CClarivyAI Decision Visibility
ZH · EN

Privacy Policy

v1.2 · Effective 21 June 2026 · Operated by HG-Solution Co., Limited (CR 80121024) · Wan Chai, Hong Kong

Contents
  1. Who we are
  2. What we collect
  3. What we do not collect
  4. Why we collect it (purpose & legal basis)
  5. Who we share it with (subprocessors)
  6. Where it is stored (data residency)
  7. How long we keep it
  8. Your rights
  9. Security measures
  10. Incident response
  11. Children's data
  12. International transfers (PIPL / Schrems II)
  13. Changes to this policy
  14. Contact & DPO

1. Who we are

Controller: HG-Solution Co., Limited, a Hong Kong private company limited by shares (CR No. 80121024, BR No. 80121024-000-04-26-9), registered office at RM 1701, 17/F Henan Building, 90 Jaffe Road, Wan Chai, Hong Kong. We operate the website clarivy.ai and the Clarivy GEO audit product.

EU/UK representative (Art. 27 GDPR): To be appointed before any EU/UK data is processed. Until then, please contact our DPO at [email protected] for any EU/UK privacy matter.

2. What we collect

3. What we do not collect

4. Why we collect it (purpose & legal basis)

PurposeCategoriesLegal basis (GDPR Art. 6)
Deliver the audit you purchasedBrand, queries, contact emailContract performance (Art. 6(1)(b))
Maintain repeat-audit continuity and purchased monitoring subscriptionsBrand/URL, prompt set, sanitized audit summaries, prior GEO scores, recurring findings, previous actions, open loops, monitoring schedule/status, hashed contact reference for opt-in subscriptionsContract performance (Art. 6(1)(b)) where included in the purchased service; legitimate interest (Art. 6(1)(f)) for service continuity, with opt-out and deletion available
Issue an invoice & collect paymentName, company, country, tax IDLegal obligation (HK IRO Cap. 112 §51C, 7-year retention)
Respond to support requestsCorrespondenceContract performance + legitimate interest (Art. 6(1)(b)+(f))
Detect abuse and secure our serviceServer logs, IP (truncated)Legitimate interest (Art. 6(1)(f))
Improve methodology (aggregated, anonymised)Audit results, no PIILegitimate interest (Art. 6(1)(f)) — opt-out available

For HK PDPO: we rely on DPP 1 (necessary & not excessive) and DPP 2 (accuracy & retention).

5. Subprocessors (who we share with)

We share the minimum data needed. The full list — with country, purpose, retention, and DPA status — lives at /legal/subprocessors.html and is also exposed as machine-readable JSON. We commit to 30-day prior notice for any new subprocessor; if you object, you may terminate affected services and receive a pro-rata refund.

6. Where it is stored (data residency)

Customer data at rest is stored in Cloudflare R2, region selected at tenant creation (default: auto-routed to nearest of US/EU/APAC; EU customers default to EU region, US customers default to US). LLM inference runs on vendor infrastructure under reviewed retention / training-control settings — see the subprocessor list for the current status per vendor.

7. How long we keep it

8. Your rights

Subject to applicable law (GDPR, UK GDPR, CCPA/CPRA, HK PDPO, PIPL):

Email [email protected] — we respond within 30 days. Most requests handled within 5 business days. For repeat-audit memory or monitoring state, you can request opt-out or deletion without cancelling access to already-delivered audit files, except where a signed order form says otherwise.

9. Security measures

10. Incident response

On confirmed breach: 48-hour preliminary report to affected customers; 72-hour notification to the lead supervisory authority (GDPR); 30-day root-cause report. Public incident log at trust.clarivy.ai/incidents (planned; not live yet).

11. Children's data

Clarivy is a B2B product. We do not knowingly collect data from anyone under 16. If you believe a minor's data is in our system, email [email protected] and we will delete it within 24 hours.

12. International transfers (PIPL / Schrems II)

For data leaving the EEA, UK, or Mainland China, we rely on (a) Standard Contractual Clauses 2021/914, (b) EU-US Data Privacy Framework for US destinations, or (c) for China-out, PIPL §38 security assessment / §39 standard contract / §40 certification — applied case-by-case. We do not transfer Mainland-China-resident data outside China without one of the three PIPL mechanisms in place.

13. Changes to this policy

Material changes are notified by email at least 30 days in advance, with a clear diff and an opt-out / terminate-and-refund path for affected customers. Non-material changes (typos, clarifications) are tracked in CHANGELOG.md on the repo.

14. Contact & DPO

Data Protection Officer: [email protected] (we will assign a named DPO before any EU/UK data is processed; until then, the founder is the contact).

Postal: HG-Solution Co., Limited, RM 1701, 17/F Henan Building, 90 Jaffe Road, Wan Chai, Hong Kong.

This policy v1.2 was published on 21 June 2026. v1.2 clarifies that repeat-audit memory supports opt-out/deletion and that approved Enterprise Monitor subscription records default to hashed contact references rather than full contact emails. It will be reviewed at least annually. The next scheduled review is 11 June 2027.