Privacy policy

This says what personal data Exclia holds, why it holds it, who else touches it, how long it stays, and what you can ask us to do about it. It covers both people whose organizations use Exclia and people who are named on the public lists Exclia reads.

Last updated July 30, 2026.
These are interim terms, published so you can read them while evaluating Exclia. They have not yet been reviewed by a lawyer, and a reviewed version replaces them before Exclia launches publicly. They describe how the product actually works today, which is why they are worth reading now.

Who we are

Exclia is operated from Spain by one person, who is the controller for the data described below. The registered legal name and address are stated in the reviewed version of this page; until then, the contact address at the bottom reaches the same person, and it is a person rather than a ticket queue.

Exclia is established in the European Union and most of the people whose records it handles are in the United States. The European rules therefore apply to how we run the service, and we apply them to everyone rather than sorting readers by where they live.

When we are a processor, and when we are a controller

For the roster — the people and organizations a customer monitors — the customer decides who is on it and why, and we act on their instructions. They are the controller and we are the processor. This is the arrangement a data processing agreement covers, and we offer one to any customer who asks.

For the account itself — the names and email addresses of the people who sign in, billing details, support correspondence, and messages sent to our dispute and privacy addresses — we decide what to do with it, so we are the controller.

What personal data Exclia holds

The roster records a customer gives us hold what is needed to tell two people with similar names apart, and nothing beyond it:

  • Names, including any former or alternative names the customer records, and a suffix.

  • A date of birth and an NPI number where the customer has them, the states a person is licensed in, their provider type, and the start date the customer records for them.

  • For organizations on a roster, a legal name and, optionally, a business employer identification number.

  • The screening history for each record: which list versions it was checked against, when, what resembled it, and how a person resolved that.

  • No Social Security numbers and no personal tax identifiers. There is no column for one anywhere in the product, so there is nothing to leak, subpoena, or lose.

What we hold about you if you use Exclia yourself

Your name and email address, held by our identity provider so you can sign in; what you did inside your organization, written to that organization’s own audit log; billing details held by our payment provider, which handles card details so that we never receive them; and any email you send us.

If you gave us your email address on this site — to have the free checker email you a result, to download the state requirements table, to join the waitlist, or to hear about new guides — we hold that address once, with a note of which of those you did and how many times. We do not store what you searched for.

Every email we send from this site carries an unsubscribe link and a postal address. Unsubscribing stops all of it, not only the kind of email you clicked from. The one thing it does not cancel is a document you ask us for afterwards: if you request a free check result or the requirements table, we will still send you that one document, because you asked for it.

We never buy, rent, or scrape email addresses. Everyone on this list gave us their address on this site.

Why we hold it

Roster records are processed on the customer’s instructions, under their own legal basis — usually a legal obligation to check that the people they pay are not on a public exclusion list, or the legitimate interest of meeting a program-integrity requirement in their provider agreement.

Account data is processed to perform the contract with the customer: we cannot run an account without knowing who is in it. Records of what was screened and how a potential match was resolved are kept because they are the evidence the product exists to produce.

Where the list data comes from

The lists Exclia reads are published by government authorities for the public to read — the OIG, the US General Services Administration, and state Medicaid agencies. Exclia copies what they publish, records the version and the date it was retrieved, and does not add to it, score it, or infer anything from it.

Nothing about a customer’s roster is sent to any of those authorities. Matching happens inside Exclia.

Who else touches it

These are the providers that process something on our behalf, and what each one actually receives. A provider added to the product is added to this list in the same change.

  • Clerk — Accounts, sign-in, sessions, organizations, and the subscription plan behind your billing. The name and email address of each of your users. No roster records — Clerk never sees the people you monitor. (United States).

  • Stripe — Card payments and invoicing, underneath Clerk Billing, plus metered API usage. Your billing details and usage quantities. No roster records and no screening results. (United States).

  • Resend — Sending notification email, and receiving mail sent to the dispute address. The recipient’s address and the message itself. A potential-match alert names the roster record it is about, so a person’s name does reach the mail provider. (United States).

  • PostHog — Counting how people find the marketing site and whether the free check leads anywhere — the two figures the decision to keep building Exclia is made from. From the marketing site only, and only if you agree to it: the pages you open, the site that linked you, and an identifier that connects those page views to each other. Never a name typed into the free checker, never an email address, and nothing at all from inside the application. (European Union).

  • Cloudflare — Object storage for report PDFs, and the bot check in front of the free public checker. Report PDFs, which name the people on your roster. From the checker: a visitor’s bot-check token. Names typed into the free checker are not sent to Cloudflare. (North America (report storage); the bot check is answered at the nearest edge).

Where the data is

The database holding rosters, screening history, and audit logs, and the operator reading it, are in Europe. Report PDFs — which name the people on a roster — are stored in North America, and our identity, payment, and email providers are US companies. For an operator established in Europe those are international transfers, so they are named here rather than left implicit.

The paperwork that covers those transfers — the agreements and standard contractual clauses with each provider — is being put in place and is not complete. It is listed as an open item on our security page rather than described here as though it were done.

How long we keep it

While a subscription is running, the roster, the screening history, the reports, and the audit log are kept, because they are what the customer is paying us to hold.

For 90 days you can sign in and export your monitored records, resolution log, and reports. After that window, this data is deleted — with the exceptions below.

Two things outlive that window on purpose:

  • The audit reports your organization generated stay available to you.

  • The resolution-log metadata that records that a screening happened, and when, is kept to preserve your evidentiary trail.

Removing one person’s details

A customer can honor an erasure request for a single record. The person’s identifying details are cleared and the record stays as a marker, so the trail showing that a screening happened, and how its matches were resolved, still holds without saying who it was about. A record in that state stops being screened.

One gap in that, which you would rather hear from us than discover: when a potential match is resolved, the evidence behind the decision is frozen as it was seen, and a later erasure clears the record without reaching into that frozen copy. The trail is deliberately not editable, which is what makes it evidence — so honoring both obligations at once needs a decision about which side gives, and that decision has not been made. It is published on our security page for the same reason it is here.

What you can ask us to do

You can ask for a copy of what we hold about you, ask us to correct it, ask us to delete it, ask us to restrict or stop a particular use, or ask for it in a portable form. Write to the privacy address and a person will answer.

If the data you are asking about is on a customer’s roster, they are the controller and we will pass your request to them and support them in answering it — that is what being a processor means, and it is not a way of avoiding the question.

You can also complain to a data protection authority. Because Exclia is established in Spain, that is the Spanish Agencia Española de Protección de Datos, or the authority in the country where you live.

Write to privacy@exclia.com

If you are named on one of the public lists

You may be here because your name appeared in something Exclia produced for one of its customers. You do not need an account, and there is nothing to pay: there is a page that explains what to do and an address that opens a tracked case with a person on it.

Write to disputes@exclia.com

Data processing agreement

A data processing agreement is available to any customer on request, covering the roster data we process on their instructions, the providers listed above, and the transfers named above. Ask at the privacy address.

Write to privacy@exclia.com

Changes to this policy

When this policy changes, the date at the top changes with it. If a change affects what we do with data we already hold, we tell account owners before it takes effect.