Legal
Privacy Notice
Last updated: 12 July 2026
1.Overview
This Privacy Notice explains how Clarus (“we”, “us”) collects, uses, and shares information in connection with the Clarus website and its interactive preview (the “Site”). The Site is a product preview and collects only a small amount of information, described below. Use of the Site is also governed by our Terms of Use.
2.No patient data or PHI
The Site is not a channel for clinical or patient data. The interactive demonstration uses only curated example inputs — it accepts no uploads and no free text — and we ask that you do not submit any protected health information (PHI) or other sensitive personal data anywhere on the Site, including the contact form.
3.Information we collect
Information you provide.If you submit the “Partner with Us” form, we receive the name, organisation, email address, and any message you choose to provide.
Information collected automatically. Like most websites, our servers and infrastructure providers log basic technical information such as IP address, browser/device type, and pages requested, for security and reliability. If we enable analytics, we use privacy-first, cookieless analytics that measure aggregate usage only and do not build personal profiles.
The interactive preview. Selecting an example variant does not collect personal information about you; there is no input field, upload, or download.
4.How we use information
- To respond to your inquiry and discuss a possible preview or partnership.
- To operate, secure, maintain, and improve the Site.
- To understand aggregate, non-identifying usage of the Site.
- To comply with law and enforce our Terms of Use.
We do not sell your information, we do not use it for third-party advertising, and we do not use information you submit to train AI models.
5.The “Run again” AI comparison
The optional “Run again” button sends only the selected curated example variant to a third-party, general-purpose AI model provider in order to generate a comparison answer. It does not send any personal information about you. The provider processes that request under its own terms and privacy policy.
6.How we share information
We share information only with service providers who process it on our behalf and under confidentiality obligations, for example:
- Website hosting and content delivery (to serve the Site).
- Email delivery (to receive and respond to contact-form submissions).
- Privacy-first analytics, if enabled (aggregate usage only).
- A general-purpose AI model provider (only for the optional comparison described above).
We may also disclose information where required by law, or in connection with a merger, acquisition, or sale of assets, subject to this Notice.
7.Cookies
The Site uses only essential cookies needed to function. Any analytics we enable are cookieless. We do not use advertising or cross-site tracking cookies.
8.Data retention
We keep contact-form submissions only for as long as needed to respond to and manage the relationship, and then delete or anonymize them. Technical logs are kept for a short period for security and diagnostics.
9.Security
Security is core to what we build. We apply industry-standard technical and organizational controls to protect information:
- Encryption in transit (HTTPS/TLS) for all traffic, and encryption at rest for data we store.
- Least-privilege access control — access is limited to personnel who need it, authenticated, and logged.
- Monitoring and logging of our infrastructure, with alerting on anomalous activity.
- Vendor review — we use reputable providers for hosting, email delivery, and analytics, and hold them to confidentiality and security obligations.
- Secure development practices, dependency review, and a documented incident-response process, including notification where required by law.
- Data minimization by design — the Site has no upload, no free-text input, and accepts no PHI, so there is very little to protect in the first place.
Compliance.We are committed to complying with applicable data-protection and healthcare regulations, and we will submit to the assessments, audits, and certifications required to operate in a clinical setting. This includes GDPR/UK GDPR and CCPA/CPRA obligations today, and — as we move from preview to production deployments — HIPAA (under a Business Associate Agreement where we process PHI on a customer's behalf) and SOC 2. The public Site described in this Notice does not process PHI.
No method of transmission or storage is completely secure, and we cannot guarantee absolute security. If you believe you have found a vulnerability, please report it to info@clarusbio.uk.
10.Your rights
Depending on where you live (for example under the GDPR/UK GDPR or the CCPA/CPRA), you may have the right to access, correct, delete, or restrict the processing of your personal information, to object to processing, and to data portability. You may also have the right not to be discriminated against for exercising these rights. To make a request, email us at the address below; we will respond as required by applicable law.
11.International transfers
The Site and its providers may process information in countries other than yours, including the United States. Where required, we rely on appropriate safeguards for such transfers. By using the Site, you understand your information may be transferred and processed in those locations.
12.Children’s privacy
The Site is intended for professional and business audiences and is not directed to children. We do not knowingly collect personal information from children. If you believe a child has provided us information, contact us and we will delete it.
13.Changes to this notice
We may update this Notice from time to time; when we do, we will revise the “Last updated” date above. Material changes will be reflected on this page.
14.Contact
Questions or requests about your privacy? Email info@clarusbio.uk.