Legal
Privacy Policy
Last updated 12 June 2026. This policy explains what Nareth Inc., a Delaware corporation does with personal information — on this website, and in the products and services we operate for customers.
1. Who we are
Nareth Inc., a Delaware corporation (“Nareth”, “we”, “us”) provides AI software and services to organisations in healthcare, corporate governance, government and infrastructure.
For privacy questions, contact privacy@nareth.ai.
2. Two different roles
Our obligations depend on which of two roles we are in, and the distinction matters:
- As a controller — for our website, marketing, recruitment and business contacts. We decide why and how that information is processed, and this policy governs it.
- As a processor — for data inside customer deployments, including patient data in ClinicOS, board and statutory records in EGP, and operational data in GeoSmart and FieldLink. There we act only on our customer’s documented instructions under a data processing agreement, and that customer’s own privacy notice governs the relationship with the individual.
3. Information we collect
Information you give us
- Contact details submitted through our forms — name, work email, organisation, role and the content of your message
- Recruitment information you send when applying for a role
- Account and configuration data for users of our products
Information collected automatically
- Standard server logs — IP address, user agent, pages requested and timestamps, retained for security and diagnostics
- Aggregate, non-identifying usage measurement. This site sets no advertising cookies and does not participate in cross-site tracking.
Information we do not want
Please do not send us special category data, protected health information or credentials through our website forms or by email. Those belong inside a contracted product environment with the appropriate agreement in place.
4. Why we process it, and on what basis
- To respond to enquiries — necessary for steps taken at your request prior to entering a contract, or our legitimate interest in answering people who contact us.
- To provide and support our products — performance of our contract with the customer organisation.
- To secure our systems — our legitimate interest in preventing abuse, fraud and unauthorised access.
- To meet legal and regulatory obligations — including records we are required to keep.
- To send you marketing — only with your consent, withdrawable at any time without affecting anything else.
5. AI and model training
We do not use customer data to train shared models, and we do not pass it to third-party model providers for training. Models fine-tuned on a customer’s data are the property of that customer and run only within that customer’s tenant. Where a deployment uses a third-party model for inference, that is disclosed in the applicable order form and the provider is bound by terms prohibiting training on submitted data.
Our systems record the model version, source data and policy behind each output so that a decision can be reconstructed. Automated processing supports human decisions in our products; it does not replace them, and no output is presented as a final determination without a person in the loop.
6. Who we share it with
We do not sell personal information. We share it only with:
- Service providers who process data on our behalf under contract — our current subprocessors are Amazon Web Services, Microsoft Azure, Snowflake, Twilio, Stripe
- Professional advisers, auditors and insurers, under a duty of confidence
- Authorities where we are legally compelled — we will notify the affected customer unless prohibited from doing so
- An acquirer, in the event of a merger or acquisition, subject to this policy continuing to apply
7. International transfers
We process data in the United States and the European Union. Transfers out of the UK or EEA rely on the European Commission’s Standard Contractual Clauses together with a transfer risk assessment. Customers requiring data to remain in a specific jurisdiction can select a regional or self-hosted deployment.
8. How long we keep it
- Enquiry and marketing records — 24 months from last contact
- Recruitment records — 12 months after a decision, unless you ask us to keep them longer
- Security logs — 12 months
- Customer deployment data — for the contracted term, then deleted or returned on the schedule set in the agreement
9. Your rights
Depending on where you live, you may have the right to access, correct, delete, port or restrict the processing of your personal information, to object to processing based on legitimate interests, and to withdraw consent. California residents have the right to know, delete, correct and opt out of sale or sharing — we do not sell or share personal information as those terms are defined under the CCPA.
Exercise any of these by writing to privacy@nareth.ai. We respond within 30 days and will not treat you differently for asking. If your data sits inside a customer’s deployment we will route your request to that customer, who is the controller.
You may also complain to your supervisory authority. We would rather you came to us first.
10. Security
We encrypt data in transit with TLS 1.3 and at rest with AES-256, enforce single sign-on and mandatory multi-factor authentication for our personnel, apply least-privilege access, and test our systems independently. Our current controls and compliance posture are documented on our Security & Trust page. No system is perfectly secure, and we will not claim otherwise.
11. Children
Our website and products are intended for organisations, not individuals under 18, and we do not knowingly collect their information through this site. Paediatric records processed within a healthcare customer’s ClinicOS deployment are handled under that customer’s instructions and applicable law.
12. Changes
We will update the date at the top of this page when this policy changes, and will give notice of material changes to affected customers before they take effect.
Note for the Nareth team: this document is a drafting starting point, not legal advice. Have counsel review it against your actual data flows, subprocessor list and contractual commitments before launch.