Legal
Data Use
How AEC ORIGIN LLC handles Customer Content when organizations use Clevis, including AI, agents, integrations, and connected systems.
1. Purpose and scope
AEC ORIGIN LLC, doing business as ClevisHQ and Clevis ("Clevis," "we," "us," or "our"), provides software that helps construction organizations coordinate projects, people, records, connected systems, and AI-assisted work. This Data Use Policy explains how Clevis handles data that customers and their authorized users provide to or make available through the Clevis services (the "Services").
This Policy is intended to give customers a clear operational account of how Customer Content is used in the Services. It supplements the Clevis Privacy Policy and the applicable customer agreement. If a customer agreement or data processing addendum imposes different or additional requirements for a customer, that agreement controls for that customer to the extent of any conflict.
2. Definitions and roles
Customer Content. Content that a customer, its users, or its authorized systems submit to, create in, or make available through Clevis. This includes project records, documents, drawings, specifications, schedules, costs, RFIs, submittals, tasks, notes, messages, prompts, files, approvals, agent instructions, connected-system records, and AI inputs and outputs.
Service Data. Account, configuration, usage, diagnostic, security, and operational information generated through the use and administration of the Services. Service Data can include Personal Data and is handled under the Privacy Policy.
Customer and Clevis roles. The customer controls the Customer Content it places in Clevis and determines the purposes for which it uses the Services. Clevis generally processes Customer Content as a service provider or processor on the customer’s behalf and according to the customer’s documented instructions, the product configuration, and the applicable agreement.
3. Our commitments for Customer Content
Customer control. Customers control what Customer Content is submitted, which users and projects may access it, which integrations are connected, and which features are enabled, subject to the Services and the applicable agreement.
No sale of Customer Content. We do not sell, rent, or trade Customer Content. We do not disclose Customer Content for cross-context behavioral advertising or another party’s independent marketing purposes.
Model improvement. Depending on your plan and workspace settings, Clevis may use Customer Content, including prompts, outputs, feedback, and related interaction data, to develop, train, evaluate, and improve Clevis and its AI-powered features. You or your workspace administrator may control this use through any available Settings control or by contacting info@clevishq.com. We do not use Customer Content from a workspace for these purposes after the applicable opt-out takes effect. Additional restrictions may apply under your agreement with us.
No direct cross-customer disclosure. We do not make one customer’s raw Customer Content available to another customer or place it in another customer’s workspace. Model improvement under this Policy does not authorize direct disclosure of source Customer Content.
4. How Clevis uses Customer Content
Clevis uses Customer Content only as reasonably necessary to provide, maintain, secure, support, and improve the Services; carry out customer instructions; comply with law; enforce applicable agreements; and protect Clevis, customers, users, and others from fraud, abuse, security threats, or unlawful activity.
Providing the Services can include storing and retrieving records, organizing project information, applying permissions, enabling search, indexing authorized content, generating reports, sending notifications, coordinating workflows, processing files, delivering support, maintaining backups, and providing AI-assisted features requested by authorized users.
We may access Customer Content when needed to investigate a support request, resolve an incident, prevent or investigate misuse, meet a legal obligation, or maintain the reliability and security of the Services. Access is limited to authorized personnel and service providers with a legitimate need and is subject to appropriate confidentiality and security controls.
5. AI models and generation services
When an authorized user requests an AI-assisted feature, Clevis may send the prompt, authorized context, instructions, attachments, and other inputs reasonably necessary to generate the requested output to an AI model or infrastructure provider. The information sent depends on the feature, selected model, customer settings, user permissions, and available context.
We select providers intended to process Customer Content for the requested service and subject to contractual confidentiality and data-protection obligations appropriate to their role. Clevis does not authorize third-party model providers acting on our behalf to use Customer Content to train their models, except where separately disclosed and authorized. A provider may process limited information for security, abuse prevention, or legal compliance as permitted by its agreement with Clevis and applicable law.
AI outputs may be inaccurate, incomplete, outdated, or unsuitable for a particular purpose. Clevis is designed to support human work, not replace professional judgment. Customers and users are responsible for reviewing outputs before relying on them, sharing them, or using them for safety, legal, contractual, employment, financial, scheduling, or project decisions.
6. Retrieval, indexing, and contextual grounding
Clevis may index, structure, summarize, or create technical representations of authorized Customer Content so users and agents can search, retrieve, relate, and reason over relevant project or company information. These operations are performed to provide the Services and remain subject to the customer’s workspace, project, membership, and permission boundaries.
Context supplied to an AI feature may include records retrieved from Clevis, documents selected or uploaded by a user, prior messages, approved workspace knowledge, connected-system information, and relevant tool results. Clevis is designed to retrieve context within the requesting user’s authorized scope. A user’s access to a source record does not automatically authorize broader access to the workspace or connected system.
Derived indexes, embeddings, metadata, summaries, relationships, and citations created from Customer Content are treated as Customer Content when they can identify, reconstruct, or meaningfully reveal the underlying customer information.
7. Agents, tools, and automation
Clevis agents can read authorized context, generate outputs, invoke configured tools, coordinate workflows, and propose or perform actions. An agent receives only the tools, data scope, and permissions available to it under its configuration and the requesting user’s authorization. Server-side controls remain authoritative for access and execution decisions.
Some actions may require human approval before execution. Approval requirements can depend on the tool, action, customer policy, project scope, and potential impact. Approval is an authorization control, not a guarantee that an action or output is correct. The approving user remains responsible for reviewing the proposed action and available context.
Clevis may retain agent run records, messages, plans, retrieved context references, tool calls and results, approvals, outputs, errors, status changes, and audit events. These records support continuity, review, troubleshooting, security, and accountability. Visibility depends on the run’s configured scope and the applicable workspace or project permissions.
8. Connected systems and integrations
Customers may connect Clevis to third-party systems such as construction-management, document, productivity, scheduling, financial, or communication services. Clevis accesses connected-system data only through the permissions, mappings, and actions authorized by the customer or user and supported by the integration.
Clevis may store connection identifiers, configuration, selected project mappings, synchronization state, cursors, external record references, health information, and limited metadata needed to operate and audit the integration. Clevis does not mirror complete external datasets by default. Some workflows may cache or materialize selected data when required to provide the configured feature.
Credentials and access tokens are handled through server-owned or provider-managed connection flows and are not included in ordinary browser responses or model-visible content. Disconnecting an integration stops future authorized access through that connection, but it does not automatically delete records previously imported, created, or retained under the customer’s instructions and applicable retention settings.
Third-party services remain responsible for their own processing. Customers are responsible for confirming they have authority to connect each system and disclose the relevant data to Clevis.
9. Agent Computer and browser sessions
When a customer enables Agent Computer or browser automation, Clevis may create and control a remote browser or computer session to perform authorized work. The session may access websites, files, and applications approved by the user or allowed by the customer’s policy. Navigation, observation, and actions remain subject to product permissions, domain controls, and applicable approval requirements.
Users may take control of a session to complete sign-in, single sign-on, or multi-factor authentication. Authentication information entered during protected human control is not intended to be exposed to the AI model. Browser session providers may retain encrypted session state or cookies as needed to preserve an authorized login between sessions, according to the applicable configuration and provider terms.
Clevis may record bounded navigation metadata, action history, screenshots, observations, downloads, approvals, and security events when needed to provide, review, and secure the feature. Clevis is designed not to place passwords, authentication tokens, private browser-storage contents, or live-view capability links in model prompts, ordinary client payloads, or audit records.
10. Access, visibility, and tenant boundaries
Customer administrators manage membership, roles, projects, workspace structure, agent configurations, integrations, and other available controls. Clevis applies server-side authorization to determine whether a user or agent may access or change a record. Customers are responsible for assigning access appropriate to each user’s responsibilities.
Customer Content is logically separated by customer, workspace, project, user, and other applicable scopes. Private prompts, messages, agent runs, personal connections, and browser sessions remain limited to their configured owners or authorized audiences. Shared content and runs can be visible to other authorized members when a customer or user intentionally selects a shared scope.
Customer administrators may be able to manage accounts, configure features, review activity, or access Customer Content within the authority granted by the customer and the Services. Users should direct questions about an organization’s access practices to that organization.
11. Service providers and subprocessors
Clevis uses service providers and subprocessors to support functions such as cloud infrastructure, hosting, storage, authentication, communications, monitoring, security, file processing, workflow execution, integrations, browser sessions, customer support, and AI generation. These providers receive only the information reasonably necessary for their function and are subject to contractual obligations appropriate to their role.
Customer Content may be processed in the United States and other countries where Clevis or our service providers operate. Where required, Clevis uses appropriate international-transfer safeguards as described in the Privacy Policy and applicable customer agreement or data processing addendum.
Enterprise customers may request current information about material subprocessors by contacting info@clevishq.com. Any contractual notification or objection rights are governed by the applicable customer agreement or data processing addendum.
12. Service improvement and de-identified data
Clevis may use Service Data and aggregated or de-identified information to measure performance, identify reliability issues, improve product quality, test features, protect the Services, allocate capacity, and understand how features are used. Where the applicable model-improvement setting permits, Clevis may also use Customer Content for the purposes described in Section 3.
When we create aggregated or de-identified information from Customer Content or Service Data, we use measures designed to prevent the information from reasonably identifying a person or customer. We maintain that information in aggregated or de-identified form and do not attempt to re-identify it except to test the effectiveness of our safeguards or as permitted by law.
Authorized Clevis personnel may review limited Customer Content when necessary to diagnose a reported problem, evaluate the safety or quality of a customer-requested feature, investigate suspected abuse, or provide support. We limit such access based on role and need.
13. Retention, deletion, and export
Customer Content is generally retained while the applicable customer account or workspace is active, subject to the customer’s instructions, plan, product configuration, and agreement. Different records may have different retention periods based on operational, security, contractual, regulatory, and legal requirements.
After account closure or a verified deletion instruction, Clevis deletes or de-identifies Customer Content through its operational deletion process, subject to legal holds, fraud and security needs, applicable law, and backup or disaster-recovery cycles. Data can remain in secure backups for a limited period before normal rotation overwrites or deletes it.
Certain audit, transaction, consent, security, support, and legal records may be retained longer when reasonably necessary to document compliance, prevent abuse, investigate incidents, resolve disputes, or meet legal obligations. When technically feasible and appropriate, Clevis limits or de-identifies retained information.
Available export capabilities depend on the product, record type, plan, and customer agreement. Customers may contact info@clevishq.com for assistance with account-level export or deletion requests. Individual users seeking access to or deletion of Customer Content should contact the organization that controls their workspace first.
14. Security and incident response
Clevis uses administrative, technical, and organizational safeguards designed to protect Customer Content. These include authentication and authorization controls, least-privilege practices, tenant and project scoping, secure development practices, audit logging, protected service credentials, provider review, and incident-response procedures appropriate to the Services and risks involved.
No system is completely secure. Customers are responsible for protecting user credentials, configuring permissions and integrations appropriately, reviewing authorized activity, and promptly reporting suspected unauthorized access. Clevis investigates suspected security incidents and provides notices when required by applicable law or contract.
15. Customer responsibilities
Customers are responsible for ensuring they have a lawful basis and all required rights, notices, and permissions to submit Customer Content to Clevis and instruct us to process it. This includes information about employees, subcontractors, clients, design professionals, project participants, site visitors, and other individuals.
Customers should avoid placing highly sensitive information in Clevis unless it is necessary for an authorized business purpose and appropriate safeguards are in place. Customers must not use the Services to process information or conduct activities prohibited by the applicable agreement or law.
Customers are responsible for reviewing their legal, contractual, employment, safety, recordkeeping, export-control, and industry-specific obligations. Clevis does not determine whether Customer Content must be retained as an official project record or whether an AI-generated output satisfies a professional or legal standard.
16. Changes to this Data Use Policy
We may update this Policy to reflect changes to the Services, our data practices, applicable law, or customer requirements. We will post the revised Policy and update the date above. If a change materially reduces customer protections or materially expands how we use Customer Content, we will provide additional notice as required by law, contract, or appropriate to the circumstances.
A customer agreement may provide different notice, amendment, or objection rights. Prior versions of this Policy may be requested at info@clevishq.com.
17. Contact us
For questions about this Data Use Policy, enterprise data handling, subprocessors, export, or deletion, contact AEC ORIGIN LLC at info@clevishq.com.
