Clervio · Data handling & confidentiality

How we handle
your data

Clervio's work involves your organizational data. We understand that this information is sensitive, and we take our responsibility to handle it carefully seriously.

The short version

We work with the minimum data necessary to produce a useful diagnostic. We do not retain your data after delivery. We do not use your data to train AI models. If your organization has data governance requirements, we have options — including anonymized exports and on-premise analysis — that address them. We are happy to sign a data processing agreement before any engagement begins.

The free assessment

The assessment collects your answers to 28 multiple-choice questions. It does not ask for your name, company name, email, or any identifying information unless you choose to provide it on the optional interest list form at the end.

The questions describe organizational patterns — how priorities are set, how decisions get made, how work flows — not specific projects, financials, or personnel.

Assessment responses are processed in your browser to generate your results. The scored results are not stored on our servers unless you submit the optional interest list form.

If you submit the interest list form, your name, email, company, and scored pattern results are sent to Clervio via a GDPR-compliant form processing service and stored only in our secure inbox. We do not sell or share this data with any third party.

No. The assessment itself does not use AI to process your responses — it is a scored questionnaire with a deterministic algorithm. If you subsequently engage Clervio for a customized playbook (which does use AI generation), see the section below on customized playbooks.

Customized playbooks

Your scored assessment results (generated automatically) and your responses to two to three optional free-text questions: a description of your biggest execution challenge and, optionally, what you have already tried.

We do not require your company name, specific project names, financial data, or personnel information. You may use pseudonyms or generalize any specifics you prefer not to share.

Yes. Your free-text responses, combined with your assessment scores, are sent to Anthropic's Claude API to generate your customized playbook. Anthropic's API terms stipulate that data submitted via the API is not used to train their models.

Anthropic's current data usage policy is available at anthropic.com/privacy.

Two easy options. First, you may describe your challenges in general terms — "we have prioritization problems and unclear ownership" is sufficient to generate a useful playbook without naming specific initiatives or leaders.

Second, we can conduct a brief intake call instead of a written form, where we capture the inputs ourselves and you retain control over what is documented. Contact us at hello@clerv.io to arrange this.

Your assessment scores and free-text inputs are retained only for the duration of the playbook generation process — typically 48–72 hours. Once the playbook is delivered, the inputs are deleted from our working environment. We do not build a database of client inputs.

The AI Diagnostic Sprint

The Diagnostic Sprint uses three data sources: a Jira or Rally export (backlog items, epics, initiatives, status, priority, team, and owner fields), OKR documentation from corporate and department levels, and your current strategic priorities or roadmap.

We do not require financials, personnel files, customer data, or any information beyond what is needed to map your portfolio against your strategy.

We have three options depending on your organization's requirements.

Anonymized export. We provide a simple template that replaces initiative names with neutral codes before the data leaves your environment. The structural relationships — which items have no owner, which have no strategic linkage, which are overloading specific teams — survive anonymization completely. This is sufficient for most enterprise clients.

On-premise analysis. For organizations with strict data governance requirements, we can conduct the analysis in a secure environment you control — your cloud tenant, a dedicated VDI session, or a sandboxed environment your IT team provisions. Your data never leaves your firewall.

Dedicated cloud environment. For regulated industries (financial services, healthcare, defense), we can provision a dedicated processing environment under a formal data processing agreement before the engagement begins.

Please raise your requirements during the scoping conversation and we will accommodate them.

No. Your portfolio data is used exclusively to generate your diagnostic output. It is not retained after delivery, not shared with any other party, and not used to train any AI model. Each engagement is entirely independent.

The only aggregate data we track is anonymous assessment completion statistics — not client portfolio data.

Yes, and we encourage it for any engagement involving portfolio data. Our standard DPA covers the purpose and scope of processing, data minimization commitments, retention and deletion timelines, sub-processor disclosure (Anthropic, Formspree), and your rights as a data controller.

Contact hello@clerv.io to request the DPA before the engagement begins.

Which option is right for your organization?
Standard
Typical org
Mid-size, private, no regulated data
What we recommend
Standard export + DPA on request
Data handling
Shared directly. Retained 72 hours. Deleted on delivery.
Cautious
Typical org
Enterprise, legal team involved
What we recommend
Anonymized export template
Data handling
Initiative names replaced with codes before sharing. No identifiable data transmitted.
Restricted
Typical org
Regulated industry (FS, healthcare, defense)
What we recommend
On-premise or dedicated cloud analysis
Data handling
Analysis runs in your environment. Data never leaves your firewall.
Our commitments
Minimum necessary data only. We do not ask for information we do not need.
No retention after delivery. Portfolio data, free-text inputs, and assessment scores are deleted within 72 hours of delivery.
No third-party sharing. We do not sell, share, or transfer your data to any third party other than the sub-processors named in our DPA (Anthropic for AI generation, Formspree for form processing).
No AI training on your data. Anthropic's API terms confirm that data submitted via the API is not used for model training.
DPA available before any portfolio engagement. Request it at hello@clerv.io.
We will accommodate your data governance requirements. If the options described here do not address your specific situation, contact us and we will find a solution that does.

Questions about data handling?

We are happy to discuss your specific requirements before any engagement begins — including signing a DPA or walking through your security team's concerns.

Get in touch at hello@clerv.io →