Privacy
How ScriptClear handles the information it collects.
This policy describes, in plain language, what information ScriptClear collects across the website and certification platform, why it is collected, how long it is kept, and how you can ask questions or exercise rights over your information.
- Standards
- v0.9 — Pilot draft
- Status
- Published
- Review cycle
- Reviewed quarterly
This page is a plain-language summary of ScriptClear's current practices. It is informational only and is not legal advice. Effective date: pending publication of v1.0 program terms. Questions can be sent through /contact.

Certification is granted for a defined scope and remains subject to monitoring.
- Standards version
- v0.9 — Pilot draft
- Decision basis
- Published criteria
- Independence
- Commercial roles excluded
- Change control
- Dated effective versions
On this page
What this page covers
- 01What is collectedCategories of information across the platform.
- 02Why it is collectedThe purposes information is used for.
- 03Legal basesWhy processing this information is appropriate.
- 04RetentionHow long information is kept.
- 05SharingWho information is shared with.
- 06Your rightsExercising rights over your information.
- 07SecurityHow information is protected.
- 08Children's dataThis platform is not directed to children.
- 09ChangesHow this policy is updated.
What is collected
Categories of information across the platform.
ScriptClear collects different information depending on how a person interacts with the platform — as a visitor, an applicant, a certified organization, or a reviewer.
- Account information: name, work email, role and authentication details for people who create a portal login
- Organization information: legal entity name, brands, domains, states of operation and points of contact supplied during application
- Application and review information: intake responses, corrective action records and decision history tied to a certification review
- Evidence: documents, screenshots, licensure records and written responses submitted to support a review
- Website-scan information: content, structure and disclosures captured from a business's public-facing pages within a review's defined scope
- Usage information: pages visited, actions taken in the portal, device and browser details, and general log data used to operate and secure the platform
Why it is collected
The purposes information is used for.
- To create and operate portal accounts and organization profiles
- To conduct certification reviews and record findings, decisions and corrective actions
- To operate continuous monitoring for organizations that hold an active certification
- To respond to inquiries submitted through /contact or the application flow
- To maintain security, prevent abuse and troubleshoot the platform
- To meet recordkeeping needs tied to certification decisions and appeals
Legal bases
Why processing this information is appropriate.
Where a legal basis is required by applicable law, ScriptClear generally relies on one or more of the following, described here in general terms rather than as a jurisdiction-specific legal determination.
- 1
Contract
Processing needed to deliver certification services a person or organization has requested.
- 2
Legitimate interest
Operating, securing and improving the platform, and maintaining accurate certification records.
- 3
Consent
Where a specific choice is presented, such as optional communications.
- 4
Legal obligation
Where retention or disclosure is required by an applicable law or a valid legal process.
Retention
How long information is kept.
Retention periods depend on the category of information and the role it plays in a certification record.
- Certification decision records and the evidence supporting them are retained for the period needed to support the decision, renewals, appeals and complaint review
- Account information is retained while an account is active and for a limited period after closure to resolve outstanding matters
- Usage and log data is retained for a limited operational period before being deleted or aggregated
- Information is deleted or de-identified once it is no longer needed for the purposes described in this policy, subject to any applicable legal hold
Your rights
Exercising rights over your information.
Depending on where you are located, you may have rights to access, correct, delete or receive a copy of your information, or to object to certain processing.
- 1
Submit a request
Send a request through /contact describing the information and the action requested.
- 2
Verification
ScriptClear may ask for information to confirm the request comes from the account holder or an authorized representative.
- 3
Response
ScriptClear responds to verified requests within a reasonable time, consistent with any applicable legal requirement.
Security
How information is protected.
Technical and organizational safeguards are described in the security overview, including how evidence and portal data are protected in transit and at rest.
See /security for the current description of ScriptClear's security practices.
Children's data
This platform is not directed to children.
ScriptClear's website and portal are directed to healthcare businesses, applicants and professional users. ScriptClear does not knowingly collect personal information from children, and any such information identified will be deleted.
Changes
How this policy is updated.
This policy may be updated as practices change or as the certification program moves from pilot to published v1.0 program terms. Material updates will be reflected on this page with an updated status note.
FAQ
Questions we hear often
- Does ScriptClear sell personal information?
- No. Information is shared only with permissioned partners a certified organization has authorized, and with service providers that help operate the platform.
- Is website-scan information kept indefinitely?
- No. It is retained for the period needed to support the related certification decision, renewal, appeal or complaint record, then deleted or de-identified.
- How do I ask a question about my data?
- Use /contact. Include enough detail to identify your account or organization so the request can be verified.
Not sure where your organization stands? Start with a preliminary eligibility check.
Compliance should be clear, not complicated
Questions about how your information is handled.
Reach the ScriptClear team through /contact for any question about this policy or a specific request.
Know where you stand. Fix what matters. Stay ready.
