority in another EU/EEA country. We'd appreciate the chance to resolve it with you first.
Children
The site and its services are intended for organisations and for individuals aged 18 or over, and are not directed at children. We do not knowingly collect personal data from anyone under 18.
Changes to this policy
If we make material changes, we'll update the "Last updated" date above. Continued use of the site after a change means you accept the updated policy.
This policy is a good-faith summary and has not yet been reviewed by a lawyer. Questions about our data practices? Contact burren.art.gallery@gmail.com.