Policy / public record
Privacy notice
This notice explains personal data processing for the public website and the company-operated Clavinci service.
Effective dateEffective on public launch
01
Scope
This notice applies to visits to the public marketing website, direct communications sent to Clavinci, and the company-operated Clavinci service.
For workforce telemetry, the customer determines the business purpose, authorized users, governance rules, and lawful basis. Clavinci operates the service and processes customer data under the applicable customer agreement and data-processing terms.
02
Website data
The public website is designed to work without an account. The hosting provider may process standard request data such as IP address, user agent, requested path, timestamp, referrer, and security events to deliver and protect the site.
If a person contacts the operator, the operator processes the contact details and message content needed to respond and maintain the relationship.
- No advertising tracker is required for the site to function.
- No sale of personal data is intended.
- Optional analytics must remain disabled until the cookie policy and consent mechanism are updated.
03
Hosted product data
Clavinci collectors capture structured engineering telemetry close to the tools where it is produced and send the allowed event contract to the company-operated service. The service joins AI assistant activity, Git output, Jira delivery, and pull request collaboration.
The product schema intentionally excludes prompt bodies, response bodies, source code, secrets, clipboard content, and other forbidden content fields. Customers should still review connector permissions, access policy, retention requirements, and workforce notices before rollout.
- AI session metadata, timing, token counts, and cost estimates
- Repository, commit, delivery, and pull request identifiers and metrics
- Access audit events for permitted individual-level reads
- Configuration, membership, and role data needed to operate the service
04
Purposes and legal bases
Website request data is processed to deliver, secure, and diagnose the website. Direct communications are processed to answer requests and take steps toward a business relationship. Where the operator relies on legitimate interests, those interests are operating a secure website, responding to inquiries, and improving clear product information.
Each customer must determine and document the lawful basis that applies to its workforce and jurisdiction. Product capability and a commercial agreement do not establish that lawful basis by themselves.
06
Retention
Security logs should be retained only for a documented period proportionate to investigation and reliability needs. Direct correspondence may be retained while the relationship is active and for a reasonable period afterward to maintain business records.
The customer agreement and product configuration must state retention for collected events, aggregates, backups, and audit records. Clavinci enforces those service-side periods and documents deletion and export behavior.
07
Privacy rights
Depending on location, a person may have rights to access, correct, delete, restrict, or object to processing, and to receive portable data. A person may also complain to an applicable supervisory authority.
Requests concerning the public website should be sent to the configured privacy contact. Requests concerning workforce data should usually be directed to the employer or customer first, with Clavinci assisting that customer as required by the applicable data-processing terms.
08
Contact
The legal operator identity, postal address, privacy contact, and representative details must be configured before this notice is treated as final. The website will display those values here when they are available.