Legal
Privacy policy
In short
We collect what's needed to run Clyffe, and we use it to provide and improve the service, nothing more. Clyffe is not a workforce surveillance tool. Your organisation's data is never sold, and never shared with third parties for their own purposes without your consent. You can opt out of your content being used to improve Clyffe at any time. Questions and requests go to privacy@clyffe.io.
This summary is for convenience; the full policy below is what applies.
1. Who we are and what this covers
This policy explains how Clyffe Pty Ltd, ABN 72 699 492 718 (Clyffe, we, us), an Australian company, handles personal information across the clyffe.io website and the Clyffe services: our applications, device agents, and related software. It applies to visitors to our website, people who hold Clyffe accounts, and people whose information is contained in the data our customers connect to Clyffe.
2. Our two roles
Clyffe is built for businesses, and that shapes how we handle data. We handle information in two ways:
- For ourselves: account details, website enquiries, and communications. For this information we decide how and why it is used (under the GDPR, we are the controller).
- On behalf of your organisation: the content a customer organisation submits or connects to Clyffe, which can include personal information about its team members (for example, details of the people who use its cloud services and devices). We process this to provide the services to that organisation, on its instructions.
If your information is in Clyffe because your employer or organisation uses our services, your organisation controls that data, so questions about it are best directed there first, and we will support them (and you) with any request. Business customers that need a data processing agreement (including GDPR Article 28 terms) can request one at legal@clyffe.io.
3. Information we collect
Account and contact information. Name, work email address, organisation details, sign-in information, and the contents of your communications with us, whether you write to us or sign up for the services.
Customer content. The data your organisation submits to Clyffe or authorises Clyffe to collect, which may include:
- information from connected cloud services. For example, when your organisation connects Google Workspace, we collect directory information about its users (such as names, email addresses, and security settings), which apps have been granted access, activity metadata, and licence information. Our use of information received from Google APIs is limited as set out in section 6;
- information from managed devices, such as device and software inventory, device health, and settings;
- support requests and their contents, which can include a description of the problem, device details, and screenshots you choose to attach;
- documents and files your organisation uploads, such as software invoices and agreements.
Payment information. When paid plans are available, payments will be handled by our payment processor. Card details are entered directly with the processor and never reach Clyffe's systems; we receive billing contact details and subscription status.
Technical and usage information. Logs, IP addresses, browser and device information, diagnostic telemetry, and records of how the services are used (associated with your organisation and account so we can operate and support the product). Our product interfaces load fonts from Google Fonts, which means your browser requests font files from Google along with standard request metadata.
On the website. Our marketing website does not use advertising cookies. We may use privacy-preserving, cookieless analytics to understand overall site usage. If you email us, we receive what you send.
4. Our approach to end-user privacy
Clyffe watches over systems and devices, and we hold a firm line about what that means for the people using them: Clyffe is not a workforce monitoring or surveillance tool, and we don't build features whose purpose is to watch people rather than protect them.
We design the services with privacy-protecting patterns that limit what we transmit and store to what the service genuinely needs. For example, the device agent never transmits the full contents of your browser or your documents. It works with the minimum required, such as device health, settings, and software inventory. Screenshots reach Clyffe only when a person chooses to attach one to a support request.
5. How we use information
We use information to:
- provide, operate, secure, and support the services;
- improve Clyffe, including its AI features (see section 6, including how to opt out);
- send service communications, such as invitations, alerts, and summaries your organisation has set up;
- keep customers informed about Clyffe products and updates. Every marketing email includes an unsubscribe link, we honour unsubscribes promptly, and where the law requires your consent first (for example under the GDPR), we ask for it; and
- comply with law and protect Clyffe, our customers, and others from harm or abuse.
These purposes are the limit: we do not share personal information or customer content with third parties for their own purposes without your consent, and we never sell it.
Where the GDPR applies, our lawful bases are: performing our contract with you (providing the services), our legitimate interests (securing, supporting, and improving the services, and communicating with business customers), your consent (marketing and optional features), and compliance with legal obligations.
6. AI features and Google user data
Some Clyffe features use AI models from third-party providers. Today that is Anthropic's Claude models, which power features such as our onboarding assistant. When you use an AI feature, the relevant content (for example, your conversation with the assistant and related workspace information) is sent to the provider only to generate the response. We do not permit providers to use that content to train their models.
We may also use service data, including customer content, to improve Clyffe and its AI features, except for information received from Google APIs, which is never used for that purpose (see below). Your organisation can opt out of this at any time by emailing privacy@clyffe.io (or through workspace settings, where available). Opting out does not limit your use of the services.
Google user data. Clyffe's use and transfer to any other app of information received from Google APIs will adhere to the Google API Services User Data Policy, including the Limited Use requirements, and to the Google Workspace API User Data and Developer Policy. In particular, we use raw or derived Google user data only to provide and improve the user-facing features of Clyffe that your organisation has connected Google Workspace to use. We do not use, transfer, or sell Google user data, whether raw, aggregated, or derived, to create, train, or improve any machine learning or artificial intelligence model, including generalised or foundational models. We do not transfer it to third parties except as necessary to provide those features, to comply with law, or as part of a merger or acquisition with prior notice. Humans do not read it except with your organisation's permission, for security or abuse investigation, to comply with law, or where it has been aggregated and anonymised.
7. Who we share information with
We share information with service providers who help us run Clyffe, only for the purposes described in this policy:
| Provider | What they do | Data involved | When |
|---|---|---|---|
| Microsoft (Azure) | Cloud hosting: compute, database, storage, messaging, secrets management, and monitoring | Service data generally, as part of hosting Clyffe | Always |
| Anthropic | AI models behind Clyffe's AI features | Content processed by an AI feature, such as onboarding conversations and related workspace information | When you use AI features |
| Resend | Delivering Clyffe's emails: invitations, device setup links, and summaries | Recipient email addresses and message content | When we email you |
| Stripe | Payment processing on Stripe-hosted pages; card details never reach Clyffe | Billing contact, organisation, and subscription details | When paid plans are available |
| The Google Workspace connector, reading your organisation's own Workspace data | The Workspace information described in section 3 | When your organisation connects Google Workspace | |
| Halo Service Solutions (HaloPSA) | Filing support tickets into your organisation's own HaloPSA instance | Ticket content, requester email, device details, and attached screenshots | When your organisation connects HaloPSA |
As Clyffe grows we may add providers; for example, a Microsoft 365 connector is in development. We update this list before a new provider begins handling customer content. If you'd like to be told about changes, email privacy@clyffe.io and we'll notify you directly; where the GDPR applies to your organisation's use of Clyffe, you may object to a change on reasonable data-protection grounds.
We may also share information:
- with a Clyffe partner (such as an IT provider) that your organisation has engaged to administer Clyffe on its behalf;
- with our professional advisers, under confidentiality;
- with authorities where the law requires it or to protect people from harm; and
- as part of a corporate transaction such as a merger or acquisition, with notice to you.
8. International transfers
The providers we work with operate in various countries, including the United States, so personal information may be stored and processed outside the country where you live. Where the GDPR applies, we rely on appropriate safeguards for those transfers, such as the European Commission's standard contractual clauses or an adequacy decision. Where Australian privacy law applies, we take reasonable steps to ensure overseas recipients handle personal information consistently with the Australian Privacy Principles.
9. Security
We design Clyffe with security at the centre: encryption in transit and at rest, secrets held in managed vaults, signed and verified software updates, access controls, and monitoring. Our security practices are managed under Clyffe's information security management system, which is aligned with recognised standards such as ISO 27001.
No service can promise perfect security, but protecting the data you trust us with is the point of Clyffe. If a data breach occurs, we comply with applicable notification laws, including Australia's Notifiable Data Breaches scheme and, where it applies, the GDPR. If you believe your data has been exposed, contact us immediately at privacy@clyffe.io.
10. How long we keep information
We keep information while your organisation's account is active and as needed for the purposes above. When an account closes, customer content is deleted within 90 days, after which it also ages out of backups. Logs and diagnostic data are kept for a limited period. We may retain some information longer where the law requires it, for example business records, or to resolve disputes.
11. Your rights and choices
Wherever you are, you can ask us to access, correct, export, or delete your personal information, object to how we handle it, opt out of AI-improvement use (section 6), and unsubscribe from marketing. Write to privacy@clyffe.io. We respond to all requests, and won't treat you differently for making one. If your information is in Clyffe through your organisation's use of the services, we may refer the request to that organisation, and we'll help them fulfil it.
Australia. Where the Privacy Act 1988 (Cth) applies to us, we handle personal information in accordance with the Australian Privacy Principles. If you have a complaint, contact us first and we will respond promptly. If you're not satisfied with our response, you can complain to the Office of the Australian Information Commissioner (oaic.gov.au).
European Union and United Kingdom. Under the GDPR and UK GDPR you also have rights to data portability, to restrict processing, to withdraw consent at any time, and to lodge a complaint with your local supervisory authority. Our lawful bases for processing are set out in section 5.
California. Under the CCPA/CPRA you have rights to know, correct, and delete personal information, and to opt out of its sale or sharing for cross-context behavioural advertising. We do not sell personal information, and we do not share it for cross-context behavioural advertising. You can exercise these rights, including through an authorised agent, via privacy@clyffe.io.
12. Cookies
The Clyffe apps use cookies that are essential to signing you in and keeping your session secure. Our marketing website does not use advertising cookies, and we don't use third-party advertising cookies anywhere. We may use privacy-preserving, cookieless analytics to understand overall site usage.
13. Children
Clyffe is a business service and is not directed at children. You must be at least 18 to hold an account. We do not knowingly collect personal information from children; if you believe we have, contact us and we will delete it.
14. Changes to this policy
We may update this policy from time to time. If a change is material, we will give you reasonable notice, by email or through the services, before it takes effect. The effective date at the top of this page always shows the current version.
15. Contact
Privacy questions, requests, and complaints go to privacy@clyffe.io. Legal notices go to legal@clyffe.io. Clyffe Pty Ltd, ABN 72 699 492 718, New South Wales, Australia.