Privacy Policy

Last updated: August 2026

This Privacy Policy explains how Clarvelo UG (haftungsbeschränkt) processes personal data when you visit the website, create an account, use Clarvelo, participate in a workshop, contact support, or pay for a subscription.

This policy should be reviewed by qualified counsel before final publication.

1. Controller

Clarvelo UG (haftungsbeschränkt)<br> Libauer Str. 9<br> 10245 Berlin<br> Germany

Email: support@clarvelo.com<br> Privacy contact: support@clarvelo.com

3. Website visits and server logs

When you visit the website or app, we process technical data such as IP address, date and time, requested URL, referrer, browser type, operating system, device information, and response codes. We use this data to deliver the website, maintain security, diagnose errors, and prevent abuse.

Legal bases: Art. 6(1)(b) GDPR where required to provide requested pages or app functions; Art. 6(1)(f) GDPR for security, diagnostics, and abuse prevention. Logs are retained for 30 days.

4. Accounts, authentication, and workspaces

To create and manage accounts, we process names, email addresses, authentication credentials or identity-provider identifiers, workspace membership, roles, preferences, onboarding status, and account activity. We use this data to provide the service, manage access, secure accounts, and communicate about the service.

Legal bases: Art. 6(1)(b) GDPR for account and contract performance; Art. 6(1)(f) GDPR for security and administration; Art. 6(1)(c) GDPR where records are legally required.

5. Workshop and participant data

Customers and users may submit workshop titles, agendas, prompts, exercises, participant names, participant email addresses, invitations, chat messages, votes, comments, summaries, and other facilitation content. We process this data to provide workshop functionality, collaboration, summaries, exports, and support.

For business customers, the customer may be the controller for participant data and Clarvelo UG (haftungsbeschränkt) may act as processor under Art. 28 GDPR. Customers are responsible for ensuring that they have a lawful basis to invite participants and upload personal data.

Legal bases for our controller processing: Art. 6(1)(b) GDPR for service delivery; Art. 6(1)(f) GDPR for service security, support, and improvement. Processor processing is governed by the customer agreement and any data processing agreement.

6. AI processing

Clarvelo may send prompts, workshop content, participant contributions, and generated outputs to AI providers to create facilitation materials, summaries, and suggestions. We use Requesty EU for AI routing, AWS Bedrock in eu-central-1 (Frankfurt) for AI session insights, and Mistral in France. All AI processing takes place within the EEA.

Customer content is not used for model training where zero-data-retention is available. Requesty uses zero-data-retention where available; AWS Bedrock does not use customer content to train models; Mistral retains data for 30 days for safety purposes in accordance with its terms.

We use AI processing to provide requested service features. Legal basis: Art. 6(1)(b) GDPR where AI features are part of the service requested by the user or customer; Art. 6(1)(f) GDPR for product improvement where applicable; Art. 6(1)(a) GDPR if optional AI processing requires consent.

Do not submit sensitive personal data unless your organisation has approved that use and the service explicitly supports it.

7. Billing and merchant-of-record processing

Paid subscriptions may be processed through Polar.sh or another merchant-of-record/payment provider. Billing data may include name, email address, billing address, VAT or tax identifiers, payment status, plan, subscription period, invoices, receipts, and transaction identifiers. Full payment card details are handled by the payment provider and are not stored by us unless explicitly stated.

Where Polar acts as merchant of record, Polar may process transaction data as an independent controller for checkout, payment, tax, invoice, fraud-prevention, and compliance purposes. Please review Polar’s privacy information at checkout.

Legal bases: Art. 6(1)(b) GDPR for paid subscriptions; Art. 6(1)(c) GDPR for tax and accounting obligations; Art. 6(1)(f) GDPR for fraud prevention and billing administration.

8. Support, contact, and communications

If you contact us, we process your contact details, message content, metadata, and related account information to respond, troubleshoot, and improve support. We may also send transactional service emails such as login, invitation, billing, security, and product-change messages.

Legal bases: Art. 6(1)(b) GDPR for service-related requests; Art. 6(1)(f) GDPR for support and administration; Art. 6(1)(c) GDPR where communication must be retained by law.

9. Newsletters and marketing

If we offer newsletters or optional marketing emails, we process your email address and subscription preferences. Marketing emails are sent only where permitted by consent or applicable law. You can unsubscribe at any time using the link in the email or by contacting us.

Legal basis: Art. 6(1)(a) GDPR for consent-based marketing; Art. 6(1)(f) GDPR for existing-customer communications where permitted by law.

10. Cookies and local storage

We use strictly necessary cookies and similar technologies for sessions, authentication, CSRF protection, and security. DataFast’s cookieless analytics script does not use cookies for visitor identification, but may use session-only browser storage for continuity within the current tab. We do not use error-monitoring or marketing cookies.

More details are available in the Cookie Policy.

11. Analytics, product telemetry, and error monitoring

We use DataFast’s cookieless analytics mode to measure website and app usage and understand which channels bring visitors to Clarvelo. DataFast may process IP addresses, pages visited, referrer information, timestamps, browser and device information, and interactions with the service. It derives a pseudonymous visitor identifier from technical signals including the IP address, browser user agent, and site domain using a salt that rotates approximately every 24 hours. This means visitors are not linked into a persistent profile across different days or domains.

DataFast acts as our processor and uses this information to provide aggregate analytics and business insights. The legal basis for this privacy-preserving analytics processing is our legitimate interest under Art. 6(1)(f) GDPR in understanding and improving the service. You may object to this processing by contacting support@clarvelo.com.

We may process essential server-side diagnostics under Art. 6(1)(f) GDPR to maintain security and reliability. We do not use a third-party error-monitoring service.

12. Recipients and subprocessors

We may share personal data with service providers that help us operate the service, including hosting, email, payment, authentication, analytics, file selection, and AI providers. Current providers are listed on the Subprocessors page.

We may also disclose data if required by law, court order, law enforcement request, corporate transaction, or to protect rights, safety, users, and the service.

13. International transfers

All AI providers process data within the EEA. For US-based subprocessors, we rely on the EU-US Data Privacy Framework and Standard Contractual Clauses.

14. Retention

We retain personal data only as long as needed for the purposes described above, unless longer retention is required by law. Typical retention periods:

  • account data: for the life of the account plus a 30-day account deletion grace period;
  • workspace and workshop content: until deleted by the customer or account closure, subject to the 30-day account deletion grace period;
  • billing and tax records: statutory retention periods;
  • server and security logs: 30 days;
  • support messages: 12 months;
  • AI provider logs and submitted content: per-provider retention (Requesty zero retention where available; AWS Bedrock according to AWS EU terms; Mistral 30 days for safety purposes).

Backups may retain deleted data for a limited period before automatic expiry.

15. Your rights

Subject to legal requirements, you have the right to access, rectification, erasure, restriction of processing, data portability, objection to processing based on legitimate interests, and withdrawal of consent with future effect. You also have the right to lodge a complaint with a supervisory authority.

To exercise rights, contact support@clarvelo.com. If your data is controlled by one of our business customers, we may forward your request to that customer or ask you to contact them directly.

16. Supervisory authority

For a Berlin-based controller, the competent supervisory authority is generally:

Berliner Beauftragte für Datenschutz und Informationsfreiheit<br> Alt-Moabit 59–61<br> 10555 Berlin<br> Website: https://www.datenschutz-berlin.de/<br> Email: mailbox@datenschutz-berlin.de

17. Automated decision-making

We do not use automated decision-making within the meaning of Art. 22 GDPR unless explicitly stated in the product.

18. Changes

We may update this Privacy Policy to reflect legal, technical, or product changes. The current version is published on this page.


Clarvelo is an AI workshop facilitator for collaborative teams.