Privacy

Last updated: 1 October 2026

The short version

1. Who is responsible

In The Clear is run by a sole trader registered in Serbia. We decide how your personal data is used, so we are the "controller" under the EU General Data Protection Regulation (GDPR) and the Serbian Law on Personal Data Protection.

For anything about your data, email hello@getintheclear.com.

2. Visiting this website

This website is hosted on GitHub Pages, a service of GitHub, Inc. in the United States. When you visit, GitHub records your IP address to deliver the pages and keep the service secure. We cannot see these logs and do not use them. GitHub handles them under its own privacy statement.

The site sets no cookies and has no analytics, tracking pixels or social media plugins. Fonts are served from this website itself, so your browser does not contact Google or other font services.

3. The scope check form

The "Book a review" buttons open our scope check form. It runs on Notion, a service of Notion Labs, Inc. in the United States. Your answers go straight into our Notion workspace.

What we collect

Why, and on what basis

We use your answers to understand your website and prepare a fixed-price quote. We use your email address to send you that quote and to answer your questions about it. We do not use it for anything else. The legal basis is taking steps at your request before entering into a contract (GDPR article 6(1)(b)).

Please do not put sensitive personal data in the free-text box. We do not need it.

Notion also processes some technical data, such as your IP address, when you load the form. See Notion's privacy policy.

4. Email

Our email runs on Google Workspace, a service of Google. When you email us, we receive your email address, name and whatever you write. We use it to answer you. The legal basis is our legitimate interest in answering messages (article 6(1)(f)), or steps towards a contract if you ask about a review (article 6(1)(b)).

5. When we contact you first

We sometimes email businesses whose websites may fall under the European Accessibility Act. For that, we use business contact details that are published on the company's own website, such as a name, role and work email address. We keep a short note of who we contacted and when.

The legal basis is our legitimate interest in offering our services to businesses (article 6(1)(f)). Every such email tells you how to say no. If you do, we stop and keep only your email address on a do-not-contact list, so we do not email you again.

6. Clients

When your business books a review, we handle the names, work email addresses and phone numbers of the people we work with, plus the details on quotes, invoices and payments. We use them to do the work, invoice and keep our accounts.

The legal basis is the contract with your business and our legitimate interest in working with its staff (article 6(1)(b) and (f)), and our legal duties under accounting and tax law (article 6(1)(c)).

7. Data we see while reviewing a website

A review looks at how a website works, not at the people who use it. Still, while testing we may see personal data on a client's site, for example in a test account, a customer review or a staging copy. Our screenshots can capture it too.

If you are a visitor of one of our clients' websites and have a question about your data, contact that business first. We will help them answer you.

8. Who else handles your data

We do not sell personal data or share it for advertising. We use these service providers, who process data for us under data processing terms:

We may also share data with our accountant, our bank and the tax authorities, where accounting or tax law requires it, and with authorities or courts when the law requires it.

9. Data outside the EU

We are based in Serbia. The European Commission has not made an "adequacy decision" for Serbia, a finding that a country protects personal data at the same level as the EU. Because we offer our services in the EU, we apply the GDPR to the personal data of people in the EU anyway. Serbian data protection law is also closely based on the GDPR.

Some of our service providers are in the United States:

Ask us if you want a copy of the safeguards that apply to your data.

10. How long we keep it

11. How we keep it safe

We protect personal data with security measures that fit the risk. Access is limited to the people who do the work, and we only use established service providers. If a data breach puts your rights at risk, we will tell you and the authorities as the law requires.

12. Your rights

You have the right to:

Email hello@getintheclear.com. We answer within one month. We may ask you to confirm who you are first.

We do not make decisions about you by automated means only, and we do not create profiles of you.

You can also complain to a data protection authority. You can choose the one in the EU country where you live or work, such as the Autoriteit Persoonsgegevens in the Netherlands or the Data Protection Authority (Gegevensbeschermingsautoriteit) in Belgium. In Serbia, it is the Commissioner for Information of Public Importance and Personal Data Protection. We would be glad if you came to us first.

13. Changes to this policy

If we change how we use personal data, we update this page and the date at the top. If a change affects you as a client, we tell you by email.