Privacy Policy
Civinc Privacy & Cookie Statement
Version 2.0 · Effective 29/7/2026
In short
Civinc is built so that we learn as little about you as possible. Five things are true of every session:
• We never ask for your name, date of birth or any other identifying detail, and we have no way of finding them out.
• Nobody at Civinc has access to your conversations.
• Your conversations are permanently deleted within 72 hours.
• The organisation hosting the session never sees who took part, or what anyone wrote.
• Taking part is voluntary. You can stop at any moment.
1. Who we are
Civinc is an online dialogue platform operated by Civinc B.V. (“Civinc”, “we”), Tweede van der Helststraat 89h, 1073 AN Amsterdam, the Netherlands.
On the platform you answer a set of statements and questions, are then matched one-on-one with someone who answered differently, and have a written conversation with them. The organisation that arranges the session (the customer) receives a report on what the group as a whole thinks. More about how the platform works: www.civinc.co/product.
This statement applies to participants in a session, to visitors of our website, and to anyone who contacts us. Questions about it go to hello@civinc.co, or by post to Civinc, attn. Privacy, at the address above.
2. Who is responsible for what
The customer decides to run a session, sets the theme and the statements, decides who is invited, chooses whether AI analysis is used, and decides what to do with the report. Under the GDPR the customer is therefore the controller, and Civinc is its processor. We process session data only on the customer’s documented instructions, under the data processing terms that form part of our agreement with every customer. Where a customer makes this privacy statement available to you, it does so in its role as controller.
For a short and separate list of processing operations we act as controller in our own right:
• keeping the platform secure, available and free of abuse;
• improving the platform, using aggregated data from which no individual can be identified;
• our website, cookies and any correspondence you send us.
These are two distinct roles, not joint control: we do not decide together with the customer why and how your data is processed.
3. What we know about you — and what we do not
We never ask for your name, email address or telephone number. The platform has no field in which to enter one. Everything you do in a session is attached to a randomly generated identifier, such as SDFJ8234SEDh2489.
There is no key that links that identifier to you. Not because we have decided not to look it up, but because it does not exist. Neither we nor the customer can produce one.
Under the GDPR that identifier still makes your data pseudonymised rather than anonymous, which is why this statement exists and why we treat the data with care.
Two things you should know
Open text fields and conversations are yours to write in. If you type your name, your job title or another detail that identifies you, that detail is in the data. We advise against it, both in the introduction shown before the session and on the platform itself.
Because we cannot identify you, we usually cannot act on a request to access, correct or erase your data, since we have no way to find it. Article 11 of the GDPR covers exactly this situation. Section 12 explains what we can do.
4. What we process
Category | What this includes |
Your answers | Your responses to statements, and your answers to the closed and open questions asked before and after the conversations. |
Conversation content | The messages you exchange with your conversation partner. Kept for a maximum of 72 hours (see section 9). |
Session metadata | Device type, operating system, browser, start and end times of the session and of each individual conversation, number of messages, conversation duration, number of conversation partners, likes given and received, who proposed to switch partner, whether you reported a conversation partner, your random user ID. |
Correspondence | Email you send us, and public posts about Civinc you leave on social media. |
Website data | Data collected through cookies on our website (see section 14). |
We do not process special categories of personal data, and we do not ask for them.
Your IP address is processed by Google Firebase to establish the connection between your device and the platform. Civinc has no access to it and does not store it. It is not part of any dataset we hold or share.
5. Why we process it
Purpose | Whose purpose | Legal basis |
Running the session: matching you to a conversation partner and enabling the chat | Customer (we act as processor) | Performance of the customer’s agreement with you, or the customer’s legitimate interest |
Producing the group report: aggregating answers and, where enabled, analysing conversations with AI | Customer (we act as processor) | The customer’s legitimate interest in understanding opinion within its organisation |
Keeping the platform secure and stable, and preventing abuse | Civinc | Our legitimate interest, and our legal obligations |
Improving the platform, on aggregated data from which no one can be identified | Civinc | Our legitimate interest |
Answering your emails and running our website | Civinc | Our legitimate interest |
Taking part in a session is voluntary, and you can stop at any point. That is the most direct way to object to processing, and it works immediately.
6. Nobody reads your conversations
Your conversation is shown to one person: your (anonymous) conversation partner.
No Civinc employee has access to the conversations. Where the customer has enabled AI analysis, conversations are read by machine only, as described in section 7.
If you report your conversation partner, we act on the report itself. We can suspend an account on the basis of the report and the surrounding metadata. We do not open the conversation to check.
The customer never receives conversation content, in any form, at any time.
7. AI analysis
AI analysis is optional. The customer decides whether it is used, and when it is, we tell you at the start of the session.
Where it is enabled, the messages sent about a given statement are pooled across conversations and analysed by a large language model, to surface the arguments, themes and lines of reasoning that came up. The analysis only runs once enough messages have been sent across enough separate conversations to reach a critical mass. The output describes the group, never contains direct quotes, and is not a judgement, score or profile of you.
Who does it
Our AI provider is Mistral AI SAS, a French company based in Paris. Mistral acts as our processor under a data processing addendum. It is a European company, subject to European law, with no parent outside the EU. Processing takes place on servers in the European Union. Your data is not used to train Mistral’s models.
Mistral retains conversation fragments for a maximum of 30 days for abuse monitoring, after which they are permanently deleted. Civinc itself deletes conversation content within 72 hours (see section 9).
What is sent, and what is not
Conversation fragments are detached from the broader context of the session and isolated from all other data, including your answers to statements and questions. Mistral does not receive the session as a whole, the customer’s identity or your user ID.
What we do not do
We do not use emotion recognition and we process no biometric data. We make no automated decisions that produce legal effects for you or similarly significantly affect you (Article 22 GDPR). Your answers to statements and questions are analysed by us, statistically, not by an AI model.
Separately, customers setting up a session can ask the same model to help draft statements. Only the administrator’s own request is sent; no participant data is involved.
8. What the customer receives
The customer receives a report describing the group: how participants answered the statements and questions, and (where AI analysis was enabled) which arguments and themes came up in the conversations.
The customer does not receive, and cannot request:
• conversation transcripts or excerpts;
• any data attached to an individual or to a user ID;
• a list of who took part, or participation rates per person.
If and when results are broken down by group (such as department, location, role) we apply a minimum of seven participants per group. Below that threshold no breakdown is produced, because with fewer people a result starts to point at individuals. The threshold is not configurable by the customer.
When a conversation starts, your conversation partner sees your answers to the statements and where relevant a group label. We and the customer agree group labels that are broad enough not to identify anyone.
9. How long we keep things
What | How long | Why |
Conversation content | Maximum 72 hours after the session ends | So the conversation can be restored if you refresh the page, and so any AI analysis can run. Encrypted on the server; permanently deleted afterwards. Our AI provider deletes its copy within 30 days (section 7). |
Answers to statements and questions, session metadata | For the term of our agreement with the customer, and no longer than three years | So that the analysis behind the customer’s report can be verified and, if needed, repeated. Deleted earlier on the customer’s instruction. |
Correspondence | For as long as it remains relevant | We keep what you send us while it is still of use to our relationship with you or to our records, and remove it when it is not. We do not delete correspondence on a fixed schedule. |
Cookie data | See the appendix | — |
At the end of our agreement with a customer, all session data belonging to that customer is deleted or returned, at the customer’s choice.
10. Who else processes data
We use a small number of providers. Each acts as our processor under a written agreement, may only process data on our instructions, and is bound to confidentiality.
Provider | Contracting entity | What it does | Where, and what protects it |
Mistral AI | Mistral AI SAS — Paris, France | AI analysis of conversation fragments, where the customer has enabled it (section 7). | Stored and processed in the European Union. No transfer outside the EU. |
Google Cloud Platform | Google Cloud EMEA Ltd — Ireland | Hosting, storage and database services for the platform. | Stored in an EU region. Google staff outside Europe may access it for support. Covered by the EU-U.S. Data Privacy Framework, with Standard Contractual Clauses as a fallback. |
Google Firebase | Google Cloud EMEA Ltd — Ireland | Connecting your device to the platform. Processes your IP address; we have no access to it. | Same as above. |
Google Analytics | Google Ireland Ltd | Website statistics, on our website only. Not used on the platform itself, and only with your consent. | Same as above. |
We tell customers before we add or replace a provider, so they can raise an objection.
11. Where data is processed
Your data is stored on servers within the European Economic Area. Our AI provider is a French company and processes entirely within the European Union.
Our hosting provider is a European company that belongs to a group with offices elsewhere, and its staff outside Europe may occasionally need access in order to support or maintain the service. Under EU rules that access counts as a transfer, even though the data itself stays on European servers.
Where that happens we rely on the European Commission’s adequacy decision for certified US companies (the EU-U.S. Data Privacy Framework) and, in every case, on the Standard Contractual Clauses as a fallback, so that the transfer stays lawful even if that adequacy decision is suspended. The table in section 10 shows which provider relies on what.
We will not move the storage of your data outside the EEA. If anything else changes, we will update this statement and tell customers in advance.
12. Security
Data is encrypted in transit and at rest. Back-end access to systems holding user data is restricted to director-level staff, granted under a non-disclosure obligation and revoked on departure. Access levels are reviewed annually. We run continuous vulnerability scanning, static code analysis, and automated testing before every release, and our hosting provider holds ISO 27001 and SOC 2 certification.
Security incidents are reported to our CTO at hello@civinc.co and handled under a documented incident process. If a data breach affects you or a customer, we notify them without undue delay. Our full Security Policy is published on our website.
13. Your rights
You have the right to access your data, to have it corrected or erased, to restrict or object to processing, to data portability, to withdraw consent where processing rests on it, and to object to automated decision-making and ask for human involvement.
In practice we can rarely act on these ourselves, because we cannot connect the data we hold to you (see section 3). Three routes are open to you:
• Stop participating. You can leave a session at any point, and nothing further is recorded.
• Contact the customer that organised the session. As controller, it handles requests about session data, and we assist it.
• Contact us at hello@civinc.co if you believe you shared something identifying, or if your question concerns our website or our correspondence with you. We will respond as quickly as we can.
You can also complain to the Dutch Data Protection Authority, the Autoriteit Persoonsgegevens, or to the supervisory authority in your own country.
14. Cookies
Cookies are small files stored on your device when you visit a website. The same rules apply to comparable techniques, such as data kept in your browser’s local storage, and where we say “cookies” below we mean both.
We use cookies on our website, civinc.co. On the platform itself we use only what is technically necessary to keep your session running.
When you first visit our website you are shown a consent banner with four categories:
• Functional — necessary to make the site work, for example to remember your language or to record your cookie choice. These are always placed, because the site cannot be delivered without them.
• Preferences — remember settings you have chosen.
• Statistics — tell us how the site is used, so we can improve it.
• Marketing — used to measure the effect of our campaigns and to reach relevant audiences.
Only the functional category is placed without your consent. Nothing in the other three categories is loaded until you accept it — our consent tool blocks those scripts until then. You can change or withdraw your choice at any time through the cookie settings link in the footer of our website, and withdrawing works as easily as giving consent.
Some of these cookies are placed by third parties, who may read them when you visit other sites. The appendix lists every cookie we use, who places it and how long it lasts.
15. If Civinc is sold or merges
If Civinc, or part of it, is transferred to or merges with another party, data may transfer with it. We will inform customers and, where we are able to reach them, participants, before that happens.
16. Changes to this statement
We update this statement when our processing changes, or when technology or the law makes it necessary. Every version carries a version number and an effective date, and we keep previous versions available on request. Where a change is material, we tell customers in advance and, where relevant, show you a notice on the platform. Where a change requires your consent, we ask for it.
Questions: hello@civinc.co
Appendix — Cookies
Functional — always placed
Required for the website and the platform to work. These are placed without consent, because the service cannot be delivered without them.
Name | Placed by | Purpose | Expires |
cmplz_banner-status | Civinc | Records that you have seen and answered the cookie banner | 365 days |
cmplz_consented_services | Civinc | Records which categories and services you consented to | 365 days |
cmplz_policy_id | Civinc | Records which version of the cookie policy you consented to | 365 days |
cmplz_functional / _preferences / _statistics / _marketing | Civinc | Record your choice per category, so blocked scripts stay blocked | 365 days |
wp-wpml_current_language | Civinc | Remembers whether you are reading the Dutch or English site | Session |
_icl_visitor_lang_js | Civinc | Detects your preferred site language on arrival | 1 day |
Statistics — placed only with your consent
Tell us how the website is used, so we can improve it. Loaded through Google Tag Manager, which itself stores nothing on your device.
Name | Placed by | Purpose | Expires |
_ga | Distinguishes one visitor from another | 2 years | |
_ga_[container-id] | Keeps track of the current visit | 2 years |
Preferences and Marketing
We currently place no cookies in these categories. If that changes, we will update this appendix and ask for your consent before anything is placed.