CLARC
Privacy Policy

Privacy Policy

Privacy Policy

Last update: June 22, 2026

This Privacy Policy includes important information about how CLARC Inc. (“CLARC”) handles data. We encourage you to read it carefully.

Welcome

CLARC Inc. provides trust and authorization infrastructure for the agent economy. We operate the CLARC registry, a neutral, independently governed system that allows Member Organizations to register AI agents and enables financial institutions and other Verifiers to confirm an agent's authorization before executing high-stakes transactions.

This Privacy Policy (“Policy”) describes the Personal Data we collect about you, how we use and share it, your rights and choices, and how to contact us.

Depending on how you interact with us, CLARC may act as a data controller (for example, when we collect your information directly to provide Services) or as a data processor (for example, when we process Personal Data on behalf of a Member Organization). This Policy primarily addresses our activities as a data controller.

Defined Terms

To make this Policy easier to read, we have defined certain terms used throughout:

  • “Personal Data” means any information relating to an identified or identifiable individual, including information you provide to us directly and information we derive or infer about you.
  • “Services” means the CLARC registry platform, Member Portal, Authorization Services, API access, and all related products and services offered by CLARC Inc.
  • “Member Organization” or “Member”means an entity that has registered with CLARC to register and manage AI agents. When we refer to “you” in the context of a Member Organization, we mean the organization itself and its authorized Representatives.
  • “Representative”means an individual acting on behalf of a Member Organization — for example, an account administrator, Delegation Authority, or other authorized user of the CLARC Member Portal.
  • “Verifier”means a financial institution, payment processor, or technology platform that queries the CLARC registry to verify an agent's authorization before executing a transaction or providing a service.
  • “Visitor” means anyone who visits clarclabs.com without creating or logging into a CLARC account.
  • “Registry Records” means the records we create and maintain in connection with agent registrations, including agent credentials, authorization scopes, and associated Member information.
  • “Attestation Data” means the signed, independently verifiable data we produce and disclose to Verifiers in response to verification queries.

This Policy is organized as follows:

  1. Personal Data we collect and how we use and share it
  2. More ways we collect, use, and share Personal Data
  3. Legal bases for processing
  4. Your rights and choices
  5. Security and retention
  6. International data transfers
  7. Updates and notifications
  8. Jurisdiction-specific provisions
  9. Contact us

1. Personal Data we collect and how we use and share it

How we collect and use Personal Data depends on who you are and how you interact with CLARC. Below we describe our practices for each category of individual.

1.1 Representatives

When you act on behalf of a Member Organization to access CLARC Services, for example, to register agents, manage credentials, or administer Member accounts, we collect and use Personal Data about you as described below.

a. Personal Data we collect about Representatives

  • Registration and account information. When you create or access a CLARC Member Account, we collect your name, email address, job title, and organizational affiliation.
  • Identity and authorization information. When you register as a Delegation Authority, i.e. the individual formally authorized by a Member Organization to bind the organization in connection with agent registrations, we may collect additional identity verification information as required to fulfill our obligations under applicable law.
  • Usage and activity data. We collect records of your activity in the CLARC Member Portal, including agent registrations, credential updates, policy configurations, and audit log access.
  • Communications. We keep records of support requests, correspondence, and other communications you have with us.

b. How we use and share Personal Data of Representatives

  • Providing the Services. We use your Personal Data to create and maintain your Member Account, process agent registrations, authenticate your identity, and provide you with access to CLARC Services.
  • Registry Records. Your name and title as Delegation Authority are included in Registry Records associated with each agent your organization registers. These records are disclosed to Verifiers as part of the verification process.
  • Regulatory compliance and fraud prevention. We use your information to comply with applicable laws and regulations, including BSA/AML requirements, OFAC sanctions obligations, and other legal requirements applicable to financial infrastructure providers.
  • Communications. We use your contact information to send you service-related notifications, including credential expiry notices, security alerts, and policy updates.

1.2 Verifiers

When a financial institution, payment processor, or technology platform queries the CLARC registry to verify an agent's authorization, we collect and use Personal Data about the individuals associated with that Verifier as described below.

a. Personal Data we collect about Verifiers

  • Account and contact information. We collect the legal entity name, contact details for the account administrator, and technical contact information for API integration and support purposes.
  • Query logs. We maintain logs of verification queries made by each Verifier, including the agent identifier queried, the timestamp of the query, and the result returned.

b. How we use and share Personal Data of Verifiers

  • Providing the Services. We use Verifier account information to manage API access, process verification queries, and return Attestation Data in response to those queries.
  • Registry integrity. We use query logs to monitor for patterns that may indicate misuse of the verification API or attempts to enumerate Registry Records.
  • Billing. We use query volume data to calculate usage-based fees where applicable under a Verifier's commercial agreement with CLARC.

1.3 Visitors

When you visit clarclabs.com without logging into or creating a CLARC account, we refer to you as a Visitor.

a. Personal Data we collect about Visitors

  • Contact information. If you submit an enquiry, request information, or contact us through the website, we collect the information you provide, which may include your name, email address, and the content of your message.
  • Technical data. We automatically collect IP address, browser type, device type, pages visited, time on page, and referral source when you visit our website.

b. How we use and share Personal Data of Visitors

  • Responding to enquiries. We use contact information to respond to your messages and follow up on information requests.
  • Website operation and improvement. We use technical data to operate, maintain, and improve the website.

2. More ways we collect, use, and share Personal Data

2.1 Attestation Records and Registry Disclosures

A fundamental feature of the CLARC Service is the disclosure of Registry Records and Attestation Data to Verifiers. When a Verifier queries the CLARC registry, we return Attestation Data that confirms whether a given AI agent is registered, the scope of its authorization, and the identity of the Member Organization that registered it.

Attestation Data contains Registry Record information including the agent identifier, the Member Organization's membership status, the authorization scopes associated with the agent, and the name and title of the Delegation Authority who authorized the registration. This disclosure is a core function of the CLARC Service and is described in the Member Agreement.

2.2 Service Providers

We share Personal Data with third-party service providers that help us deliver the CLARC Services, including cloud infrastructure providers, identity verification vendors, communication platforms, analytics providers, and privacy-friendly bot-detection and abuse-prevention providers. These service providers are contractually required to use Personal Data only to provide services to us and in accordance with applicable law.

2.3 Legal and Regulatory Disclosure

We may disclose Personal Data where required by applicable law, court order, or governmental authority. We may also disclose Personal Data to protect the rights, property, or safety of CLARC, our Members, Verifiers, or others.

2.4 Corporate Transactions

If CLARC is involved in a merger, acquisition, financing, or sale of all or substantially all of its assets, Personal Data may be transferred as part of that transaction. We will notify affected individuals as required by applicable law.

2.5 No Sale of Personal Data

CLARC does not sell Personal Data to third parties for their own commercial or marketing purposes.

3. Legal bases for processing

Where applicable law requires us to identify a legal basis for processing Personal Data, we rely on the following:

  • Contract performance: To provide the Services under our agreement with you or your organization.
  • Legal obligation: To comply with applicable laws and regulations, including BSA/AML requirements, OFAC sanctions obligations, and other legal requirements applicable to financial infrastructure providers.
  • Legitimate interests: To operate and improve the CLARC platform, detect fraud and misuse, maintain registry integrity, and communicate with Members and Verifiers about the Services.
  • Consent: Where required by applicable law, for example in connection with certain marketing communications or non-essential cookies.

4. Your rights and choices

Depending on your jurisdiction, you may have rights with respect to Personal Data we hold about you. These may include the right to access, correct, delete, or port your Personal Data, to restrict or object to certain processing, and to withdraw consent where processing is based on consent.

Please note that certain Registry Records and temporal audit logs may be subject to mandatory retention obligations that limit our ability to delete or modify them in response to individual requests. We will inform you of any such limitations when you exercise your rights.

To exercise any of your rights, please contact us at privacy@clarclabs.com. We will respond within the timeframe required by applicable law.

5. Security and retention

5.1 Security

We implement appropriate technical and organizational security measures designed to protect Personal Data against unauthorized access, disclosure, alteration, or destruction.

No security system is impenetrable. While we work to protect your information, we cannot guarantee that our security measures will prevent every unauthorized access to or use of Personal Data.

To help protect our contact form from spam and automated abuse, we use a privacy-friendly bot-detection service (Cloudflare Turnstile). This service does not use tracking cookies and does not collect Personal Data for advertising or cross-site tracking purposes.

5.2 Retention

We make reasonable efforts to provide a level of security appropriate to the risk associated with the processing of your Personal Data.

We encourage you to assist us in protecting your Personal Data. If you hold a CLARC account, you can do so by using a strong, unique password and keeping your account credentials confidential.

We retain your Personal Data for as long as we continue to provide the CLARC Services to you, or for a period in which we may have a legal obligation or legitimate interest to retain it, including to:

  • Comply with our legal and regulatory obligations;
  • Enable fraud monitoring, detection, and prevention activities; and
  • Comply with our tax, accounting, and financial reporting obligations, including when such retention is required by our contractual commitments to Members and Verifiers.

In cases where we keep your Personal Data, we do so in accordance with any limitation periods and record retention obligations that are imposed by applicable law.

6. International data transfers

CLARC Inc. is based in the United States. If you are located outside the United States, your Personal Data may be transferred to and processed in the United States or other countries that may not provide the same level of data protection as your home country.

Where we transfer Personal Data from the European Economic Area, United Kingdom, or Switzerland to the United States or another country that has not been deemed to provide an adequate level of protection, we do so using appropriate safeguards, such as standard contractual clauses approved by the relevant authorities.

7. Updates and notifications

We may update this Policy from time to time. When we make material changes, we will notify Members by email and by posting the updated Policy on our website with a new effective date.

Your continued use of the CLARC Services after any changes to this Policy constitutes your acceptance of the updated Policy.

8. Jurisdiction-specific provisions

8.1 United States — California

If you are a California resident, the California Consumer Privacy Act (CCPA) as amended by the California Privacy Rights Act (CPRA) may provide you with additional rights with respect to your Personal Data, including the right to know, delete, correct, and opt out of the sale or sharing of Personal Data. As noted above, CLARC does not sell Personal Data. To exercise your rights under the CCPA/CPRA, please contact us at privacy@clarclabs.com.

8.2 European Economic Area and United Kingdom

If you are located in the EEA or UK, the General Data Protection Regulation (GDPR) or UK GDPR (as applicable) provides you with rights including access, rectification, erasure, restriction of processing, data portability, and the right to object to processing. You also have the right to lodge a complaint with your local data protection authority. To exercise your rights, contact us at privacy@clarclabs.com.

9. Contact us

If you have questions about this Policy, wish to exercise your privacy rights, or want to report a privacy concern, please contact us:

General enquiries: privacy@clarclabs.com

Website: clarclabs.com

CLARC Inc. New York, United States