ClairifyTrust Center

GDPR Compliance Assessment

Self-Assessment · March 2026

This report presents the results of Clairify's self-assessment against the six core requirements of the General Data Protection Regulation (GDPR). The assessment reflects Clairify's compliance posture as of March 2026. Clairify operates as a data controller for individual users and processes personal data including email content via AI Large Language Models.

DPO: Mehul Patel · [email protected]Version: 1.0Classification: Confidential — Internal Use Only

Executive Summary

#AreaStatusSummary
1Privacy PolicyMediumCookie Notice blank; right to object not explicit
2Data Processing Agreement (DPA)N/ANot applicable — no B2B processor relationships
3Records of Processing Activities (RoPA)PassApproved March 2026; 5 processing activities documented
4Data Subject Rights (DSR) ProcessPassRights articulated; DSAR process in place
5Lawful Basis for ProcessingMediumLIA approved; opt-out operationalization pending engineering
6Data Protection Impact Assessment (DPIA)PassApproved March 2026; covers AI email ingestion

Risk Classification

Pass

Requirement met; no action required.

Medium

Partial compliance; remediation required but not immediately critical.

High

Direct regulatory exposure; immediate remediation required.

N/A

Not applicable to Clairify's current operating model.

Assessment Details

Remediation Roadmap

ItemPriorityOwnerAction
Complete Cookie Notice in Privacy PolicyHighLegal / ProductUpdate Termly policy with cookie inventory, purpose, duration, and opt-out
Hash retained email + enforce 12-month expiryMediumEngineeringStore SHA-256 hash on deletion; purge after 12 months
Add explicit right to object to marketing in Privacy PolicyMediumLegalAdd standalone Article 21(2) statement to rights section
Add Article 22 automated decision-making disclosureMediumLegalAdd dedicated AI processing disclosure to Privacy Policy
Tighten sensitive data basis in Privacy PolicyMediumLegalUpdate to reflect Contract basis as documented in DPIA
Reference LIA in Privacy PolicyMediumLegalAdd reference to LIA availability on request
Marketing opt-out toggle in account settingsMediumEngineeringImplement opt-out toggle; add unsubscribe to all marketing emails
Post-deletion marketing opt-inMediumEngineeringPresent explicit opt-in at account deletion flow
Reconcile CCPA table Category CLowLegalConfirm whether gender/age/race data is collected; update table accordingly
DPO Sign-off

This self-assessment was reviewed and approved by the designated Data Protection Officer. The findings and remediation items have been logged in the compliance backlog and are being actively tracked.

Mehul Patel · Data Protection Officer · [email protected] · March 2026