Privacy Policy
Last updated: 13 March 2026
1. Controller
KlarHealth is operated by KlarHealth GmbH (in formation). For data protection queries: privacy@staffwaresolutions.com.
2. What We Collect
- Account data: name, email, phone, password hash.
- Health data: medical records, appointment history, insurance information (with your explicit consent).
- Usage data: log files, IP addresses, browser type (for security and analytics).
- Communication: emails you send us and notification preferences.
3. Legal Basis (GDPR Article 6 & 9)
- Contract performance (Art. 6(1)(b)): Account creation, appointment booking.
- Explicit consent (Art. 9(2)(a)): Health data processing, AI translations.
- Legitimate interest (Art. 6(1)(f)): Security, fraud prevention, platform improvements.
- Legal obligation (Art. 6(1)(c)): Compliance with German healthcare regulations.
4. AI Processing
When you use our AI translation or assessment features, your medical data is sent to our AI provider (Anthropic or OpenAI) via encrypted API calls. Data is used solely for the requested task and is not used to train AI models. You can disable AI features at any time in your profile settings.
5. Data Retention
- Account data: retained until account deletion + 30 days.
- Medical records: retained until you delete them or request account deletion.
- Appointment data: 10 years (German medical records retention obligation, §630f BGB).
- Log files: 90 days.
6. Your Rights
Under GDPR, you have the right to: access, rectify, erase, restrict processing, data portability, and object to processing. To exercise these rights, email privacy@staffwaresolutions.com. You also have the right to lodge a complaint with your national data protection authority.
7. Security
We use TLS encryption in transit, AES encryption at rest for sensitive data, Argon2id password hashing, and regular security audits. Our servers are located in Germany.
8. Cookies
We use only technically necessary cookies for session management. No tracking or advertising cookies. No third-party analytics without consent.