Help us improve Clevis

Optional analytics help us understand which pages and product journeys are useful. Clevis does not send customer content, prompts, document data, or direct identifiers. You can change this choice at any time.

Read the Cookie Policy
Skip to content
Clevis
  • Why Clevis
  • Security

Legal

Privacy Policy

How AEC ORIGIN LLC collects, uses, discloses, and protects personal data in connection with Clevis.

On this page

  1. 01Scope and who we are
  2. 02Our role: controller and processor
  3. 03Personal Data we collect
  4. 04How we use Personal Data
  5. 05Legal bases for processing
  6. 06AI features and Customer Content
  7. 07Cookies and similar technologies
  8. 08How we disclose Personal Data
  9. 09We do not sell Customer Content
  10. 10International data transfers
  11. 11Data retention and deletion
  12. 12Security
  13. 13Your privacy rights and choices
  14. 14Additional information for EEA, UK, and Swiss individuals
  15. 15Additional information for United States residents
  16. 16Children
  17. 17Third-party links and customer responsibilities
  18. 18Changes to this Privacy Policy
  19. 19Contact us

1. Scope and who we are

AEC ORIGIN LLC, doing business as ClevisHQ and Clevis ("Clevis," "we," "us," or "our"), provides software for construction organizations to coordinate projects, people, records, connected systems, and AI-assisted work. This Privacy Policy explains how we collect, use, disclose, retain, and otherwise process Personal Data when you visit our public websites, use Clevis, communicate with us, attend an event, participate in research, or otherwise interact with our services (collectively, the "Services").

"Personal Data" means information that identifies, relates to, describes, is reasonably capable of being associated with, or could reasonably be linked to an individual or household. It includes information called "personal information" or similar terms under applicable law. "Customer Content" means content that a customer, its users, or its authorized agents submit to Clevis or make available through the Services, including project records, documents, messages, prompts, files, connected-system data, and AI inputs and outputs.

This Policy does not cover third-party websites, services, or applications that you choose to connect to Clevis, or services that link to this Policy but publish their own privacy notice. Their data practices are governed by their own terms and privacy notices. This Policy also does not override a written agreement between Clevis and a business customer. Where we process Customer Content on behalf of a customer, the applicable customer agreement and data processing addendum, if any, govern that processing to the extent they conflict with this Policy.

2. Our role: controller and processor

For account, billing, website, marketing, support, security, and direct business relationship data, Clevis generally acts as the business or data controller. We determine the purposes and means of processing that data, subject to applicable law.

For Customer Content processed in a Clevis workspace, Clevis generally acts as a service provider or processor on the customer organization’s behalf. The customer organization decides what Customer Content to place in the Services, who may access it, how long it should be retained, and the lawful basis for its processing. That organization is responsible for providing required notices to its personnel, clients, subcontractors, and other individuals whose Personal Data it provides to us, and for obtaining any necessary permissions or consents.

If you use Clevis through an organization, direct questions about that organization’s Customer Content, including requests to access, correct, or delete it, to the organization first. We will assist our customer as required by our agreement and applicable law.

3. Personal Data we collect

Information you provide directly. We collect contact and account details, such as your name, business email address, phone number if provided, organization, job title, password or single sign-on information, profile information, and workspace or project role. We also collect communications you send to us, registration and event information, feedback, survey responses, and information you provide when requesting a demo, support, or other information about Clevis.

Customer Content and collaboration data. We process information that users submit, create, upload, share, generate, or configure in the Services. Depending on how a customer uses Clevis, this may include construction project information, contacts, team membership, schedules, costs, RFIs, submittals, documents, drawings, specifications, messages, notes, tasks, approvals, notifications, workspace settings, and associated metadata. Customer Content may contain Personal Data.

AI, automation, and agent data. When you use AI-assisted features, we process prompts, attached or retrieved context, model outputs, tool inputs and results, approvals, agent instructions, and run history. To operate secure, reviewable automations, we may also process records of the tools used, actions proposed or performed, timestamps, status, error information, and relevant audit events. Certain features may create or access browser sessions or connected-system information only when enabled and authorized under the applicable product controls.

Information from integrations. If you or your organization connects a third-party service, we receive information that the connection is configured and authorized to make available, such as account or connection status, selected records, identifiers, metadata, and activity necessary to provide the integration. The scope depends on the provider, permissions, settings, and actions chosen by your organization. External credentials and tokens are handled through the applicable connection flow and are not included in ordinary Clevis client responses.

Information collected automatically. When you use our websites or Services, we may collect log, device, and usage information, including IP address, browser and operating system type, device and session identifiers, pages or features accessed, referring URLs, approximate location derived from IP address, dates and times, performance information, crash or diagnostic data, and security signals. We use cookies and similar technologies as described in our Cookie Policy.

Information from other sources. We may receive business contact information from event partners, publicly available sources, referral sources, customer administrators, identity providers used for single sign-on, service providers, payment processors, security providers, and third parties that you authorize to share information with us. We use this information in accordance with this Policy and applicable law.

4. How we use Personal Data

We use Personal Data to provide, administer, support, and improve the Services. This includes creating and managing accounts; authenticating users; applying permissions and workspace controls; maintaining project and collaboration features; processing requests; providing support; administering subscriptions and commercial relationships; and communicating about transactions, product changes, security matters, or service operations.

We use Personal Data to deliver AI-assisted and automation features that you or your organization enable, including generating responses, retrieving authorized context, executing authorized tools, recording run history, presenting approval requests, and maintaining auditability. We use only the data reasonably necessary for the enabled feature and its configured scope.

We use Personal Data to maintain the security, integrity, availability, and resilience of our Services. This includes monitoring, troubleshooting, debugging, enforcing our terms and policies, preventing fraud, abuse, and unauthorized access, investigating incidents, preserving evidence, and protecting the rights, safety, and property of Clevis, our customers, users, and others.

We use Personal Data to understand and improve the Services, develop and test features, conduct product research, measure performance, produce analytics, and create aggregated or de-identified information. We maintain aggregated or de-identified information in that form and do not attempt to re-identify it except where necessary to test the effectiveness of our de-identification safeguards or as permitted by law.

We use business contact information to respond to inquiries, provide customer success and support, send requested communications, and market Clevis to business contacts where permitted by law. You may opt out of marketing emails using the unsubscribe link in those messages or by contacting us. Transactional, administrative, security, and legal notices are not marketing communications and may continue where necessary.

5. Legal bases for processing

Where data protection law requires a legal basis, we process Personal Data as necessary to perform a contract with you or your organization, to take steps at your request before entering into a contract, to comply with legal obligations, to protect vital interests, with your consent where required, and for our legitimate interests when those interests are not overridden by your rights and interests. Our legitimate interests include operating, securing, improving, and promoting our Services; supporting customers; preventing misuse; and defending legal claims.

Where we process Customer Content as a processor or service provider, we do so on our customer’s documented instructions, including as set out in the applicable customer agreement, unless otherwise required by law. If law requires us to process Customer Content for another purpose, we will provide notice to the customer unless legally prohibited.

6. AI features and Customer Content

Model improvement. Depending on your plan and workspace settings, Clevis may use Customer Content, including prompts, outputs, feedback, and related interaction data, to develop, train, evaluate, and improve Clevis and its AI-powered features. You or your workspace administrator may control this use through any available Settings control or by contacting [email protected]. We do not use Customer Content from a workspace for these purposes after the applicable opt-out takes effect. Additional restrictions may apply under your agreement with us.

AI features may send the prompts, authorized context, and related inputs needed to provide a requested feature to model or infrastructure providers acting on our behalf or under a customer-enabled connection. We select and contract with providers to process this information for the requested service and subject to appropriate confidentiality and data-protection obligations. AI-generated information can be inaccurate or incomplete. Users and customer organizations remain responsible for appropriate human review, authorization, and use of outputs, particularly where an output could affect safety, legal compliance, financial commitments, employment, or project decisions.

Clevis may use aggregated or de-identified operational and product signals to improve reliability, quality, security, and safety. We may retain limited security and abuse-prevention records when necessary to investigate suspected misuse or meet legal obligations.

7. Cookies and similar technologies

We and our service providers use cookies, local storage, pixels, software development kits, and similar technologies to operate and secure the Services, remember preferences, understand performance and use, and, where permitted, measure marketing. Some technologies are essential to sign-in, session management, fraud prevention, load balancing, and core functionality. You can manage browser settings and, where available, our cookie preferences controls. Blocking essential technologies may prevent parts of the Services from working properly.

When you affirmatively accept analytics, Clevis loads PostHog from its EU Cloud region for optional product intelligence. We send normalized route and outcome categories, a stable internal user UUID after sign-in, and a workspace UUID group. We do not send customer content, prompts, document data, project names or numbers, contact data, billing details, or direct identifiers. Session recording is not enabled and autocapture is disabled. See the Cookie Policy for the consent and preference controls.

Clevis may use browser Sentry for strictly diagnostic error reporting and server-side OpenTelemetry or Langfuse for operational tracing and AI reliability metadata when those deployments are configured. These systems use PII-off, replay-off, and content-minimizing settings. They may receive normalized routes, release and error categories, and pseudonymous internal UUID metadata, but not prompts, model outputs, tool payloads, document contents, cookies, authorization headers, or other Customer Content. These operational services are not controlled by the PostHog analytics consent choice.

For more detail about these technologies and choices, see our Cookie Policy. Where law requires consent before setting or reading non-essential technologies, we will request it. Where applicable law requires us to honor an opt-out preference signal, such as Global Privacy Control, we will treat a recognized signal as an opt-out for that browser or device to the extent required by law.

8. How we disclose Personal Data

We disclose Personal Data to service providers and subprocessors that help us provide the Services, including providers of hosting, cloud infrastructure, data storage, identity and authentication, communications, customer support, security, monitoring, analytics, payment processing, AI and model services, and professional services. These parties may process Personal Data only for the purposes authorized by Clevis and subject to contractual obligations appropriate to their role.

Operational monitoring providers, including Sentry and any configured OpenTelemetry or Langfuse destination, receive only the bounded diagnostic and reliability metadata described in this Policy. Their integrations are disabled when deployment credentials are absent, and they are not used to receive unrestricted Customer Content.

We disclose Customer Content and other information to other users and recipients as directed by you or your organization through the Services. For example, workspace and project permissions, sharing settings, reports, messages, notifications, and customer-enabled integrations may make information available to authorized colleagues, administrators, project participants, or third-party systems. Customer administrators are responsible for configuring access and sharing settings appropriately.

We disclose information to third-party integrations that you or your organization elects to connect, and to providers necessary to complete a transaction or request you initiate. Once information is disclosed to a third party at your direction, that third party’s practices govern its handling of the information.

We may disclose information to comply with applicable law, regulation, legal process, subpoena, or enforceable governmental request; to enforce agreements; to protect against fraud, security threats, or illegal activity; to protect the rights, property, and safety of Clevis, our customers, users, or the public; or to establish, exercise, or defend legal claims. We will evaluate requests and disclose only what we reasonably believe is required or permitted by law.

We may disclose information in connection with an actual or proposed corporate transaction, such as a financing, merger, acquisition, reorganization, sale of assets, bankruptcy, or transition of service to another provider. Where required, we will provide notice and apply appropriate protections to the information involved.

9. We do not sell Customer Content

Clevis does not sell Customer Content. We do not rent or trade Customer Content for another party’s independent marketing purposes. We do not knowingly disclose Customer Content for cross-context behavioral advertising.

We may use optional website measurement or marketing technologies as described in our Cookie Policy. To the extent disclosure of website identifiers to an advertising or measurement partner constitutes a "sale" or "sharing" under applicable United States privacy law, you may opt out through the applicable cookie preference controls, a recognized browser opt-out preference signal, or by contacting us at [email protected]. This does not affect disclosures that are necessary to provide the Services, process a request, detect security incidents, or otherwise permitted by law.

10. International data transfers

Clevis and our service providers may process Personal Data in the United States and other countries where we, our customers, or our service providers operate. Those countries may have data-protection laws that differ from the laws of your place of residence.

When we transfer Personal Data internationally, we use safeguards required by applicable law. Depending on the transfer, these may include contractual protections such as the European Commission’s Standard Contractual Clauses, the United Kingdom International Data Transfer Addendum or equivalent terms, adequacy decisions, or another valid transfer mechanism. A customer may request information about the applicable transfer safeguards through its account representative or [email protected].

11. Data retention and deletion

We retain Personal Data for as long as reasonably necessary for the purposes described in this Policy, including to provide the Services, maintain business and security records, resolve disputes, enforce agreements, comply with legal obligations, and protect our rights. Retention depends on the type of data, the customer’s configuration and agreement, the nature of the Services used, and applicable legal requirements.

Customer Content is generally retained while the applicable workspace or customer account remains active, subject to the customer’s instructions, plan, and agreement. Following account closure or a verified deletion request, we delete or de-identify Customer Content within our operational deletion process, subject to applicable law, legal holds, fraud and security needs, and backup or disaster-recovery cycles. Information may persist in secure backups for a limited period before it is overwritten or otherwise deleted through normal backup rotation.

We may retain account, transaction, consent, opt-out, security, audit, and legal records for longer where reasonably necessary to document compliance, prevent fraud or abuse, investigate incidents, preserve evidence, or meet accounting, tax, regulatory, and legal requirements. Where technically feasible and appropriate, we will de-identify rather than retain identifiable information.

12. Security

We use administrative, technical, and organizational measures designed to protect Personal Data against accidental or unlawful destruction, loss, alteration, unauthorized disclosure, or access. These measures include access controls, authentication and authorization mechanisms, least-privilege practices, logging and audit capabilities, secure development practices, service-provider review, and safeguards appropriate to the nature of the Services and the risks involved.

No method of transmission, storage, or processing is completely secure. You are responsible for protecting your credentials, using available account-security controls, maintaining appropriate workspace permissions, and promptly notifying us of suspected unauthorized access. We will investigate suspected security incidents and provide notifications when required by applicable law or contract.

13. Your privacy rights and choices

Depending on where you live and the nature of our processing, you may have the right to request access to Personal Data, correction of inaccurate data, deletion, restriction of processing, objection to processing based on legitimate interests, portability, withdrawal of consent, and information about disclosures. You may also opt out of marketing communications as described above. These rights are not absolute and may be subject to conditions and exceptions under applicable law.

To make a request regarding Personal Data for which Clevis acts as controller, email [email protected] with "Privacy Request" in the subject line and describe your request. We may need to verify your identity or authority before acting. If you are an authorized agent, we may request evidence of your authority and identity information needed to verify the request. We will not discriminate against you for exercising applicable privacy rights.

If your request concerns Customer Content in an organization’s workspace, contact the organization that controls the workspace first. We will route or assist with such requests as appropriate, consistent with our obligations to the customer and applicable law. We cannot change or delete Customer Content at an individual’s request when doing so would conflict with a customer’s lawful instructions, rights, or legal obligations.

14. Additional information for EEA, UK, and Swiss individuals

If you are in the European Economic Area, United Kingdom, or Switzerland, you may have the rights described in Section 13, including the right to lodge a complaint with your local data-protection authority. Where Clevis acts as controller, the legal bases described in Section 5 apply. Where Clevis processes Customer Content as a processor, the relevant customer organization is ordinarily the controller and is responsible for responding to your request.

You may object at any time to processing based on our legitimate interests, including direct marketing. We will stop the relevant processing unless we have compelling legitimate grounds that override your interests, rights, and freedoms, or the processing is necessary for legal claims. You may withdraw consent at any time where we rely on consent, without affecting the lawfulness of processing before withdrawal.

15. Additional information for United States residents

In the preceding 12 months, we may have collected the following categories of Personal Data: identifiers and professional information, such as name, email address, organization, job title, account identifiers, and IP address; commercial information, such as subscription and transaction information; internet, device, and network activity, such as log, usage, browser, and diagnostic information; approximate geolocation derived from IP address; Customer Content; and inferences or preferences derived from use of the Services. We collect these categories from you, your organization, your device or browser, integrations you enable, service providers, and the other sources described in Section 3.

We use these categories for the purposes described in Section 4 and disclose them to the recipients described in Section 8. We use account authentication information only as necessary to provide and secure the Services. We do not use or disclose sensitive Personal Data to infer characteristics about individuals or for purposes that require a separate right to limit under applicable law.

Subject to applicable law, residents of certain United States states may request to know or access Personal Data, correct inaccuracies, delete Personal Data, receive a portable copy, opt out of targeted advertising, opt out of sale or sharing, and opt out of certain profiling with legal or similarly significant effects. Clevis does not use Personal Data for solely automated decisions that produce legal or similarly significant effects about consumers. To exercise a right, follow Section 13. If we deny your request, you may appeal by replying to our decision with "Privacy Appeal" in the subject line. We will respond to an appeal as required by applicable law and provide information about further review where required.

16. Children

Clevis is a business service and is not directed to children. We do not knowingly collect Personal Data from children under 16, or a higher minimum age where required by applicable law, without appropriate authorization. If you believe a child has provided Personal Data to us without authorization, contact us at [email protected]. If we learn that we collected such information unlawfully, we will take appropriate steps to delete it.

17. Third-party links and customer responsibilities

The Services may link to, embed, or interoperate with third-party services. Clevis does not control the privacy, security, or content practices of those services. Review their notices before providing information or authorizing a connection. A customer that connects an external service is responsible for confirming it has authority to do so and for configuring the connection, permissions, and sharing scope appropriately.

Customers are also responsible for determining whether and how their use of Clevis is subject to industry-specific, employment, construction, export-control, recordkeeping, or other legal requirements. Clevis does not provide legal advice through this Policy or the Services.

18. Changes to this Privacy Policy

We may update this Privacy Policy to reflect changes to the Services, our processing practices, applicable law, or other operational, legal, or regulatory reasons. We will post the revised Policy on this page. If a change materially reduces privacy rights or materially expands how we process Personal Data, we will provide additional notice as required by law or appropriate to the circumstances, such as through the Services or by email to the relevant account contact.

The revised Policy applies from its effective date. If a customer agreement requires a different notice or amendment process, that agreement controls for the customer relationship. Prior versions may be requested at [email protected].

19. Contact us

AEC ORIGIN LLC is responsible for the Personal Data covered by this Policy when it acts as controller. For questions, concerns, accessibility requests, or privacy requests, contact us at [email protected].

Put your company context to work.

Get Started Talk to the Clevis team
Clevis

The operational brain for your construction company.

Product

CommandProjectsSentinelContextAgentsIntegrations

Solutions

General contractorsOwnersSpecialty contractors

Company

Why ClevisContact

Legal

Terms of ServicePrivacy PolicyData UseSecurityCookie Policy

© 2026 Clevis, Inc.

Built for the people who build.Back to top ↑