CLARIDY Privacy Policy

Version: 2.0 | Last updated: March 19, 2026

Claridy B.V. | Amsterdam, the Netherlands | legal@claridy.ai

1. Introduction

Claridy B.V. ("Claridy", "we", "us" or "our") provides an AI-powered accounts payable automation platform that streamlines invoice processing, matching and approval workflows for finance teams.

We respect your privacy and are committed to protecting your personal data in accordance with the General Data Protection Regulation (GDPR) and other applicable Dutch and European data protection legislation.

In most cases, we act as a processor on behalf of our business customers who use the Claridy platform. In certain cases — such as when you visit our website, request a demo or communicate with us directly — we act as a data controller. This policy describes both roles.

2. Data Controller

Claridy B.V.

Amsterdam, the Netherlands

KVK: 97842184

VAT: NL868255749B01

Email: privacy@claridy.ai

3. Categories of Personal Data We Collect

3.1 Data you provide directly

  • Account registration: Name, email address, company name, job title and phone number when creating an account or requesting a demo.
  • Communication: Any information you provide when contacting us via email, forms or chat, including support requests.
  • Invoice and financial data: Invoices, credit notes and related documents processed through the platform, including vendor names, amounts, VAT details and payment information.
  • Employee identifiers: Names and email addresses of employees designated as approvers or users within a customer's platform.

3.2 Data collected automatically

  • Website usage: IP address, browser type, device information, pages visited and referral sources via analytics tools.
  • Cookies: Functional, analytical and (with consent) marketing cookies. See section 9 for details.
  • API logs: Technical logs of API calls for performance monitoring and debugging, including timestamps, request metadata and response status codes.

3.3 Data processed on behalf of customers

When our business customers use the Claridy platform to process invoices, we act as a processor. The personal data in those invoices (such as contact names, email addresses or employee data) is processed solely on the customer's instructions and in accordance with our data processing agreement.

4. Legal Bases and Purposes

PurposeLegal Basis
Providing the Service (invoice processing, matching, approvals)Art. 6(1)(b) — Performance of a contract
Account management and user authenticationArt. 6(1)(b) — Performance of a contract
Service communications (status updates, notifications)Art. 6(1)(b) — Performance of a contract
Improving AI models and service accuracyArt. 6(1)(f) — Legitimate interest
Security monitoring and fraud preventionArt. 6(1)(f) — Legitimate interest
Compliance with legal obligations (tax, accounting)Art. 6(1)(c) — Legal obligation
Marketing (newsletters, product upgrades — opt-in)Art. 6(1)(a) — Consent

5. Subprocessors

SubprocessorPurposeLocation & safeguards
Fly.ioCloud hosting of application infrastructureEU (Amsterdam)
Google GeminiAI-powered invoice data extractionUSA (SCCs in place)
Anthropic PBCAI-powered invoice data extractionUSA (SCCs in place)
OpenAIAI-powered invoice data extractionUSA (SCCs in place)
Perplexity AIAI-powered reasoning and data enrichmentUSA (SCCs in place)
UnipileEmail integration and inbox connectivityEU
Meta / WhatsAppMessaging integrationUSA/EU (SCCs in place)

We do not sell, rent, or trade your personal data to third parties. Data is only shared with subprocessors to the extent necessary for service delivery and under appropriate contractual safeguards.

6. International Data Transfers

When personal data is transferred outside the European Economic Area (EEA), we ensure an adequate level of protection through Standard Contractual Clauses (SCCs) as approved by the European Commission. Upon request, we can provide a copy of the applicable SCCs.

7. Data Retention

  • Account data: Retained for the duration of your account and up to 12 months after termination, unless otherwise required by law.
  • Invoice data (as processor): Retained in accordance with the customer's instructions and the data processing agreement, typically up to 7 years under Dutch tax law.
  • Website analytics: Anonymized data is retained for a maximum of 26 months.
  • Communication data: Support and communication data is retained for up to 24 months after last contact.

After retention periods expire, personal data is securely deleted or anonymized. You may request deletion of your data at any time (see section 8).

8. Your Rights Under GDPR

Under the GDPR, you have the following rights with respect to your personal data:

  • Right of access: Request a copy of the personal data we hold about you.
  • Right to rectification: Request correction of inaccurate or incomplete data.
  • Right to erasure: Request deletion of your personal data when it is no longer necessary.
  • Right to restriction: Request restriction of processing in certain circumstances.
  • Right to data portability: Receive your data in a structured, commonly used and machine-readable format.
  • Right to object: Object to processing based on legitimate interest.
  • Right to withdraw consent: Where processing is based on consent, you may withdraw it at any time.

To exercise any of these rights, contact us at privacy@claridy.ai.

You also have the right to lodge a complaint with the Autoriteit Persoonsgegevens.

9. Cookies and Website Tracking

  • Functional cookies: Necessary for website operation (e.g., session, language preference). No consent required.
  • Analytical cookies: Used to understand website usage and improve the experience (e.g., Google Analytics with IP anonymization).
  • Marketing cookies: Used for measuring advertising campaigns (e.g., Google Ads, LinkedIn). Only placed with your explicit consent.
  • Live chat: When you open the chat yourself, Chatwoot stores an identifier in your browser to remember your conversation so you can see our reply. It is only loaded after you click the chat button.

On your first visit to our website, we ask for your consent for non-essential cookies via our cookie banner. You can change your preferences at any time.

10. Data Security

  • Encryption of data in transit (TLS) and at rest (AES-256).
  • Role-based access controls and the principle of least privilege for all systems.
  • Regular security audits, penetration tests and vulnerability scans.
  • Incident response plan with notification procedures in accordance with the GDPR 72-hour requirement.

11. Changes to This Policy

We may update this privacy policy from time to time to reflect changes in our practices, technologies or legal requirements. Material changes will be communicated via email or a notification on our platform. The most recent version is always available on our website.

12. Contact Us

If you have questions about this privacy policy, our data practices or wish to exercise any of your rights, please contact us:

Claridy B.V.

Amsterdam, the Netherlands

Email: legal@claridy.ai

Website: www.claridy.ai