Public legal document

Privacy Policy (GDPR)

This policy describes how Clara OS collects, uses, protects and retains personal data as part of its operations, in accordance with the General Data Protection Regulation (GDPR).

Publisher: Vital Delicacies SRLDomain: www.claraos.aiLast updated: 13 August 2026

1. Publisher identity and data controller

This privacy policy is published by Vital Delicacies SRL, with its registered office at Rue Cesar de Paepe 114, 6040 Jumet, Belgium, registered under VAT number BE 0737.842.376. The company acts as data controller for the processing carried out in the course of operating Clara OS, except where processing is performed on behalf of a client organisation under a specific contractual framework.

For any question about data protection or about exercising your rights, write to privacy@claraos.ai. For general assistance requests: support@claraos.ai.

2. About the application

Clara OS is a SaaS application designed to help organisations centralise, organise, automate and steer certain operational and administrative processes. Depending on the modules enabled, Clara OS may assist with the management of tasks, documents, schedules, dashboards, internal workflows and integrations with third-party services.

The application may be provided through a web interface, workspaces organised per client, conversational features and technical connectors allowing external services to be integrated within the scope authorised by the user or by the client organisation.

3. Categories of data processed

  • identification and contact data, such as last name, first name, business email address, business phone number, job title and organisation name;
  • account and authentication data, such as technical identifiers, login history, roles, permissions and security settings;
  • workspace configuration data and usage preferences;
  • content and usage data, such as requests, documents, instructions, messages, activity logs, tasks, schedule items, stock data, reporting data and other content processed in Clara OS;
  • audio and visual content you send to Clara, such as voice notes and photos of documents, labels or deliveries;
  • data from third-party services connected with authorisation, including certain Google data when the user explicitly chooses to connect their Google account;
  • technical data, such as IP addresses, device identifiers, error logs, security traces and metadata required to administer and protect the service;
  • billing and subscription data when paid services are enabled.

We limit processing to data that is strictly relevant, useful and proportionate to the operation of the service.

4. How data is collected

Data is collected directly from you when you create an account, use the application, fill in a form, contact support or enable an integration. Some data is also collected automatically while using the service through technical logs, cookies or similar technologies, error traces and security measures. Finally, data may be received from connected third-party services, within the limits of the authorisations granted and the purposes described in this policy.

5. Purposes of processing

  • provide, operate, administer and secure Clara OS;
  • create and manage user accounts, workspaces and authorisations;
  • run the features requested by the user or by the client organisation;
  • produce the answers, analyses and actions requested from Clara using artificial-intelligence models;
  • enable the use of third-party integrations and connectors;
  • maintain the integrity, availability and traceability of the service;
  • prevent abuse, fraud, unauthorised access and security incidents;
  • respond to support, assistance and account deletion requests;
  • comply with our legal, contractual and regulatory obligations.

6. Legal bases

Depending on the case, processing relies on the performance of a contract or pre-contractual measures, on compliance with legal obligations, on our legitimate interest in operating and securing the service or, where required, on your consent — in particular for certain optional integrations or non-essential trackers.

7. Artificial-intelligence processing

Clara OS runs on artificial-intelligence models. To produce an answer or carry out a requested action, the relevant content of the request is sent to model providers: the message text, the documents, images or voice notes you send, and the business context required (records, stock, schedules, conversation history).

  • OpenRouter (OpenRouter, Inc., United States): the gateway through which requests to the language models used by Clara and its agents transit, including web searches. Depending on the model selected for the request, OpenRouter routes it to that model's provider;
  • OpenAI (OpenAI, L.L.C., United States): transcription of voice messages, real-time voice features, and the similarity vectors that power Clara's memory.

The sole purpose of those transmissions is to produce the requested answer or action. Clara OS does not train any model on its clients' content, does not sell that content and does not use it for any advertising purpose.

Speech recognition on the connected glasses runs on the device: only the resulting text is sent to Clara OS.

Answers are generated automatically and may contain errors or omissions. They are neither legal, accounting, food-safety nor medical advice, nor an automated decision producing legal effects within the meaning of Article 22 GDPR: the user remains in control of the checks performed and of the decisions taken on the basis of those answers.

8. Use of Google data

General principle

When you choose to connect a Google account to Clara OS, the application only accesses the data and permissions required to run the features you enable. The access requested is limited to what is strictly necessary and is not used for advertising, data resale or any misuse of Google information.

Use of Google data

Depending on the modules enabled, Clara OS may use certain Google data to display or process Google Drive files, work with Google Docs or Google Sheets content, coordinate certain Google Calendar events, identify the user during authentication or run workflows explicitly requested by the user or by the client organisation.

Scope of permissions

The permissions requested through OAuth correspond to active features that are understandable to the user. If a Google module is not enabled, the corresponding permission is not requested. We aim to favour the least intrusive scopes compatible with the intended purpose.

Sharing and retention

Google data is not sold. It is shared only with the technical processors or services required for Clara OS to operate, within the limits of their remit and the applicable contractual safeguards. It is retained for no longer than necessary to run the enabled feature, subject to applicable legal or contractual obligations.

9. Cookies and similar technologies

Clara OS and its public website may use cookies or similar technologies to ensure the technical operation of the site and the application, maintain a secure user session, remember certain preferences, measure technical performance, detect anomalies and, where applicable, produce audience statistics subject to the applicable legal requirements.

Cookies strictly necessary for the operation of the service may be set without prior consent where the law allows. Other non-essential cookies or trackers, if used, are subject to an information mechanism and, where required, to consent.

10. Retention periods

We retain personal data for no longer than necessary for the purposes for which it is processed, subject to legal retention obligations.

  • account data is retained for as long as the account is active, then archived or deleted under the applicable rules;
  • technical and security logs are retained for a period proportionate to security, audit and abuse-prevention needs;
  • data linked to accounting, tax or contractual obligations may be retained for the legally required period;
  • security backups are retained for a limited time and follow an overwrite or purge cycle.

11. Recipients and main third parties involved

Personal data may be accessible, within the limits of their remit, to our authorised staff, our technical processors and the third-party services enabled by the user or by the client organisation.

  • OpenRouter and OpenAI for the artificial-intelligence processing described above;
  • Hostinger for hosting the application servers and the database, located in Paris (France);
  • Stripe for subscription payments and billing follow-up;
  • Brevo for the platform's transactional emails (verification, notifications, invoices);
  • Meta (WhatsApp Business Cloud API) and Telegram for routing conversations on those channels;
  • Twilio for sending SMS where that option is used;
  • Google (Gmail, Calendar, Drive, Sheets, Contacts, Google Business Profile, Google Places) and Microsoft 365 (Outlook, OneDrive, SharePoint) when the user connects those accounts;
  • Calendly, Spotify, TripAdvisor and n8n when the client organisation enables those connectors;
  • Mailgun, Resend, SendGrid, Postmark or an SMTP/IMAP server chosen by the client organisation, when it configures its own email-sending channel;
  • monitoring, backup and maintenance providers acting on our behalf, on instruction and under contract.

This list covers the recipients the service actually relies on. A connector that is not enabled triggers no transmission, and no data is passed to third parties for advertising or resale purposes.

12. Data security

We implement appropriate technical and organisational measures to protect data against unauthorised access, loss, alteration, disclosure or unauthorised destruction. Those measures may include access-rights management, authentication, logging, encryption of exchanges in transit (TLS), logical segmentation of environments, backups and security monitoring.

Clara OS does not sell its users' personal data and does not monetise Google data or data from client integrations through advertising or database resale.

13. Transfers outside the European Union

Clara OS's application servers and database are hosted in France (Paris). Some of the recipients listed above nevertheless process data outside the European Economic Area, mainly in the United States: OpenRouter, OpenAI and Twilio, as well as Google, Microsoft, Meta and Stripe for some or all of their processing.

Those transfers are framed by the mechanisms recognised under the GDPR: the European Commission's standard contractual clauses and, where the recipient is certified under it, the EU–US Data Privacy Framework adequacy decision.

14. Policy regarding minors

Clara OS is intended for professional use. The application is not designed to be used by minors outside a legally authorised and supervised framework. If we learn that data has been collected in breach of the applicable rules, we will take appropriate steps to delete or regularise it.

15. Your rights

Subject to the conditions set out by the applicable regulation, you have a right of access, rectification, erasure, restriction, objection and portability, as well as the right to withdraw your consent where processing is based on it.

You can exercise your rights by writing to privacy@claraos.ai. We may ask for additional information in order to verify your identity and secure the handling of your request. You may also lodge a complaint with the competent supervisory authority.

16. Account deletion and data erasure

You can request the deletion of your Clara OS account and, depending on your capacity, the erasure of the data associated with your user or your workspace, by writing to privacy@claraos.ai or support@claraos.ai.

Every deletion request is subject to identity verification and, where it concerns an organisation, to verification that the requester is authorised. Once validated, the active data of the account or workspace concerned is deleted or anonymised within a maximum of thirty calendar days, unless a legal obligation or legitimate ground for retention applies. Security backups still containing certain data are purged according to their normal overwrite cycle, within a further maximum of ninety days.

17. Changes to the policy

This privacy policy may be amended at any time to reflect legal, regulatory, technical or functional developments. The version in force is the one published on our site on the date of consultation.