CLW Network privacy policy
Privacy Policy, Terms and Data Protection
These terms explain how CLW Network portal access, customer workspace records, quote enquiry forms, digital products, Google Calendar connections and data protection responsibilities are handled. Last updated: 26 June 2026.
Terms and Conditions
The portal is provided for CLW Network users to manage travel business workflows, customer records, enquiries, quotes, documents, digital products, reminders and related administrative activity.
Users are responsible for entering accurate information, keeping account access secure, using customer data only for appropriate business purposes, and removing records that are no longer needed.
Digital products, templates, media and PDFs are supplied for the purchasing user or business. They must not be resold, redistributed or presented as a separate CLW Network product unless written permission is given.
The portal may be updated, reorganised or temporarily unavailable for maintenance, security, hosting, payment, storage or supplier reasons. CLW Network will aim to keep disruption limited and proportionate.
Nothing in these terms removes statutory rights that cannot legally be excluded. Business users should review customer-facing booking terms, supplier terms, insurance wording and package travel obligations before sending final travel documents.
Data Protection Notice
CLW Network handles personal data in line with UK data protection requirements, including the UK GDPR and Data Protection Act 2018. The main lawful bases are contract, legitimate interests, legal obligation and, where needed, consent.
Customer data should only be entered when it is relevant to an enquiry, quote, booking, support request, portal account, purchase, document, reminder or customer relationship task.
- Names, contact details, addresses, passenger details, travel dates, preferences, notes and quote information.
- Documents, media, quote files and customer records uploaded or saved in the portal.
- Account, subscription, purchase, billing, support and security information needed to run the service.
Google Data Access, Use, Sharing, and Retention
If you connect Google Calendar, CLW Network requests Google OAuth scopes for identity and Calendar access. The connection is optional and is used only to provide calendar sync features inside the portal.
CLW Network's use and transfer of Google user data is limited to providing and improving the user-facing calendar sync feature, keeping the service secure, complying with law, and meeting the Google API Services User Data Policy, including Limited Use requirements.
Data Accessed
- Google identity data from the OAuth connection: openid identifier, email address, and basic profile information needed to show which Google account is connected.
- Google Calendar event data from calendars you own, currently used against your primary Google Calendar: event ID, title/summary, description, start date/time, end date/time, and calendar link where returned by Google.
- OAuth token data needed to maintain the connection: access token, refresh token, token type, granted scopes, expiry time, connected email address, and last sync time.
- The Google scope requested by CLW Network is openid email profile plus https://www.googleapis.com/auth/calendar.events.owned, which allows the portal to view, create, update, and delete events on calendars you own.
Data Usage
- Confirm the Google account connected to your CLW Network profile.
- Import selected upcoming Google Calendar events into your portal planner when you choose to sync.
- Create and update CLW Portal reminders, to-dos, CRM follow-ups, and planner items as events on your primary Google Calendar.
- Check existing calendar events before sync so CLW Network can avoid duplicate entries and update or delete only matching CLW-created events.
- Refresh expired access tokens through Google OAuth so the calendar connection continues to work until you disconnect or revoke access.
- Google user data is not used for advertising, profiling, unrelated marketing, or training generalized AI or machine-learning models.
Data Sharing
- Google user data is sent to Google APIs only to complete the calendar actions you request in CLW Network.
- Events created by CLW Network include a small CLW marker in the event description so the portal can match, update, deduplicate, or delete its own synced events.
- Google user data may be processed by our secure hosting, database, logging, and infrastructure providers only as needed to operate, secure, troubleshoot, and maintain CLW Network.
- We do not sell Google user data, share it with advertising networks, or transfer it to unrelated third parties.
- We may disclose limited data if required for legal compliance, security protection, fraud prevention, or to respond to a valid lawful request.
Storage & Protection
- We store one signed-in Google connection record per connected user: provider, email, access token, refresh token, token type, granted scope, expiry time, and sync timestamp.
- Google tokens and connection metadata are stored server-side in access-restricted application storage and are not exposed to browser JavaScript.
- Calendar API calls, token exchanges, and token refresh requests are made over HTTPS from server-side routes.
- Access to production systems is limited to authorised support and technical operators who need it to run, secure, or support the service.
- We review calendar access when changing the feature and aim to request only the minimum Google scopes needed for the calendar sync functionality.
Retention & Deletion
- Google connection records are kept only while your CLW Network account remains connected to Google Calendar.
- You can disconnect Google Calendar from the portal notifications area. Disconnecting removes the stored Google token and connection record from CLW Network.
- You can also revoke CLW Network access from your Google Account permissions page at any time.
- Calendar events that CLW Network creates in your Google Calendar remain in Google Calendar unless you delete them, disconnect and remove them manually, or use CLW Network delete/sync tools where available.
- For deletion, access, correction, portability, or residual data requests, email christina@clwnetwork.uk from your registered email address. We aim to respond within 30 days.
For data-subject requests (access, correction, deletion, portability), email us at christina@clwnetwork.uk and include your registered email address.
Outlook Data Access, Use, Sharing, and Retention
If you connect Outlook Calendar, CLW Network requests Microsoft identity and Calendar scopes and uses only what is needed for reminders, to-do sync, and user-visible calendar context.
Data Accessed
- Microsoft account email address (from Microsoft Graph /me endpoint) at first connect.
- Outlook Calendar event identifiers and metadata from your primary calendar: event ID, subject, body preview, and start date/time.
- Connection tokens and scope values used to maintain the authenticated session.
Data Usage
- Show a read-only view of non-CLW events in your portal planner.
- Create and update reminders as calendar events in your primary Outlook calendar.
- Delete CLW-created Outlook events when the corresponding planner reminder is removed.
- Use refresh-token flow to keep the Outlook connection active after token expiry.
Data Sharing
- We only transmit Outlook data to Microsoft Graph APIs for the specific actions you trigger through CLW Network.
- Events pushed from CLW include an internal CLW marker in the event body/subject so duplicates can be detected and cleaned.
- We do not sell, rent, or transfer Outlook personal data to third parties unrelated to the calendar sync feature.
Storage & Protection
- We store one Outlook connection record per signed-in user: provider, email, access token, refresh token, token type, scope, expiry time, and sync timestamp.
- Tokens are kept server-side and are never exposed to the browser.
- All Microsoft token exchange, refresh, and calendar API calls are sent from server routes over HTTPS.
Retention & Deletion
- Outlook connection records are kept while the account is connected.
- Use Disconnect in portal notifications to remove stored Outlook connection data immediately.
- If permissions are revoked in Microsoft, calendar actions will fail and you should reconnect or disconnect in CLW Network.
- You can revoke app access in your Microsoft account security settings.
- For deletion or data-access requests, email us at the address below.
For data-subject requests (access, correction, deletion, portability), email us at christina@clwnetwork.uk and include your registered email address.