Legal
Privacy Policy
How AEC ORIGIN LLC collects, uses, discloses, and protects personal data in connection with Clevis.
1. Scope and who we are
AEC ORIGIN LLC, doing business as ClevisHQ and Clevis ("Clevis," "we," "us," or "our"), provides software for construction organizations to coordinate projects, people, records, connected systems, and AI-assisted work. This Privacy Policy explains how we collect, use, disclose, retain, and otherwise process Personal Data when you visit our public websites, use Clevis, communicate with us, attend an event, participate in research, or otherwise interact with our services (collectively, the "Services").
"Personal Data" means information that identifies, relates to, describes, is reasonably capable of being associated with, or could reasonably be linked to an individual or household. It includes information called "personal information" or similar terms under applicable law. "Customer Content" means content that a customer, its users, or its authorized agents submit to Clevis or make available through the Services, including project records, documents, messages, prompts, files, connected-system data, and AI inputs and outputs.
This Policy does not cover third-party websites, services, or applications that you choose to connect to Clevis, or services that link to this Policy but publish their own privacy notice. Their data practices are governed by their own terms and privacy notices. This Policy also does not override a written agreement between Clevis and a business customer. Where we process Customer Content on behalf of a customer, the applicable customer agreement and data processing addendum, if any, govern that processing to the extent they conflict with this Policy.
2. Our role: controller and processor
For account, billing, website, marketing, support, security, and direct business relationship data, Clevis generally acts as the business or data controller. We determine the purposes and means of processing that data, subject to applicable law.
For Customer Content processed in a Clevis workspace, Clevis generally acts as a service provider or processor on the customer organization’s behalf. The customer organization decides what Customer Content to place in the Services, who may access it, how long it should be retained, and the lawful basis for its processing. That organization is responsible for providing required notices to its personnel, clients, subcontractors, and other individuals whose Personal Data it provides to us, and for obtaining any necessary permissions or consents.
If you use Clevis through an organization, direct questions about that organization’s Customer Content, including requests to access, correct, or delete it, to the organization first. We will assist our customer as required by our agreement and applicable law.
3. Personal Data we collect
Information you provide directly. We collect contact and account details, such as your name, business email address, phone number if provided, organization, job title, password or single sign-on information, profile information, and workspace or project role. We also collect communications you send to us, registration and event information, feedback, survey responses, and information you provide when requesting a demo, support, or other information about Clevis.
Customer Content and collaboration data. We process information that users submit, create, upload, share, generate, or configure in the Services. Depending on how a customer uses Clevis, this may include construction project information, contacts, team membership, schedules, costs, RFIs, submittals, documents, drawings, specifications, messages, notes, tasks, approvals, notifications, workspace settings, and associated metadata. Customer Content may contain Personal Data.
AI, automation, and agent data. When you use AI-assisted features, we process prompts, attached or retrieved context, model outputs, tool inputs and results, approvals, agent instructions, and run history. To operate secure, reviewable automations, we may also process records of the tools used, actions proposed or performed, timestamps, status, error information, and relevant audit events. Certain features may create or access browser sessions or connected-system information only when enabled and authorized under the applicable product controls.
Information from integrations. If you or your organization connects a third-party service, we receive information that the connection is configured and authorized to make available, such as account or connection status, selected records, identifiers, metadata, and activity necessary to provide the integration. The scope depends on the provider, permissions, settings, and actions chosen by your organization. External credentials and tokens are handled through the applicable connection flow and are not included in ordinary Clevis client responses.
Information collected automatically. When you use our websites or Services, we may collect log, device, and usage information, including IP address, browser and operating system type, device and session identifiers, pages or features accessed, referring URLs, approximate location derived from IP address, dates and times, performance information, crash or diagnostic data, and security signals. We use cookies and similar technologies as described in our Cookie Policy.
Information from other sources. We may receive business contact information from event partners, publicly available sources, referral sources, customer administrators, identity providers used for single sign-on, service providers, payment processors, security providers, and third parties that you authorize to share information with us. We use this information in accordance with this Policy and applicable law.
4. How we use Personal Data
We use Personal Data to provide, administer, support, and improve the Services. This includes creating and managing accounts; authenticating users; applying permissions and workspace controls; maintaining project and collaboration features; processing requests; providing support; administering subscriptions and commercial relationships; and communicating about transactions, product changes, security matters, or service operations.
We use Personal Data to deliver AI-assisted and automation features that you or your organization enable, including generating responses, retrieving authorized context, executing authorized tools, recording run history, presenting approval requests, and maintaining auditability. We use only the data reasonably necessary for the enabled feature and its configured scope.
We use Personal Data to maintain the security, integrity, availability, and resilience of our Services. This includes monitoring, troubleshooting, debugging, enforcing our terms and policies, preventing fraud, abuse, and unauthorized access, investigating incidents, preserving evidence, and protecting the rights, safety, and property of Clevis, our customers, users, and others.
We use Personal Data to understand and improve the Services, develop and test features, conduct product research, measure performance, produce analytics, and create aggregated or de-identified information. We maintain aggregated or de-identified information in that form and do not attempt to re-identify it except where necessary to test the effectiveness of our de-identification safeguards or as permitted by law.
We use business contact information to respond to inquiries, provide customer success and support, send requested communications, and market Clevis to business contacts where permitted by law. You may opt out of marketing emails using the unsubscribe link in those messages or by contacting us. Transactional, administrative, security, and legal notices are not marketing communications and may continue where necessary.
5. Legal bases for processing
Where data protection law requires a legal basis, we process Personal Data as necessary to perform a contract with you or your organization, to take steps at your request before entering into a contract, to comply with legal obligations, to protect vital interests, with your consent where required, and for our legitimate interests when those interests are not overridden by your rights and interests. Our legitimate interests include operating, securing, improving, and promoting our Services; supporting customers; preventing misuse; and defending legal claims.
Where we process Customer Content as a processor or service provider, we do so on our customer’s documented instructions, including as set out in the applicable customer agreement, unless otherwise required by law. If law requires us to process Customer Content for another purpose, we will provide notice to the customer unless legally prohibited.
6. AI features and Customer Content
Model improvement. Depending on your plan and workspace settings, Clevis may use Customer Content, including prompts, outputs, feedback, and related interaction data, to develop, train, evaluate, and improve Clevis and its AI-powered features. You or your workspace administrator may control this use through any available Settings control or by contacting [email protected]. We do not use Customer Content from a workspace for these purposes after the applicable opt-out takes effect. Additional restrictions may apply under your agreement with us.
AI features may send the prompts, authorized context, and related inputs needed to provide a requested feature to model or infrastructure providers acting on our behalf or under a customer-enabled connection. We select and contract with providers to process this information for the requested service and subject to appropriate confidentiality and data-protection obligations. AI-generated information can be inaccurate or incomplete. Users and customer organizations remain responsible for appropriate human review, authorization, and use of outputs, particularly where an output could affect safety, legal compliance, financial commitments, employment, or project decisions.
Clevis may use aggregated or de-identified operational and product signals to improve reliability, quality, security, and safety. We may retain limited security and abuse-prevention records when necessary to investigate suspected misuse or meet legal obligations.
8. How we disclose Personal Data
We disclose Personal Data to service providers and subprocessors that help us provide the Services, including providers of hosting, cloud infrastructure, data storage, identity and authentication, communications, customer support, security, monitoring, analytics, payment processing, AI and model services, and professional services. These parties may process Personal Data only for the purposes authorized by Clevis and subject to contractual obligations appropriate to their role.
Operational monitoring providers, including Sentry and any configured OpenTelemetry or Langfuse destination, receive only the bounded diagnostic and reliability metadata described in this Policy. Their integrations are disabled when deployment credentials are absent, and they are not used to receive unrestricted Customer Content.
We disclose Customer Content and other information to other users and recipients as directed by you or your organization through the Services. For example, workspace and project permissions, sharing settings, reports, messages, notifications, and customer-enabled integrations may make information available to authorized colleagues, administrators, project participants, or third-party systems. Customer administrators are responsible for configuring access and sharing settings appropriately.
We disclose information to third-party integrations that you or your organization elects to connect, and to providers necessary to complete a transaction or request you initiate. Once information is disclosed to a third party at your direction, that third party’s practices govern its handling of the information.
We may disclose information to comply with applicable law, regulation, legal process, subpoena, or enforceable governmental request; to enforce agreements; to protect against fraud, security threats, or illegal activity; to protect the rights, property, and safety of Clevis, our customers, users, or the public; or to establish, exercise, or defend legal claims. We will evaluate requests and disclose only what we reasonably believe is required or permitted by law.
We may disclose information in connection with an actual or proposed corporate transaction, such as a financing, merger, acquisition, reorganization, sale of assets, bankruptcy, or transition of service to another provider. Where required, we will provide notice and apply appropriate protections to the information involved.
9. We do not sell Customer Content
Clevis does not sell Customer Content. We do not rent or trade Customer Content for another party’s independent marketing purposes. We do not knowingly disclose Customer Content for cross-context behavioral advertising.
We may use optional website measurement or marketing technologies as described in our Cookie Policy. To the extent disclosure of website identifiers to an advertising or measurement partner constitutes a "sale" or "sharing" under applicable United States privacy law, you may opt out through the applicable cookie preference controls, a recognized browser opt-out preference signal, or by contacting us at [email protected]. This does not affect disclosures that are necessary to provide the Services, process a request, detect security incidents, or otherwise permitted by law.
10. International data transfers
Clevis and our service providers may process Personal Data in the United States and other countries where we, our customers, or our service providers operate. Those countries may have data-protection laws that differ from the laws of your place of residence.
When we transfer Personal Data internationally, we use safeguards required by applicable law. Depending on the transfer, these may include contractual protections such as the European Commission’s Standard Contractual Clauses, the United Kingdom International Data Transfer Addendum or equivalent terms, adequacy decisions, or another valid transfer mechanism. A customer may request information about the applicable transfer safeguards through its account representative or [email protected].
11. Data retention and deletion
We retain Personal Data for as long as reasonably necessary for the purposes described in this Policy, including to provide the Services, maintain business and security records, resolve disputes, enforce agreements, comply with legal obligations, and protect our rights. Retention depends on the type of data, the customer’s configuration and agreement, the nature of the Services used, and applicable legal requirements.
Customer Content is generally retained while the applicable workspace or customer account remains active, subject to the customer’s instructions, plan, and agreement. Following account closure or a verified deletion request, we delete or de-identify Customer Content within our operational deletion process, subject to applicable law, legal holds, fraud and security needs, and backup or disaster-recovery cycles. Information may persist in secure backups for a limited period before it is overwritten or otherwise deleted through normal backup rotation.
We may retain account, transaction, consent, opt-out, security, audit, and legal records for longer where reasonably necessary to document compliance, prevent fraud or abuse, investigate incidents, preserve evidence, or meet accounting, tax, regulatory, and legal requirements. Where technically feasible and appropriate, we will de-identify rather than retain identifiable information.
12. Security
We use administrative, technical, and organizational measures designed to protect Personal Data against accidental or unlawful destruction, loss, alteration, unauthorized disclosure, or access. These measures include access controls, authentication and authorization mechanisms, least-privilege practices, logging and audit capabilities, secure development practices, service-provider review, and safeguards appropriate to the nature of the Services and the risks involved.
No method of transmission, storage, or processing is completely secure. You are responsible for protecting your credentials, using available account-security controls, maintaining appropriate workspace permissions, and promptly notifying us of suspected unauthorized access. We will investigate suspected security incidents and provide notifications when required by applicable law or contract.
13. Your privacy rights and choices
Depending on where you live and the nature of our processing, you may have the right to request access to Personal Data, correction of inaccurate data, deletion, restriction of processing, objection to processing based on legitimate interests, portability, withdrawal of consent, and information about disclosures. You may also opt out of marketing communications as described above. These rights are not absolute and may be subject to conditions and exceptions under applicable law.
To make a request regarding Personal Data for which Clevis acts as controller, email [email protected] with "Privacy Request" in the subject line and describe your request. We may need to verify your identity or authority before acting. If you are an authorized agent, we may request evidence of your authority and identity information needed to verify the request. We will not discriminate against you for exercising applicable privacy rights.
If your request concerns Customer Content in an organization’s workspace, contact the organization that controls the workspace first. We will route or assist with such requests as appropriate, consistent with our obligations to the customer and applicable law. We cannot change or delete Customer Content at an individual’s request when doing so would conflict with a customer’s lawful instructions, rights, or legal obligations.
14. Additional information for EEA, UK, and Swiss individuals
If you are in the European Economic Area, United Kingdom, or Switzerland, you may have the rights described in Section 13, including the right to lodge a complaint with your local data-protection authority. Where Clevis acts as controller, the legal bases described in Section 5 apply. Where Clevis processes Customer Content as a processor, the relevant customer organization is ordinarily the controller and is responsible for responding to your request.
You may object at any time to processing based on our legitimate interests, including direct marketing. We will stop the relevant processing unless we have compelling legitimate grounds that override your interests, rights, and freedoms, or the processing is necessary for legal claims. You may withdraw consent at any time where we rely on consent, without affecting the lawfulness of processing before withdrawal.
15. Additional information for United States residents
In the preceding 12 months, we may have collected the following categories of Personal Data: identifiers and professional information, such as name, email address, organization, job title, account identifiers, and IP address; commercial information, such as subscription and transaction information; internet, device, and network activity, such as log, usage, browser, and diagnostic information; approximate geolocation derived from IP address; Customer Content; and inferences or preferences derived from use of the Services. We collect these categories from you, your organization, your device or browser, integrations you enable, service providers, and the other sources described in Section 3.
We use these categories for the purposes described in Section 4 and disclose them to the recipients described in Section 8. We use account authentication information only as necessary to provide and secure the Services. We do not use or disclose sensitive Personal Data to infer characteristics about individuals or for purposes that require a separate right to limit under applicable law.
Subject to applicable law, residents of certain United States states may request to know or access Personal Data, correct inaccuracies, delete Personal Data, receive a portable copy, opt out of targeted advertising, opt out of sale or sharing, and opt out of certain profiling with legal or similarly significant effects. Clevis does not use Personal Data for solely automated decisions that produce legal or similarly significant effects about consumers. To exercise a right, follow Section 13. If we deny your request, you may appeal by replying to our decision with "Privacy Appeal" in the subject line. We will respond to an appeal as required by applicable law and provide information about further review where required.
16. Children
Clevis is a business service and is not directed to children. We do not knowingly collect Personal Data from children under 16, or a higher minimum age where required by applicable law, without appropriate authorization. If you believe a child has provided Personal Data to us without authorization, contact us at [email protected]. If we learn that we collected such information unlawfully, we will take appropriate steps to delete it.
17. Third-party links and customer responsibilities
The Services may link to, embed, or interoperate with third-party services. Clevis does not control the privacy, security, or content practices of those services. Review their notices before providing information or authorizing a connection. A customer that connects an external service is responsible for confirming it has authority to do so and for configuring the connection, permissions, and sharing scope appropriately.
Customers are also responsible for determining whether and how their use of Clevis is subject to industry-specific, employment, construction, export-control, recordkeeping, or other legal requirements. Clevis does not provide legal advice through this Policy or the Services.
18. Changes to this Privacy Policy
We may update this Privacy Policy to reflect changes to the Services, our processing practices, applicable law, or other operational, legal, or regulatory reasons. We will post the revised Policy on this page. If a change materially reduces privacy rights or materially expands how we process Personal Data, we will provide additional notice as required by law or appropriate to the circumstances, such as through the Services or by email to the relevant account contact.
The revised Policy applies from its effective date. If a customer agreement requires a different notice or amendment process, that agreement controls for the customer relationship. Prior versions may be requested at [email protected].
19. Contact us
AEC ORIGIN LLC is responsible for the Personal Data covered by this Policy when it acts as controller. For questions, concerns, accessibility requests, or privacy requests, contact us at [email protected].
