Clarrif (“Company,” “we,” “us,” or “our”) provides an AI-powered platform for diagnostic laboratories, hospitals, and healthcare organizations (“Customers”). This Privacy Policy explains how we collect, process, use, and protect personal data when our Customers use the Clarrif platform (“Service”).
This Policy applies to organizational Customers and their authorized users. Clarrif does not provide services directly to individual patients.
Our Customers (labs, hospitals, clinics):
Customers act as the Data Controller under applicable privacy laws.
Clarrif acts as a Data Processor and processes data only:
We do not determine the purpose of processing patient data.
We may collect:
This data is used for:
Customers may upload Lab Reports containing:
We process this data solely to:
We do not use Customer Data for advertising or resale.
Processed Lab Reports and associated AI Outputs are retained for 7 days by default. After the retention period:
Customers may configure shorter or longer retention periods through platform settings (where available). The Customer is responsible for ensuring retention settings comply with applicable laws and medical record requirements.
Residual system backups are purged according to internal secure deletion schedules.
Customers are responsible for ensuring that:
The platform provides:
Clarrif does not guarantee complete removal of all identifiers and relies on Customer oversight.
Data may be processed on secure cloud infrastructure located outside the country of origin, including outside India. By using the Service, Customers confirm that:
We implement contractual and security safeguards for international processing.
Clarrif may use third-party service providers, including:
These providers:
We may use third-party artificial intelligence providers to power certain features of the Service, including large language models (LLMs) used for generating summaries and insights. These providers may include, for example:
Such providers process data solely on our instructions and are bound by confidentiality and data protection obligations. We do not permit these providers to use Customer Data to train public models where contractual controls are available.
We implement technical and organizational safeguards including:
However, no system is 100% secure.
Clarrif does not directly collect patient consent. The Customer is responsible for:
Clarrif is not responsible for failure by the Customer to obtain proper consent.
Since Customers act as Data Controllers:
In the event of a confirmed data security incident affecting Customer Data, Clarrif will:
Customers are responsible for regulatory reporting obligations.
We may use cookies and analytics tools on our website or dashboard to:
Analytics data is anonymized where feasible and not used for profiling patients.
Clarrif does not knowingly collect data directly from children. If a Customer uploads reports relating to minors, the Customer confirms that it has obtained necessary parental or guardian consent.
Upon termination of service:
Customer Data is treated as confidential and is accessed only:
Clarrif is designed to support compliance with:
However, Customers remain responsible for their own regulatory compliance.
We may update this Privacy Policy periodically. Updated versions will be posted with a revised effective date. Continued use of the Service constitutes acceptance of updates.
For privacy-related inquiries:
If translated, the English version shall prevail in case of inconsistencies.
Last Updated: 1 Feb 2026