// LEGAL
Data Use Policy
Last updated: 1 September 2026
This Data Use Policy explains how Clarius uses your data within the platform, including how AI services process your information and what controls are in place. It should be read alongside our Privacy Policy.
KEY POINT
Your company data is used to generate your compliance outputs. It is not used to train AI models, sold to third parties, or shared with other Clarius customers. All AI-generated outputs require human review and approval before use.
1. How Your Data Flows Through the Platform
When you use Clarius, your data moves through a nine-gate compliance workflow:
- You provide company profile information, emissions data, uploaded evidence documents, and responses to workflow prompts
- This information is sent to AI services (Anthropic Claude API) to generate compliance analysis, gap assessments, materiality assessments, scenario analyses, and draft report content
- AI-generated outputs are presented to you for review, editing, and approval at each gate
- Approved outputs are stored in your organisation's workspace and form part of your audit trail
- No output is transmitted to ASIC or any external party without your explicit action
2. AI Services and Model Training
Clarius uses the following AI services:
- Anthropic Claude API: used to analyse your company profile, generate compliance assessments, and draft report sections. Under our agreement with Anthropic, your data is not used to train Anthropic's AI models.
- Voyage AI: used to generate semantic embeddings for our internal ASRS regulatory knowledge base. Voyage AI processes queries against our pre-built knowledge base; your company data is not stored or embedded by Voyage AI.
3. Regulatory Knowledge Base
Clarius maintains an internal knowledge base of AASB S2, ASRS, and related regulatory content (sourced from AASB, ASIC, and the Corporations Act). When you use the platform, relevant regulatory content is retrieved from this knowledge base to ground AI outputs in current Australian requirements. This knowledge base is built and maintained by Clarius and does not contain your company data.
4. Data Retention
- Your compliance workflow data (gap analyses, materiality assessments, emissions data, reports, declarations) is retained for the duration of your subscription and for a minimum of 7 years post-termination to support regulatory audit requirements
- Audit trail entries (gate transitions, approvals, timestamps) are retained indefinitely as they form part of your compliance record
- You may request export or deletion of your data subject to our legal retention obligations
5. Data Isolation
Your organisation's data is logically isolated from other Clarius customers. Each organisation has its own database namespace, and access is strictly controlled by session tokens tied to your organisation's account. No Clarius customer can access another customer's data.
6. Audit Trail
Every gate transition, edit, approval, and declaration within the workflow is logged with a timestamp, the identity of the actor, and their role. This audit trail is retained as part of your compliance record and is available to your organisation for assurance and regulatory purposes. The audit trail is immutable — it cannot be edited or deleted by users.
7. Data Deletion
You may request deletion of your Customer Data upon termination of your subscription, subject to any minimum retention period we are required to maintain for legal or audit-trail purposes. To request deletion, contact hello@clariusonline.com.
8. Questions
For questions about how your data is used, contact us at hello@clariusonline.com.