Privacy Policy
Last updated 1 September 2026. Written to be read, not skimmed. If anything here is unclear, write to privacy@retrievant.example.
Who we are
Retrievant SAS, registered in Paris, France, with a US subsidiary, Retrievant Inc., in Boston, Massachusetts. We operate a platform that retrieves medical records on a patient's instruction and delivers them to an organisation the patient has chosen.
Our two roles
When you are a patient using our consent flow or dashboard, we act as a data controller for your account and consent records, and as a processor (US: business associate) for the medical records we retrieve on behalf of the organisation you authorised.
When you are a customer (a law firm, insurer, clinic or app), you are the controller and we process records under a Data Processing Agreement or Business Associate Agreement.
What we collect
| Category | Examples | Source |
|---|---|---|
| Identity | Name, date of birth, contact details | You, or the requesting organisation |
| Consent records | What you authorised, when, from what device | You |
| Medical records | Encounters, labs, imaging, medications, claims | Providers and insurers you authorised us to contact |
| Retrieval logs | Calls, transcripts, portal sessions, agent decisions | Generated by our systems |
| Technical | IP address, browser, pages visited on this site | Your device |
Why we process it
- To fulfil your instruction. Retrieving and assembling the record you asked us to retrieve. Legal basis: explicit consent (GDPR Art. 9(2)(a)); HIPAA authorisation.
- To keep an audit trail. Legal obligation and legitimate interest in demonstrating compliance.
- To improve retrieval. Learning how each provider prefers to be contacted. Uses provider metadata, not your medical content. Legitimate interest.
- To run this website. Essential cookies only unless you opt in to analytics.
AI and your data
Our agents use machine learning models to plan retrievals, converse with provider staff, navigate portals and structure documents. Your medical records are processed by these models to complete your retrieval. They are not used to train foundation models. Model improvements use synthetic data and de-identified data from patients who separately opted in.
When a voice agent calls a provider, it discloses that it is an automated system in its first sentence. Calls are recorded and the recordings form part of the retrieval log.
Who we share with
- The organisation you authorised, and only that organisation.
- Providers and insurers we contact on your behalf, who receive your identity and consent document to verify the request.
- Infrastructure providers under contract (cloud hosting, telephony, fax), bound by DPAs and, in the US, BAAs.
- We do not sell personal data. We do not share it with advertisers. Ever.
How long we keep it
| Data | Retention |
|---|---|
| Assembled medical record | 30 days after delivery, then deleted (unless the customer extends under contract) |
| Consent record | 7 years (legal obligation) |
| Retrieval audit log | 7 years, with medical content redacted after 30 days |
| Your dashboard account | Until you delete it |
Your rights
You can access, correct, export or delete your data, restrict or object to processing, and withdraw consent at any time. Most of these are one click in the patient dashboard. For the rest, email us. We respond within 30 days (GDPR) or as required under applicable US state law. You may also complain to the CNIL (France) or your local supervisory authority.
International transfers
EU patient data is stored and processed in the EU. US patient data in the US. We only move data across regions when a patient explicitly requests a cross-border retrieval, and then under Standard Contractual Clauses.
Contact
Data Protection Officer: dpo@retrievant.example. Retrievant SAS, Paris, France. US privacy inquiries: Retrievant Inc., Boston, MA.