Privacy Policy

How we collect, use, and protect your data.

Updated 12 September 2026

What we collect

  • Contact form submissions – name, email, and message when you reach out to us
  • Survey responses – NPS scores, comments, and driver selections submitted by your clients or employees, collected on behalf of your firm
  • Platform usage – basic analytics to improve the service (page views, feature usage). We do not use third-party tracking pixels
  • Account information – name, email, role, and firm association for authenticated platform users

Website technical data

Our websites use Google Analytics to measure page views; your browser sends your IP address and page-view data to Google in that request.

Where a firm displays a served credential mark or reviews widget on its own website, the visitor's browser requests it from our servers or from trustedfirms.global, and we receive that visitor's IP address in the request, as with any web request; we use it only to serve the mark and for security logging.

How we use your data

  • Deliver survey programs and feedback reports to your firm
  • Generate anonymised insights and analytics using AI (see below)
  • Improve and maintain the platform
  • Respond to your enquiries

We do not sell, rent, or share your personal information with third parties for marketing purposes.

Ephemeral Data Retention

Our Ephemeral Data Retention framework gives each firm direct control over how long verbatim comments are retained – each firm configures its own retention period, from short windows for firms with strict data minimisation requirements through to extended retention for firms that want longer review windows.

NPS scores, loyalty driver selections and response metadata (dates sent and submitted, and the assigned professional) are retained as structured data for trend analysis and contain no free-text content. They remain linked to the client record for the life of your firm's engagement – that is what lets you see a client's history and act on a falling score – and are de-identified when the engagement ends. Free-text comments are retained only for the period your firm chooses. A daily automated process deletes verbatim comments once they pass your firm's retention period, recording only counts in the audit log – never content. The more privacy-protective setting always wins: shortening the period also removes existing comments older than the new period; lengthening it never restores anything already deleted. Expired staff survey invitations are anonymised by a separate daily cycle.

AI processing

Most of our platform uses no third-party AI at all. Dashboards, trend charts, NPS benchmarks and longitudinal reports all run on structured data we hold ourselves.

Custom Reports – draft commentary. When a Client Culture analyst prepares a report, the platform sends the firm's aggregate results for the period – loyalty-driver profile, theme labels, office, division and industry segment names, and a kudos count – to Anthropic under their enterprise data processing agreement, and receives draft commentary. The firm's name is replaced with a neutral reference before sending. No client names, professional names or verbatim comments are sent. Anthropic is contractually prohibited from training on this data, and all transmission is encrypted. The analytical content of every report – themes, interpretations, recommendations – and the selection and attribution of client quotes are done by Client Culture analysts from the platform. AI output is a starting input that accelerates drafting; it is not the deliverable.

Help assistant. If you use the in-platform help assistant, your typed question is sent to Anthropic with a role prompt; no platform data is attached. We record that a question was asked – when, from which page, and its length – but not what it said. Do not include client details in a help question.

EphemeralAI™ is our trademark for AI processing that strips personal identifiers before any model call. It has applied to Custom Reports commentary since 12 September 2026: the firm's name is replaced before the model call, no client, professional or verbatim content is sent, and nothing from the exchange is stored beyond the draft the analyst chooses to keep. Ephemeral Data Retention, above, is the same principle applied to your data.

Data retention

  • Survey verbatim comments – retained according to your firm's chosen retention period and deleted automatically by a daily process once that period passes
  • Anonymised themes and scores – retained for ongoing analytics and benchmarking
  • Account data – retained while your firm's account is active, deleted on request
  • Contact form data – retained only as long as needed to respond to your enquiry

Sub-processors

We use a small number of trusted third-party services to operate the platform. All sub-processors are contractually bound to protect your data.

ProviderPurposeLocation
Neon (a Databricks company)Primary database platformAWS Sydney, Australia (ap-southeast-2)
VercelApplication hosting and computeSydney, Australia
ResendTransactional and survey email deliveryTokyo, Japan
Anthropic, PBCAI-assisted draft commentary for custom reports (operator-triggered); help assistantUS
UpstashRate-limiting counters (IP-derived keys, short time-to-live, no content)Singapore (AWS)
GitHub (Microsoft)Encrypted backup storage (ciphertext only; the key is held by Client Culture)United States

Neon, Vercel, Resend and Upstash operate on Amazon Web Services infrastructure; client feedback data is stored in the AWS Sydney region. This table is the sub-processor register in section 7 of our Information Security Policy (v1.3, 12 September 2026); the same six rows, with the data that reaches each, are on our security page. Details of downstream sub-processors are available in each provider's own trust documentation.

Your rights

Depending on your jurisdiction, you may have the right to:

  • Access the personal information we hold about you
  • Request correction of inaccurate information
  • Request deletion of your personal information
  • Object to or restrict certain processing
  • Withdraw consent where processing is based on consent

To exercise any of these rights, contact privacy@clientculture.com.

Regional compliance

Client Culture operates under the Australian Privacy Act 1988 and the Australian Privacy Principles (APPs). For clients in the United Kingdom and European Economic Area, we also comply with UK GDPR and EU GDPR respectively. Regional addenda covering specific obligations are included in our full privacy policy.

Our complete privacy policy – including detailed data processing terms and regional addenda – is available at app.clientculture.com/privacy.

Questions?

For privacy enquiries, contact privacy@clientculture.com. For security-related concerns, contact security@clientculture.com.