Privacy Policy

This Privacy Policy explains how Clairsyn collects, uses, stores, and protects personal information in connection with the Clairsyn Threshold assessment platform. We are committed to handling information responsibly and transparently.

Last updated 17 August 2026 · Effective 29 July 2026 · Version 2.2

Clairsyn Business Services Limited · New Zealand · hello@clairsyn.com · clairsyn.com

This policy complies with the New Zealand Privacy Act 2020, the Australian Privacy Principles (Privacy Act 1988 (Cth)), Canada's PIPEDA and Quebec Law 25, and, for customers in the United Kingdom and European Union, the UK GDPR and EU GDPR respectively. US customers should refer to Section 10 for jurisdiction-specific information.

1. Who we are

Clairsyn is a New Zealand-based organisational strategy consultancy. We operate Clairsyn Threshold at assess.clairsyn.com. We are the data controller for all personal information collected through this platform.

Contact: hello@clairsyn.com · Website: clairsyn.com · Country: New Zealand

2. What we collect and why

From purchasers

InformationWhy we collect itKept for
Name and email addressTo deliver the assessment, send progress updates, and deliver the reportFor as long as your account is active, as an ordinary business record
Organisation name, sector, size, countryTo appear on the report and for anonymised benchmarkingFor as long as your account is active, as an ordinary business record
Payment informationProcessed by Stripe, we do not store card detailsNot stored by us
Invoice and transaction recordsLegal obligation, financial records retention7 years

From respondents

InformationWhy we collect itKept for
Role group (e.g. employee, leader, governance)To show group pattern analysis in the report24 months
Function, tenure band, countryTo show group pattern analysis in the report24 months
Survey responses (scores 1–5 or N/A per question)To calculate scores and generate the report24 months
Email address (managed outreach add-on only)To send invitation, reminders, and report delivery24 months from when the assessment closes, then permanently removed

We do not collect respondent names. We do not link individual survey responses to named individuals. Demographic categories are used only to calculate group averages for the perception gap analysis in the report. Where fewer than 3 people in a group respond, that group is merged or excluded from the breakdown so individuals cannot be identified.

Technical data. Our platform collects standard server logs including IP addresses, browser type, and page access times. This is used for security monitoring and is not linked to individual users. Retained for 30 days.

3. How we use information

  • To deliver the assessment you have purchased and generate your report
  • To send you progress updates, reminders, and your final report
  • To process payment and maintain financial records
  • To provide customer support
  • To improve the platform and methodology using anonymised, aggregated data, no organisation is identified
  • To build anonymised sector benchmarks, data is de-identified before any benchmark use

We do not use your information for advertising. We do not sell your data. We do not use personal information to train AI models.

4. Legal basis for processing

For customers in the UK and EU, our legal basis is:

  • Contract performance, necessary to deliver the assessment you have purchased
  • Legitimate interests, security monitoring, anonymised product improvement, and benchmarking
  • Legal obligation, financial records retention

For New Zealand and Australian customers: we comply with the NZ Privacy Act 2020 and Australian Privacy Principles. For Canadian customers: we comply with PIPEDA and applicable provincial privacy legislation. For US customers: see Section 10.

5. Who we share information with

Third partyPurposeLocation
StripePayment processingUnited States
SupabaseDatabase and file storageUnited States (AWS us-east-1)
VercelApplication hosting and CDNUnited States / Global
ResendTransactional email deliveryUnited States
OpenAI (Phase 2 only)Report narrative assembly, structured score data only, no personal informationUnited States

We do not share personal information with any other third parties. All processors are required to maintain appropriate security measures and process data only for the purposes we specify.

6. Cross-border data transfers

Our infrastructure providers are primarily based in the United States. By using Clairsyn Threshold, you consent to your information being transferred to and processed in the United States. Safeguards in place: Stripe participates in the EU-US Data Privacy Framework; Standard Contractual Clauses apply for EEA/UK transfers with Supabase, Vercel and Resend.

7. Security

  • Encryption in transit (HTTPS/TLS) for all data
  • Encryption at rest for all database content
  • Row-level security, organisations cannot access each other's data
  • Time-limited signed URLs for report access
  • Environment-based secret management, no API keys in code
  • Staff access limited to what is necessary to deliver the service

8. Your rights

New Zealand and Australia. Under the NZ Privacy Act 2020 and Australian Privacy Principles, you have the right to request access to, and correction of, personal information we hold about you, and to complain if you believe we have breached your privacy rights. NZ complaints: privacy.org.nz. Australian complaints: oaic.gov.au.

UK and EU (GDPR). In addition, if you are in the UK or EU you have the right to object to processing, request erasure, request restriction, request data portability, and lodge a complaint with your national supervisory authority.

9. Data retention

Data typeRetention periodReason
Survey responses and scores24 months after report generationProduct improvement and benchmarking
Generated reports (PDF)24 months, then customer may request a copyClient access and reference
Purchaser records (name, email, org)For as long as your account is activeOrdinary business record, client support and follow-up
Financial and transaction records7 yearsLegal obligation (tax records)
Respondent email addresses (managed outreach)24 months from assessment closeSupports the re-measure comparison and aggregate research, then permanently removed
Server logs30 daysSecurity monitoring

10. United States, jurisdiction-specific information

CalOPPA. We operate a website and collect personal information online. In compliance with CalOPPA, this Privacy Policy is published at clairsyn.com/privacy and discloses what information we collect, how we use it, and how users can access or correct it.

CCPA / CPRA. The California Consumer Privacy Act currently applies to for-profit businesses with annual gross revenue exceeding $26.625 million, or that process the personal information of 100,000+ California consumers annually, or derive 50%+ of revenue from selling personal information. Clairsyn does not currently meet any of these thresholds. If our scale of operations grows to meet them, we will update this policy to include full CCPA/CPRA disclosures. California residents may contact us at any time at hello@clairsyn.com to request information about data we hold about them.

Automated decision-making. California's September 2025 CCPA regulations introduced requirements for businesses using automated decision-making for significant decisions affecting consumers. Our report assembly process involves automated selection of pre-written content based on scores. We do not believe this constitutes a significant decision about a California consumer within the meaning of the regulations. We will monitor regulatory guidance as it develops.

Other US state privacy laws. At Clairsyn's current scale, we do not meet the revenue or data volume thresholds that trigger most US state consumer privacy laws. Residents of all US states may contact us at hello@clairsyn.com to request access to or deletion of any personal information we hold about them.

CAN-SPAM Act. All commercial emails we send to US recipients comply with the CAN-SPAM Act. Every commercial email includes our business contact information, a clear subject line, and a functional unsubscribe mechanism. We honour unsubscribe requests within 10 business days.

11. Canada, jurisdiction-specific information

PIPEDA and provincial privacy laws. We comply with Canada's Personal Information Protection and Electronic Documents Act (PIPEDA) and, for Quebec residents, the Act Respecting the Protection of Personal Information in the Private Sector (Law 25). Our practices meet the PIPEDA principles of consent, purpose limitation, collection limitation, use and disclosure limitation, accuracy, safeguards, openness, individual access, and challenging compliance. Quebec residents have additional rights under Law 25, including data portability and de-indexation. To exercise these rights, contact hello@clairsyn.com.

CASL. All electronic messages we send to Canadian recipients comply with CASL. Assessment invitations, progress updates and report delivery emails are transactional messages directly facilitating a transaction the recipient's organisation has agreed to, and are exempt from CASL consent requirements. Where a purchaser has opted in to receive commercial communications, we rely on express consent. All commercial messages include our name, a contact address, and a clear unsubscribe mechanism honoured within 10 business days. We do not add purchasers or respondents to marketing lists without express consent.

12. Data breaches

If we become aware of a personal information breach likely to cause serious harm, we will notify affected individuals and the relevant regulator as soon as practicable. For NZ: Office of the Privacy Commissioner. For AU: OAIC under the Notifiable Data Breaches scheme. For UK/EU: relevant supervisory authority within 72 hours. For Canada: Privacy Commissioner of Canada and affected individuals under PIPEDA's breach of security safeguards requirements.

13. Cookies

Clairsyn Threshold uses only essential cookies necessary for the platform to function, a session cookie to maintain your state during a purchase, and a Stripe cookie for payment security. We do not use tracking, advertising, or analytics cookies without your consent.

14. Children

Clairsyn Threshold is not directed at individuals under 18. We do not knowingly collect personal information from anyone under 18. Contact hello@clairsyn.com if you have concerns.

15. Changes to this policy

We may update this Privacy Policy from time to time. The current version is always published at clairsyn.com/privacy. Material changes will be communicated to active purchasers by email.

16. Contact us

Email hello@clairsyn.com, or visit clairsyn.com. We will respond to all privacy requests within 20 working days.

Questions about this document? Email hello@clairsyn.com.