Privacy notice
Last updated 14 August 2026. This notice explains what Clevor CommV does with personal data of people who hold an account on Clevor Connect.
What this notice does and does not cover
It covers you: your account, and the record of how you used the service.
It does not cover the business records this service reads out of your organisation’s Odoo — customers, orders, invoices and the people named in them. For those we act only on your organisation’s instructions, as its processor, under the data processing agreement. Your organisation decides what happens to that data and owes those individuals their own privacy notice.
Who is responsible
Clevor CommV, Ter Mote 5, 9850 Nevele, Belgium, enterprise number BE 0745.722.241. For anything in this notice, write to info@clevor.be.
What we hold, why, and on what legal basis
| Data | Why | Legal basis |
|---|---|---|
| Name, email address, password hash | To give you an account and let you sign in | Performance of a contract, Art. 6(1)(b) |
| Workspace membership and role | To decide what you may see and change | Performance of a contract, Art. 6(1)(b) |
| Your Odoo login and API key, held encrypted | To connect to Odoo as you, so your own Odoo permissions apply | Performance of a contract, Art. 6(1)(b) |
| Your Microsoft 365 sign-in tokens, held encrypted | To reach the shared mailboxes your workspace allows, as you, so your own Exchange permissions apply | Performance of a contract, Art. 6(1)(b) |
| Invitation email addresses | To let a colleague join your workspace | Legitimate interest, Art. 6(1)(f) — running a shared workspace |
| Audit events: who called which tool, on which workspace, against which Odoo model, the field names and operators used, row counts and timing | To detect misuse, investigate incidents, and show your organisation what happened | Legitimate interest, Art. 6(1)(f) — security and accountability |
We do not use this data for advertising, we do not sell it, and there is no automated decision-making with legal effects.
What is not recorded
Audit events keep the shape of a request and not its content. Field names and operators are recorded; the values compared against them are not. Results are never logged, and neither are API keys. Odoo business records pass through memory to answer a request and are not written down anywhere by us.
Who else sees it
Only the providers we need to run the service. All of them keep the data in the EU. The current list, with what each one receives, is on the sub-processors page: Render Services, Inc., Neon, Inc., Axiom, Inc.
The AI assistant you connect is licensed by you and is not one of our sub-processors; see the sub-processors page for what that means.
How long we keep it
| Account and workspace data | For as long as the account exists, then deleted with it. |
| Odoo API keys | Until you replace them, or you leave the workspace or it is deleted. Stored encrypted with AES-256-GCM under a key derived per workspace; never readable back through the interface. |
| Microsoft 365 sign-in tokens (shared mailbox connector) | Until you disconnect your Microsoft account, leave the workspace or it is deleted. Stored encrypted with AES-256-GCM under a key derived per workspace. The service never stores or reads the content of your mail: it handles message ids, folder names, categories and the draft text you ask it to write. |
| Invitations | Until accepted or revoked. |
| Audit events | For as long as they are useful for security monitoring and incident investigation, and in any case no longer than 12 months. |
| Odoo business records | Not retained. They pass through memory to answer a request and are gone when it ends. |
Your rights
You can ask for access to your data, correction, erasure, restriction, portability, and you can object to processing based on legitimate interest. Write to info@clevor.be and we will respond within one month.
If you are unhappy with how we handle it, you can complain to the Gegevensbeschermingsautoriteit (GBA), Drukpersstraat 35, 1000 Brussel.
Where the data sits
Application, database and audit log all run in Frankfurt, Germany. We do not transfer your account data outside the EU. Any transfer that happens when your AI assistant reads from this service is under your own agreement with that provider.
Security
Traffic is encrypted in transit. Odoo API keys are encrypted at rest with AES-256-GCM under a key derived separately for each workspace, and cannot be read back through the interface by anyone, including us. The database enforces row-level security so one workspace cannot reach another’s rows. Every member connects with their own Odoo key, so Odoo’s own permissions decide what each person can see.
Microsoft 365 sign-in tokens are encrypted the same way, one key per workspace. The shared mailbox connector holds delegated permissions only: it can list folders, read message metadata, write a draft, set a category and move a message into a folder an owner allowed. It cannot send, forward or delete mail, and it never requests message bodies.
Changes
If this notice changes materially we will say so on this page and in the dashboard before it takes effect, and write to the contact we hold for your organisation.