1. Overview
This Privacy Policy explains how Clevera Inc. (“Clevera”, “we”, “us”) handles personal information in connection with our websites, marketing, events, sales and support communications, and the administration of customer accounts for Authority, our authorization and decision platform for autonomous AI agents (together, the “Services”).
When our business customers use Authority to govern their AI agents, we process data on their behalf and under their instructions (“Customer Data”). That processing is governed by our agreement with the customer, including any data processing agreement. Section 5 summarizes how we handle Customer Data. If you are an employee or end user of one of our customers, please also refer to their privacy notice.
2. Information we collect
Information you provide
- Contact and briefing requests: name, work email, company, role and the details you share about your use case.
- Account and administration data: name, business email, role, identity-provider identifiers and preferences for people who administer Authority for a customer.
- Communications: messages, support requests, meeting notes and feedback you send us.
- Event and program data: registrations and participation in events, research or our design partner program.
Information collected automatically
- Device and usage data: IP address, browser and device type, pages viewed, referring URLs and timestamps.
- Security logs: request metadata used to protect the website and Services against abuse, bots and attacks.
- Cookies and similar technologies: see Section 4.
Information from other sources
We may receive business contact information from partners, event organizers and publicly available professional sources, where permitted by law.
3. How we use information
- Respond to inquiries, schedule briefings and evaluate partnerships.
- Provide, administer, support and improve the Services.
- Operate, secure and improve our websites, including detecting and preventing fraud, abuse and security incidents.
- Send service, security and administrative messages, and — where permitted — information about Authority, our design partner program and events. You can opt out of marketing at any time.
- Produce aggregated, de-identified analytics.
- Comply with legal obligations and enforce our agreements.
Legal bases (EEA, UK and Switzerland). We rely on performance of a contract, our legitimate interests (such as responding to business inquiries, securing our services and business-to-business marketing), your consent (for example, for non-essential cookies) and compliance with legal obligations.
4. Cookies and analytics
We use strictly necessary cookies and similar technologies to deliver and secure our websites. We use privacy-friendly, aggregated analytics to understand how the website is used. Where we use cookies or similar technologies that are not strictly necessary, we ask for your consent where required by law, and you can withdraw it at any time.
You can also control cookies through your browser settings. Blocking some cookies may affect how the website works.
5. Customer Data in the Authority platform
We process Customer Data as a processor or service provider on behalf of our customers, who control its purposes. Authority is designed to minimize the personal and sensitive data it handles:
- By default, evidence records store hashes, non-secret canonical representations of agent actions, policy versions, reason codes and references — not raw prompts or full tool payloads.
- Raw prompt content is retained only if the customer enables content retention. Secrets, tokens and downstream credentials are never stored in evidence.
- Customers can run the enforcement data plane inside their own cloud environment, so raw payloads remain with their workloads and our control plane receives minimized metadata and evidence.
- Customer Data is logically isolated per tenant. We do not use one customer’s data to train models offered to other customers unless that customer explicitly agrees in writing.
- Retention and deletion follow the customer’s configuration and agreement.
7. International transfers
We may process personal information in the United States and other countries where we or our service providers operate. Where required, we use appropriate safeguards for international transfers, such as the European Commission’s Standard Contractual Clauses and the UK International Data Transfer Addendum.
8. Retention
We keep personal information only for as long as needed for the purposes described in this policy — for example, for the duration of a business relationship and a reasonable period afterwards — or as required by law. We then delete or de-identify it. Customer Data is retained according to the customer’s configuration and agreement.
9. Security
We use administrative, technical and physical safeguards designed to protect personal information, including encryption in transit and at rest, least-privilege access and managed key storage. No method of transmission or storage is completely secure. Learn more on our Security page.
10. Your rights and choices
Depending on where you live, you may have the right to access, correct, delete or port your personal information, to object to or restrict certain processing, and to withdraw consent. You can opt out of marketing emails using the unsubscribe link in any message.
US state privacy rights. Residents of California and other US states with comprehensive privacy laws may have rights to know, access, correct and delete personal information, and to opt out of its sale, sharing or use for targeted advertising. We do not sell or share personal information as those terms are defined, and we do not use sensitive personal information to infer characteristics. We will not discriminate against you for exercising your rights. You may use an authorized agent, and you may appeal a decision on your request by contacting us.
To exercise your rights, email 1corporate@clevera.com. We may need to verify your identity before responding. If your request relates to Customer Data, we will refer it to the relevant customer. You also have the right to lodge a complaint with your local data protection authority.
11. Children
The Services are designed for businesses and are not directed to children. We do not knowingly collect personal information from children under 16. If you believe a child has provided us with personal information, please contact us and we will delete it.
12. Third-party sites and services
Our websites and Services may link to or integrate with third-party services. Their privacy practices are governed by their own policies, not this one.
13. Changes to this policy
We may update this policy from time to time. We will revise the “Last updated” date above and, where changes are material, provide additional notice.
14. Contact us
Questions or requests about this policy can be sent to Clevera Inc. at 1corporate@clevera.com.