This policy explains what personal information Clariva collects, why we collect it, who else touches it, where it is stored, how long we keep it, and how you can get it back or have it deleted. It applies to this website and to every client engagement.
We handle personal information in accordance with Canada's Personal Information Protection and Electronic Documents Act (PIPEDA), British Columbia's Personal Information Protection Act (PIPA), and Canada's Anti-Spam Legislation (CASL).
We collect what we need to do the work and nothing else. We never sell, rent or trade your information. Your business figures are confidential and are used only to build your deliverables. A small number of service providers – hosting, email, payments, and AI tools that are barred from training on our inputs – process data on our behalf, some of them outside Canada. Analysts who occasionally assist work under written NDAs. This site sets no cookies and runs no advertising trackers; the one measurement tool we use counts pages and clicks without identifying anybody. You can ask us at any time what we hold, correct it, or have it deleted.
- Who is responsible
- What we collect
- Why we collect it
- Consent, and withdrawing it
- Data you give us about other people
- Your business data is confidential
- Who else processes your data
- AI tools
- Storage outside Canada
- How we protect it
- How long we keep it
- If there is a breach
- Your rights
- Email and CASL
- This website
- Children
- Visitors outside Canada
- Complaints
- Changes
- Contact
1. Who is responsible
Clariva is a consulting practice – business planning, financial modeling, marketing strategy and websites – carried on as a sole proprietorship by Artur Podgornyi in Nanaimo, British Columbia, Canada, registered with BC Registries under firm registration number FM1115647 (“Clariva”, “we”, “us”).
Artur Podgornyi is our Privacy Officer and is accountable for the personal information in our custody, including information handled by service providers and subcontractors on our behalf. Reach the Privacy Officer at info@clarivagroups.ca.
“Personal information” means information about an identifiable individual. Information about a business itself – its revenue, costs or margins – is not personal information, but we treat it as confidential regardless (section 6).
2. What we collect
- Contact details you give us – name, email address, phone or messaging handle, business name, links to your website and social profiles, and anything else you include when you write to us, request a resource, request a First Look, or place an order.
- Engagement information – the business details you provide through our intake, by email, or on a call: revenue, costs, pricing, staffing, goals, financing needs and supporting documents. This may include personal information about you as an owner.
- Datasets you share for analysis – for example, a booking, point-of-sale or CRM export used for client segmentation. These may contain personal information about your customers; section 5 governs it.
- Correspondence – emails and WhatsApp messages you send us, kept as the record of the engagement.
- Payment records – invoices, amounts, dates and the confirmation reference from the payment method used. We never see or store full card numbers; card payments, where offered, are handled entirely by the payment provider.
- Technical data – our hosting provider records standard server and security logs (IP address, timestamp, page requested, browser type) to serve the site and defend it against abuse.
We do not collect sensitive categories of personal information such as health, biometric or government identification data, and we ask you not to send them. We do not buy contact lists.
3. Why we collect it
- To deliver the service you ordered – building your model, plan or report, and corresponding with you about it.
- To answer your enquiry, prepare a quote, or produce a complimentary First Look from your public website and social profiles.
- To send you the specific resource you asked for, such as a checklist or sample report.
- To invoice you, take payment, and keep the financial and tax records the law requires us to keep.
- To provide support during the revision window and, where you have subscribed to it, ongoing service.
- To keep this website secure and working, and to understand in aggregate how it is used.
- To send you occasional email about our services, where you have consented (section 14).
We do not use your information for any new purpose without telling you and, where required, obtaining your consent. We do not sell, rent or trade personal information. Ever.
4. Consent, and withdrawing it
We collect and use personal information with your knowledge and consent. Sending us an enquiry or an intake form is your consent to use that information to respond and to prepare or deliver the work. For marketing email, we rely on your express consent or, where CASL allows, the implied consent that follows from an existing business relationship.
You may withdraw consent at any time by writing to us, subject to legal or contractual restrictions and reasonable notice. If withdrawing consent means we can no longer deliver a service you have ordered, we will tell you before acting on it. We may retain limited information after withdrawal where the law requires it – see the retention schedule.
5. Data you give us about other people
Marketing work often runs on an export of your own customer or booking records. When you send us such a dataset:
- You remain the organization responsible for that personal information. We act as your service provider, processing it only on your instructions and only for the engagement.
- You confirm that you collected it lawfully and may disclose it to us for this purpose.
- We do not contact the individuals in it, we do not use it for any other client, and we do not add it to any list.
- We ask you to send the least identifying version that still works – a customer ID instead of a name, an initial instead of a full name, no more fields than the analysis needs. We are glad to advise on what to strip before you export.
- Raw datasets are deleted or returned within 90 days of final delivery unless you ask us to keep them for the support window. What we retain after that is our own analysis, not your raw records.
6. Your business data is confidential
The financial and operating details you share for an engagement are confidential. We use them only to produce your deliverables, and we do not disclose them except as described in section 7 or where the law compels us. We do not reference identifiable client information in our marketing without your written permission – our public case studies are demonstration cases or are anonymized so the business cannot reasonably be identified. Contractual confidentiality obligations are set out in our Terms of Service.
7. Who else processes your data
We keep the list short on purpose. Each provider receives only what it needs, and each is bound by its own contractual and privacy obligations.
| Who | What they handle | Where |
|---|---|---|
| Website hosting and CDN (Cloudflare) | Serving this site; standard server and security logs | Global edge network, incl. United States |
| Email provider | Our correspondence with you | Canada / United States |
| WhatsApp (Meta), if you message us there | Message content and your phone number, under Meta's own policy | United States / Ireland |
| Payment provider / your bank | Payment processing and confirmation; we never receive full card details | Canada / United States |
| Intake form provider, when our online form is live | The answers you submit at intake | European Union / United States |
| Professional AI tools | Research, drafting and analysis during production – see section 8 | United States |
| Subcontracted analysts | Production support at peak times, under written NDAs and reviewed by us before delivery | Canada and abroad |
We may also disclose personal information where required by law, a court order or a regulator, to collect an unpaid account, or to establish or defend a legal claim. Where we are permitted to tell you first, we will. If the practice is ever sold or reorganized, client records may transfer to the successor, who would be bound by this policy.
8. AI tools
We use professional AI tools in research, drafting and analysis. Our commitments:
- We use them under business terms that do not permit the provider to train its models on our inputs, and we do not put client material into consumer-grade AI tools.
- Every deliverable is reviewed, tested and signed off by a person before it reaches you. Responsibility for the work is ours, not a tool's.
- If you would rather your files were not processed with such tools, tell us before the engagement begins and we will accommodate it.
9. Storage outside Canada
We are based in British Columbia and our working files are held on access-controlled systems under our own control. Some of the providers in section 7 store or process data outside Canada, principally in the United States and the European Union. While information is in another country it is subject to that country's laws, and may be accessible to its courts, law enforcement or national security authorities under those laws. If you would prefer that your engagement be handled without any provider outside Canada, write to us before you order and we will tell you what is possible.
10. How we protect it
- Working files are held on encrypted, password- and multi-factor-protected devices and accounts, accessible only to people who need them for your engagement.
- Data in transit is encrypted (TLS). This site is served over HTTPS.
- Subcontractors sign written confidentiality agreements before receiving anything, and receive only the portion of the material they need.
- We keep the amount of personal information we hold to what the work requires, and delete raw datasets on the schedule below.
- No system is perfectly secure. Email in particular is not a secure channel – if a document is highly sensitive, ask us for a secure transfer link instead of attaching it.
11. How long we keep it
| What | How long | Why |
|---|---|---|
| Engagement files and deliverables | 7 years after the engagement ends | Tax and business records, and so we can support you or reconstruct the work |
| Raw datasets you shared for analysis | Deleted or returned within 90 days of final delivery | We only need the analysis, not your raw records |
| Invoices and payment records | 7 years | Required for Canadian tax records |
| Enquiries and quotes that did not become engagements | 24 months | To answer follow-ups; then deleted |
| Email subscriber records | Until you unsubscribe, plus 3 years of proof of consent | CASL requires us to be able to prove consent |
| Website server logs | Per our hosting provider's retention period (short-term) | Security and abuse prevention |
At the end of a retention period, information is securely deleted or anonymized. You can ask us to delete your information earlier – see section 13. Backups are overwritten on a rolling cycle, so a deleted item may persist briefly in a backup before it is purged.
12. If there is a breach
If personal information in our custody is lost, accessed without authorization, or disclosed in a way that creates a real risk of significant harm, we will report it to the Office of the Privacy Commissioner of Canada and notify the affected individuals as soon as feasible, describing what happened and what to do about it. Where a client is the responsible organization for the data (section 5), we will notify that client without delay so they can meet their own obligations. We maintain a record of every breach of security safeguards for at least 24 months, as PIPEDA requires.
13. Your rights
You may ask us to:
- Access the personal information we hold about you, and tell you how it has been used and to whom it has been disclosed.
- Correct it if it is inaccurate or incomplete.
- Delete it, or return it to you, subject to information we must retain by law (for example, invoices) or to complete an active engagement.
- Withdraw consent to further contact or to a particular use.
Write to info@clarivagroups.ca. We respond within 30 days, and will tell you in advance if we need the extension the legislation permits. We may ask you to confirm your identity before releasing information. Access requests are normally free; if a request requires substantial work, we will give you a cost estimate first and proceed only with your approval. If we cannot give you access to something – for example, because it would reveal another person's personal information – we will tell you why.
14. Email and CASL
- We send commercial email only where you have given express consent or where an existing business relationship gives us implied consent under CASL.
- Every commercial message identifies us, gives our contact information, and carries a working unsubscribe link. Unsubscribes are actioned promptly and always within 10 business days.
- Transactional messages about an engagement you have ordered – questions, drafts, invoices, delivery – are not marketing and continue regardless of marketing preferences.
- Requesting a free resource does not sign you up to anything: we will say plainly at the point of download if we are also asking to email you.
15. This website
- Cookies. This site sets no cookies. The one thing it keeps in your browser is the figures you type into the free Tariff Check, held in that browser's local storage so they survive a reload; they never leave your device, and clearing the tool or your browser data removes them.
- Analytics. We run Plausible Analytics and no advertising trackers. Plausible is cookieless and stores no personal data: it reports aggregate statistics only – pages viewed, referral source, approximate region, device type, and which buttons were clicked – and never builds a profile, follows you across sites, or identifies an individual visitor. No IP address is stored. Data is processed on EU servers. We use it for one purpose: to see which pages and offers people actually use, so we can fix the ones they don't.
- Fonts. The typefaces are served from this domain. Your browser makes no font request to Google or any other third party.
- Message widget. The floating message button opens WhatsApp or your email app. Nothing is sent, and no third-party script runs, unless you choose to start a message.
- Downloads. Sample reports and checklists download directly. We do not require an email address to read them, and we do not track who opens a PDF.
- Links. Where we link to another site, that site's own privacy policy governs what it collects.
16. Children
Our services are directed at business owners and are not intended for children. We do not knowingly collect personal information from anyone under the age of majority. If you believe a minor has given us information, write to us and we will delete it.
17. Visitors outside Canada
Clariva serves clients in Canada. If you contact us from elsewhere, your information will be handled in Canada under Canadian privacy law, which may differ from the law where you live. If you are in the European Economic Area or the United Kingdom and want to exercise rights available to you there, write to us and we will do our best to accommodate the request.
18. Complaints
Raise any privacy concern with our Privacy Officer first, at info@clarivagroups.ca. We will acknowledge it promptly, investigate, and reply in writing with what we found and what we changed.
If you are not satisfied with our answer, you may complain to:
- Office of the Privacy Commissioner of Canada – priv.gc.ca, 1-800-282-1376.
- Office of the Information and Privacy Commissioner for British Columbia – oipc.bc.ca, 250-387-5629.
19. Changes
If this policy changes, the new version is posted here with a new date and version number. Where a change materially affects how we handle information belonging to active clients or subscribers, we will tell them by email before it takes effect.
20. Contact
Privacy Officer – Artur Podgornyi
Clariva, a sole proprietorship · BC registration FM1115647
Nanaimo, British Columbia, Canada
info@clarivagroups.ca