1. Scope
This draft applies to the Cleverlever.ai website, public enquiry, Blueprint-request and Executive Opportunity Diagnostic forms, consented Snapshot submissions, authenticated Client Partner Workspace records and documents, and private Site Owner administration.
2. Information collected
Public forms may collect names, organisation and business details, work contact information, workflow descriptions, stakeholder and systems context, security or procurement requirements, preferences and consent records. A Cleverlever customer account stores the supplied name, email, business, credential-security records, session records, workspace and saved project content. Passwords, recovery codes and session tokens are not stored in plaintext. The Snapshot stores answers and results only when the visitor chooses to provide identifying details and consents.
3. Local-only Snapshot use
Visitors may complete the assessment without consenting to identifiable storage. In that case, answers and the result remain in that visitor’s browser storage and are not submitted to Cleverlever’s database.
4. Purpose
Information is used to route and assess fit, provide human review, prepare a diagnostic or Executive Opportunity Brief shell, prepare or deliver a Blueprint or pilot, manage client knowledge and approvals, maintain project records, secure access, prevent abuse and preserve an audit trail.
5. Measurement and analytics choices
Cleverlever records privacy-safe, first-party aggregate events in D1, such as a page path or successful form category. These events exclude form contents, names, contact details, reference numbers, Snapshot answers and exact scores, voice transcripts, uploads, client identifiers and private routes.
Optional Google Analytics loads only after a visitor chooses Accept analytics. Advertising, remarketing, Google Signals, User-ID, enhanced conversions and advertising personalisation remain disabled. Visitors can reject, manage or withdraw analytics choices, and Global Privacy Control and Do Not Track signals are respected.
6. Storage, customer accounts and providers
Structured records are stored in the Sites-provided D1 database. Client-uploaded files use Sites-provided R2 object storage with ownership metadata in D1. Customers use a first-party Cleverlever account and server session; they are not signing into ChatGPT. OpenAI models may process prompts or content through Cleverlever’s protected service-provider architecture. Cleverlever does not receive a customer’s ChatGPT conversations, ChatGPT memory, ChatGPT files or ChatGPT billing information. Infrastructure providers may process data outside Australia; data-residency commitments must not be assumed.
7. Access controls
Public visitors cannot access private records. Signed-in customers are matched to one Cleverlever account and may access only that account’s records and files. Customer identity cannot satisfy the separate Site Owner guard. Owner administration retains its stronger sign-in and explicit private allowlist.
8. Retention, access and correction
The controlled pilot provides export, correction, archive and deletion-request controls. Final retention periods, legal holds and deletion timing require professional review and confirmed business policy. Requests may be made through the Contact page using the displayed reference number or by email to privacy@cleverlever.ai.
9. Security and limitations
Controls include standards-based password derivation with unique salts, opaque server sessions, secure HTTP-only cookies, session expiry and revocation, rate limits, same-origin mutation checks, account-scoped records, secure file access and audit events. Recovery codes are displayed once and stored only as secure hashes. No internet service can promise absolute security. Do not submit payment-card data, identity documents, health information or unnecessary sensitive material. No payment is collected during the controlled pilot.
10. Overseas processing and complaints
Final professional review must confirm cross-border disclosures and Australian Privacy Act obligations. Privacy enquiries may be submitted to privacy@cleverlever.ai.
