SECTION 01
1. Scope
This Policy applies to personal information processed through:
Cliodot websites User accounts Organizations and projects Connectors Workflows Surface Gateways OAuth applications Authentication applications Webhook applications Remote capabilities SDKs and APIs Connector Hub Arrikk AI Support and business communications
A customer may use Cliodot to process personal information on behalf of its own users or customers.
In those situations, the customer determines the purpose of processing and Cliodot acts as a service provider or processor according to the applicable agreement.
Questions about data controlled by a Cliodot customer should normally be directed to that customer.
SECTION 02
2. Information We Collect
Account information
We may collect:
Name Email address Password or authentication identifier Profile information Organization Role Account preferences Organization and billing information
We may collect:
Organization name Team membership Billing contact Subscription information Payment status Tax information Transaction records
Payment card details may be processed directly by a payment provider rather than stored by Cliodot.
Platform configuration
We may process information contained in:
Connector definitions Connector installations Workflow configurations Surface capabilities API and SDK configuration Environment settings Custom domains Permissions Schedules Remote capability requests Logs and execution metadata Credentials and authorization information
Depending on the selected configuration, we may process:
API keys Access tokens Refresh tokens OAuth authorization data Authentication configuration Encrypted secrets Customer-supplied authorization payloads
Credential handling depends on whether the connection is Cliodot-managed, customer-managed or hybrid.
Customer Content
The Services may process information submitted through connectors, workflows, APIs, webhooks, SDK calls and other executions.
The content depends on how each customer configures the Services.
Cliodot does not determine the categories of Customer Content submitted by a customer.
Usage and device information
We may collect:
IP address Browser type Device information Operating system Pages visited Feature usage API request metadata Execution counts Error information Log timestamps Referral information Session identifiers Support and communications
We may collect information you provide when you:
Contact support Request a demonstration Report a problem Participate in research Respond to a survey Communicate with our team Subscribe to product updates
SECTION 03
3. How We Collect Information
We collect information:
Directly from you
For example, when you create an account, configure a connector, contact support or submit a form.
Through your use of the Services
For example, when the platform records executions, requests, logs, errors and usage.
From connected systems
When you authorize Cliodot to interact with a third-party application or internal service.
From your organization
An organization administrator may create your account, invite you to a project or provide account information.
From service providers and business partners
For example, authentication, analytics, infrastructure, payment or communication providers.
SECTION 04
4. How We Use Information
We may use personal information to:
Provide and operate the Services Authenticate users Execute connectors and workflows Process API and SDK requests Manage organizations and permissions Maintain environments and deployments Provide customer support Process payments Measure usage Enforce quotas and rate limits Monitor performance Diagnose failures Prevent abuse and fraud Protect platform security Improve the Services Develop new features Communicate service information Send marketing communications where permitted Comply with legal obligations Enforce our agreements
We do not use Customer Content for unrelated advertising purposes.
Any use of Customer Content to improve AI features should be described in the applicable product settings, agreement or service documentation.
SECTION 05
5. Legal Bases
Where applicable law requires a legal basis, we may process personal information based on:
Contract
Processing necessary to provide the Services or take steps requested before entering into an agreement.
Legitimate interests
Processing necessary for security, support, service improvement, fraud prevention and business operations, where those interests are not overridden by individual rights.
Consent
Processing based on permission, such as selected communications or optional cookies.
Legal obligation
Processing required to comply with law, regulation, legal process or enforceable government request.
The applicable legal basis depends on the information and processing context.
SECTION 06
6. Customer-Controlled Processing
Customers may use Cliodot to process information from their own applications, users, employees, partners or systems.
The customer is responsible for:
Providing required privacy notices Obtaining necessary permissions Selecting lawful processing purposes Configuring retention Restricting access Responding to individual requests Determining which systems may be connected Ensuring published capabilities expose only permitted information
Cliodot processes Customer Content according to the customer’s configuration and contractual instructions.
SECTION 08
8. Third-Party Services
Cliodot connects to services selected by customers.
When information is transmitted to a third-party provider, that provider’s privacy practices apply.
Customers should review the privacy and security terms of each provider they connect.
Cliodot is not responsible for the independent processing activities of third-party services.
SECTION 09
9. AI Features
Arrikk AI and other AI-assisted features may process prompts, schemas, connector information, workflow configuration and generated output.
Depending on the feature, selected information may be processed by third-party model providers.
We take steps to limit the information sent to those providers according to the purpose of the feature and applicable configuration.
Users should avoid entering sensitive information into AI features unless the relevant environment, agreement and model configuration are appropriate for that information.
AI-specific data controls may be provided through product settings or enterprise agreements.
SECTION 11
11. Data Retention
We retain personal information for as long as reasonably necessary to:
Provide the Services Maintain accounts Fulfil contracts Resolve disputes Enforce agreements Meet legal obligations Protect platform security Support legitimate business operations
Retention periods depend on:
The type of information Customer configuration Subscription status Contractual requirements Security needs Legal obligations
Customer Content may be deleted or returned according to the applicable agreement and product capabilities.
Backup copies may remain for a limited period before being overwritten or deleted.
SECTION 12
12. Security
We use technical and organizational safeguards designed to protect personal information.
Measures may include:
Encryption in transit Encryption of selected stored data Access controls Credential protection Environment separation Logging and monitoring Rate limits Secure development practices Infrastructure controls Incident response procedures
No system can guarantee absolute security.
Customers are responsible for configuring their projects, permissions, credentials and published capabilities appropriately.
SECTION 13
13. International Data Transfers
Cliodot and its service providers may process information in countries other than the country where it was collected.
Where required, we use appropriate safeguards for international transfers, which may include contractual protections or other legally recognized mechanisms.
Enterprise customers may contact us for information about applicable hosting and transfer arrangements.
SECTION 14
14. Your Rights
Depending on your location, you may have the right to:
Access personal information Correct inaccurate information Request deletion Restrict processing Object to processing Receive a portable copy Withdraw consent Appeal certain decisions Complain to a data protection authority
These rights may be limited by applicable law.
To submit a request, contact us using the information below.
We may need to verify your identity before completing a request.
When Cliodot processes information on behalf of a customer, we may direct the request to that customer.
SECTION 15
15. Account and Communication Choices
You may update selected account information through the Services.
You may unsubscribe from marketing emails using the link provided in the message.
We may continue sending transactional or service-related communications necessary to operate your account.
Organization administrators may control certain settings for users within their organization.
SECTION 16
16. Children’s Privacy
The Services are not directed to children below the minimum age required to consent to online services in their jurisdiction.
We do not knowingly collect personal information from children in violation of applicable law.
Contact us when you believe a child has provided personal information improperly.
SECTION 17
17. Changes to This Policy
We may update this Policy as the Services, laws and business practices change.
We will post the updated version and revise the effective date.
Where required, we will provide additional notice of material changes.
SECTION 18
18. Contact Us
Questions or requests regarding this Privacy Policy may be sent to:
Cliodot Privacy email: [privacy@cliodot.com] Address: [Registered Business Address]
Where applicable:
Data Protection Officer: [DPO Name or Contact] DPO email: [dpo@cliodot.com]