← Back to AI Clarity

Privacy Policy

This notice explains which personal data AI Clarity processes, for what purpose, and what rights you have.

Controller

Sebastian Großalber – AI Clarity Rechte Wienzeile 163/47, 1050 Vienna, Austria Email: s.grossalber@hotmail.com Sebastian Großalber is also the contact person for all data protection inquiries; no separate data protection officer has been appointed (not legally required for a project of this size).

What AI Clarity is

AI Clarity is a web platform for diagnosing an organization's AI readiness and guiding AI adoption. It is developed and operated as part of a doctoral dissertation.

What data we process

Account data (name, email address, sign-in method) via Firebase Authentication. Organization data (organization name, sector, size band, locale). Answers from the readiness assessment (Quick Triage and AI Readiness Assessment), including optional free-text answers. Content you create in the toolkit tools and initiatives (e.g. initiative charter, responsibilities, risk assessments). Privacy-minimal product lifecycle events scoped to the organization (e.g. assessment completed, recommendation decided, intervention status changed). These events contain no names, email addresses, user IDs, URLs, assessment answers, free text, or Advisor content. Messages you send to the AI Advisor and its responses. When using a paid plan: payment and subscription data, processed directly by Stripe (card details never reach our own servers). Voluntarily given research consent (see separate section below).

Legal bases

Art. 6(1)(b) GDPR (performance of a contract) for core platform operation. Art. 6(1)(a) GDPR (consent) for the optional research use of your data and for the analysis of free-text answers. Art. 6(1)(f) GDPR (legitimate interest) for technical logging, privacy-minimal product lifecycle measurement, security and abuse prevention (e.g. rate limiting, the owner-action audit log).

Retention periods

Account data: up to 30 days after removal from an organization or account deletion. Organization and assessment data: 24 months from the organization's last activity (last completed assessment, last Advisor message, or last member sign-in), deliberately sized to cover two reassessment cycles (every 90 days) without forcing you to start over. Privacy-minimal product lifecycle events: 180 days. AI Advisor conversations: 90 days from the message date, independent of the organization's 24-month window. The full internal retention policy (including the deletion mechanism) follows GDPR Art. 5(1)(e) and Art. 17.

Recipients and processors

Google (Firebase Authentication): management of sign-in data. Google Cloud Platform: hosting of the application and database, Frankfurt/Germany data center (region europe-west3), within the EU. Anthropic PBC, USA: processes the messages sent to the AI Advisor to generate responses; according to Anthropic, this data is not used for training and is retained server-side for a maximum of 30 days. Stripe: payment processing, once a paid plan is actively used. Resend: delivery of transactional emails (invitations, password resets, reminders). Where data is transferred to the USA (Anthropic, potentially Stripe), we rely on the European Commission's Standard Contractual Clauses or corresponding adequacy decisions, to the extent provided by the respective vendor.

Subprocessor list

In addition to the overview above, we maintain a complete, continuously updated subprocessor list with location, purpose, and contractual basis per vendor (Paket 4 Teil 3, Compliance-Readiness-Pack): Google/Firebase Authentication (sign-in data), Google Cloud Platform (hosting, region europe-west3/Frankfurt), Anthropic PBC (AI Advisor response generation, USA), Stripe (payment processing, USA), Resend (transactional email delivery). Customer organizations with a data processing agreement receive the full, contractually binding version of this list on request, including a notification obligation for changes. Contact us at s.grossalber@hotmail.com.

Cookies and tracking

AI Clarity does not currently use analytics or marketing cookies. Only technically necessary session data (Firebase authentication tokens) is used, without which signing in would not be possible.

Voluntary research use

When creating an organization, you can voluntarily agree that anonymized or aggregated data from your organization is used for scientific analysis as part of the underlying dissertation. This consent can be withdrawn at any time in the organization settings and has no effect on your ability to use the platform.

Your rights

You have the right to access, rectification, erasure, restriction of processing, data portability, and objection. You can trigger complete deletion of your organization yourself at any time via the organization settings. For all other requests, contact s.grossalber@hotmail.com. You also have the right to lodge a complaint with the Austrian data protection authority (Barichgasse 40–42, 1030 Vienna, dsb@dsb.gv.at).

Changes to this notice

This notice is updated as needed, in particular when new data categories or processors are added. The date of the last update is shown at the bottom of the page.

Last updated: July 29, 2026