Privacy Policy

    What we collect, why we collect it, who helps us handle it, and what you can ask us to do. In plain words.

    Last updated: October 6, 2026

    Who we are

    Paresium Technologies Inc. ("Paresium", "we", "us") makes Clara, a governed AI assistant for businesses. This policy explains what personal information we collect, why, who helps us handle it, and what choices you have.

    It covers this website, the Clara portal and API, and the messaging channels a firm can connect to Clara. If your employer or another firm gives you access to Clara, that firm decides what goes in, and we handle it on the firm's behalf. Questions about what a firm does with your information are best asked of the firm first.

    What we collect

    • Account details. Your name, work email and sign-in details, and the firm and team you belong to. Sign-in is handled by Clerk.
    • Firm content. What you and your firm give Clara: messages, documents, knowledge, rules, assistants, and the answers Clara produces. If a firm connects a Google Drive folder, Clara keeps read-only copies of the documents in it.
    • Usage and records. The record of each governed run: what was checked, which rules applied, what it cost, and the final decision. We also keep credit and usage ledgers, and technical measurements such as timings that do not contain your content.
    • Payment details. Card and billing details are handled by Stripe. We keep the credit purchases and balances that go with your account.
    • Channel messages. If a firm turns on a channel such as WhatsApp, SMS, voice, Slack or Teams, the messages sent through it reach Clara, and we keep session details such as which number or workspace was used. Twilio carries WhatsApp, SMS and voice traffic for us.
    • Website forms. If you write to us through a form on this site, we receive what you type, such as your name, email address and message.

    How we use it

    We use personal information to:

    • run Clara and give you the answers and records you asked for;
    • sign you in, keep each firm's data apart from every other firm's, and keep accounts secure;
    • charge and track credits;
    • answer your questions and requests;
    • meet our legal duties and prevent misuse of the service;
    • improve the service, within the limits in the model improvement section below.

    How AI models handle your content

    Clara uses AI models to read, check and answer. Before a model sees your text, we mask structured identifiers such as account numbers. Names, addresses and organisation names are masked only when your firm's privacy shields are switched on, so please do not assume every name is hidden. Model providers are listed on our subprocessors page.

    Model improvement. Like most AI companies, we improve our service over time. Unless your firm turns it off in portal Settings, a generalized form of your firm's data is eligible for that work. What is shared is never your original wording, and anything left that could identify a person causes the export to fail rather than ship. Enterprise data is never used this way. To opt out, someone with access to the firm's settings signs in to the Clara portal, opens Settings, and switches off the model improvement setting. It takes effect from the next export, and nothing else about the service changes. You can also email [email protected] and we will help. The full detail, tier by tier, is on our trust page.

    Clara's answers are produced by AI and can be wrong. See our terms.

    Who we share it with

    We share personal information only with the companies that help us run Clara, and only as needed to do their job. They are named on our subprocessors page, and we give customers 30 days notice before a new company that handles your content is added.

    We may also disclose information when the law requires it, to protect people or the service from harm, or as part of a sale or reorganisation of the business, in which case this policy continues to apply to the information. We do not sell personal information.

    Where your data is stored, and moving it across borders

    Our home region is Canada. A firm's records, chats, documents, knowledge and deletion certificates are stored in Azure in the Canada East region. Account, billing and ledger records are also kept in Canada.

    Some things are stored or handled elsewhere. Names and work emails for sign-in are held by Clerk, which is in the United States. Card details are held by Stripe. The step that reads and prepares your request runs on Google Cloud in the United States. The AI models we call are deployed on infrastructure that can process a request outside Canada, so your message content can be handled outside Canada today. Our network provider, Cloudflare, carries traffic between you and us.

    Because of this, your information can be subject to the laws of other countries and may be accessible to their courts and authorities. Our trust page says exactly where each step runs and what is still being built.

    We are building regional options for the United Arab Emirates, Saudi Arabia and the European Union. They are not offered yet, so this policy does not apply the European Union's GDPR to any firm today.

    How long we keep it, and deletion

    By default, we keep:

    • the record of each governed run for 7 years, unless your firm sets a stricter period;
    • technical measurements that do not contain your content for 90 days;
    • temporary caches for no more than 7 days.

    You do not have to wait for those periods to end. You can ask us to delete your information at any time by emailing [email protected], and we act on the request within 30 days. We may need to confirm who you are first. We may keep information we are required by law to keep, or that is under a legal hold, and we will tell you if that applies.

    Website form messages are kept for as long as we need them to answer you and keep a reasonable record of the conversation.

    How we protect it

    Each firm's data is kept apart from every other firm's. Data is encrypted at rest, and signing keys are kept under controlled custody. Clara keeps a tamper-evident ledger of what it did. If we have a breach that affects a firm, we tell the firm within 48 hours.

    More about how Clara keeps its promises is on the trust page. No system is perfectly secure, so we cannot promise that nothing will ever go wrong.

    Your rights

    Under Canada's Personal Information Protection and Electronic Documents Act (PIPEDA) and similar laws, you can ask us to:

    • tell you what personal information we hold about you, and show it to you;
    • correct information that is wrong or out of date;
    • delete information we no longer need, or stop using it for something you did not agree to;
    • explain how we handle your information.

    Write to [email protected]. We act on your request within 30 days. We may need to confirm who you are first. If we hold your information for a firm, we may pass your request to that firm.

    If you are not happy with our answer, you can complain to the Office of the Privacy Commissioner of Canada. We would like the chance to fix it first.

    Cookies

    This website does not run advertising or analytics tools, and its own code does not set cookies. The spam check on our contact forms, Cloudflare Turnstile, loads from Cloudflare and may use technical storage in your browser to tell people from bots. Signing in to the Clara portal uses Clerk, which uses cookies to keep you signed in.

    Children

    Clara is for businesses and their staff. It is not meant for children, and we do not knowingly collect information from them. If you think a child has given us information, write to us and we will delete it.

    Changes to this policy

    When we change this policy, we will update the date at the top. For a change that matters, we will also tell account holders by email or in the portal.

    Contact us

    Paresium Technologies Inc.
    Privacy and data requests: [email protected]