Clevik — Privacy Policy

Last updated: June 10. 2026

This Privacy Policy describes how Clevik LLC ("Clevik," "we," "us," or "our") collects, uses, shares, and protects information in connection with the Clevik platform and related services (the "Service"). This policy applies to all users of the Service, including account administrators and authorized users.

By using the Service, you acknowledge that you have read and understood this Privacy Policy.

Our roles (controller vs. processor). For the business data you connect to the Service (your Customer Business Data), your organization is the controller (and "business" under U.S. state law) and Clevik acts as your processor / service provider — we handle that data on your documented instructions, as governed by our Data Processing Agreement. For the account and usage information described in Sections 1.1 and 1.3, Clevik is itself the controller. This Policy describes both roles; where they differ, the Data Processing Agreement governs our processing of Customer Business Data.


1. Information We Collect

1.1. Account Information

When you register for the Service, we collect:

  • Full name
  • Email address
  • Company name and details
  • Job title or role
  • Phone number (optional)
  • Billing and payment information (processed by Stripe; we do not store full payment card numbers)

1.2. Customer Business Data

When you connect your business systems to Clevik, we sync and store data from your connected sources, which may include:

  • Data from ERP, CRM, and other business applications
  • Database contents synced via our on-premise sync agent or direct connections
  • Documents uploaded to the knowledge base (processed into text chunks and vector embeddings)

The specific data synced depends on the connections you configure and the permissions you grant. Customer Business Data may contain personal data about your employees, customers, vendors, or other individuals within your business systems. As described above, Clevik processes Customer Business Data as your processor/service provider.

1.3. Usage Data

We automatically collect information about how you interact with the Service, including:

  • Queries submitted to the AI
  • Features used and frequency of use
  • Credit consumption and usage patterns
  • Device type, browser type, and operating system
  • IP address and approximate location (derived from IP)
  • Session duration and timestamps
  • Error logs and performance data

1.4. Cookies and Similar Technologies

We use cookies, local storage, and similar technologies to:

  • Maintain your authenticated session (strictly necessary)
  • Remember your preferences and settings
  • Analyze usage patterns and improve the Service (analytics)
  • Support our Microsoft Teams integration

Strictly necessary cookies are required for the Service to function. For non-essential cookies (such as analytics), where required by applicable law — including in the EEA, UK, and Switzerland — we will obtain your prior consent through a consent banner or similar mechanism before such cookies are set, and you can withdraw consent at any time. You can also manage cookie preferences through your browser settings. Disabling certain cookies may affect Service functionality.


2. How We Use Your Information

We use the information we collect for the following purposes:

2.1. Providing the Service

  • Authenticating your identity and managing your account
  • Syncing, storing, and processing your Customer Business Data
  • Processing AI queries and generating outputs (answers, charts, reports)
  • Delivering the Service via web application, Microsoft Teams, and other supported channels
  • Sending transactional communications (account confirmations, billing receipts, security alerts)

2.2. Billing and Account Management

  • Processing subscription fees and overage charges via Stripe
  • Tracking credit usage
  • Managing your subscription plan

2.3. Improving the Service

  • Analyzing aggregated, de-identified usage patterns to improve features and performance
  • Identifying and resolving bugs, errors, and performance issues
  • Developing new features based on usage trends

Important: We do not use your Customer Business Data to train AI models, and we do not use identifiable Customer Business Data to develop new features or products. When your data is sent to third-party AI providers for query processing, it is used solely to generate your requested output and is not retained by those providers for training purposes.

2.4. Customer Support

  • Responding to your inquiries and support requests
  • Troubleshooting technical issues
  • Providing onboarding assistance

2.5. Legal and Compliance

  • Complying with applicable laws and regulations
  • Enforcing our Terms of Service
  • Protecting the rights, safety, and security of Clevik, our customers, and the public

2.6. Automated Decision-Making

The Service uses AI to generate answers, summaries, and recommendations to assist your decision-making. Clevik does not use these outputs to make decisions about individuals that produce legal or similarly significant effects without human involvement; you remain responsible for reviewing AI Outputs before acting on them (see Terms of Service Section 7.4).


3. How We Share Your Information

We do not sell your personal information or Customer Business Data, and we do not "share" it for cross-context behavioral advertising. We share information only as described below:

3.1. Third-Party Service Providers (Sub-Processors)

We use third-party service providers (sub-processors) to operate the Service. Our current sub-processors, the processing they perform, and their locations are maintained in our sub-processor list at clevik.com/legal/subprocessors, which is governed by the change-notification and objection process in our Data Processing Agreement (Section 4). A snapshot as of the date above:

ProviderPurposeData ProcessedLocation
Microsoft AzureCloud hosting, infrastructure, and AI model routing (Azure AI Foundry)All Service dataEast US 2 region, United States
ClickHouse CloudAnalytics databaseCustomer Business Data (synced data)East US 2 region, United States
SupabaseApplication database (PostgreSQL)Account data, application dataEast US 1 region, United States
StripePayment processingBilling and payment informationUnited States
AI model processing (via Microsoft Azure AI Foundry)Generating AI responsesQuery context and relevant Customer Data excerptsProcessed via Azure infrastructure

AI Provider Data Handling: When you submit queries, relevant portions of your data are sent to AI models through Microsoft Azure AI Foundry for processing. The data is processed solely to generate your response. Per the applicable agreements, your data is not used for model training and is not retained beyond the processing window.

3.2. Legal Requirements

We may disclose information if required by law, subpoena, court order, or government request, or if we believe disclosure is necessary to protect our rights, your safety, or the safety of others.

3.3. Business Transfers

In the event of a merger, acquisition, bankruptcy, or sale of assets, your information may be transferred as part of the transaction. We will notify you of any such transfer and any choices you may have regarding your information.

3.4. With Your Consent

We may share information with third parties when you explicitly direct us to do so.


4. Data Retention

4.1. Active Accounts. We retain your account information and Customer Business Data for as long as your account is active and as necessary to provide the Service.

4.2. Terminated Accounts. Upon account termination, your Customer Business Data will be available for export for thirty (30) days following the effective date of termination. We will delete your Customer Business Data and personal information within ninety (90) days following the effective date of termination (which period includes the 30-day export window), except as required by law or for legitimate, documented business purposes (e.g., billing records, dispute resolution).

4.3. Usage Data. Aggregated, de-identified usage data may be retained indefinitely for analytics and product improvement. Clevik maintains such data in a manner that does not identify any individual and commits not to attempt to re-identify it.

4.4. Backups. Copies of your data may persist in encrypted backups for a limited period following deletion. Backup data is overwritten through our normal backup rotation cycle and is not actively processed in the meantime.


5. Data Security

We implement and maintain commercially reasonable technical and organizational measures to protect your information. The detailed measures are set out in our Data Processing Agreement (Section 5):

5.1. Encryption. All data is encrypted in transit (TLS 1.2+) and at rest (AES-256 or equivalent).

5.2. Tenant Isolation. Customer data is logically isolated in our multi-tenant architecture. No customer can access another customer's data. There is no cross-tenant data sharing.

5.3. Access Controls. Access to customer data by Clevik personnel is restricted to authorized employees who require access for support or operational purposes, and is subject to logging and review.

5.4. Infrastructure Security. Our infrastructure is hosted on Microsoft Azure (East US 2 region) and other sub-processors listed in Section 3.1, which maintain their own security certifications and compliance programs.

5.5. On-Premise Sync Agent. The sync agent installed on your network communicates with Clevik's cloud services over encrypted connections. The sync agent does not store data locally beyond what is necessary for active synchronization.

5.6. SOC 2 Compliance. Clevik is pursuing SOC 2 Type II certification. We will update this policy and notify customers upon achieving certification.

5.7. Incident Response. We maintain an incident response plan and will notify affected customers of confirmed personal data breaches in accordance with our Data Processing Agreement (Section 6) and applicable law.


6. Your Rights and Choices

Depending on your jurisdiction, you may have the following rights regarding your personal information. Where Clevik processes Customer Business Data as your processor/service provider, we will refer requests from individuals to you and assist you in responding, as described in our Data Processing Agreement.

6.1. Access

You may request a copy of the personal information we hold about you.

6.2. Correction

You may request that we correct inaccurate or incomplete personal information.

6.3. Deletion

You may request that we delete your personal information. We may retain certain information as required by law or for legitimate business purposes.

6.4. Data Export / Portability

You may export the data that originates in or is generated by the Service — the documents you upload to the knowledge base and your AI Outputs — at any time through the Service's built-in export functionality. Synced Customer Business Data held in the Service is a copy of data that originates in, and remains available in, your own source systems; the Service is not your system of record for that data. We also provide export functionality to help you (and, where you are a controller, to help you support your own data subjects') data-portability requests, and you may request a copy of your personal information in a portable format. See our Data Processing Agreement (Section 8) for how export and deletion work on termination.

6.5. Opt-Out of Non-Essential Communications

You may opt out of marketing or promotional communications at any time by using the unsubscribe link in such communications or by contacting us at privacy@clevik.com. Transactional communications related to your account and the Service are not subject to opt-out.

6.6. Exercising Your Rights

To exercise any of these rights, contact us at privacy@clevik.com. We will respond to verified requests within thirty (30) days, or within the timeframe required by applicable law.


7. California Residents (CCPA/CPRA)

If you are a California resident, the California Consumer Privacy Act as amended by the California Privacy Rights Act (CCPA/CPRA) provides you with the following rights. Because the CPRA removed the prior business-to-business exemption, these rights extend to our business contacts (including account administrators and authorized users), not only to consumers.

7.1. Right to Know / Access. You may request the categories and specific pieces of personal information we have collected, the sources, the business or commercial purpose for collecting it, and the categories of third parties and service providers with whom we share it.

7.2. Right to Correct. You may request that we correct inaccurate personal information we maintain about you.

7.3. Right to Delete. You may request deletion of your personal information, subject to certain exceptions.

7.4. Right to Opt Out of Sale or Sharing. We do not "sell" personal information and do not "share" it for cross-context behavioral advertising. If this changes, we will update this policy and provide a "Do Not Sell or Share My Personal Information" mechanism.

7.5. Right to Limit Use of Sensitive Personal Information. To the extent we process sensitive personal information, we use it only for purposes permitted under the CPRA. We do not use sensitive personal information to infer characteristics about you.

7.6. Non-Discrimination. We will not discriminate against you for exercising your rights.

7.7. Authorized Agents and Appeals. You may use an authorized agent to submit requests, and you may appeal a denial as permitted by law.

7.8. Submitting Requests. Submit requests by emailing privacy@clevik.com. We will verify your identity before fulfilling your request.


8. Other U.S. State Privacy Rights

If you are a resident of a U.S. state with a comprehensive consumer privacy law (which may include Texas, Virginia, Colorado, Connecticut, Utah, Oregon, Montana, and others), you may have rights to access, correct, delete, and obtain a portable copy of your personal information, and to opt out of targeted advertising, the sale of personal information, and certain profiling. We do not sell personal information or use it for targeted advertising. To exercise these rights, contact privacy@clevik.com; we will verify your request and respond within the period required by your state's law. Where a state law provides a right to appeal a denial, instructions will be provided with our response.


9. European Economic Area, UK, and Swiss Residents (GDPR)

If you are located in the European Economic Area (EEA), United Kingdom, or Switzerland, the following applies:

9.1. Legal Basis for Processing. We process personal data under the following legal bases:

  • Contract performance: Processing necessary to provide the Service you requested.
  • Legitimate interests: Improving the Service, ensuring security, and fraud prevention.
  • Legal obligation: Complying with applicable laws.
  • Consent: Where specifically obtained (e.g., optional marketing communications and non-essential cookies).

9.2. Additional Rights. In addition to the rights in Section 6, you may have the right to restrict processing, object to processing based on legitimate interests, withdraw consent, and lodge a complaint with your local data protection authority.

9.3. International Transfers. Where your data is transferred to and processed in the United States or another country without an adequacy decision, we rely on Standard Contractual Clauses (SCCs) and other appropriate safeguards. See our Data Processing Agreement (Section 10) for details.

9.4. Data Processing Agreement. If you are a controller of personal data processed through the Service, our Data Processing Agreement (available at clevik.com/legal/dpa) governs our processing of that data on your behalf.


10. Children's Privacy

The Service is not intended for individuals under the age of 18. We do not knowingly collect personal information from children under 18. If we learn that we have collected personal information from a child under 18, we will take steps to delete that information promptly. If you believe a child under 18 has provided us with personal information, please contact us at privacy@clevik.com.


11. Third-Party Links and Integrations

The Service may contain links to third-party websites or integrate with third-party services (e.g., Microsoft Teams, your ERP/CRM systems). This Privacy Policy does not apply to third-party services. We encourage you to review the privacy policies of any third-party services you use in connection with Clevik.


12. Changes to This Privacy Policy

We may update this Privacy Policy from time to time. For material changes, we will provide at least thirty (30) days' advance notice via email or through the Service. Changes to our sub-processors are handled through the notice-and-objection process in our Data Processing Agreement rather than this Section. Your continued use of the Service after the effective date of any update constitutes acceptance of the revised Privacy Policy.


13. Contact Us

If you have questions or concerns about this Privacy Policy or our data practices, please contact us at:

Clevik LLC
3571 Far West Blvd #3798
Austin, Texas, 78731 USA
Email: legal@clevik.com (data/privacy) · support@clevik.com (general)
Website: clevik.com

For data protection inquiries from the EEA, UK, or Switzerland, contact privacy@clevik.com with the subject line "Data Protection Inquiry."