Clear to Apply
ServicesFAQFor experts
Sign in
Legal

Privacy Policy

Platform-wide privacy information for customers, applicants, account users, website visitors, approved experts, expert applicants, and business contacts.

9/18/2026
Create a support requestPrivacy Policy

Effective date: September 18, 2026.

1. About this Policy

This Privacy Policy explains how Clear to Apply collects, uses, discloses, retains and protects personal data when people:

  • browse or interact with cleartoapply.com;
  • explore any of our application-assistance services;
  • create or use a member account;
  • prepare, review or manage an application;
  • upload information or documents;
  • purchase a service or request a refund;
  • communicate with an approved expert or support team;
  • apply to become, or work as, an approved expert;
  • receive service or marketing communications; or
  • otherwise interact with Clear to Apply online or offline.

Clear to Apply is a broad application-assistance platform serving many types of applications. Examples in this Policy are illustrative and do not limit its scope to one service category, country, institution or application type.

This Policy applies to customers, applicants, prospective customers, account users, website visitors, approved experts, expert applicants, business contacts and other people whose personal data we process. It does not apply to an independent third party's own website or service.

We make this Policy available at or before relevant data collection. Short, service-specific notices may highlight an unusual data category, recipient, retention period or choice without replacing this Policy.

2. Controller and privacy roles

The controller responsible for this Policy is INFINITE8 - FZE, trading as Clear to Apply, registered or licensed under 2665 by Dubai Integrated Economic Zones Authority, with its registered office at DSO-OPERATIONS CENTRE-1-A-101-11-10, OPC, Dubai Silicon Oasis, Dubai, United Arab Emirates ("Clear to Apply", "we", "us" or "our").

We generally act as controller for the operation of the platform, member accounts, service delivery, expert administration, security, support, marketing and compliance. This means we determine why and how personal data is processed for those purposes.

Other organisations may act as:

  • processors, when they process personal data only on our documented instructions;
  • independent controllers, when they determine their own legally required purposes, such as certain payment, fraud-prevention, professional or institutional activities; or
  • joint controllers, only where the parties jointly determine purposes and means and a lawful arrangement is in place.

Section 28 identifies the providers and processing categories currently used for this service. A service-specific notice may explain a recipient's separate privacy responsibilities.

3. Important platform-wide privacy commitments

We apply the following commitments across the Clear to Apply platform:

  • We collect only data reasonably needed for the selected service, platform operation, security or legal obligations.
  • We do not require every user to provide every category of data described in this Policy.
  • Application answers, uploaded documents and expert review notes are not used for behavioural advertising.
  • Advertising providers do not receive application documents, application answers, expert notes or sensitive service details from us.
  • Payment providers receive only the data reasonably needed to process the transaction, prevent fraud, provide receipts, manage refunds and satisfy their legal duties.
  • We do not use uploaded documents or application answers to train publicly available or general-purpose AI models without separate, explicit permission.
  • Approved experts may access only assigned work and data reasonably needed for that work.
  • We do not sell application files or operate as a data broker.
  • We provide meaningful choices over non-essential cookies, advertising and direct marketing.

4. Personal data we collect

The data collected depends on the person, selected service, country, stage and features used.

4.1 Identity and profile data

This may include:

  • name, previous name, preferred name and title;
  • date and place of birth, age and gender where relevant;
  • nationality, citizenship, residence and language;
  • photograph, signature and identity-reference information;
  • identity-document details where required for the selected service;
  • account identifier, profile preferences and accessibility preferences; and
  • authority to act for another applicant, including guardian or representative information.
4.2 Contact and account data

This may include:

  • postal and residential address;
  • email address and telephone number;
  • passwordless access, authentication and account-recovery records;
  • communication preferences;
  • member-area activity; and
  • records showing acceptance of policies, consents and authorisations.
4.3 Application and service data

Depending on the chosen service, this may include information concerning:

  • education, qualifications, admissions and academic history;
  • scholarships, grants, funding and research;
  • employment, careers, professional history and references;
  • training, memberships, certification and accreditation;
  • business, startup, licence, permit, tender or vendor applications;
  • financial, banking, insurance, tax or benefit applications;
  • housing, rentals, property and utilities;
  • health, disability, accessibility and care needs;
  • family relationships, civil status, identity and life events;
  • travel, entry, residence, citizenship or consular matters;
  • claims, complaints, legal or regulatory processes;
  • sport, events, competitions, creator, talent and media applications;
  • charitable, community, humanitarian or public programmes; and
  • any other facts, declarations, preferences or eligibility information required for the selected application-assistance service.

We do not assume that all of these categories apply to you. The form for each service should request only data relevant to that service.

4.4 Documents, images and media

This may include:

  • identification or civil-status documents;
  • certificates, transcripts, CVs, references and statements;
  • financial, tax, employment or address evidence;
  • photographs, selfies, signatures, audio or video where required;
  • supporting correspondence and application records; and
  • documents uploaded for expert review, formatting, translation or submission assistance.

Where OCR or similar tools are enabled, we may extract text or structured fields from a document to reduce manual entry and identify possible inconsistencies.

4.5 Sensitive and special-category data

Some services may require data treated as sensitive under applicable law, such as:

  • government-issued identifiers;
  • precise financial or account information;
  • health, medical, disability or accessibility information;
  • biometric information used to identify a person;
  • racial or ethnic origin, religious or philosophical belief;
  • political opinion or association;
  • trade-union membership;
  • sex life or sexual orientation;
  • criminal allegations, convictions or offences; and
  • information about children or vulnerable people.

We collect sensitive data only when it is reasonably necessary for the selected service or a lawful requirement and when an appropriate legal condition applies. Where required, we request separate explicit consent or provide a service-specific notice. Sensitive data is not used to create advertising audiences.

4.6 Transaction and payment data

This may include:

  • selected service and package version;
  • order reference, amount, currency, tax and discount;
  • payment status, risk result and payment-provider reference;
  • billing contact and limited payment-method information, such as card brand and last four digits where provided by the payment provider;
  • refund, reversal, dispute, reserve and chargeback records;
  • invoice, receipt and payout information; and
  • official or third-party fees where separately itemised.

Full card numbers, security codes and payment credentials are entered into and handled by the configured payment provider. Clear to Apply does not store full card numbers or card security codes.

4.7 Expert and professional data

For expert applicants and approved experts, we may process:

  • identity, contact and profile details;
  • professional history, skills, languages, qualifications and licences;
  • references, screening and verification results;
  • work eligibility, tax, payment and payout information;
  • availability, service-category permissions and assigned work;
  • training, quality, performance, complaint and audit records;
  • communications with customers and support; and
  • security and access activity.
4.8 Communications and support data

This may include messages, emails, call metadata, attachments, correction requests, complaints, satisfaction feedback, consent records and support outcomes. Calls are recorded only after appropriate notice and where lawful.

4.9 Device, usage and security data

This may include:

  • IP address and approximate location derived from it;
  • browser, device, operating system and language;
  • session, authentication and security events;
  • pages viewed, referral source, timestamps and interactions;
  • error, performance and diagnostic information;
  • cookie, advertising or similar identifiers where permitted; and
  • suspected fraud, abuse or account-compromise signals.

We design URLs and analytics events so that names, emails, document numbers, application answers and other sensitive data are not placed in page URLs, query strings or advertising parameters.

4.10 Marketing and advertising data

This may include:

  • marketing preferences and consent status;
  • campaign, referral and conversion identifiers;
  • interactions with our advertisements or marketing messages;
  • audience suppression records;
  • limited first-party contact data used for measurement only where law and provider policy permit; and
  • opt-out requests and recorded cookie choices.

5. How we obtain personal data

We may obtain personal data:

  • directly from you through the Website, forms, uploads, purchases, messages or calls;
  • from a customer, parent, guardian, employer or authorised representative acting for an applicant;
  • from an approved expert working on an assigned service;
  • from payment, fraud-prevention, identity-verification, communications or security providers;
  • from an institution or recipient involved in a service when authorised or otherwise lawful;
  • from publicly available sources where necessary and lawful;
  • through cookies, pixels, tags, SDKs, logs and similar technologies subject to applicable choices; and
  • from advertising partners that report an advertisement interaction or referral.

If you provide another person's data, you must have lawful authority to do so and must make this Policy available to them. We may request evidence of authority.

Where we receive personal data indirectly and applicable law requires direct notice, we will provide it at the first communication, first disclosure or within the legally required period, unless a lawful exception applies.

6. Why we process personal data

We may process data to:

  • show and explain available services;
  • assess whether we can offer a requested service;
  • create and secure member accounts;
  • save progress and personalise the application experience;
  • prepare, organise, translate, review or validate application material;
  • assign and supervise an approved expert;
  • request corrections and communicate about the service;
  • transmit information to a selected recipient when expressly authorised and permitted;
  • process orders, payments, invoices, payouts, refunds and disputes;
  • provide support and resolve complaints;
  • prevent fraud, misuse, unauthorised access and security incidents;
  • maintain audit, consent and transaction records;
  • improve accessibility, reliability and user experience;
  • analyse aggregated platform performance;
  • measure advertising and understand which campaigns lead to general service purchases;
  • send marketing where permitted;
  • recruit, verify and manage experts;
  • establish, exercise or defend legal claims;
  • comply with tax, accounting, sanctions, regulatory and other legal obligations; and
  • protect customers, applicants, experts, Clear to Apply and the public.

We do not use personal data for a materially incompatible new purpose without providing required notice and establishing a valid legal basis.

7. Legal bases

The applicable legal basis depends on the person, purpose and jurisdiction.

  • Answering a request and determining service availability — Steps requested before a contract; legitimate interests
  • Creating an account and delivering a purchased service — Contract; steps before a contract
  • Preparing and reviewing application material — Contract; explicit consent or another lawful sensitive-data condition when required
  • Assigning an approved expert — Contract; legitimate interests; consent where required
  • Payment, invoices, refunds and disputes — Contract; legal obligation; legitimate interests
  • Account, platform and fraud security — Legitimate interests; legal obligation; protection of legal rights
  • Required records and compliance — Legal obligation; public-interest or legal-claims grounds where applicable
  • Service communications — Contract; legitimate interests
  • Optional marketing email or text — Consent or another lawful marketing basis where expressly permitted
  • Non-essential analytics and advertising technologies — Consent where required; legitimate interests only where lawful
  • Product and service improvement — Legitimate interests using minimised or de-identified data; consent where required
  • Sensitive or special-category data — Explicit consent or another specific lawful condition under applicable law

Where we rely on legitimate interests, we consider necessity, proportionality, reasonable expectations and potential impact. You may request information about a relevant assessment where law provides that right.

Acceptance of our Terms does not replace separate consent where consent is legally required. You may withdraw consent at any time, without affecting processing already lawfully performed.

8. Automated assistance, OCR and artificial intelligence

We may use OCR, rules-based validation and AI-assisted tools to:

  • extract information from uploaded material;
  • organise or format answers;
  • translate or summarise text;
  • detect missing fields or possible inconsistencies;
  • identify document-quality issues; and
  • support an approved expert or authorised operator.

These tools can make mistakes. They support preparation and do not themselves decide whether an applicant is accepted, approved or eligible by an external recipient. Users must review important extracted or generated information and can request correction or human assistance.

We do not use uploaded documents, application answers or private expert notes to train publicly available or general-purpose AI models without separate explicit permission. Providers supporting AI-assisted functions must be approved, subject to appropriate data terms before production use.

Where applicable law gives rights concerning solely automated decisions with legal or similarly significant effects, we will provide the required information and review mechanism. Clear to Apply does not intend to make such decisions solely by automation.

9. Approved experts and human review

Experts must pass our manual approval process before receiving assignments. Approval may include identity, qualification, experience, category and compliance checks appropriate to the proposed work.

Approved experts:

  • receive access only to assigned applications and necessary information;
  • must use the data only to perform the assigned service;
  • are subject to confidentiality, privacy and security obligations;
  • may not use applicant data for their own marketing;
  • may not sell, retain or reuse application information outside permitted workflows;
  • must report suspected security incidents promptly; and
  • lose access when an assignment or expert relationship ends, subject to necessary records.

An expert may be our processor, contractor or an independent professional controller depending on the service and legal relationship. Where an expert acts independently, we will provide their identity, role and relevant privacy information before disclosing data where required.

Expert access and material actions should be logged and reviewable. Users may contact support about expert access, assignment or conduct.

10. Payments and financial partners

Payments are processed by the provider identified at checkout. Current technical providers are identified in Section 28. The actual provider depends on the configured country, currency, service and payment method.

A payment provider may receive:

  • name and contact details;
  • billing information;
  • order reference, general description, amount and currency;
  • device, IP and fraud-prevention signals;
  • payment credentials entered directly with that provider; and
  • refund, dispute and transaction communications.

Payment providers may process data as our processor and/or as an independent controller for payment, fraud prevention, compliance, reporting and legal obligations. Their own privacy notice applies to their independent processing. If a provider acts as merchant of record, checkout will clearly identify that role and the possible billing descriptor.

We do not send application answers, uploaded documents, expert notes or sensitive application details to a payment provider merely to process payment. The payment description should use a neutral service or order reference and not reveal a sensitive application category.

11. Advertising, analytics and conversion measurement

Google Ads measurement and site analytics are separate, optional choices in Cookie preferences. Google Ads measurement starts only after you choose it; analytics consent does not grant advertising consent. You may reject either choice and still use necessary service functions. Current providers and information about their data use are identified in Section 28.

Subject to consent and applicable law, these providers may receive limited data such as:

  • cookie or advertising identifiers;
  • IP address and approximate location;
  • browser and device information;
  • referring page, public landing page and campaign identifier;
  • general Website interactions; and
  • a generic conversion event, order value and currency.
11.1 Protected areas where advertising tags are prohibited

Advertising, remarketing and non-essential analytics tags must not operate on:

  • application questionnaires or review screens;
  • document-upload or identity-verification pages;
  • private member-account pages containing application information;
  • approved-expert workspaces;
  • support messages or complaint records; or
  • any page or event that would disclose sensitive data or a sensitive application category.
11.2 Conversion measurement

For Google Ads measurement, we match a consented advertising click identifier with a generic completed service-order, verified expert-activation or submitted service-request event. An import may include the click identifier, event time, service-fee value and currency, an opaque hashed order or event reference, and consent signals. Government fees and taxes are excluded from the service value. We do not send application answers, documents, names, contact details, expert notes, secure account links or sensitive service descriptions in these exports.

Our current Google Ads conversion exports do not include email addresses, phone numbers, names or addresses, whether plain or hashed. Enabling a capability in an advertising account does not itself deploy collection on our website. Any later contact-data matching requires a separate reviewed implementation, appropriate notice and required consent; hashing does not remove privacy obligations.

11.3 Personalised advertising and audiences

We do not build advertising audiences from application answers, uploaded documents, expert notes, health, disability, financial hardship, criminal, religious, political, biometric, child or other sensitive information.

The current Google Ads measurement implementation sends a denial of advertising personalisation and does not create remarketing or customer-list audiences. Any later audience feature requires separate legal and policy review, appropriate notice and required consent, and may never use sensitive application data.

12. Cookies and similar technologies

We use necessary cookies and browser storage for authentication, security, saved progress, language and your cookie choices. Current customer-facing cookie limits are: customer session up to 30 days; temporary customer-link handoff 5 minutes; Google sign-in state 10 minutes when that sign-in method is used; language preference 1 year; the separate analytics and advertising choice cookie 30 days; and application-entry context 30 minutes. An earlier analytics-only choice cookie may remain for up to 1 year but never grants advertising consent. A session or token can become invalid sooner through logout, revocation or its own validity checks.

The first-party acquisition session lasts up to 30 days and is created only after an applicable optional choice. Analytics and landing-test information requires analytics consent; advertising click identifiers require the separate Google Ads measurement consent. These choices can apply across ClearToApply subdomains in the same browser. Rejecting optional cookies does not prevent necessary service functions.

Your browser may also store the theme preference, a recent-application list and application progress, including answers, pending edits and a resume token. This local storage has no automatic time expiry. Anyone with access to the same browser profile may be able to access it. Use a private device and clear site storage when appropriate; clearing unsaved progress can remove edits that have not yet reached the server.

You can change or withdraw either optional choice through Cookie preferences. Withdrawing Google Ads measurement permission removes the click identifiers from the live acquisition records associated with that browser session and stops future conversion exports for those records. It does not undo disclosures already made to Google. Contact our privacy address for a request concerning previously shared data. You can also remove cookies or local storage through your browser; doing so does not itself delete server-side application or transaction records.

13. Marketing communications

Service communications—such as access links, receipts, correction requests, security notices and status updates—are necessary to provide or protect the service and are not marketing.

We send promotional email, text or similar direct marketing only where permitted. Where consent is required, marketing consent is separate, optional and not a condition of purchasing unrelated services.

You may unsubscribe through the message or change preferences in your account. We may retain a minimal suppression record so we do not contact you again through the opted-out channel. Unsubscribing from marketing does not stop necessary service or legal communications.

We do not give application documents or answers to advertising partners for their own direct marketing.

14. When we disclose personal data

We may disclose only necessary data to the following recipients:

14.1 Approved experts

Assigned experts receive data needed to deliver the purchased service under Section 9.

14.2 Technology and operational providers

These may provide hosting, databases, storage, security, monitoring, authentication, communications, customer support, document processing, OCR, translation, AI assistance, analytics and other infrastructure.

14.3 Payment and fraud-prevention providers

These recipients process data as described in Section 10.

14.4 Advertising and analytics providers

These recipients receive limited data subject to Sections 11 and 12 and applicable choices.

14.5 Application recipients and service partners

At your direction or where otherwise lawfully authorised, we may transmit necessary material to the institution, organisation, portal, programme, business, professional or other recipient connected with the selected application. That recipient may act as an independent controller under its own privacy notice.

14.6 Professional advisers and insurers

We may disclose necessary data to lawyers, auditors, accountants, insurers and other advisers subject to confidentiality obligations.

14.7 Authorities and legal recipients

We may disclose data where reasonably necessary to comply with law, a valid legal process, a regulatory obligation, or to protect rights, safety and security. We assess requests and object where appropriate and legally permitted.

14.8 Business transfers

Data may be reviewed or transferred as part of a genuine financing, merger, acquisition, restructuring or sale, subject to confidentiality and applicable notice or choice requirements.

Processors must use personal data only for authorised purposes, protect it and support applicable rights. Current technical providers are identified in Section 28.

15. Sale, sharing and targeted advertising disclosures

We do not sell personal data for money and do not sell application files. We do not use or disclose application answers, documents or expert notes for cross-context behavioural advertising.

Some privacy laws define sale or sharing broadly enough that limited advertising-cookie or identifier disclosures may qualify even when no money is paid for the data. You may opt out through Cookie Settings or by contacting the privacy contact in Section 30. Applicable statutory opt-out rights remain available.

We do not knowingly sell or share the personal data of children for targeted advertising.

16. Aggregated and de-identified information

We may create aggregated or de-identified information that is not reasonably linkable to an individual and use it for analytics, security, capacity planning, service improvement and business reporting.

We maintain measures designed to prevent re-identification and do not attempt to re-identify information treated as de-identified except to test whether de-identification controls work or where law permits.

17. International transfers

Transfers outside your country are subject to the conditions and safeguards required by applicable law. Depending on the recipient, purpose and destination, the law may require an adequacy decision, approved contractual safeguards or another permitted basis. Contact privacy@cleartoapply.com for information relevant to your data. This Policy does not state that every listed mechanism applies to every recipient.

18. Retention

We retain personal data for the purposes for which it was collected and for applicable legal, accounting, security and dispute obligations. Retention depends on whether the service or account remains active, the sensitivity of the data, outstanding support or claims, statutory recordkeeping and a valid deletion or restriction request.

Application answers and supporting documents are retained while needed to deliver and support the requested service or resolve a related issue. Financial, invoice and transaction evidence may need to be retained after other application material is removed. Legal holds or binding obligations can prevent immediate deletion; we will explain the applicable reason when responding to a request.

Submitting an account-deletion request restricts the account and revokes its sessions. It does not mean that every answer, file, transaction or backup has already been erased. Deletion requests require review of the data and any lawful retention exceptions. Request the retention criteria for your record or exercise a right at privacy@cleartoapply.com.

Google advertising click identifiers in live acquisition records are scheduled for deletion no later than 90 days after the acquisition session starts, or removed earlier on withdrawal of that session's advertising consent. Our export excludes records beyond that deadline. Consent evidence, including the choice, time and notice shown, is retained for accountability under the criteria above. Encrypted, access-restricted recovery backups can retain copies after removal from the live service; live deletion and backup retention are separate processes. This Policy does not promise immediate erasure from every backup. Browser storage is separate as described in Section 12.

19. Security

We use risk-based technical and organisational measures designed to protect personal data. Depending on the system and risk, these may include:

  • encryption in transit and at rest;
  • role-based and least-privilege access;
  • multi-factor authentication for privileged and expert access;
  • environment and provider separation;
  • secure secrets and key management;
  • logging, monitoring and audit records;
  • vulnerability, dependency and patch management;
  • backups and recovery controls;
  • secure development and change review;
  • processor due diligence and contractual safeguards;
  • staff and expert confidentiality and security training;
  • incident-response procedures; and
  • secure deletion or de-identification.

No online service can guarantee absolute security. You should protect your email, device, one-time codes and passwordless links; use a private device for sensitive uploads; and contact us promptly if you suspect misuse.

20. Personal-data incidents

We investigate suspected unauthorised access, loss, alteration or disclosure. We take reasonable containment, recovery and prevention steps and notify affected people and regulators where required by applicable law.

Processors and approved experts must report suspected incidents to us promptly. Security concerns can be reported to privacy@cleartoapply.com.

21. Accuracy and correction

Application outcomes may depend on accurate information. You can update some information through the member area or request correction through support.

We may retain an audit record of a change where required for security, transaction integrity, a submitted application, dispute handling or law. Correcting information within Clear to Apply does not automatically correct material already transmitted to an independent recipient.

22. Your privacy rights

Depending on applicable law, you may have rights to:

  • receive information about processing;
  • access personal data;
  • correct inaccurate or incomplete data;
  • delete personal data;
  • restrict processing;
  • object to processing, including direct marketing;
  • receive portable data in a usable format;
  • withdraw consent;
  • opt out of sale, sharing or targeted advertising;
  • limit certain uses of sensitive personal data;
  • request review of certain automated decisions;
  • appeal a refusal of a privacy request; and
  • complain to a regulator or seek another legal remedy.

Rights are not absolute. For example, we may retain transaction data required by law or evidence needed for a dispute.

23. Exercising your rights

Submit a request by emailing privacy@cleartoapply.com. Describe the right requested and the relevant account or service.

We may take proportionate steps to verify identity and authority. We will not request more verification data than reasonably needed. An authorised agent may submit a request where law permits, but we may verify their authority and, where lawful, confirm the request with the individual.

We respond within the period required by applicable law and explain any permitted extension. We do not discriminate against a person for exercising a privacy right. If we deny a request, we will explain the reason and any available appeal or complaint route.

24. Advertising and cookie choices

You can manage non-essential cookies and advertising through:

  • the Website's Cookie Settings control;
  • the privacy contact described in Section 30; and
  • unsubscribe controls included in optional marketing messages. Applicable statutory opt-out rights remain available.

Choices may be browser- or device-specific unless connected to an authenticated account. Clearing cookies can also clear a locally stored choice.

25. Children and minor applicants

The platform is not directed to children who are legally unable to contract independently. A parent, guardian or other legally authorised adult must purchase and manage a service for such a minor.

Some legitimate services may concern a child or minor applicant. In that case, we process only data reasonably needed for the selected service, verify adult authority where appropriate, provide age-appropriate information where required, and do not use the child's application data for behavioural advertising.

If we learn that a child directly provided data without required authority or consent, we will take appropriate steps to restrict or delete it. Contact privacy@cleartoapply.com with concerns.

26. Third-party websites and recipients

The Website may link to an institution, professional, official portal, payment page, social network or other independent site. Their privacy practices apply once you interact with them. A link does not mean we control or endorse their privacy practices.

Before sending application material to a selected recipient, review that recipient's instructions and privacy information. Clear to Apply is not responsible for independent processing by a recipient, but remains responsible for its own transmission and service obligations.

27. Regional disclosures

27.1 UAE residents

Where the UAE Personal Data Protection Law applies, individuals may have rights concerning information, access, correction, deletion, restriction, objection, portability, automated processing and complaints, subject to applicable conditions and exceptions. Cross-border transfers are subject to applicable UAE requirements.

Privacy requests and complaints may be sent to privacy@cleartoapply.com. The controller's verified identity and address are stated in Section 2. You may also complain to the competent authority under applicable UAE law; official guidance is available at https://u.ae/en/about-the-uae/digital-uae/data/data-protection-laws. This contact route does not restrict any statutory remedy.

27.2 EEA and UK residents

Where the GDPR or UK GDPR applies, Sections 2, 6, 7, 17, 18, 22 and 23 provide the core controller, purpose, legal-basis, transfer, retention and rights information. Individuals may complain to the data-protection authority where they live or work or where an alleged infringement occurred.

27.3 United States residents

Residents of states with applicable consumer privacy laws may have rights to know, access, correct, delete or obtain personal data and to opt out of sale, sharing, targeted advertising or certain profiling. They may also have rights concerning sensitive data, authorised agents, appeals and non-discrimination.

Our category disclosures are contained in Sections 4, 5, 6, 14, 15 and 18. We do not sell personal data for money. Limited advertising-technology disclosures may constitute "sharing" or targeted advertising under some state laws and can be opted out through Cookie Settings or by contacting the privacy contact in Section 30.

We will add any state-specific metrics, financial-incentive notice or additional language if and when legally required by our scale and practices.

27.4 Other countries

Additional local rights, contacts or restrictions may apply. We honour applicable mandatory privacy law and may publish a regional supplement when necessary.

28. Current providers and recipient information

Current technical providers include Hetzner for hosted infrastructure and encrypted recovery storage, Cloudflare for DNS, Resend for transactional email delivery, and Commas for the configured payment checkout and payment processing. They receive only the data relevant to their function, such as connection information, delivery addresses and message content, or checkout and transaction information. Google Ads receives the limited, consented conversion-measurement data described in Section 11 when those records are imported. Google explains how it uses partner data at https://policies.google.com/technologies/partner-sites and its privacy practices at https://policies.google.com/privacy. Our current conversion exports do not send contact details, application data or documents to Google.

Passport OCR and file malware scanning run in our own hosted environment; they are not a statement that an external AI or OCR vendor receives every document. Official authorities receive application data only as part of the authorized service process.

Provider roles, processing locations and applicable transfer arrangements depend on the provider and purpose. Contact privacy@cleartoapply.com for the information relevant to your data or a request concerning safeguards. This list identifies current use and does not claim that every provider has the same legal role or processing location.

29. Changes to this Policy

We may update this Policy to reflect new services, providers, laws or practices. The current version will show its effective date and remain accessible at https://cleartoapply.com/legal/privacy-policy.

Material changes will be communicated through an appropriate channel, such as the Website, member area or email, before they take effect where required. A policy update does not retroactively create consent for a materially new purpose.

Previous versions will be retained through our governed legal-content process where required for accountability and order records.

30. Contact and complaints

Privacy questions, rights requests or complaints can be sent to:

Clear to Apply / INFINITE8 - FZE

Email: privacy@cleartoapply.com

Postal address: DSO-OPERATIONS CENTRE-1-A-101-11-10, OPC, Dubai Silicon Oasis, Dubai, United Arab Emirates

Privacy choices: Cookie Settings or the privacy contact above.

Withdraw from contract here

Clear to Apply

ClearToApply helps people find application services, complete guided forms, and continue saved applications in one place. Scope, support, prices, and responsibility vary by service.

ClearToApplyAboutSupportFor expertsFAQ
ServicesExplore servicesResume applicationSign inService status
HelpCreate a support requestsupport@cleartoapply.com
LegalImpressum
© 2026 INFINITE8 - FZE, FZCO2665DSO-OPERATIONS CENTRE-1-A-101-11-10, OPC, Dubai Silicon Oasis, Dubai, United Arab Emirates