Privacy by design
Privacy and your data
Privacy is built into the clarity instruments, not bolted on. This page describes the design honestly.
Privacy by design
Awaken Logic's clarity instruments read how people experience their workplace. That is sensitive, so the instruments are designed around three principles: collect only the data a clarity reading needs, handle employee responses so that no individual is identifiable in any report, and obtain explicit, informed consent at the point of collection. These are design constraints, not promises added afterward.
What we collect, and why
We work with three kinds of data, and only the data each purpose needs:
- Enquiry and buyer contacts. When you make an enquiry we collect your name, work email, and organization, plus -- if you choose to provide them -- your role, your organization's size, and what is prompting the enquiry. We use this only to respond to you and to assess fit.
- Site usage signal. We measure how the site is used in aggregate -- which pages are read, whether an enquiry was started -- with no identifier attached to a person. This is non-identifying by design: no advertising cookies, no fingerprinting, no cross-site tracking. It also honors your browser's Global Privacy Control or Do Not Track preference: if your browser sends either, nothing is recorded for your visit -- a choice we make even though an aggregate, non-identifying count is not a sale or share of your personal data.
- Engagement respondent data. During an engagement, leadership and employee respondents answer the clarity instrument itself. This is the most sensitive category, and it is collected only with each respondent's informed consent before they answer.
How employee responses stay confidential
The report works at the level of patterns, never people. Employee responses are aggregated, and results are suppressed wherever a group is too small to keep an individual unidentifiable -- the protection lives in how the data is handled, not in a setting on a screen. No manager, and no one in your organization, sees an individual employee's answers.
Two respondent groups, two consents
Leadership respondents and employee respondents each give informed consent before they answer. Participation is voluntary: any respondent can decline, or withdraw after starting, without consequence.
Website analytics
We use Plausible Analytics to understand how the website is used -- which pages are read and whether an enquiry was started -- in aggregate only. Plausible is a privacy-respecting analytics service: it sets no cookies, collects no personal data, builds no profile of you, and does no cross-site tracking and no advertising. It never identifies an individual visitor. It honors your browser's Global Privacy Control or Do Not Track preference -- if your browser sends either, nothing is recorded for your visit.
Cookies and similar technologies
We use no advertising, profiling, or cross-site tracking cookies anywhere on this site, and our website analytics, described above, set none.
The cookies we do use are strictly necessary, first-party, and tied to the secure account areas of the platform: your account, the dashboard, and the sign-in and security pages that protect them. They fall into three groups:
- Authentication and session. These keep you signed in as you move between pages, and enforce the session time limits that protect your account. Most last only for your session or a few minutes, such as while you complete a second-factor or password-reset step; the longest sets an outer limit on how long a single sign-in lasts before you sign in again.
- Security. These protect the actions you take on your account against cross-site request forgery, so a change to your account can come only from you.
- Preferences. These remember functional choices inside the app, such as which organization you are currently viewing and whether you have dismissed a one-time prompt.
Because these cookies are strictly necessary to provide the service you have asked for, PIPEDA and Quebec's Law 25 do not require a consent banner for them; we describe them here so the disclosure is made plainly. They are never used to advertise to you or build a profile of you, and they are not shared with anyone. Clearing them in your browser signs you out and resets these preferences.
Paying online
If and when online payment goes live, card details will be entered on the payment processor's own secure, independently certified payment page -- never on ours. Card numbers never pass through or rest on our systems; we receive confirmation that a payment happened, not the card.
Your responses and AI
Your raw responses are never sent to an outside AI provider that retains data. Where automated reasoning is used to help prepare an engagement, it works from derived fields only, never from raw respondent answers.
Sub-processors and international transfer
A small number of carefully chosen sub-processors help us operate the platform, each for a specific purpose and each under contract. Our database and authentication provider stores your data in Canada, in the Montreal region. Our payment processor and our email provider operate in the United States, so using them involves a transfer of personal information outside Canada. Where a transfer happens, it is assessed in our data protection impact assessment and governed by contract, and the information is protected to the standard this notice describes. We notify customers before we add or change a sub-processor. The current list, with each provider's purpose, region, and cross-border status, is published on our Trust Center.
Your rights
Personal information is handled under Canada's Personal Information Protection and Electronic Documents Act (PIPEDA). For personal information collected from individuals in Quebec, it is also handled under Quebec's Act Respecting the Protection of Personal Information in the Private Sector (Law 25 / Loi 25). You may ask what we hold about you, ask us to correct it, withdraw your consent, and ask us to delete your information or remove your organization's data from any benchmark. You may also raise a concern with the Office of the Privacy Commissioner of Canada. If you are in Quebec, you may also raise a concern with the Commission d'accès à l'information (CAI) at cai.gouv.qc.ca.
Exercising your rights. To exercise any of these rights, such as asking what we hold about you, correcting it, withdrawing a consent, or deleting your information, contact our privacy officer at privacy@awakenlogic.ai and a real person will action your request.
How long we keep data
We keep each kind of personal data only as long as its purpose requires, and then we destroy it. The retention periods are set in advance, so the rules are fixed before any data is collected rather than decided afterward. In plain terms:
- Enquiry and buyer contacts. Kept for up to two years after we last hear from you, then deleted, so a contact that never becomes an engagement is not held indefinitely.
- Account details. Kept while your account is open. If you close it, or ask us to delete it, we remove your personal data after a short grace period, keeping only what the law requires us to keep.
- Employee and leadership responses, the most sensitive data. Once your Clarity Report has been delivered and accepted, the raw individual responses are destroyed, or permanently de-linked from any person, within about 90 days. We keep only the aggregated, suppressed patterns the report is built from, never anything that can identify an individual. This is deliberate: the raw answers have served their purpose once the report exists, so we do not keep them.
- Consent records. Even after an account closes, we keep a minimal record that a consent was given or withdrawn for about three years, because we are accountable for being able to prove consent under Canadian law. We keep the fact of the consent, not unnecessary detail.
- Billing and tax records. Where tax law requires it, financial records are kept for about six years. These live with our payment processor and accounting system; we hold only references to them, never your card details.
- Payment-outcome and entitlement records. When an order is paid, we keep a record of the outcome and of any resulting access decision, meaning whether an order granted or changed access to the platform, for about six years from the settlement date, as Canadian tax law requires. This record is linked to your organization, not to any individual, and holds no card details.
- Security and access logs. Records of sign-ins and security events are kept for about two years to protect your account, then removed.
Wherever the law does not require us to keep something, we destroy it rather than attempt to anonymize it. You can also ask us to delete your information sooner, or to remove your organization's data from any benchmark, at any time (see "Your rights" above). Internal run records carry metadata and references, not the content of anyone's responses.
Governed by a data protection impact assessment
The consent and data-handling design described here is documented in a data protection impact assessment. It is reviewed and signed off before any respondent or buyer data is collected, so the protections are settled before collection begins, not after.
Privacy officer
Awaken Logic's designated privacy officer is Danny Tuff, Founder, who is accountable for the protection of personal information under PIPEDA and Quebec's Law 25. For any question about how your personal information is handled, or about this privacy notice, contact the privacy officer directly at privacy@awakenlogic.ai.