GDPR Compliance

GDPR Commitment

clarife is fully committed to GDPR compliance. As a SaaS solution processing data of EU residents, we implement all required technical and organizational measures to protect personal data.

Your Rights Under GDPR

RightHow clarife supports it
Right of access (Art. 15)Export your data anytime as a ZIP file
Right to rectification (Art. 16)Edit your profile and data directly
Right to erasure (Art. 17)Delete your account with 30-day grace period
Right to data portability (Art. 20)Data export in structured JSON format
Right to restriction (Art. 18)Contact support to restrict processing
Right to object (Art. 21)Contact support to object to specific processing
Right to withdraw consent (Art. 7)Revoke cookie consent, disable optional features

Data Export (Right of Access & Portability)

  1. Go to Data Export - Navigate to Settings > Data Export.
  2. Request export - Click Export All Data to generate a complete copy of your data.
  3. Download - Download the ZIP file containing your data in structured, machine-readable JSON format.

ℹ️ Info: Data exports include all personal data, documents, screenshots, and metadata. The format is structured JSON, fulfilling the "machine-readable" requirement of Article 20.

Account Deletion (Right to Erasure)

  • Request deletion from Settings > Account
  • 30-day grace period allows cancellation
  • After 30 days, all data is permanently erased from all systems
  • Billing records retained for legal compliance (6 years per tax law)

Data Processing

RoleEntity
Data controllerclarife (Tomasz Sawko)
Data processorsSupabase, Backblaze, Paddle, AWS, Google Cloud, Vercel

All data processors are bound by Data Processing Agreements (DPAs) that meet GDPR requirements.

Data Processing Agreement (DPA)

A DPA is available for Business plan customers upon request. Contact legal@clarife.app to receive a copy.

Cookie Consent

clarife implements cookie consent:

Cookie typePurposeConsent required
EssentialAuthentication, preferencesNo (legitimate interest)
AnalyticsAnonymized usage (Umami)Yes

💡 Tip: You can manage cookie preferences at any time by clicking the cookie settings link in the footer of any clarife page.

Minimal Data Collection

clarife follows the principle of data minimization:

  • Only data necessary for the service is collected
  • Analytics are privacy-friendly (Umami, no PII)
  • IP addresses and device fingerprints are hashed before storage
  • No data is sold or shared for marketing

Security Measures (Article 32)

MeasureImplementation
Encryption in transitTLS 1.2+
Encryption at restAES-256
Access controlRow Level Security, role-based permissions
AuthenticationBcrypt, TOTP 2FA
Regular auditsRegular security audits
Incident responseMonitoring, alerting, documented procedures

⚠️ Warning: If you believe your data has been compromised or you want to exercise a GDPR right not covered in the UI, contact privacy@clarife.app. We respond to all GDPR requests within 30 days.


Is clarife GDPR compliant?

Yes. clarife implements all required technical and organizational measures, supports all data subject rights, stores data in the EU, and uses GDPR-compliant data processors.

Can I get a Data Processing Agreement (DPA)?

Yes. DPAs are available for Business plan customers. Contact legal@clarife.app.

How long does it take to respond to a GDPR request?

We respond to all GDPR data subject requests within 30 days, as required by the regulation.

Where can I find the privacy policy?

The full privacy policy is available at clarife.app/privacy.