Clearly
Legal/Privacy Policy

Draft for legal review — these documents are not yet in force.

Clearly — Privacy Policy

Version 1.1 (draft for counsel review) — [DATE] Operator: [LEGAL ENTITY NAME], [ADDRESS], Switzerland ("Clearly", "we"). Contact for data protection: [privacy@clearly.app] · [postal address] EU representative (Art. 27 GDPR): [NAME, ADDRESS — appoint before EU launch; see §7.2] UK representative (Art. 27 UK GDPR): [NAME, ADDRESS — appoint before UK launch]

This policy explains how we process personal data when you visit our website, create an account, or use the Clearly service — a live briefing instrument that transcribes meetings and builds a structured, cited brief during the conversation. Clearly is operated from Switzerland and offered worldwide. This policy is written to satisfy the Swiss Federal Act on Data Protection (FADP, Art. 19 et seq.), the EU and UK GDPR, and applicable US state privacy laws. One policy, one set of practices; §7 states the additional rights your region gives you.

1. The two roles we play

For your account, billing, and our website, Clearly decides how data is processed: we are the controller (under CCPA/CPRA terminology, the "business").

For the content of your meetings — transcripts, briefs, flags, participant names, anything spoken in the room — the agency that runs the meeting (our customer) is the controller, and Clearly processes that content strictly on the customer's instructions as a processor (Art. 9 FADP / Art. 28 GDPR; a "service provider" under CCPA/CPRA). That processing is governed by our Data Processing Agreement, not by this policy. If you participated in a meeting run with Clearly and want to exercise your rights regarding what was said, the agency that invited you is your first point of contact; we support them in responding.

2. What we process, why, and on what basis

Where the GDPR applies, the legal basis for each activity is given in parentheses (Art. 6(1) GDPR).

2.1 Website visitors

  • Data: server logs (IP address, user agent, timestamps) held by our hosting provider; cookieless, aggregated page analytics (no advertising trackers, no cross-site identifiers, no consent-banner cookies).
  • Purpose / basis: operating and securing the site; measuring aggregate usage (legitimate interest, Art. 6(1)(f)).

2.2 Account and workspace data

  • Data: name, business email address, password (stored as a hash by our authentication provider), workspace/agency name, workspace role, the email addresses you invite.
  • Purpose / basis: providing the service you signed up for (performance of contract, Art. 6(1)(b)); service communications (Art. 6(1)(b), and Art. 6(1)(f) for security notices).

2.3 Billing data

  • Data: customer identifiers with our payment provider Stripe, subscription status, and a minute-ledger of purchases, grants, and per-meeting consumption. Card data is entered directly with Stripe and never touches our systems; for payment processing, Stripe acts in part as an independent controller under its own privacy terms.
  • Purpose / basis: contract performance (Art. 6(1)(b)); statutory accounting retention (Art. 6(1)(c); Art. 958f Swiss Code of Obligations — 10 years).

2.4 Meeting content (we are processor — summary for transparency)

When a facilitator runs a session:

  • Meeting audio is streamed from the facilitator's browser directly to our speech-to-text provider over an encrypted connection. Clearly never receives, stores, or has access to the audio.
  • The resulting transcript text (speaker-diarized), the brief built from it (each field citing the verbatim sentence it came from), AI-suggested clarification flags, open questions, participant names and roles, and the end-of-meeting summary are stored for the customer's workspace.
  • During the meeting, transcript excerpts and the brief state are sent to our AI provider (OpenAI) to produce brief updates and flag suggestions. Meeting content is not used to train AI models — our provider agreements exclude training use, and our speech-to-text provider's model-improvement program is switched off for all Clearly traffic.
  • Nothing from a meeting is shown on the shared client display unless the facilitator explicitly chooses to surface it.
  • Before each session, the facilitator completes a consent confirmation step — confirming that all participants were informed and consented — which is stored with a timestamp (see our Meeting Participant Notice); the customer is responsible for obtaining that consent under our Terms of Service.
  • The customer's legal basis for this processing is the customer's own determination as controller (typically Art. 6(1)(b)/(f) GDPR plus the all-party consent practice required by our Terms).

2.5 Optional calendar integration (Microsoft 365)

If a workspace connects Microsoft Teams, we read upcoming calendar events (title, time, attendee names and email addresses, organizer) to pre-fill sessions (Art. 6(1)(b)). Tokens are stored encrypted at rest and deleted on disconnect. The integration is read-only with respect to your calendar.

2.6 Emails

Transactional emails only (e.g., workspace invitations) (Art. 6(1)(b)). No marketing emails without separate consent (Art. 6(1)(a)).

3. Where your data lives, and cross-border transfers

3.1 Where your data lives

Stored data lives in the European Union. Our database and authentication provider (Supabase) runs in AWS eu-west-1 (Ireland) — all workspace data, transcripts, briefs, and account records are stored at rest in the EU. Our application compute is pinned to Dublin, Ireland (Vercel region dub1); only static assets (no personal data) are delivered from a global edge network.

3.2 Recipients

Some processing leaves the EU during a meeting: audio goes to our US speech-to-text provider, and transcript excerpts to our US AI provider. We use a small set of service providers (processors/subprocessors), each bound by a data processing agreement:

ProviderFunctionCountryTransfer safeguard
SupabaseDatabase & authenticationEU — Ireland (AWS eu-west-1)DPA; data at rest in the EU [verify DPF status for support access]
DeepgramSpeech-to-text (audio in, text out)USADPA with EU SCCs + Swiss addendum; model-improvement program opted out
OpenAIAI analysis of transcriptsUSA [EU residency under evaluation]DPA; [DPF status to verify] / SCCs + Swiss addendum
StripePaymentsUSA/globalStripe DPA; [DPF status to verify] / SCCs
VercelHosting (compute: Dublin) & cookieless analyticsEU compute / USA entityDPA; Swiss–U.S. & EU–U.S. Data Privacy Framework certified
MicrosoftCalendar integration (only if connected)Per your M365 tenantMicrosoft DPA
ResendInvitation emails (optional)USASwiss–U.S. & EU–U.S. Data Privacy Framework certified

The always-current list is published at SUBPROCESSORS.md ([clearly.app/legal/subprocessors]).

3.3 Transfer mechanisms

Where recipients are in the USA, transfers from Switzerland rely on the Swiss–U.S. Data Privacy Framework (Federal Council adequacy decision, in force since 15 September 2024) for certified recipients; transfers from the EU/EEA rely on the EU–U.S. Data Privacy Framework for certified recipients; otherwise we use the EU Standard Contractual Clauses (2021/914) with the Swiss addendum recognized by the FDPIC and, for UK data, the UK Addendum / IDTA. We perform and document transfer impact assessments where required.

We disclose personal data to authorities only where legally required.

4. Retention

DataRetention
Account & workspace dataLife of the account. Self-service deletion is built in: you can delete your workspace (owner, with confirmation) and your entire account at any time.
Billing records10 years (Art. 958f CO). When a session is deleted, its ledger entry survives content-free — minutes and timestamps only, no meeting content.
Meeting contentCustomer-controlled. Sessions (transcript + brief + record) and clients can be deleted at any time in the product. Workspaces can set a retention policy that automatically deletes transcripts after a chosen number of days (briefs are kept); a nightly job enforces it.
Consent confirmationsTimestamped, stored with the session's pre-meeting context; lifecycle follows the session.
Server logs & security telemetryShort rotation windows set by our hosting provider.

5. Security and incidents

Workspace isolation is enforced twice — at the database layer (row-level security) and again in every API route. All traffic is encrypted in transit (TLS); stored data is encrypted at rest by our database provider. Meeting audio is never stored. Payment data never reaches our systems. Access to production systems is restricted and logged. A plain-language description of the architecture is published in our Trust Overview.

If a security incident affects your personal data, we will notify affected customers without undue delay with what we know, what it means, and what we are doing — and notify regulators where the law requires it (FADP Art. 24, GDPR Art. 33/34, and US state breach-notification statutes).

6. Children

Clearly is a business tool and is not directed at children. We do not knowingly process personal data of anyone under 16, and we do not permit account creation by minors. If you believe a minor has provided us data, contact [privacy@clearly.app] and we will delete it.

7. Your rights

Wherever you are, you can ask us for access, correction, deletion, a portable copy, and restriction of or objection to processing based on legitimate interest. Contact [privacy@clearly.app]; we respond within 30 days (or the shorter period your local law sets). We never discriminate against you for exercising your rights. For meeting content, where we act as processor, we will refer your request to the responsible agency and support their response. A per-region quick reference lives in REGIONAL-NOTICES.md.

7.1 Switzerland (FADP)

You have the rights of access, rectification, deletion, and data portability (Art. 25, 28, 32 FADP). You may complain to the Swiss Federal Data Protection and Information Commissioner (FDPIC).

7.2 EU/EEA (GDPR)

You have the rights of access (Art. 15), rectification (Art. 16), erasure (Art. 17), restriction (Art. 18), data portability (Art. 20), and objection to legitimate-interest processing (Art. 21). The legal basis for each processing activity is stated in §2. You may lodge a complaint with a supervisory authority, in particular in your member state of residence, work, or the place of the alleged infringement (Art. 77 GDPR). Transfers out of the EEA are protected as described in §3.3 (DPF and EU SCCs); you may request a copy of the applicable safeguards.

As a Swiss company without an EU establishment, we have appointed [EU REPRESENTATIVE NAME, ADDRESS, e-mail] as our representative in the Union under Art. 27 GDPR. [Note to counsel: appointment required before offering to EU data subjects unless the narrow Art. 27(2) occasional-processing exemption applies — given ongoing account processing it will not. Appoint before EU go-live.]

7.3 United Kingdom (UK GDPR)

The rights in §7.2 apply equally under the UK GDPR and Data Protection Act 2018. You may complain to the Information Commissioner's Office (ICO). Our UK representative under Art. 27 UK GDPR is [UK REPRESENTATIVE NAME, ADDRESS — appoint before UK launch]. UK transfers rely on the UK Addendum to the EU SCCs or the IDTA, and the UK–US Data Bridge for certified recipients.

7.4 United States (CCPA/CPRA and other state laws)

This section applies to residents of California and, in substance, to residents of states with comparable laws (Virginia VCDPA, Colorado CPA, Connecticut CTDPA, and others).

  • What we collect and disclose. In the preceding 12 months we collected these categories: identifiers (name, business email), commercial information (subscription and minute-ledger), internet activity (server logs, cookieless aggregate analytics), professional information (workspace, role), and — only as a service provider acting for our customers — audio/electronic information (transient audio streams, transcripts, briefs). Each category is disclosed only to the service providers in §3.2 for the business purposes in §2. The full mapping is our Data Inventory.
  • No sale, no sharing. We do not sell personal information, and we do not share it for cross-context behavioral advertising. We have not done so in the preceding 12 months. We use no advertising trackers at all.
  • Your rights: to know/access, to delete, to correct, to data portability, to opt out of sale/sharing (moot — see above), and to non-discrimination for exercising any of them. Exercise them by emailing [privacy@clearly.app] or using the in-product deletion controls (§4); we verify requests against your account email. An authorized agent may submit a request on your behalf with proof of authorization; we may ask you to verify your identity directly.
  • Global Privacy Control. Our site sets no advertising or cross-context tracking cookies, so there is nothing for a GPC signal to switch off — but we honor the posture: a browser sending GPC is treated as opted out of any sale/sharing. [Verify at publication that the analytics configuration is still cookieless.]
  • No dark patterns. Rights requests and deletion controls are symmetric and free of obstruction; saying no is as easy as saying yes.
  • Sensitive personal information: we do not collect it for our own purposes and do not use or disclose it beyond what CPRA permits for service provision.

7.5 Everywhere else

We extend the rights in the first paragraph of §7 to all users worldwide, regardless of local law. Where your local law grants more, it prevails.

8. Automated decision-making

Clearly's AI suggests brief fields and clarification flags; a human (the facilitator) reviews and decides on every suggestion before anything is shared. Clearly makes no automated decisions producing legal or similarly significant effects on individuals (Art. 21 FADP / Art. 22 GDPR).

9. Do Not Track and Global Privacy Control

We don't track you across sites, so both signals are honored by default: no advertising cookies, no cross-site identifiers, no behavioral profiles. See §7.4 for the formal GPC statement.

10. Changes

We will post updates to this policy here, with the version and date at the top. For material changes affecting account holders, we notify workspace owners by email at least 30 days before they take effect. Earlier versions are available on request.


This document is a draft prepared for review by qualified counsel (Swiss lead; EU/UK/US local review for §7) and has placeholders ([...]) that must be completed before publication.