Privacy Policy

This policy explains what personal data Clear Now Customs Ltd collects, why we collect it, who we share it with, and what rights you have. It covers this website and the customs brokerage services we provide.

Who we are

Clear Now Customs Ltd is the data controller.

  • Company registration (CRO): 798081
  • EORI: IE4480804MH (IE) · GB047761986000 (GB)
  • Registered office: Saggart, Co. Dublin, Ireland
  • Privacy contact: info@clearnow.eu

What we collect, and why

1. Website visitors

DataWhyLegal basis
Enquiry form: your name, email address, subject and message To answer your enquiry and, if it leads somewhere, to quote for work Legitimate interests (responding to someone who contacted us), moving to contract if we go on to work together
Server logs kept by our hosting provider (IP address, request, timestamp) Security, abuse prevention and keeping the site running Legitimate interests (operating a secure service)

Enquiry-form submissions are emailed to us. They are not stored in a database on this website.

2. Clients and prospective clients

To act as your customs agent we process business contact details, EORI and VAT numbers, representation authorisations, and the commercial documents behind each declaration — invoices, packing lists, transport documents and certificates. Most of this is company information rather than personal data, but it commonly contains named individuals, so we treat it as personal data throughout.

Legal basis: performance of our contract with you, and compliance with legal obligations under the Union Customs Code and Irish and UK customs and tax law.

3. Hauliers, drivers and other third parties

Creating a Goods Movement Reference (GMR) or a declaration means processing data about people who are not our clients — typically driver names and vehicle or trailer registrations supplied to us by a client or a haulier.

Legal basis: legal obligation (this data is required by HMRC and Revenue for the movement to be lawful) and legitimate interests in completing the movement we were engaged to handle.

Third parties who process data for us

We do not sell personal data. We share it only with the processors below, and only for the purposes described.

ProcessorWhat it handlesWhere
Google — Gemini API Client commercial documents. We use an automated extraction tool to read invoices and supporting documents and turn them into declaration data. The document — including any names, addresses, EORI numbers and values it contains — is transmitted to Google's Gemini API for processing. We use the paid tier, under which Google does not use submitted content to train its models and does not subject it to human review. United States. See international transfers below.
Hostinger Website and application hosting, email European Union
Revenue (Ireland) and HMRC (UK) Declaration and movement data, as required by law. These are recipients in their own right, not our processors. Ireland / United Kingdom

International transfers

Google processes client documents on servers in the United States. Transfers outside the European Economic Area are made under the safeguards permitted by Chapter V of the GDPR — the EU–US Data Privacy Framework where the recipient is certified, or Standard Contractual Clauses. You can ask us which mechanism applies to a particular processor.

The Gemini transfer is the one most likely to matter to a client, so to be explicit: if you send us a commercial invoice, that document is processed by Google in the United States. If you would prefer your documents were not processed this way, tell us and we will handle them manually instead.

How long we keep it

DataRetention
Customs declarations and their supporting documents Six years. The Union Customs Code requires at least three years (Article 51), but Irish VAT and company law require six, so six is the period we work to.
Accounting and invoicing recordsSix years
Enquiries that do not become workUp to 24 months, then deleted

Your rights

Under the GDPR and the Data Protection Act 2018 you can ask us to:

  • give you a copy of the personal data we hold about you (access);
  • correct data that is wrong or incomplete (rectification);
  • delete data (erasure) — though we cannot delete records we are legally required to retain for customs or tax purposes;
  • restrict or object to a particular use, including any processing we base on legitimate interests;
  • receive data you gave us in a portable format;
  • withdraw consent at any time, where consent is the basis we rely on.

Email info@clearnow.eu and we will respond within one month. There is no charge unless a request is manifestly unfounded or excessive.

If you are not satisfied with how we have handled your data, you can complain to the Data Protection Commission, 6 Pembroke Row, Dublin 2, D02 X963 — dataprotection.ie.

Security

Access to our systems requires an individual account, and staff accounts are protected by two-factor authentication. Client documents are stored outside the public web root and are reachable only through an authenticated application. Financial records are held in an append-only ledger that cannot be silently edited or deleted. Backups are encrypted before they leave our systems.

Changes to this policy

If we change how we handle personal data we will update this page and the date at the top. Material changes affecting clients will also be notified directly.