Status, Scope, And Operator
This notice applies to the ClaraFerti Clinic Match questionnaire, generated match explanations, account controls, and related privacy evidence. Public educational articles can be read without creating an account.
The service operates under the ClaraFerti brand. Before this notice becomes effective, the exact contracting legal entity, formation jurisdiction, registered postal address, privacy officer, effective date, and archived release hash must be published here. Privacy questions can currently be sent to contact@claraferti.com.
Data Categories, Sources, And Inferences
Clinic Match collects broad country and state, fertility goals, prior-care categories, language, travel, timing, clinic-priority, and payment-route answers directly from the person using the questionnaire. It also creates a shortlist, compatibility scores, reasons, trade-offs, and audit records from those answers and the reviewed clinic directory.
The MVP is designed not to request exact dates of birth, street addresses, government identifiers, insurance member IDs, exact lab values, documents, medication lists, or free-text medical histories.
Purposes And Current Recipients
Broad answers are used only to create, store, secure, resume, and explain the Clinic Match and to maintain consent, rights, and security evidence. Completing a questionnaire or creating an account does not create a CRM lead.
Amazon Web Services currently hosts the application and restricted product stores in the United States using Cognito, API Gateway, Lambda, DynamoDB, S3, SQS, KMS, Secrets Manager, CloudFront, and CloudWatch. Contracting-entity, DPA, subprocessor, and workforce-location evidence must be approved before this notice becomes effective.
No clinic receives questionnaire data in the current beta. The current design prohibits sale, targeted-advertising use, identifiable model training, and automatic clinic handoff. Follow-up requires a separate verified request and purpose-specific consent.
Retention And Deletion
Current technical limits are up to 90 days for anonymous incomplete journeys, up to 180 days for purpose data, 30 days for privacy export files, 90 days for application logs, and up to six years for minimized consent and compliance evidence. These are maximum system settings, not a legally approved schedule, and may be shortened by the final record-class decision.
Deletion requests are verified, propagated to approved stores and processors, and may preserve narrowly minimized evidence or data subject to a documented legal hold. Backups expire on their controlled lifecycle rather than being restored for ordinary processing.
Access, Correction, Withdrawal, Deletion, Recipients, And Appeal
An anonymous user can review and withdraw processing consent for the exact journey available in this browser at /match/privacy. No account is required. Withdrawing processing consent stops new consent-dependent matching and follow-up activity; it is not itself a deletion request.
Account holders can use the account privacy controls for access, correction, portable export, journey-specific withdrawal, deletion, and appeal. A person may also contact the privacy channel without including medical records. Washington requests are designed for response within 45 days, subject to a permitted explained extension.
Withdrawing follow-up consent removes the linked lead from the operator action queue. A request for a list of recipients is handled through the access/privacy-request workflow.
Security, Changes, And Mandatory Rights
Questionnaire, account, results and admin routes are designed without advertising pixels, session replay, third-party chat, health-answer analytics, browser-storage answers, or shared-cache responses.
We use encrypted transport and storage, purpose-limited access, mandatory workforce MFA, recent-authentication checks for privileged actions, immutable consent evidence, and bounded serverless capacity. No system can promise absolute security.
A material purpose, recipient, sale/share status, or data-category change requires a new notice version and fresh consent where required. Terms and liability limitations do not waive non-waivable privacy, consumer, or health-data rights.