Home/Privacy

Privacy Policy

Last updated 1 September 2026. Written to be read, not skimmed. If anything here is unclear, write to privacy@retrievant.example.

Who we are

Retrievant SAS, registered in Paris, France, with a US subsidiary, Retrievant Inc., in Boston, Massachusetts. We operate a platform that retrieves medical records on a patient's instruction and delivers them to an organisation the patient has chosen.

Our two roles

When you are a patient using our consent flow or dashboard, we act as a data controller for your account and consent records, and as a processor (US: business associate) for the medical records we retrieve on behalf of the organisation you authorised.

When you are a customer (a law firm, insurer, clinic or app), you are the controller and we process records under a Data Processing Agreement or Business Associate Agreement.

What we collect

CategoryExamplesSource
IdentityName, date of birth, contact detailsYou, or the requesting organisation
Consent recordsWhat you authorised, when, from what deviceYou
Medical recordsEncounters, labs, imaging, medications, claimsProviders and insurers you authorised us to contact
Retrieval logsCalls, transcripts, portal sessions, agent decisionsGenerated by our systems
TechnicalIP address, browser, pages visited on this siteYour device

Why we process it

  • To fulfil your instruction. Retrieving and assembling the record you asked us to retrieve. Legal basis: explicit consent (GDPR Art. 9(2)(a)); HIPAA authorisation.
  • To keep an audit trail. Legal obligation and legitimate interest in demonstrating compliance.
  • To improve retrieval. Learning how each provider prefers to be contacted. Uses provider metadata, not your medical content. Legitimate interest.
  • To run this website. Essential cookies only unless you opt in to analytics.

AI and your data

Our agents use machine learning models to plan retrievals, converse with provider staff, navigate portals and structure documents. Your medical records are processed by these models to complete your retrieval. They are not used to train foundation models. Model improvements use synthetic data and de-identified data from patients who separately opted in.

When a voice agent calls a provider, it discloses that it is an automated system in its first sentence. Calls are recorded and the recordings form part of the retrieval log.

Who we share with

  • The organisation you authorised, and only that organisation.
  • Providers and insurers we contact on your behalf, who receive your identity and consent document to verify the request.
  • Infrastructure providers under contract (cloud hosting, telephony, fax), bound by DPAs and, in the US, BAAs.
  • We do not sell personal data. We do not share it with advertisers. Ever.

How long we keep it

DataRetention
Assembled medical record30 days after delivery, then deleted (unless the customer extends under contract)
Consent record7 years (legal obligation)
Retrieval audit log7 years, with medical content redacted after 30 days
Your dashboard accountUntil you delete it

Your rights

You can access, correct, export or delete your data, restrict or object to processing, and withdraw consent at any time. Most of these are one click in the patient dashboard. For the rest, email us. We respond within 30 days (GDPR) or as required under applicable US state law. You may also complain to the CNIL (France) or your local supervisory authority.

International transfers

EU patient data is stored and processed in the EU. US patient data in the US. We only move data across regions when a patient explicitly requests a cross-border retrieval, and then under Standard Contractual Clauses.

Contact

Data Protection Officer: dpo@retrievant.example. Retrievant SAS, Paris, France. US privacy inquiries: Retrievant Inc., Boston, MA.