← Clevor Connect

Privacy notice

Last updated 14 August 2026. This notice explains what Clevor CommV does with personal data of people who hold an account on Clevor Connect.

What this notice does and does not cover

It covers you: your account, and the record of how you used the service.

It does not cover the business records this service reads out of your organisation’s Odoo — customers, orders, invoices and the people named in them. For those we act only on your organisation’s instructions, as its processor, under the data processing agreement. Your organisation decides what happens to that data and owes those individuals their own privacy notice.

Who is responsible

Clevor CommV, Ter Mote 5, 9850 Nevele, Belgium, enterprise number BE 0745.722.241. For anything in this notice, write to info@clevor.be.

What we hold, why, and on what legal basis

DataWhyLegal basis
Name, email address, password hashTo give you an account and let you sign inPerformance of a contract, Art. 6(1)(b)
Workspace membership and roleTo decide what you may see and changePerformance of a contract, Art. 6(1)(b)
Your Odoo login and API key, held encryptedTo connect to Odoo as you, so your own Odoo permissions applyPerformance of a contract, Art. 6(1)(b)
Your Microsoft 365 sign-in tokens, held encryptedTo reach the shared mailboxes your workspace allows, as you, so your own Exchange permissions applyPerformance of a contract, Art. 6(1)(b)
Invitation email addressesTo let a colleague join your workspaceLegitimate interest, Art. 6(1)(f) — running a shared workspace
Audit events: who called which tool, on which workspace, against which Odoo model, the field names and operators used, row counts and timingTo detect misuse, investigate incidents, and show your organisation what happenedLegitimate interest, Art. 6(1)(f) — security and accountability

We do not use this data for advertising, we do not sell it, and there is no automated decision-making with legal effects.

What is not recorded

Audit events keep the shape of a request and not its content. Field names and operators are recorded; the values compared against them are not. Results are never logged, and neither are API keys. Odoo business records pass through memory to answer a request and are not written down anywhere by us.

Who else sees it

Only the providers we need to run the service. All of them keep the data in the EU. The current list, with what each one receives, is on the sub-processors page: Render Services, Inc., Neon, Inc., Axiom, Inc.

The AI assistant you connect is licensed by you and is not one of our sub-processors; see the sub-processors page for what that means.

How long we keep it

Account and workspace dataFor as long as the account exists, then deleted with it.
Odoo API keysUntil you replace them, or you leave the workspace or it is deleted. Stored encrypted with AES-256-GCM under a key derived per workspace; never readable back through the interface.
Microsoft 365 sign-in tokens (shared mailbox connector)Until you disconnect your Microsoft account, leave the workspace or it is deleted. Stored encrypted with AES-256-GCM under a key derived per workspace. The service never stores or reads the content of your mail: it handles message ids, folder names, categories and the draft text you ask it to write.
InvitationsUntil accepted or revoked.
Audit eventsFor as long as they are useful for security monitoring and incident investigation, and in any case no longer than 12 months.
Odoo business recordsNot retained. They pass through memory to answer a request and are gone when it ends.

Your rights

You can ask for access to your data, correction, erasure, restriction, portability, and you can object to processing based on legitimate interest. Write to info@clevor.be and we will respond within one month.

If you are unhappy with how we handle it, you can complain to the Gegevensbeschermingsautoriteit (GBA), Drukpersstraat 35, 1000 Brussel.

Where the data sits

Application, database and audit log all run in Frankfurt, Germany. We do not transfer your account data outside the EU. Any transfer that happens when your AI assistant reads from this service is under your own agreement with that provider.

Security

Traffic is encrypted in transit. Odoo API keys are encrypted at rest with AES-256-GCM under a key derived separately for each workspace, and cannot be read back through the interface by anyone, including us. The database enforces row-level security so one workspace cannot reach another’s rows. Every member connects with their own Odoo key, so Odoo’s own permissions decide what each person can see.

Microsoft 365 sign-in tokens are encrypted the same way, one key per workspace. The shared mailbox connector holds delegated permissions only: it can list folders, read message metadata, write a draft, set a category and move a message into a folder an owner allowed. It cannot send, forward or delete mail, and it never requests message bodies.

Changes

If this notice changes materially we will say so on this page and in the dashboard before it takes effect, and write to the contact we hold for your organisation.