Data processing agreement
Version 1.0, 14 August 2026. This agreement governs personal data that Clevor CommV (“we”, the processor) handles on behalf of a customer (“you”, the controller) through Clevor Connect. It forms part of the terms of service and takes effect when you start using the service. It satisfies Article 28(3) GDPR; we will countersign a copy on request.
1. What we process, and why
| Subject matter | Providing a connection between your Odoo and an AI assistant you license, and, where you enable it, between that assistant and the Microsoft 365 shared mailboxes a workspace has allowed. |
| Duration | For as long as you use the service. |
| Nature and purpose | Reading records from your Odoo, and — where you have enabled write access — creating or changing them, in each case only when a user of yours asks for it through their assistant. Records are transmitted in response to a request; we do not store them. |
| Types of personal data | Whatever your Odoo holds and the requesting user is permitted to see: typically names, contact details, addresses, order and invoice data. Plus the account details of your users of this service. From an allowed shared mailbox: message metadata (subject, sender, recipients, dates, categories, folder), folder names, and the draft text a user asks the assistant to write. Message bodies are never read or stored by the service. |
| Categories of data subjects | Your customers, suppliers and contacts, and your own staff. |
We do not seek out special categories of data under Article 9. If your Odoo holds any, it may pass through in the same way as anything else the requesting user can already see.
2. Documented instructions — Art. 28(3)(a)
We process personal data only on your documented instructions. Your instructions are: this agreement, the terms of service, the settings you choose in the dashboard, and the individual requests your users make. We will not process it for any other purpose, and in particular we do not use it to train models, to build profiles, or for our own analysis.
Every user connects with their own Odoo API key, so the scope of what we can reach is set by your own Odoo permissions and is yours to change at any time. If we believe an instruction breaches data protection law, we will tell you.
3. Confidentiality — Art. 28(3)(b)
Everyone we authorise to handle personal data is bound to confidentiality. Access is limited to what a person needs to run and support the service.
4. Security — Art. 28(3)(c), Art. 32
- All traffic encrypted in transit.
- Odoo API keys encrypted at rest with AES-256-GCM under a key derived separately per workspace, and never readable back through the interface.
- Microsoft 365 sign-in tokens encrypted the same way, one key per workspace. The connector holds delegated permissions only, so it can never send or delete mail.
- Row-level security in the database, so one workspace cannot reach another’s rows.
- Per-user credentials, so your own Odoo permissions decide what each person can reach — we do not hold a shared administrative key.
- Write access off by default; a workspace owner has to turn it on deliberately.
- An audit trail of every call that records who, what and when, but never keys, values or results.
- Business records are not stored, which limits what any breach could expose.
5. Sub-processors — Art. 28(2), 28(3)(d)
You give general authorisation for the sub-processors listed on the sub-processors page. We impose the same data protection obligations on each of them, and we remain fully liable to you for their performance.
Before adding or replacing one, we will update that page and write to the contact we hold for your organisation, in both cases at least 30 days in advance. You may object on reasonable data protection grounds within that period; if we cannot offer an alternative, you may terminate the affected service without penalty.
6. Helping you answer data subjects — Art. 28(3)(e)
Taking into account the nature of the processing, we will assist you with appropriate technical and organisational measures in responding to requests from data subjects exercising their rights. In practice, because we store no business records, such requests are answered directly from your Odoo.
7. Helping you meet Articles 32 to 36 — Art. 28(3)(f)
We will assist you with security, breach notification and impact assessments, given the information available to us. We will notify you without undue delay and in any event within 48 hours of becoming aware of a personal data breach affecting your data, with what we know about its nature, likely consequences and the measures taken.
8. Deletion or return — Art. 28(3)(g)
On termination, or at your choice during the term, we delete your account data, workspace data and stored credentials. Because we hold no copy of your business records, there is nothing of yours to return. Copies held in our database provider’s automated backups are removed as those backups expire. Audit events may be retained to the end of the period stated in the privacy notice as a record of what happened.
9. Information and audits — Art. 28(3)(h)
We will make available the information needed to demonstrate compliance with this article, and allow and contribute to audits by you or an auditor you appoint. In the first instance we will answer a written questionnaire; where that is not enough, an on-site or remote audit can be arranged on reasonable notice, no more than once a year unless an incident gives cause.
10. International transfers
We keep your data in the European Union. We will not move processing outside the EU without telling you first and putting a valid transfer mechanism in place.
The AI assistant you connect is licensed by you and reads from this service as your user. Any transfer it makes falls under your agreement with that provider and outside this agreement; see the sub-processors page.
11. Liability and precedence
This agreement forms part of the terms of service. Where the two conflict on the processing of personal data, this agreement prevails. Liability is governed by the terms of service, save that nothing here limits liability that cannot be limited by law.
12. Contact
For anything under this agreement, including breach notification and audit requests: info@clevor.be.
Clevor CommV, Ter Mote 5, 9850 Nevele, Belgium, enterprise number BE 0745.722.241.