Privacy Policy
-
Second Look Advisory (ABN 38 101 747 913) is a sole trader business based in Sydney, Australia, founded by Abigail Schoenheimer. We provide culture and organisational assessment consulting, and we build and operate The Clearing, a facilitated team reflection tool.
For any privacy question, or to exercise any of the rights described below, contact abigail@secondlookadvisory.com
-
We keep three groups of people separate, because what we hold about each is different.
People who use The Clearing as a facilitator or consultant. Name, email address, and a password stored only as a cryptographic hash, never in plain text. If you're part of a consulting engagement, we may also hold the name of your organisation.
Participants in a Clearing session. Participants don't have an account and don't log in. When you complete a prework survey, we collect your answers to a set of reflection questions, some free text, some scaled. We do not collect or store your name, your email address, an employee identifier, or your IP address against your response. If you tick the box to have your private note emailed to you, see section 5 below, because that's handled differently and kept separate from everything else.
Visitors to our website. Standard information collected by our website host (Squarespace) about how the site is used, covered in section 9.
We don't collect employee identifiers, HR data, performance data, salary data or demographic data, and we don't hold any of our clients' customer data. The Clearing does not connect to or integrate with any system inside your organisation.
-
Facilitator and consultant account details are used to run your account, run your sessions, and get in touch with you about your account. Participant prework responses are combined with other participants' responses in the same session and, once a minimum number of people have responded, used to generate an aggregate summary of insights and a facilitation guide. No individual response is ever surfaced on its own, to anyone, at any point in that process.
-
Nobody in your organisation, including whoever is running the session, can retrieve an individual participant's response. This is enforced in the database itself, not just hidden by the screen you're looking at. Only the combined, aggregate picture is ever shown, and only once enough people have responded that no individual answer could be isolated.
One person at Second Look Advisory can read individual raw responses, for quality assurance while the tool is generating insights. That access is logged and time-limited, as described in section 6. Nobody connected to your workplace has that access, at any tier.
-
At the end of the prework survey you can tick a box to have your private note emailed to you, with a follow-up nudge 30 days later. If you do:
We send you the note by email straight away.
We store your email address and the date, in a store that has no connection to your session, your team or your organisation. A copy of that store on its own tells us nothing about who you work for or what you were doing.
Your note itself is never stored. Once it's emailed, it's gone from our systems.
Your email address is deleted the moment the second email is sent, or after 35 days, whichever comes first, whether or not the send succeeded.
Every email includes a one-click, no-login link to stop the reminder, which deletes the stored row immediately.
Nobody at Second Look Advisory, including the founder, can read this store. It exists only to trigger two scheduled emails.
-
Retention is automatic and runs on a fixed schedule. We don't offer different retention periods to different clients.
Individual prework responses (all free text and per-response detail) are permanently deleted 60 days after your session's insights and facilitation guide are generated, or after a shorter fallback period if a session never generates a guide.
Aggregate insights and the facilitation guide are permanently deleted 18 months after the session was created.
Reminder email addresses (section 5) are deleted on send or after 35 days, whichever is sooner.
Facilitator and consultant account details are kept while your account is active, and deleted on request or on account closure.
Deletion is a genuine, permanent deletion from our live systems, not a flag or an archive. Deleted records can remain in routine platform backups for a further period (currently up to approximately 14 days) before those backups themselves expire.
If you ask us to delete your data, or your organisation's data, sooner, we can normally do that within one business day, subject to the backup period above.
-
We're an Australian business, but our data is not currently stored in Australia. The Clearing's database runs on Lovable Cloud, which runs on Supabase's infrastructure hosted by Amazon Web Services, currently in the Asia Pacific (Singapore) region. Supabase and Lovable each hold ISO 27001 and SOC 2 Type II certification.
Because this involves sending personal information outside Australia, here's what that means under Australian privacy law: we remain accountable for what happens to your information even once it's overseas, and we've chosen providers on the strength of their independent security certification, not because it's the cheapest option.
To generate aggregate insights, prework responses are processed by third-party AI language model infrastructure. As currently configured, this runs through Lovable's AI gateway, which may route to providers including OpenAI, Google Gemini or OpenRouter. We do not have a direct agreement of our own with these providers at this time; we're relying on Lovable's stated position that raw or identifiable personal data is not used to train models. We're working towards a direct provider relationship with clearer, contracted retention and non-training terms, and will update this policy when that changes.
Our website is hosted by Squarespace.
We don't sell your information to anyone, and we don't share it with third parties for their own marketing.
-
The Clearing generates aggregate insights and a facilitation guide using AI language models, based on combined, de-identified participant responses. This output is a summary intended to support a facilitator's or leader's own judgment; it does not make a decision about, and is not applied to, any individual person, and no individual participant's access to anything, or standing with their employer, is determined by it. We keep this section under review as Australian privacy law's transparency requirements for automated decision-making take effect from 10 December 2026.
-
If you sign in to The Clearing using "Sign in with Google," we receive your name, email address and profile picture from your Google account, as needed to create and verify your account. We don't request access to your Gmail, Google Drive, contacts, or any other Google data, and we don't use your Google account information for anything beyond identifying you and running your Clearing account.
-
Our website, hosted on Squarespace, uses standard cookies and analytics tools to understand how the site is used. You can control cookies through your browser settings. The Clearing product itself does not use advertising or tracking cookies.
-
We apply security measures appropriate to the sensitivity of what we hold, including encryption of data at rest and in transit, database-level access controls (not just screen-level hiding), multi-factor authentication on our own administrative accounts, and additional application-layer encryption for the reminder email store described in section 5.
No system is completely immune to risk. If we become aware of a data breach likely to result in serious harm, we'll notify affected individuals and, where required, the Office of the Australian Information Commissioner, in line with the Notifiable Data Breaches scheme.
-
Under the Australian Privacy Principles, you can ask us for access to the personal information we hold about you, ask us to correct it, and ask us to delete it, subject to the limits described in this policy (for example, we may not hold much to give you, because most participant responses aren't linked to an identity in the first place). To make a request, contact [privacy email address].
If you're not satisfied with our response, you can complain to the Office of the Australian Information Commissioner at oaic.gov.au.