Privacy Policy
- Who we are
- What we collect
- What we do not collect
- Why we collect it (purpose & legal basis)
- Who we share it with (subprocessors)
- Where it is stored (data residency)
- How long we keep it
- Your rights
- Security measures
- Incident response
- Children's data
- International transfers (PIPL / Schrems II)
- Changes to this policy
- Contact & DPO
1. Who we are
Controller: HG-Solution Co., Limited, a Hong Kong private company limited by shares (CR No. 80121024, BR No. 80121024-000-04-26-9), registered office at RM 1701, 17/F Henan Building, 90 Jaffe Road, Wan Chai, Hong Kong. We operate the website clarivy.ai and the Clarivy GEO audit product.
EU/UK representative (Art. 27 GDPR): To be appointed before any EU/UK data is processed. Until then, please contact our DPO at [email protected] for any EU/UK privacy matter.
2. What we collect
- Account & billing — name, work email, company name, country, VAT/GST number (where applicable), invoice ID, and payment reference. During the Day 1-7 validation phase, we do not collect or store credit card numbers.
- Audit input — the brand/URL you submit and the 5 Snapshot queries you want tested. (Those queries define the Snapshot scope — we do not crawl or scrape anything else from your website beyond the publicly fetchable HTML needed to score a citation.)
- Repeat-audit memory & monitoring state — for the same customer subject, we may store sanitized audit summaries such as prior GEO scores, recurring findings, previous actions, open loops, prompt-set names, and monitoring schedule/status. This memory is used to compare future Clarivy audits against earlier Clarivy runs and to support voluntary monitoring subscriptions when purchased.
- Enterprise Monitor subscription records — when a customer explicitly approves a recurring Enterprise Monitor subscription, our default long-lived subscription record stores a hashed contact reference and a masked contact hint, not the full contact email. The current invoice for a billing period may contain the email needed to send that invoice; invoice and tax records follow the legal retention period below.
- Correspondence — emails you send us, briefing call recordings only with your consent.
- Operational telemetry — anonymous page-view counts (Plausible or self-hosted, no cross-site cookies), server logs retained ≤ 30 days for security.
3. What we do not collect
- We do not collect special-category data (race, religion, health, sexual orientation, etc.).
- We do not collect end-user PII from the websites we audit. We score AI-search answers about brands — we do not build consumer profiles.
- We do not put contact details, billing data, tax IDs, raw LLM response text, or raw JSON payloads inside repeat-audit memory.
- We do not automatically enroll Snapshot, Professional, or one-time Enterprise Audit customers into monitoring or recurring billing. Enterprise Monitor requires separate explicit approval before any subscription record or recurring billing is created.
- We do not use customer audit inputs, raw responses, repeat-audit memory, or monitoring history to train Clarivy-owned or third-party foundation models.
- We do not use any third-party advertising, retargeting, or social-graph trackers.
4. Why we collect it (purpose & legal basis)
| Purpose | Categories | Legal basis (GDPR Art. 6) |
|---|---|---|
| Deliver the audit you purchased | Brand, queries, contact email | Contract performance (Art. 6(1)(b)) |
| Maintain repeat-audit continuity and purchased monitoring subscriptions | Brand/URL, prompt set, sanitized audit summaries, prior GEO scores, recurring findings, previous actions, open loops, monitoring schedule/status, hashed contact reference for opt-in subscriptions | Contract performance (Art. 6(1)(b)) where included in the purchased service; legitimate interest (Art. 6(1)(f)) for service continuity, with opt-out and deletion available |
| Issue an invoice & collect payment | Name, company, country, tax ID | Legal obligation (HK IRO Cap. 112 §51C, 7-year retention) |
| Respond to support requests | Correspondence | Contract performance + legitimate interest (Art. 6(1)(b)+(f)) |
| Detect abuse and secure our service | Server logs, IP (truncated) | Legitimate interest (Art. 6(1)(f)) |
| Improve methodology (aggregated, anonymised) | Audit results, no PII | Legitimate interest (Art. 6(1)(f)) — opt-out available |
For HK PDPO: we rely on DPP 1 (necessary & not excessive) and DPP 2 (accuracy & retention).
5. Subprocessors (who we share with)
We share the minimum data needed. The full list — with country, purpose, retention, and DPA status — lives at /legal/subprocessors.html and is also exposed as machine-readable JSON. We commit to 30-day prior notice for any new subprocessor; if you object, you may terminate affected services and receive a pro-rata refund.
6. Where it is stored (data residency)
Customer data at rest is stored in Cloudflare R2, region selected at tenant creation (default: auto-routed to nearest of US/EU/APAC; EU customers default to EU region, US customers default to US). LLM inference runs on vendor infrastructure under reviewed retention / training-control settings — see the subprocessor list for the current status per vendor.
7. How long we keep it
- Audit reports & raw JSON — 12 months from delivery, then auto-archived to cold storage for 24 more months, then deleted. Customer may request earlier deletion at any time.
- Repeat-audit memory & monitoring state — retained for the same period as the related audit reports unless a signed Order Form or DPA sets a shorter period. On cancellation, termination, opt-out, or written deletion request, we delete repeat-audit memory and monitoring state within 30 days, except records we must keep by law.
- Enterprise Monitor subscription records — retained while the approved subscription is active and for up to 12 months after cancellation for support and dispute handling, unless a shorter signed Order Form or DPA applies. Long-lived subscription records default to hashed contact references; invoices and tax records are separate legal records.
- Invoices & tax records — 7 years (HK Inland Revenue Ordinance Cap. 112 §51C).
- Server logs — 30 days.
- Backups — 30-day rolling, then permanently deleted (end-of-window, no indefinite backup retention).
8. Your rights
Subject to applicable law (GDPR, UK GDPR, CCPA/CPRA, HK PDPO, PIPL):
- Access (Art. 15) — request a copy of the data we hold about you.
- Rectification (Art. 16) — fix inaccurate data.
- Erasure (Art. 17) — "right to be forgotten."
- Restriction (Art. 18) — pause processing while a dispute is resolved.
- Portability (Art. 20) — export your data as JSON/CSV.
- Object (Art. 21) — including objection to legitimate-interest processing.
- Withdraw consent (Art. 7(3)) — at any time, without retroactive effect.
- Complain to a supervisory authority (Art. 77) — e.g. PCPD (HK), BfDI (DE), CNIL (FR), ICO (UK). We will not retaliate.
Email [email protected] — we respond within 30 days. Most requests handled within 5 business days. For repeat-audit memory or monitoring state, you can request opt-out or deletion without cancelling access to already-delivered audit files, except where a signed order form says otherwise.
9. Security measures
- Transport: TLS 1.3 with forward secrecy (TLS_AES_256_GCM_SHA384).
- At rest: AES-256, per-tenant key rotation every 12 months.
- Access: least-privilege RBAC, mandatory MFA on all production systems.
- Vendors: every LLM subprocessor must have a reviewed data-control posture before real customer delivery; we will not silently route customer prompts to an engine with weaker retention / training controls than the order form and methodology disclose.
10. Incident response
On confirmed breach: 48-hour preliminary report to affected customers; 72-hour notification to the lead supervisory authority (GDPR); 30-day root-cause report. Public incident log at trust.clarivy.ai/incidents (planned; not live yet).
11. Children's data
Clarivy is a B2B product. We do not knowingly collect data from anyone under 16. If you believe a minor's data is in our system, email [email protected] and we will delete it within 24 hours.
12. International transfers (PIPL / Schrems II)
For data leaving the EEA, UK, or Mainland China, we rely on (a) Standard Contractual Clauses 2021/914, (b) EU-US Data Privacy Framework for US destinations, or (c) for China-out, PIPL §38 security assessment / §39 standard contract / §40 certification — applied case-by-case. We do not transfer Mainland-China-resident data outside China without one of the three PIPL mechanisms in place.
13. Changes to this policy
Material changes are notified by email at least 30 days in advance, with a clear diff and an opt-out / terminate-and-refund path for affected customers. Non-material changes (typos, clarifications) are tracked in CHANGELOG.md on the repo.
14. Contact & DPO
Data Protection Officer: [email protected] (we will assign a named DPO before any EU/UK data is processed; until then, the founder is the contact).
Postal: HG-Solution Co., Limited, RM 1701, 17/F Henan Building, 90 Jaffe Road, Wan Chai, Hong Kong.
This policy v1.2 was published on 21 June 2026. v1.2 clarifies that repeat-audit memory supports opt-out/deletion and that approved Enterprise Monitor subscription records default to hashed contact references rather than full contact emails. It will be reviewed at least annually. The next scheduled review is 11 June 2027.