Recordal
How it worksPricingSign in
Legal

Privacy Policy

Effective Date: July 27, 2026

This Privacy Policy describes how Clarhet Inc. (“Clarhet,” “we,” “us,” or “our”) collects, uses, discloses, and secures personal information in connection with Recordal (the “Service”), our executive reporting platform available at recordal.co.

1. Our Two Roles: Controller and Processor

This distinction determines who you contact about your data.

We are a Processor for the business data our customers connect, upload, or generate through the Service – including financial figures from connected systems, board packs, investor updates, quarterly reviews, uploaded documents, and the contents of any artifact drafted or finalized in Recordal. We process this data only on our customer’s documented instructions. We have no direct relationship with individuals whose information appears inside a customer’s account. If you are a director, contributor, board member, or employee whose information appears in a customer’s Recordal account, direct access, correction, and deletion requests to that customer (the Controller), not to us. We will refer such requests to the customer.

We are a Controller for information we collect directly about account holders and website visitors – including your name, work email, organization name, billing details, authentication records, and support correspondence.

A Data Processing Addendum (DPA) incorporating Standard Contractual Clauses is available on request at privacy@recordal.co.

2. Personal Information We Collect

CategoryExamplesSource
Identifiers & contact detailsName, work email address, organization name, job title, user ID, authentication recordsDirectly from you at sign‑up
Billing informationBilling contact, plan, transaction history. We do not collect or store payment card numbers – payments are processed by Stripe, a PCI‑DSS compliant processorYou, via our payment processor
Service usage dataFeature usage, packs drafted and finalized, connection status, error and performance logsAutomatically, in the course of operating the Service
Connected system dataFinancial and operational data retrieved from systems you connect (for example Stripe, QuickBooks, your CRM or HRIS), and documents you upload or email in. Processed on your behalf as Processor – see Section 1Your connected accounts, uploads, and email‑in address
Support correspondenceEmails and messages you send usDirectly from you

We do not collect biometric data, precise geolocation, demographic or diversity self‑identification data, phone‑call recordings, or special‑category / sensitive personal data as defined under the GDPR. We have no need for it and do not ask for it.

3. How We Use Personal Information

  • Operating the Service: authenticating you, maintaining your account, syncing your connected systems, drafting and delivering artifacts, and providing support.
  • Security and integrity: detecting and preventing fraud, abuse, and unauthorized access; maintaining audit logs.
  • Service communications: notifying you about outages, security matters, changes to the Service, and responses to your requests.
  • Improving the Service: diagnosing errors and improving reliability and performance using operational logs and aggregated, non‑identifying usage data.
  • Legal compliance: meeting statutory obligations and responding to lawful requests.

We do not use personal information for advertising, ad targeting, or audience profiling.

European legal bases (GDPR / UK GDPR)

  • Contractual necessity – providing the Service you or your organization contracted for.
  • Legitimate interests – securing, operating, and improving the Service, where not overridden by your rights.
  • Legal obligation – statutory and regulatory duties.
  • Consent – where required, and withdrawable at any time.

4. What We Do Not Do

  • We do not sell personal information, and we do not share it for cross‑context behavioral advertising, as those terms are defined under the CCPA/CPRA and comparable state laws.
  • We do not use advertising cookies, ad networks, or tracking pixels.
  • We do not use third‑party analytics or session‑replay tools.
  • We do not permit our AI provider to train models on your content (see Section 6).
  • We do not write to your connected systems. Connections are read‑only by design; where a provider supports restricted credentials, we require them and reject credentials with write access.

5. How We Share Information

We share personal information only with:

Subprocessors who provide infrastructure necessary to operate the Service, under written agreements limiting their use of the data. Our complete, current subprocessor list is published at recordal.co/why-us#subprocessors and includes the following as of the Effective Date:

  • Vercel – hosting / application infrastructure
  • Neon – database
  • Google / Firebase – authentication
  • Stripe – payment processing
  • Merge.dev – connectivity to customer systems (CRM / HRIS / accounting, etc.)
  • Anthropic – AI drafting
  • Resend – transactional email
  • PDF rendering infrastructure – finalized artifacts may be rendered to PDF using our hosting provider and/or a specialized PDF rendering provider (currently Browserless when configured)

We will update the list at recordal.co/why-us#subprocessors when subprocessors change and provide notice for material changes as described in our DPA.

Connected Systems are not subprocessors. When you authorize Recordal to read from a system you already use – for example Stripe, QuickBooks, your CRM, HRIS, Slack, or Google Workspace – data flows from that system to us at your direction. We do not send your data to those providers for their own purposes. Stripe and Google each appear in both roles: Stripe as our payment processor (a subprocessor) and as a system you may connect (a data source); Google as our authentication provider (a subprocessor) and as a system you may connect.

Legal and regulatory authorities, where required by law, subpoena, or court order, or to establish or defend legal claims.

A successor entity, in connection with a merger, acquisition, or sale of assets, subject to this Policy.

Clarhet Inc. is a single legal entity. We do not share information with subsidiaries.

6. Artificial Intelligence

Recordal uses AI to draft narrative content.

  • Figures are not generated by the model. Numeric values in your artifacts are retrieved from your connected sources and inserted by our systems with their source and as‑of date. The model writes prose around those figures.
  • Your content is not used to train models. API usage is governed by Anthropic’s commercial terms, under which customer content is not used for model training by default.
  • Retention at the AI provider. API inputs and outputs are deleted by the provider within approximately 30 days by default, subject to the provider’s then‑current terms.
  • Your review remains required. You are responsible for reviewing AI‑drafted content before finalizing or distributing it. See Terms of Use, Section 5.

If Anthropic’s applicable terms change in a way that materially affects the commitments in this Section, we will update this Policy and notify account holders as described in Section 13.

7. Cookies and Similar Technologies

We use only strictly necessary cookies – those required to keep you signed in, maintain your session, and protect against security threats. We do not use analytics, performance, functional, or advertising cookies, and we therefore do not operate a consent banner for non‑essential cookies. If this changes, we will update this Policy and implement consent controls before deploying any such technology.

8. International Data Transfers

Clarhet Inc. is based in the United States. We and our subprocessors process personal information in the United States and in other jurisdictions where those providers operate. Where personal information is transferred from the EEA, the United Kingdom, or Switzerland, we rely on Standard Contractual Clauses (and the UK International Data Transfer Addendum where applicable), as set out in our DPA.

We are not certified under the EU‑U.S. Data Privacy Framework, the UK Extension to it, or the Swiss‑U.S. DPF, and we do not rely on those frameworks for transfers. Transfers out of the EEA, UK, and Switzerland are covered by the Standard Contractual Clauses described above.

9. Security

We maintain technical and organizational measures appropriate to the risk, including encryption in transit (TLS), encryption of stored third‑party credentials (AES‑256‑GCM), per‑organization data isolation enforced at the query layer, and read‑only connection design.

Our current security posture is described at recordal.co/why-us#trust. No system is perfectly secure, and you are responsible for safeguarding your account credentials.

Security incident notification. If we become aware of a personal data breach affecting your information, we will notify affected customers without undue delay and, where we act as Processor, within 72 hours of becoming aware of the breach – or sooner if required to allow the customer to meet its own notification obligations.

10. Data Retention

We retain personal information for as long as your account is active and as necessary to provide the Service, then delete or anonymize it, subject to legal retention requirements and the deletion process in Section 11.

11. Your Rights, Export, and Deletion

Depending on your location, you may have rights of access, rectification, erasure, restriction, portability, objection, and withdrawal of consent. To exercise them, contact privacy@recordal.co. We verify identity before acting and will not discriminate against you for exercising these rights.

If your data sits inside a customer’s Recordal account, contact that customer – see Section 1.

Export

Yes – your packs, metric history, and sources are always yours to take, with no lock‑in. Full self‑serve export arrives August 2026; until then, email privacy@recordal.co and we'll deliver your complete data within 48 hours.

Deletion

Yes. Full self‑serve deletion arrives August 2026; until then, email privacy@recordal.co and we'll remove your data from active systems within 48 hours of confirming your request.

Deletion is requested by the organization owner or administrator and requires written confirmation of intent. On confirmed deletion:

  1. Director and contributor portal access ends;
  2. Directors are notified and have 30 days to download packs previously delivered to them;
  3. After the grace period, we perform a hard purge of the organization’s data, including stored connection credentials and finalized‑pack snapshots;
  4. We confirm completion in writing.

Copies held by our AI provider age out under that provider’s standard retention window as described in Section 6.

12. Children’s Privacy

The Service is for business use by adults. It is not directed to anyone under 16, and we do not knowingly collect information from them. If we learn we have, we will delete it.

13. Changes

We may update this Policy. For material changes we will update the effective date and notify account holders by email or in‑product notice before the changes take effect.

14. Contact

Clarhet Inc.
16192 Coastal Highway
Lewes, Delaware 19958
privacy@recordal.co

Recordal
PrivacyWhy usSecurityTermsLinkedInX© 2026 Clarhet Inc.