Privacy Policy
Last updated
This Privacy Policy explains how Redon Emini Tech SH.P.K., a company registered in the Republic of Kosovo, trading as Clairwire ("Clairwire", "we", "us"), collects, uses and protects personal data when you use the Clairwire platform, websites and related services (the "Service"). It also explains the choices and rights you have.
Clairwire is a media monitoring and PR intelligence platform: it collects publicly available content from online sources configured by our customers and analyzes it with artificial intelligence. That makes two perspectives relevant below — data about users of the Service, and personal data appearing in monitored public content.
1. Data we collect about users
- Account data. Name, email address, password hash (we never store plaintext passwords) and, if you sign in with Google, the basic profile information Google shares for authentication.
- Organization data. Organization name, team membership, roles, invitations, and the client workspaces, sources, alert rules and notification channels you configure.
- Billing data. Subscriptions and invoices are handled by our payment processor acting as merchant of record. We receive subscription status and billing metadata; we do not store full payment card details.
- Usage and log data. Standard technical logs (IP address, browser type, timestamps, pages and actions) used for security, debugging and understanding aggregate product usage. We do not sell this data or use it for third-party advertising.
- Communications. Messages you send us (for example to support) and delivery records for notifications we send you (email, Slack, push).
2. Data in monitored public content
When customers configure monitoring for a client, the Service collects content that is publicly accessible online — news articles, posts, videos, comments and similar material — from sources such as news sites, RSS feeds and social platforms. This content may include personal data of the people who wrote it or are mentioned in it (for example an author's name and public handle).
For this processing:
- We collect only content that is publicly available at the time of collection; the Service does not access private accounts, private groups or non-public communications.
- The content is processed to produce analysis for the customer that configured the monitoring — sentiment, credibility, influence and virality scores, classifications, summaries, alerts and briefings — under our customers' instructions. In data-protection terms, the customer is generally the controller of this monitoring data and Clairwire processes it on their behalf; the lawful basis is typically the customer's legitimate interest in monitoring public commentary relevant to their clients.
- Our Terms of Service prohibit using the Service to surveil or harass private individuals outside a legitimate professional communications context.
If you believe content about you is being processed in the Service and wish to exercise your rights, contact us (Section 9) — we will respond directly or route the request to the relevant customer as appropriate.
3. AI processing
Mention analysis, briefings and recommendations are generated using large language models operated by third-party AI providers under data-processing agreements. Content sent for analysis is limited to what is needed for the feature (the mention content and relevant context). We do not permit our AI providers to use customer data or monitored content to train their models. Every AI-generated score or recommendation shown in the Service includes a plain-language rationale so that human reviewers can evaluate it.
4. How we use data
We use the data above to: provide and secure the Service (authentication, multi-tenancy isolation, abuse prevention); run the monitoring, analysis, alerting and briefing features; deliver notifications to channels you configure; process subscriptions; provide support; understand aggregate usage to improve the product; and comply with legal obligations. We do not sell personal data, and we do not use it for third-party advertising or profiling unrelated to the Service.
5. Sharing and subprocessors
We share data only with service providers ("subprocessors") that help us run the Service, each bound by contract to protect it: cloud hosting and database infrastructure, AI analysis providers, our payment processor / merchant of record, email delivery, product analytics (PostHog), the messaging platforms you explicitly connect (for example Slack, which receives the briefings and alerts you configure to be sent there), and, for our public website only, Meta, which receives the advertising-measurement events described in section 10, and Cal.com, which provides the calendar used to book a walkthrough call (also section 10). We may also disclose data where required by law, to protect the rights and safety of users or the public, or as part of a merger or acquisition (with notice).
6. International transfers
We are based in the Republic of Kosovo, whose Law on Protection of Personal Data closely mirrors the GDPR, and our infrastructure and subprocessors may process data in the European Union, the United States and other countries. Where data protected by EU/UK or Kosovo data-protection law is transferred internationally, we rely on appropriate safeguards such as Standard Contractual Clauses.
7. Retention
- Account and organization data — kept while your account is active and deleted or anonymized within 90 days after account deletion, except records we must keep for legal or accounting purposes.
- Monitored content and analysis — kept while the associated client workspace is active so trends and history remain useful; deleted in the ordinary course after the workspace or account is deleted.
- Logs — retained for a limited period appropriate to security and debugging, then deleted or aggregated.
8. Security
We apply industry-standard measures appropriate to the data we handle: encryption in transit, hashed credentials, tenant isolation enforced at the data layer (every record is scoped to its organization and client workspace), role-based access, and the principle of least privilege internally. No system is perfectly secure; if we learn of a breach affecting your personal data we will notify you as required by law.
9. Your rights
Depending on your location (including under GDPR and CCPA/CPRA), you may have rights to access, correct, delete, export or restrict processing of your personal data, to object to processing based on legitimate interest, and to lodge a complaint with a supervisory authority. You can exercise most account-data rights directly in the Service (profile and organization settings); for anything else, contact us at [email protected] and we will respond within the timelines required by applicable law. We do not discriminate against you for exercising privacy rights.
10. Cookies, analytics and advertising measurement
The signed-in Service uses essential cookies only: a session cookie for authentication and security.
Our website also uses two measurement tools. Both run from your first page view. The cookie notice at the bottom of the page lets you opt out at any time.
PostHog (product analytics). PostHog sets a first-party cookie and may record your visit (the pages you open, where you click and scroll, and what you type into non-sensitive fields; passwords and payment fields are never captured) to help us improve the site. If you sign in, the recording is linked to your account. If you opt out, PostHog only counts page views, clicks and time on page, with nothing stored in your browser, so two visits cannot be linked.
Meta Pixel (advertising measurement). The pixel sets the _fbp and _fbc cookies and tells Meta which pages you viewed, whether you opened the checkout, and similar events, so we can see whether our ads on Facebook and Instagram work. When you create an account or start a subscription, our server also sends Meta a matching event through Meta's Conversions API containing a hashed (SHA-256) version of your email address, your IP address, your browser identifier and the two cookies above. Meta processes this data under its own privacy policy and data processing terms. If you opt out, the pixel stops and its cookies are removed.
Opting out puts both tools in their minimal state and removes the cookies they set; the site works the same either way. You can change your answer at any time with "Privacy choices" in the footer. We also honour the Global Privacy Control browser signal: when your browser sends it, you are not asked, neither tool runs in full and nothing is sent to Meta. You can also block either tool with a content blocker, or ask us to stop using your data for analytics or advertising measurement by emailing [email protected].
11. Children
The Service is a professional tool and is not directed at children under 16. We do not knowingly collect personal data from children; if you believe a child has provided us personal data, contact us and we will delete it.
12. Changes to this policy
We may update this policy as the Service evolves. Material changes will be announced via the Service or email before they take effect; the date at the top of this page always reflects the latest revision.
Contact
Privacy questions and requests: [email protected].