Privacy Policy
Last updated 2026-08-28
Overview
DRAFT — for engineering preview only. Legal counsel must review and approve before production sales.
This Privacy Policy describes how ClevSync ("we") processes personal data when you use our service. Employers using ClevSync are typically data controllers for their staff data; we act as a processor for that workforce data.
Data we process
Account data: name, email, role, authentication metadata.
Workforce data you enter: schedules, leave, attendance, availability, support tickets.
Billing metadata: plan, status, provider customer ids — not full payment card numbers (checkout is hosted by Razorpay/Paddle).
Technical logs: IP address, request ids, audit events (metadata only, no PII values in audit metadata).
Sub-processors
We use infrastructure and service providers listed in our sub-processor register (see docs/PROCESSORS.md in the repository; publish a customer-facing summary before launch).
Retention
We retain data according to configured retention targets (e.g. attendance records where law requires). You may export or request erasure of your personal profile via Settings → Privacy, subject to legal exceptions.
Your rights (GDPR / similar)
Depending on jurisdiction you may have rights to access, rectify, erase, restrict, or port your data. Org admins can self-serve export/erase in the product; contact support@clevsync.com for assistance.
See docs/runbooks/DSAR.md for our data-subject request process.