Two privacy roles
We run the public site, customer account, billing, and security services. Your organization controls the employee, payroll, email, file, and workspace data it puts in MySuite.
ClearWorkSuite explains how customer and platform information is handled when you use our website and customer services.
This summary highlights the choices and protections that matter most. The complete policy is reproduced below in the scrollable reader.
We run the public site, customer account, billing, and security services. Your organization controls the employee, payroll, email, file, and workspace data it puts in MySuite.
We use information to provide, secure, support, bill for, and improve the service—not to turn Tenant Customer Data into advertising audiences.
AI, security scanning, public links, webhooks, SMS, and connected services send data to third parties—on some routes including raw file content—when an authorized user or tenant enables them.
Scroll inside this panel to read every section.
This Privacy Policy explains how ClearWorkSuite and the provider identified in a customer order, invoice, or other written agreement (together, ClearWorkSuite, we, us, or our) handle personal information in connection with clearworksuite.com, customer-account services, the MySuite platform, and the mobile, desktop, device-enrollment, and other client applications we make available (together, the Services). It applies as those Services change, and to features, apps, and integrations added after the date below, unless a feature is covered by its own notice presented at the time you use it.
There are two different privacy relationships in MySuite:
If your employer or another organization gave you access to MySuite, that organization’s privacy notice, employment policies, retention schedule, and instructions are the primary notice for its Customer Data. This Policy does not replace them, a Customer’s data processing addendum, or a business associate agreement.
We receive information directly from you, from the Customer that administers your account, automatically through use of the service, and from integrations that you authorize or a Customer enables.
We use personal information only as necessary and proportionate to:
We do not sell Tenant Customer Data or use it to build advertising audiences. We do not intentionally disclose personal information for cross-context behavioral advertising. If our actual practices change, we will update this Policy and provide any choice mechanism required by law.
We do not use Tenant Customer Data to train generally available AI models, our own or a third party’s, and we do not do so in any future release without the Customer’s separate, informed agreement. Where we use Customer Data to improve the Services, we do so in aggregated or de-identified form, or within the Customer’s own tenant to serve that Customer. This commitment binds ClearWorkSuite; it does not bind an AI provider, endpoint, or connected service that a Customer chooses to enable, whose training and retention practices are described in Section 6 and governed by that provider’s terms.
Where the GDPR, UK GDPR, or similar law applies, our legal bases depend on the context. They may include:
A Tenant, not ClearWorkSuite, is responsible for selecting an appropriate lawful basis and any special-category condition for its employment, payroll, monitoring, health, benefits, or other Customer Data. An employee’s acknowledgement of an optional feature is not, by itself, a universal legal basis for an employer’s processing.
We disclose information to providers only for the applicable purpose and subject to appropriate contractual, technical, or organizational safeguards. The provider list can change as the service changes; an up-to-date list for a Customer’s service configuration is available from us on request. Important current categories include:
Standard VirusTotal scans need special care. If a standard file scan is enabled, raw file content—not only a hash—may be sent to VirusTotal. Standard scanning is not a private confidential-analysis service; VirusTotal may retain or share submitted material and results under its own terms. Customers should not enable that route for privileged, health, payroll, HR, bank, or other restricted content unless they have assessed the disclosure, have the necessary authority, and use a suitable private arrangement where one is required.
Customer-directed disclosures. A Tenant may configure outbound webhooks, bring its own AI endpoint, connect another service, or create a public link. These recipients are selected by the Tenant, not ordinary ClearWorkSuite subprocessors. The Customer is responsible for confirming the recipient, scope, lawful basis, notice, contractual protections, and any employee or data-subject rights that apply. Webhook events can include employment, time-off, document-sharing, or payroll event metadata and may be retried and logged for delivery/security purposes.
AI features are optional. When an authorized user invokes one, the prompt, selected context, attachments, images, audio, instructions, and resulting output may be sent through our AI-routing provider to the selected or automatically routed model provider. Model provider, processing location, retention, and training practices can vary by model, endpoint, Customer configuration, and enabled tools such as web search.
Do not submit highly sensitive, regulated, confidential, biometric, health, payroll, bank, authentication, or other restricted information to an AI feature unless the Customer has assessed and authorized that specific route and provider. We do not authorize use of Tenant Customer Data for an unrelated ClearWorkSuite purpose, but we do not promise that every AI provider offers zero retention, does not train on inputs, or processes only in a particular country. Third-party provider terms and the Customer’s configuration can govern downstream processing.
MySuite records limited AI-related operational information, such as usage, model/provider selection, safety events, cost, and—in applicable attachment controls—file-name and egress records. Retention is controlled by the relevant service policy and may be required for security, billing, dispute resolution, or legal compliance.
MySuite can host email, files, documents, versions, attachments, public links, collaboration records, and audit trails. A Tenant controls who may access those features and is responsible for its internal notices, monitoring policy, and access decisions. Administrative access to email or content must be limited to authorized purposes such as administration, security, support, legal compliance, or the Customer’s documented instructions.
Public links are designed to be shareable outside a Tenant. Depending on its configuration, a link may let an unauthenticated guest view or edit material. A link may be time limited, revocable, password protected, or download limited, but these are controls rather than proof of a recipient’s identity; anyone who receives the link, password, or a downloaded copy may be able to access, copy, or forward the material. We may record link-token checks, IP/device/browser information, timestamps, access or download counts, and related audit data. Do not use public links for restricted content unless the Customer has assessed the risk and expressly permits it.
Customers using workplace monitoring, time, audit, security, email, or collaboration features must provide legally required worker notices, choose a lawful and proportionate configuration, and complete a privacy/impact assessment where required. ClearWorkSuite does not decide why a Customer monitors its workforce.
We retain personal information for the period reasonably necessary for the purposes described here, the Customer’s service configuration and instructions, dispute resolution, security, and legal obligations. Retention is not one universal period. It varies by data type, the Customer’s settings, contract, jurisdiction, and whether a legal hold, investigation, or regulatory requirement applies.
For example, account, billing, tax, payroll, wage-and-hour, personnel, benefits, time, safety, security, and audit records may need longer retention than an active session or temporary upload. Customer-configurable file-trash, export, document-history, and operational-log retention settings do not override mandatory legal retention or an active legal hold. Deletion from a live workspace may therefore move a record to a protected archive or leave a recoverable copy in backup systems until the applicable retention and backup cycle expires.
When a Customer ends service or requests deletion, we will follow the applicable contract and law. We may return or make Customer Data available where agreed, then delete or de-identify it when no longer required. We may retain the minimum necessary information for legal, accounting, fraud, security, backup, and enforcement purposes.
We use administrative, technical, and organizational measures designed to protect information, including access controls, role separation, encryption where applicable, tenant isolation, logging, and security monitoring. No system is perfectly secure. You must protect credentials, use available account-security controls, and promptly report suspected misuse.
If we identify a security incident involving Customer Data, we will investigate and notify the affected Customer as required by applicable law and contract so that it can meet its own obligations. We may notify individuals directly where required or appropriate.
We and our providers may process information in countries other than the country where it was collected, including the United States. Where we act as controller and transfer personal information out of the EEA, the UK, or Switzerland to a country without an adequacy decision, we rely on an approved transfer mechanism—normally the European Commission’s Standard Contractual Clauses together with the UK International Data Transfer Addendum—and we apply supplementary technical and organizational measures where a transfer assessment calls for them. You may request details of the mechanism used for a specific transfer at the contact address in Section 14.
Where we act as processor for Tenant Customer Data, the mechanism and any supplementary safeguards are those set out in the Customer’s agreement or data processing addendum. Customers remain responsible for evaluating their selected integrations, AI endpoints, webhooks, and public sharing destinations, which are Customer-directed transfers.
We use essential cookies, tokens, local storage, and similar technology to keep sessions secure, remember necessary settings, prevent unauthorized actions, and operate the service. We do not require an advertising cookie to use the standard website. If a third-party CAPTCHA is configured, the CAPTCHA provider may collect device, browser, IP, token, and anti-abuse information under its own notice. Optional connected services may place or use their own technology after you choose to use them. Where a non-essential storage or access technology requires prior consent, we will provide the required choice before enabling it.
Where we are the controller, you may request access, correction, deletion, restriction, objection, portability, withdrawal of consent, or information about our processing, subject to applicable law and verification. You may opt out of ClearWorkSuite marketing communications through the unsubscribe mechanism in the message or by contacting us. Transactional, security, account, and legally required notices may still be sent.
If you are in California or another U.S. state with applicable privacy rights, you may request to know, access, correct, or delete covered personal information, appeal a rights decision where required, and exercise applicable opt-out rights. We will not discriminate against you for exercising applicable privacy rights. We may need to verify your identity and may deny or limit a request where law permits or requires it.
For Tenant Customer Data, including employee, email, payroll, HR, file, or workspace content, contact the organization that controls the account first. We will assist the Customer as required by our contract and applicable law, but cannot change, disclose, or delete Customer Data contrary to the Customer’s lawful instructions or a legal obligation.
Where the GDPR or UK GDPR applies, you also have the right to lodge a complaint with your local supervisory authority or the UK Information Commissioner’s Office. We ask that you contact us first so we can try to resolve the matter, but that is a request, not a condition of your right to complain.
Automated decisions. We do not use the personal information we hold as controller to make decisions producing legal or similarly significant effects about you by automated means alone. Where a feature would do so in a future release, we will identify it, explain the logic and consequences involved, and provide the human review, explanation, and challenge rights that apply. A Customer that configures the Services to inform decisions about its own workforce is responsible for the review, notice, and appeal obligations described in the Terms of Use.
The public website and service are not directed to children under 13. A Customer that permits access by a minor is responsible for obtaining any notices, permissions, or safeguards required by law.
We may update this Policy to reflect product, provider, operational, or legal changes. For a material change, we will provide notice in a manner required by applicable law or contract; we will not rely on a buried policy update to create a use of personal information that requires a different legal basis or affirmative consent.
For privacy questions, rights requests, a current provider list, or to identify the ClearWorkSuite service provider for your account, contact us at support@clearwork.email.