Legal

Privacy Policy

Last updated: 7 April 2026
Data controller: Scintillation Research and Analytics Services Pvt. Ltd. (Scintillation Research), Mohali, Punjab, India

This policy explains what personal data ClaimHit collects, why we collect it, how we use it, and your rights under the General Data Protection Regulation (GDPR) and applicable data protection laws. We are committed to processing your data lawfully, fairly, and transparently.

1. Who We Are

ClaimHit is operated by Scintillation Research and Analytics Services Pvt. Ltd. (Scintillation Research), a company registered in India with its principal place of business in Mohali, Punjab, India ("we", "us", "our"). We are the data controller for personal data processed through claimhit.com and the ClaimHit Live application.

For privacy-related questions or to exercise your rights, contact us at: privacy@claimhit.com

2. What Data We Collect

Account data

When you create a ClaimHit account, we collect:

  • Full name
  • Email address
  • Company or organisation name
  • Job title or professional role
  • Password (stored as a bcrypt hash — we never store your plain-text password)

Usage data

When you use ClaimHit, we collect:

  • Patent numbers you search for and the results returned
  • Search mode selections (products, standards, both)
  • Hit Charts you generate and their results
  • Expert review requests you submit, including your notes and any budget information
  • Credit purchases and transaction history
  • Team membership and collaboration activity

Expert review contact data

When you submit an Expert Review request, we additionally collect:

  • Phone number (optional)
  • Additional notes, jurisdiction information, and case details you provide
  • Budget information if provided

Technical data

  • IP address (collected by our infrastructure provider, Vercel)
  • Browser type and version
  • Pages visited and time spent (via Google Analytics 4)
  • Session identifiers (stored in your browser)

What we do NOT collect

  • Payment card numbers or bank details — payments are processed by PayU India directly
  • Biometric data
  • Sensitive personal data as defined under GDPR Article 9
  • Data from children under 18

3. Why We Collect It — Legal Bases

PurposeData usedLegal basis
Providing the ClaimHit serviceAccount data, usage dataContract (Art. 6(1)(b)) — necessary to deliver the service you signed up for
Processing expert review requestsAccount data, contact data, request detailsContract (Art. 6(1)(b)) — necessary to fulfil your order
Processing paymentsEmail, transaction amountsContract (Art. 6(1)(b)) — necessary for billing
Sending service emails (alerts, monitoring updates)Email, search resultsContract (Art. 6(1)(b)) — part of the monitoring service you purchased
Improving our AI models and search qualityAggregated, anonymised search patternsLegitimate interests (Art. 6(1)(f)) — improving service quality
Analytics and usage statisticsTechnical data via Google AnalyticsConsent (Art. 6(1)(a)) — collected only after cookie consent
Security and fraud preventionIP address, session dataLegitimate interests (Art. 6(1)(f)) — protecting our platform and users
Legal complianceAccount data, transaction recordsLegal obligation (Art. 6(1)(c)) — tax and regulatory requirements

4. How Long We Keep Your Data

Data typeRetention periodReason
Account dataUntil account deletion + 30 daysService provision
Search resultsUntil account deletionService feature (history access)
Expert review orders7 years after deliveryLegal obligation (tax, contract records)
Transaction records7 yearsTax and accounting requirements
Analytics data14 months (Google Analytics default)Aggregated, anonymised
Security logs90 daysSecurity and fraud prevention

5. Who We Share Your Data With

We do not sell your personal data. We share data only with the processors necessary to operate the service:

ProcessorPurposeLocationSafeguards
Supabase Inc.Database and authenticationUS (AWS us-east-1)Standard Contractual Clauses, DPA signed
Vercel Inc.Application hosting and CDNUS / Global edgeStandard Contractual Clauses, DPA available
Anthropic PBCAI inference (Claude)USZero data retention policy on API calls
OpenAI LLCAI inference (GPT-4o)USAPI data not used for training by default
Google LLCAI inference (Gemini) + AnalyticsUS / GlobalStandard Contractual Clauses
Perplexity AI Inc.AI inference (Sonar Pro)USAPI terms apply
PayU India Pvt. Ltd.Payment processingIndiaPCI DSS compliant
Crisp IM SARLCustomer support chatFrance (EU)GDPR compliant processor

Patent data entered into ClaimHit (patent numbers and the results returned) is transmitted to AI providers for processing. Patent numbers are public information. We do not transmit your account identity to AI providers — searches are anonymous at the API level.

6. Cookies

We use the following cookies:

CookieTypePurposeDuration
sb-auth-tokenEssentialAuthentication sessionSession
claimhit-consentEssentialStores your cookie consent choice12 months
_ga, _ga_*AnalyticsGoogle Analytics 4 usage statistics14 months
crisp-client/*FunctionalSupport chat sessionSession / 6 months

Analytics and functional cookies are only set after you provide consent via our cookie banner. Essential cookies are set automatically as they are necessary for the service to function.

7. Your Rights Under GDPR

If you are located in the European Economic Area, United Kingdom, or another jurisdiction with applicable data protection laws, you have the following rights:

Right of access
Request a copy of all personal data we hold about you. We will respond within 30 days.
Right to rectification
Request correction of inaccurate or incomplete personal data. You can update most data directly in your account settings.
Right to erasure
Request deletion of your account and personal data. You can do this directly from Account → Profile → Delete Account. We will delete your data within 30 days, subject to legal retention obligations.
Right to data portability
Request your data in a structured, machine-readable format. Email us at privacy@claimhit.com and we will provide a JSON export of your account data and search history.
Right to restrict processing
Request that we limit how we use your data while a dispute is resolved. Contact us at privacy@claimhit.com.
Right to object
Object to processing based on legitimate interests, including for marketing purposes. Contact us at privacy@claimhit.com.
Right to withdraw consent
Withdraw analytics cookie consent at any time by clicking "Cookie Settings" in the footer or contacting us.
Right to lodge a complaint
Lodge a complaint with your local data protection authority. In the EU, find your authority at edpb.europa.eu.

To exercise any of these rights, email privacy@claimhit.com. We will respond within 30 days. We may request identity verification before fulfilling a request.

8. International Data Transfers

ClaimHit is operated from India and uses infrastructure providers based primarily in the United States. If you are located in the EU or UK, your personal data will be transferred to countries that may not provide the same level of data protection as your home country.

We rely on the following transfer mechanisms:

  • Standard Contractual Clauses (SCCs) — for transfers to Supabase, Vercel, and Google
  • Adequacy decisions — where available
  • API zero-retention policies — for AI inference providers (Anthropic, OpenAI) where data is processed but not retained

9. Security

We implement appropriate technical and organisational measures to protect your personal data, including:

  • All data encrypted in transit using TLS 1.2 or higher
  • Database encryption at rest (Supabase AES-256)
  • Passwords hashed using bcrypt with appropriate cost factor
  • Row-level security policies on all user data tables
  • Access to production systems limited to authorised personnel only
  • Regular security reviews of our codebase and infrastructure

For full details of our security practices, see our Security page.

10. Children's Data

ClaimHit is a professional tool intended for adults. We do not knowingly collect personal data from anyone under the age of 18. If you believe a child has provided us with personal data, contact us at privacy@claimhit.com and we will delete it promptly.

11. Changes to This Policy

We will update this policy from time to time as our practices change or as required by law. When we make material changes, we will notify registered users by email and update the "Last updated" date at the top of this page. Your continued use of ClaimHit after notification constitutes acceptance of the updated policy.

12. Contact Us

For any privacy-related questions, data subject requests, or concerns:

  • Email: privacy@claimhit.com
  • Company: Scintillation Research and Analytics Services Pvt. Ltd. (Scintillation Research)
  • Address: Mohali, Punjab, India

We aim to respond to all privacy enquiries within 5 business days and all formal data subject requests within 30 days as required by GDPR.

ClaimHit
Privacy PolicySecurityBlog

© 2026 Scintillation Research and Analytics Services Pvt. Ltd. (Scintillation Research)