Legal

Privacy Policy

Last updated: 25 June 2026 Version 1.0 Clarity Codes App and Websites (claritty.com and clarity.codes)

1. Introduction

1.1 This Privacy Policy explains how Professional Hair Products Limited, trading as Professional Hair Labs ("we", "us", "our"), collects, uses, shares and protects personal data when you use the Clarity Codes mobile application (the "App") and the websites at claritty.com and clarity.codes (together, the "Service").

1.2 We are the data controller for the personal data described in this Policy. Our details are:

Controller details Controller: Professional Hair Products Limited
Registered office: Wexford Office & Business Park, Whitemill Industrial Estate, Wexford, Ireland Y35 X0TK
Privacy contact: info@clarity.codes
Data protection point of contact: Privacy Services (info@clarity.codes)

1.3 Our affiliated operations in the United States (located in Zephyrhills, Florida) may process personal data on our behalf as part of our group. Where they do, we remain responsible to you as controller.

1.4 We are committed to processing personal data in accordance with the EU General Data Protection Regulation (Regulation (EU) 2016/679) ("GDPR"), the Data Protection Act 2018 (Ireland), and other applicable data protection laws.

2. Summary of how we use your data

What we collectWhy we use itLegal basis
Scan data (Code scanned, time, App-generated identifiers, approximate location) To produce an Authentication Result and to monitor the integrity of our authentication system Our legitimate interests in providing the Service and protecting our brand; consent for precise location
Report data (your concern, where and when you purchased, optional photos/receipts) To investigate suspected counterfeiting, diversion and unauthorised sales Our legitimate interests in protecting consumers and our intellectual property
Contact details you choose to provide (name, email, phone) To acknowledge and follow up on your Report Our legitimate interests in responding to you, or steps taken at your request
Device and technical data (device type, OS, app version, diagnostics) To operate, secure and improve the Service Our legitimate interests in a secure, functioning Service
Website usage data and cookies To run our websites and understand how they are used Consent (non-essential cookies); legitimate interests (essential operation) - see our Cookie Policy

3. Personal data we collect

3.1 Scan data. When you scan a Code, we may collect the Code identifier, the date and time of the scan, an App-generated device or installation identifier, and the approximate or (with your permission) precise location of the scan. Most scans can be performed without you providing your name or contact details.

3.2 Report data. When you submit a Report, we collect the information you provide about your concern, including where and when you purchased the product, the seller or retailer, and any photographs, receipts or supporting material you choose to attach.

3.3 Contact details. If you choose to provide them, we collect your name, email address and/or telephone number so that we can acknowledge or follow up on your Report. Providing contact details is optional, but without them we may be unable to update you on the outcome of your Report.

3.4 Device and technical data. We collect information about the device and software you use, including device model, operating system, App version, language settings, and diagnostic and crash data.

3.5 Website data. When you visit our websites, we collect information through cookies and similar technologies as described in our Cookie Policy.

3.6 We do not intentionally collect special category personal data. Please do not include such data in a Report unless it is strictly necessary.

4. How and why we use your data

4.1 We use personal data to:

  • (a) operate the App and produce Authentication Results;
  • (b) receive, assess, investigate and act on Reports;
  • (c) investigate, prevent and pursue suspected counterfeiting, product diversion, and unauthorised or unlawful sales of products bearing our brands;
  • (d) protect the health and safety of consumers and the integrity of our products;
  • (e) respond to your queries and communicate with you about your Report;
  • (f) maintain the security, integrity and performance of the Service, including detecting and preventing fraud and misuse;
  • (g) comply with our legal and regulatory obligations; and
  • (h) establish, exercise or defend legal claims.

4.2 Legitimate interests. Where we rely on legitimate interests, those interests are: protecting consumers from unsafe or counterfeit goods; protecting our intellectual property, brand and revenue; maintaining a secure and reliable Service; and pursuing enforcement against counterfeiters. We have considered the impact of this processing on you and have concluded that it does not override your rights and freedoms. You can ask us for more information about this balancing assessment using the contact details below.

4.3 Consent. Where we rely on consent (for example, for precise location or non-essential cookies), you may withdraw it at any time. Withdrawing consent does not affect processing carried out before withdrawal.

5. Counterfeit investigations

5.1 The core purpose of the Service is to help us identify and act against counterfeit, diverted and unauthorised products. The information in your Reports may be combined with scan data and other intelligence to investigate suspicious activity, identify problem sellers and supply chains, and support enforcement action.

5.2 As part of this, we may share relevant information (which may include the purchase details you provide and, where relevant, your contact details) with the parties described in clause 6. We will only share what is reasonably necessary for the investigation.

6. When we share your data

6.1 We may share personal data with:

  • (a) our group companies and affiliates, including our Florida operations, for the purposes described in this Policy;
  • (b) service providers and processors who help us operate the Service (for example, hosting, analytics, customer support and IT providers), under contracts that require them to protect your data and act only on our instructions;
  • (c) law enforcement, customs authorities, regulators and trading standards bodies, where relevant to a counterfeit, safety or legal matter;
  • (d) online marketplaces and platforms (for example, where a counterfeit product was sold online), to enable takedowns and enforcement;
  • (e) our professional advisers, including legal advisers and investigators; and
  • (f) a buyer or successor, if we sell or reorganise our business, subject to appropriate confidentiality protections.

6.2 We may also disclose personal data where required to comply with a legal obligation, court order, or to protect the rights, property or safety of any person.

6.3 We do not sell your personal data.

7. International transfers

7.1 As a group with operations in Ireland and the United States, we may transfer personal data outside the European Economic Area ("EEA"), including to our affiliate and service providers in the United States.

7.2 Where we transfer personal data outside the EEA, we put in place appropriate safeguards, such as the European Commission's Standard Contractual Clauses, an adequacy decision, or another lawful transfer mechanism. You can request a copy of the relevant safeguards using the contact details below.

8. How long we keep your data

8.1 We keep personal data only for as long as necessary for the purposes for which it was collected, including to satisfy legal, accounting, regulatory or reporting requirements.

8.2 In general:

  • (a) scan and technical data are retained for 24 months for service, security and analytics purposes;
  • (b) Report data and related investigation records are retained for as long as necessary to investigate and act on the matter and to establish, exercise or defend legal claims, typically up to 6 years after the matter is concluded; and
  • (c) contact details are retained for the duration of any related correspondence and investigation, and then deleted or anonymised.

8.3 When we no longer need personal data, we securely delete or anonymise it.

9. Security

We use appropriate technical and organisational measures to protect personal data against unauthorised access, loss, misuse or alteration, including access controls, encryption in transit, and limiting access to those who need it. No system can be guaranteed to be completely secure, and you share information with us at your own risk.

10. Your rights

10.1 Subject to the conditions and exceptions in applicable law, you have the right to:

  • (a) access the personal data we hold about you;
  • (b) request rectification of inaccurate or incomplete data;
  • (c) request erasure of your data in certain circumstances;
  • (d) request restriction of processing in certain circumstances;
  • (e) object to processing based on legitimate interests, including profiling;
  • (f) request portability of certain data; and
  • (g) withdraw consent where we rely on it.

10.2 Because some scan data is not linked to your identity, we may be unable to identify you within our records. In that case we may ask you for additional information to help locate your data, or we may be unable to action a request without it.

10.3 To exercise any of these rights, contact us at info@clarity.codes. We will respond within the timeframes required by law (generally within one month). There is normally no charge.

10.4 Complaints. If you are not satisfied with how we handle your data, you can lodge a complaint with the Irish Data Protection Commission (www.dataprotection.ie), or with the supervisory authority in your country of residence. We would, however, appreciate the chance to address your concerns first.

11. United States residents

11.1 If you are a resident of the United States, additional rights may apply to you under state privacy laws (for example, in California). These may include the right to know what personal information we collect, to request deletion, and to opt out of certain disclosures. We do not sell your personal information.

11.2 To exercise any such rights, contact us at info@clarity.codes.

12. Children

The Service is not directed at children. We do not knowingly collect personal data from children under the age of 16 (or the applicable age of digital consent in your jurisdiction). If you believe a child has provided us with personal data, please contact us and we will take appropriate steps to delete it.

13. Analytics and software development kits

The App may include third-party software development kits (SDKs) and analytics tools, such as crash-reporting and usage-analytics services, that collect device and usage data to help us monitor performance and improve the Service. These providers act as our processors or, where they determine their own purposes, as separate controllers. Details of the providers we currently use are reflected in our App Store privacy disclosures and are available on request from info@clarity.codes.

14. Third-party links

The Service may contain links to third-party websites or services that we do not control. This Policy does not apply to those third parties, and we are not responsible for their privacy practices.

15. Changes to this Policy

We may update this Policy from time to time. The "Last updated" date shows the latest revision. Where changes are material, we will take reasonable steps to notify you through the Service.

16. Contact us

Get in touch

For any questions about this Policy or your personal data:

Email: info@clarity.codes

Post: Privacy Services, Professional Hair Products Limited, Wexford Office & Business Park, Whitemill Industrial Estate, Wexford, Ireland Y35 X0TK