Privacy Policy

Last updated: April 2026

1. Scope

This policy describes how Clarix (“we”) collects, uses, and protects information when you use the Service.

2. What we collect

3. How we use it

4. Tenant isolation

Each firm's data is partitioned by a tenant identifier and is not accessible to other firms. Staff access is role-restricted within your firm.

5. Sub-processors

We use third-party infrastructure providers to host the Service (e.g. Supabase for the database, Railway and Vercel for application hosting, Cloudflare R2 or AWS S3 for object storage, Resend or SendGrid for email). These providers process data only to the extent necessary to deliver their service.

6. AI features

AI-assisted endpoints send relevant request data (such as trial-balance summaries or working-paper notes) to a model provider for inference. We do not transmit data beyond what is necessary for the requested computation.

7. Retention

We retain tenant data while your account is active and for a reasonable period afterwards to satisfy legal, tax, or audit requirements. You may request export or deletion of your tenant data by contacting support.

8. Security

We use TLS in transit, hashed passwords, signed session tokens, and tenant-scoped access controls. No system is perfectly secure; you should also follow strong password and access-management practices.

9. Your rights

Depending on your jurisdiction, you may have rights to access, correct, export, or delete your personal data. Email privacy@clarix.io to exercise these rights.

10. Changes

We may update this policy. Material changes will be communicated via the Service or by email.

11. Contact

Privacy enquiries: privacy@clarix.io