Privacy Policy
Last updated 17 August 2026 · Effective 29 July 2026 · Version 2.2
Clairsyn Business Services Limited · New Zealand · hello@clairsyn.com · clairsyn.com
This policy complies with the New Zealand Privacy Act 2020, the Australian Privacy Principles (Privacy Act 1988 (Cth)), Canada's PIPEDA and Quebec Law 25, and, for customers in the United Kingdom and European Union, the UK GDPR and EU GDPR respectively. US customers should refer to Section 10 for jurisdiction-specific information.
1. Who we are
Clairsyn is a New Zealand-based organisational strategy consultancy. We operate Clairsyn Threshold at assess.clairsyn.com. We are the data controller for all personal information collected through this platform.
Contact: hello@clairsyn.com · Website: clairsyn.com · Country: New Zealand
2. What we collect and why
From purchasers
| Information | Why we collect it | Kept for |
|---|---|---|
| Name and email address | To deliver the assessment, send progress updates, and deliver the report | For as long as your account is active, as an ordinary business record |
| Organisation name, sector, size, country | To appear on the report and for anonymised benchmarking | For as long as your account is active, as an ordinary business record |
| Payment information | Processed by Stripe, we do not store card details | Not stored by us |
| Invoice and transaction records | Legal obligation, financial records retention | 7 years |
From respondents
| Information | Why we collect it | Kept for |
|---|---|---|
| Role group (e.g. employee, leader, governance) | To show group pattern analysis in the report | 24 months |
| Function, tenure band, country | To show group pattern analysis in the report | 24 months |
| Survey responses (scores 1–5 or N/A per question) | To calculate scores and generate the report | 24 months |
| Email address (managed outreach add-on only) | To send invitation, reminders, and report delivery | 24 months from when the assessment closes, then permanently removed |
We do not collect respondent names. We do not link individual survey responses to named individuals. Demographic categories are used only to calculate group averages for the perception gap analysis in the report. Where fewer than 3 people in a group respond, that group is merged or excluded from the breakdown so individuals cannot be identified.
Technical data. Our platform collects standard server logs including IP addresses, browser type, and page access times. This is used for security monitoring and is not linked to individual users. Retained for 30 days.
3. How we use information
- To deliver the assessment you have purchased and generate your report
- To send you progress updates, reminders, and your final report
- To process payment and maintain financial records
- To provide customer support
- To improve the platform and methodology using anonymised, aggregated data, no organisation is identified
- To build anonymised sector benchmarks, data is de-identified before any benchmark use
We do not use your information for advertising. We do not sell your data. We do not use personal information to train AI models.
4. Legal basis for processing
For customers in the UK and EU, our legal basis is:
- Contract performance, necessary to deliver the assessment you have purchased
- Legitimate interests, security monitoring, anonymised product improvement, and benchmarking
- Legal obligation, financial records retention
For New Zealand and Australian customers: we comply with the NZ Privacy Act 2020 and Australian Privacy Principles. For Canadian customers: we comply with PIPEDA and applicable provincial privacy legislation. For US customers: see Section 10.
5. Who we share information with
| Third party | Purpose | Location |
|---|---|---|
| Stripe | Payment processing | United States |
| Supabase | Database and file storage | United States (AWS us-east-1) |
| Vercel | Application hosting and CDN | United States / Global |
| Resend | Transactional email delivery | United States |
| OpenAI (Phase 2 only) | Report narrative assembly, structured score data only, no personal information | United States |
We do not share personal information with any other third parties. All processors are required to maintain appropriate security measures and process data only for the purposes we specify.
6. Cross-border data transfers
Our infrastructure providers are primarily based in the United States. By using Clairsyn Threshold, you consent to your information being transferred to and processed in the United States. Safeguards in place: Stripe participates in the EU-US Data Privacy Framework; Standard Contractual Clauses apply for EEA/UK transfers with Supabase, Vercel and Resend.
7. Security
- Encryption in transit (HTTPS/TLS) for all data
- Encryption at rest for all database content
- Row-level security, organisations cannot access each other's data
- Time-limited signed URLs for report access
- Environment-based secret management, no API keys in code
- Staff access limited to what is necessary to deliver the service
8. Your rights
New Zealand and Australia. Under the NZ Privacy Act 2020 and Australian Privacy Principles, you have the right to request access to, and correction of, personal information we hold about you, and to complain if you believe we have breached your privacy rights. NZ complaints: privacy.org.nz. Australian complaints: oaic.gov.au.
UK and EU (GDPR). In addition, if you are in the UK or EU you have the right to object to processing, request erasure, request restriction, request data portability, and lodge a complaint with your national supervisory authority.
9. Data retention
| Data type | Retention period | Reason |
|---|---|---|
| Survey responses and scores | 24 months after report generation | Product improvement and benchmarking |
| Generated reports (PDF) | 24 months, then customer may request a copy | Client access and reference |
| Purchaser records (name, email, org) | For as long as your account is active | Ordinary business record, client support and follow-up |
| Financial and transaction records | 7 years | Legal obligation (tax records) |
| Respondent email addresses (managed outreach) | 24 months from assessment close | Supports the re-measure comparison and aggregate research, then permanently removed |
| Server logs | 30 days | Security monitoring |
10. United States, jurisdiction-specific information
CalOPPA. We operate a website and collect personal information online. In compliance with CalOPPA, this Privacy Policy is published at clairsyn.com/privacy and discloses what information we collect, how we use it, and how users can access or correct it.
CCPA / CPRA. The California Consumer Privacy Act currently applies to for-profit businesses with annual gross revenue exceeding $26.625 million, or that process the personal information of 100,000+ California consumers annually, or derive 50%+ of revenue from selling personal information. Clairsyn does not currently meet any of these thresholds. If our scale of operations grows to meet them, we will update this policy to include full CCPA/CPRA disclosures. California residents may contact us at any time at hello@clairsyn.com to request information about data we hold about them.
Automated decision-making. California's September 2025 CCPA regulations introduced requirements for businesses using automated decision-making for significant decisions affecting consumers. Our report assembly process involves automated selection of pre-written content based on scores. We do not believe this constitutes a significant decision about a California consumer within the meaning of the regulations. We will monitor regulatory guidance as it develops.
Other US state privacy laws. At Clairsyn's current scale, we do not meet the revenue or data volume thresholds that trigger most US state consumer privacy laws. Residents of all US states may contact us at hello@clairsyn.com to request access to or deletion of any personal information we hold about them.
CAN-SPAM Act. All commercial emails we send to US recipients comply with the CAN-SPAM Act. Every commercial email includes our business contact information, a clear subject line, and a functional unsubscribe mechanism. We honour unsubscribe requests within 10 business days.
11. Canada, jurisdiction-specific information
PIPEDA and provincial privacy laws. We comply with Canada's Personal Information Protection and Electronic Documents Act (PIPEDA) and, for Quebec residents, the Act Respecting the Protection of Personal Information in the Private Sector (Law 25). Our practices meet the PIPEDA principles of consent, purpose limitation, collection limitation, use and disclosure limitation, accuracy, safeguards, openness, individual access, and challenging compliance. Quebec residents have additional rights under Law 25, including data portability and de-indexation. To exercise these rights, contact hello@clairsyn.com.
CASL. All electronic messages we send to Canadian recipients comply with CASL. Assessment invitations, progress updates and report delivery emails are transactional messages directly facilitating a transaction the recipient's organisation has agreed to, and are exempt from CASL consent requirements. Where a purchaser has opted in to receive commercial communications, we rely on express consent. All commercial messages include our name, a contact address, and a clear unsubscribe mechanism honoured within 10 business days. We do not add purchasers or respondents to marketing lists without express consent.
12. Data breaches
If we become aware of a personal information breach likely to cause serious harm, we will notify affected individuals and the relevant regulator as soon as practicable. For NZ: Office of the Privacy Commissioner. For AU: OAIC under the Notifiable Data Breaches scheme. For UK/EU: relevant supervisory authority within 72 hours. For Canada: Privacy Commissioner of Canada and affected individuals under PIPEDA's breach of security safeguards requirements.
13. Cookies
Clairsyn Threshold uses only essential cookies necessary for the platform to function, a session cookie to maintain your state during a purchase, and a Stripe cookie for payment security. We do not use tracking, advertising, or analytics cookies without your consent.
14. Children
Clairsyn Threshold is not directed at individuals under 18. We do not knowingly collect personal information from anyone under 18. Contact hello@clairsyn.com if you have concerns.
15. Changes to this policy
We may update this Privacy Policy from time to time. The current version is always published at clairsyn.com/privacy. Material changes will be communicated to active purchasers by email.
16. Contact us
Email hello@clairsyn.com, or visit clairsyn.com. We will respond to all privacy requests within 20 working days.
Questions about this document? Email hello@clairsyn.com.