CHOIVE tells businesses the truth about where they stand — even when the answer is uncomfortable. This page applies the same standard to your data. Every sentence on this page is written to inform you, not protect us.
From the moment you hit the button to the moment your result appears. Nothing omitted. Nothing softened.
Data protection law requires a specific legal basis for each type of processing. Here is ours — one line per activity, no padding.
| What we do | Legal basis | Why this applies |
|---|---|---|
| Running your free diagnostic | Legitimate interest | You submitted business information to receive a result. We have a proportionate interest in processing it to deliver what you asked for. |
| Delivering a paid Analysis or Report | Contract performance | Processing is necessary to fulfil your purchase. No purchase, no processing. |
| Sending your result link by email | Consent | You typed your email and clicked send. No automatic enrolment anywhere. To withdraw consent at any time, email hello@choive.com with "Unsubscribe" in the subject — we action it within 24 hours. |
| Storing your result for retrieval | Legitimate interest | The shareable link is a core feature. Storing the result to power it is proportionate and expected. |
| Security and abuse prevention | Legitimate interest | Protecting the integrity of the service is a necessary operational function. |
| Retaining payment records | Legal obligation | Tax law requires financial records for seven years. This is not discretionary. |
Most companies bury this. We lead with it because it is the most important thing to disclose. CHOIVE's entire product is automated AI assessment. You have a right to understand it completely.
What your score is not. It is not a human judgement. Not a legal assessment. Not a commercial guarantee. It is an AI-generated analysis of publicly observable signals at the time of the diagnostic. Signals shift. Scores can be re-run. The product is designed to reflect reality — not to flatter.
A note on profiling. Under GDPR Article 4(4), what CHOIVE does constitutes profiling — automated processing of data to evaluate aspects of a business. Specifically: its market position, AI recommendation likelihood, competitive standing, and structural gaps. We name this directly because the law requires it and because you deserve to know. The result of that profiling is your CHOIVE Index and everything that flows from it. Your right to object to this profiling is described in the Your Rights section.
Your right to challenge an automated result. If you believe your score is based on inaccurate data, or if the result has affected you in a way you consider unjust, email hello@choive.com with "Automated decision review" in the subject. We examine the specific data and methodology behind your diagnostic and respond within 14 days. This right exists regardless of where you are in the world.
On Anthropic's use of your data. When your information is sent to Anthropic's API, it is processed under Anthropic's API terms. Per those terms, Anthropic does not use API inputs to train its models. Your business data is used for your diagnostic session only.
If a service receives any part of your data as part of delivering CHOIVE, it is in this table. We will update it before adding any new processor.
| Company | What they receive | Why | Where | Transfer safeguard |
|---|---|---|---|---|
| Anthropic | Business name, category, city, website, optional description, competitors, and all collected evidence | Core AI diagnostic engine — generates your score, findings, competitor identification, and report | United States | Standard Contractual Clauses (SCCs) |
| Serper | Business name, category, and city as search query terms | Retrieves live search signals for your category | United States | SCCs |
| Apify | Website URL and business name | Website inspection and independent citation data retrieval | EU — Czech Republic | No transfer — EU-based |
| Supabase | Diagnostic results, business name, category, city, job IDs, email addresses if provided | Database — stores results to power the shareable link | United States | SCCs |
| Resend | Email address and result link or Report PDF | Delivers result emails and Report PDFs | United States | SCCs |
| Stripe | Payment card details — handled entirely by Stripe. CHOIVE receives only a confirmation and job ID. | Payment processing | United States | SCCs + EU-US Data Privacy Framework |
| Netlify | IP address and standard request logs | Hosting and serverless function execution | United States | SCCs |
Most of CHOIVE's infrastructure runs on US-based services. If you are in the European Economic Area or the United Kingdom, your data crosses borders when you use CHOIVE. That is not something we hide — it is how the internet works for a global product built on best-in-class tools.
The legal safeguards that govern those transfers:
Using CHOIVE means accepting that the delivery of the diagnostic requires your business information to be processed in the United States under these safeguards. If that is not acceptable, do not run a diagnostic.
EU representative. As CHOIVE grows its European user base, we are in the process of appointing an EU representative under GDPR Article 27. Until that appointment is confirmed and published here, data queries from EEA residents are handled directly by the team at hello@choive.com with the same 48-hour response commitment.
| Data | How long | Why |
|---|---|---|
| Free diagnostic results | 90 days from creation | Powers the shareable link during a reasonable retrieval window |
| Paid Analysis results | 24 months from purchase | Supports retrieval, re-access, and dispute resolution |
| Report PDF content | 24 months from purchase | Enables redelivery if the original email was not received |
| Email addresses | 24 months from collection | Supports result redelivery on request |
| Payment records | 7 years | Tax law. Non-negotiable. Cannot be deleted earlier regardless of request. |
| Server and request logs | 90 days, rolling | Security monitoring — overwritten automatically |
After a retention period ends, data is deleted from active systems. Any residual copies in automated backups are overwritten within 30 days. To request early deletion of anything except payment records, email hello@choive.com — subject: "Data deletion." We confirm within 30 days.
One email does it: hello@choive.com — subject: "Data rights request." No forms, no ticket systems, no waiting rooms. If you are in the EEA or UK and our response does not satisfy you, you have the right to escalate to your local supervisory authority.
California has the strongest consumer data rights in the United States. If you are a California resident using CHOIVE, those rights apply to you. Here is what they mean in practice — not in legal abstractions.
Right to know. You can ask us what personal information we collect about you, why we collect it, and who we share it with. The data journey section above answers this for everyone. California residents can also request a formal disclosure — email hello@choive.com with "CCPA — right to know" in the subject.
Right to delete. You can ask us to delete personal information we have collected about you. We will do so within 30 days, subject to legal retention requirements. Email us with "CCPA — deletion request."
Right to opt out of sale. CHOIVE does not sell personal information. There is nothing to opt out of. This is not a policy position — it is how the product works. We have no advertising revenue, no data broker relationships, and no mechanism through which your data is transferred in exchange for value.
Right to non-discrimination. Exercising any CCPA right will not result in you receiving a different level of service, a higher price, or any other penalty. The diagnostic works the same regardless of whether you have exercised data rights.
How to submit a CCPA request. Email hello@choive.com — include "CCPA request" in the subject and specify which right you are exercising. We respond within 45 days. No fee. No verification process beyond confirming you are the person whose data is at issue.
HTTPS everywhere. Encrypted storage at rest. Role-based database access — the number of people who can touch production data is deliberately small. We do not log sensitive form inputs beyond what the diagnostic requires.
Something will eventually go wrong somewhere. If a breach puts your data at risk:
If you think your data has been compromised, email hello@choive.com now. Security reports go to the top of the queue.
CHOIVE uses only the cookies required for the service to function. There is no advertising infrastructure, no behavioural analytics platform, and no third-party tracking script embedded anywhere on this site.
Because we use only strictly necessary cookies, no consent banner is required. If this changes, we update this section and add the right controls before touching anything.
CHOIVE is a professional business intelligence tool. It is built for adults who own, operate, or manage businesses. We do not knowingly collect personal data from anyone under 18. We do not market to minors. The service has no features designed for or directed at children.
If you believe a minor has submitted data through CHOIVE — whether by running a diagnostic or making a purchase — email hello@choive.com immediately. We will delete all associated data without delay and, where a purchase was made, issue a full refund.
Parents and guardians who discover that a minor in their care has used CHOIVE should contact us. We take these cases seriously and resolve them the same day.
The date at the top of this page changes whenever this policy changes. For material changes — anything that meaningfully affects how we collect, use, or share your data — we post a notice on the CHOIVE homepage for at least 14 days before the change takes effect.
Previous versions are available on request. If a material change is not acceptable to you, email us to delete your data before the new version kicks in. Using CHOIVE after that date means you accept the updated policy.
We do not apply policy changes retroactively to data already collected under a prior version.
No ticket system. No privacy form that routes to nobody. If something on this page is unclear, or if how we handled your data does not feel right — send an email. We read everything and respond within 48 hours.
hello@choive.com