Tenant-controlled data
Organizations remain responsible for their workforce, customer, and business data—including notices, permissions, retention, and any connected recipient they choose.
Rules that govern your access to our website, customer portal, and related services.
This summary is an orientation guide. The complete Terms of Use are reproduced below in the scrollable reader.
Organizations remain responsible for their workforce, customer, and business data—including notices, permissions, retention, and any connected recipient they choose.
AI, email, public links, security scans, webhooks, payroll records, and bank details require authorized, lawful, appropriately configured use.
Unless a separate written agreement says otherwise, MySuite prepares and stores records; it does not initiate ACH, hold funds, file taxes, or make employment decisions.
Scroll inside this panel to read every section.
These Terms of Use govern access to the ClearWorkSuite website, customer services, MySuite platform, and the mobile, desktop, device-enrollment, and other client applications we make available (the Services). They apply as the Services change, and to features, applications, and integrations released after the date above, unless a particular release is presented under its own separate terms. ClearWorkSuite, we, us, and Provider mean the service provider identified on the applicable customer order, invoice, or other written agreement. A business or organization purchasing or administering the Services is the Customer; people it authorizes to use them are Authorized Users.
A paid-service agreement may be accepted only through a signed order, an approved click-through acceptance, or another authorized agreement process. Reading public pages alone does not grant a paid-service license. If a signed master services agreement, order, data processing addendum, business associate agreement, or other written agreement conflicts with these Terms, that agreement controls for its stated subject matter.
Eligibility. The Services are offered for business and organizational use. You must be at least 18 years old, or the age of majority where you live if that is higher, to create an account or accept these Terms. An Authorized User under that age may be given access only by a Customer that has obtained the permissions, notices, and safeguards its jurisdiction requires and that remains responsible for that access.
Customers and Authorized Users must provide accurate account information, protect credentials, use available security controls, and promptly report a suspected compromise. A Customer is responsible for its administrators, access configuration, Authorized Users, and activity conducted through its accounts unless caused by our breach of these Terms or applicable law.
Anyone accepting for a Customer represents that they have authority to bind that Customer. Customers must promptly remove access for people who no longer need it and must not share credentials or circumvent role, tenant, authentication, or other security controls.
Customer Data means information a Customer or its Authorized Users submit to, generate in, or connect to the Services, including workforce, payroll, benefits, time, email, files, documents, communications, contacts, customer, financial, and integration data. The Customer retains its rights in Customer Data. We receive only the limited, non-exclusive right to host, process, transmit, display, secure, back up, and otherwise handle Customer Data as necessary to provide, support, improve the reliability and security of, and protect the Services, subject to these Terms, the applicable agreement, and law.
The Customer is normally the controller/employer or equivalent business responsible for Customer Data. It must: (a) have all necessary rights, notices, lawful bases, consents, and instructions to use the Services and submit Customer Data; (b) provide required privacy, workplace-monitoring, employment, and communications notices; (c) honor data-subject, employee, and customer rights; (d) configure access, sharing, retention, and integrations appropriately; and (e) ensure that its use does not violate law or another person’s rights. Where required and executed, a separate data processing addendum governs the processor/service-provider relationship; these Terms and the public Privacy Policy do not themselves replace that agreement.
We may access, preserve, or disclose Customer Data only as reasonably necessary to provide, support, or secure the Services; follow the Customer’s documented instructions; investigate abuse; protect rights, safety, or the Services; or comply with law or valid legal process. Where lawful and practical, we will give the affected Customer notice of a legally compelled disclosure.
You may not use the Services to break the law; infringe rights; distribute malware; commit fraud; send unlawful or deceptive communications; evade security, privacy, payroll, tax, employment, or records obligations; interfere with another tenant or user; probe, scrape, reverse engineer, or overload the Services except where law cannot prohibit it; or use the Services to develop, train, or operate a competing service using our confidential material or system access.
You may not upload, share, scan, transmit, or expose information that you are not authorized to disclose. You must not use public links, webhooks, AI, email, or APIs to circumvent confidentiality restrictions, exfiltrate data, or send content to a recipient that the Customer has not authorized.
Customers control their files, documents, email content, and workspace sharing. Public links are intentionally external-sharing features. Depending on the link configuration, an unauthenticated guest may be able to view or edit shared material. A link may be time limited, revocable, password protected, or download limited, but those controls cannot prove a recipient’s identity or prevent a recipient from forwarding a link or retaining a downloaded copy. Customers must restrict public links for confidential, regulated, or restricted content unless they have assessed and accepted the risk.
Security features may scan files, attachments, hashes, URLs, or related metadata for malware, threats, or prohibited content when the Customer or Provider enables them. Standard VirusTotal file scanning can transmit raw file content to a third party and is not a private confidential-analysis service. Customers must not enable that route for privileged, health, payroll, HR, bank, or other restricted material unless they have the necessary authority and a suitable private arrangement where one is required. A Customer must not enable any third-party scan or content-classification route for material it lacks authority to disclose to that provider. Security results are risk signals, not a guarantee that content is safe, lawful, or suitable.
Customers are responsible for lawful use of hosted email, SMS, telephony, directories, notifications, and employee communications. They must obtain any required consent, provide required disclosures, honor marketing opt-outs, and comply with laws such as CAN-SPAM, TCPA, workplace-monitoring, interception, employment, and data-protection requirements that apply to their communications.
Customer administrators may be able to access or administer content and security records according to Customer configuration. The Customer must limit that access to legitimate, authorized, proportionate purposes and provide worker notice and impact assessment where required. The Services are not an emergency communication service and are not represented as a legally certified email archive, records-management system, or proof-of-delivery service.
We use third-party providers for functions such as storage, payment processing, communications, identity, security, and AI. Their handling of information is described in the Privacy Policy and applicable provider terms. We may replace or add providers as the Services evolve, subject to any applicable Customer agreement or data processing addendum.
Customer-selected services—including outbound webhooks, bring-your-own AI endpoints, public links, or connected accounts—are Customer-directed disclosures. The Customer is solely responsible for selecting each recipient and scope; verifying security, data location, retention, and contractual terms; providing required notices; and obtaining any required authorization. Webhook deliveries may be signed, queued, retried, and logged, but they are delivered on a best-efforts basis and are not guaranteed to be real-time or exactly once.
AI features are optional and may be limited by plan, role, policy, model availability, safety controls, or configuration. When an Authorized User invokes AI, prompts, selected context, attachments, images, audio, instructions, and outputs may be sent through an AI-routing provider to a selected or automatically routed model provider. Provider, location, availability, retention, and training practices can vary. The Privacy Policy explains why we do not make a blanket zero-retention, no-training, or single-country promise for all AI routes.
Customers must not submit sensitive, regulated, confidential, biometric, health, payroll, bank, credential, or other restricted information to an AI route unless they have assessed and authorized that specific provider and configuration. AI output may be incomplete, inaccurate, unsafe, biased, infringing, or unsuitable. It is an assistive tool, not professional advice or a substitute for independent review.
Customers may not use AI or monitoring output as the sole or substantial basis for a decision with legal or similarly significant effects on a person—including hiring, firing, promotion, compensation, benefits, discipline, work assignment, scheduling, or access—unless they have independently confirmed that use is lawful and have implemented meaningful human review, required notice, assessment, and challenge or appeal processes. We do not make employment, credit, insurance, medical, legal, tax, or other high-impact decisions for Customers.
The Services may help Customers organize employment, time, payroll, withholding, year-end, and disbursement information. The Customer remains solely responsible for wages, classifications, benefits, tax calculations and filings, payroll approvals, record retention, employment decisions, and compliance with applicable law. The Services are not legal, tax, accounting, benefits-administration, banking, or payroll advice.
Unless a separate written payment-services agreement expressly states otherwise, ClearWorkSuite does not initiate ACH transfers, create or transmit a NACHA file, hold or transmit funds, act as an ODFI or payment processor for payroll, or file or remit taxes. Current direct-deposit functionality stores encrypted account details and prepares disbursement records or exports; the Customer must independently review, authorize, and execute any actual payment process.
The Services are not represented as HIPAA-compliant or as a substitute for a business associate agreement. A covered entity or business associate may not use the Services to create, receive, maintain, or transmit electronic protected health information unless a written business associate agreement and the required security configuration have been agreed.
Fees, plan limits, billing cycles, renewal, cancellation, and payment terms are stated in the applicable order, checkout, or plan page. Customers must pay undisputed fees and applicable taxes other than taxes imposed on our net income. Our payment processor—currently Stripe—may provide the hosted checkout and billing portal; its terms may separately apply to payment processing. We may change our payment processor, and we may change fees or plans prospectively on notice given in the manner the applicable agreement or law requires.
Preview, early-access, and free access. Some access is offered before general release, at no charge, at a reduced rate, or subject to capacity limits. Preview and free access is provided for evaluation, may be limited in features, availability, support, and data durability, and may be changed, suspended, or ended at any time without liability. It creates no right to continued free or discounted access, no committed service level, and no obligation to release a feature. Where an account moves to a published paid plan, the fees and terms of that plan apply from that point forward. We will not charge for the Services without a published plan or agreed order and any acceptance the applicable law or checkout process requires.
We work to maintain the Services but do not promise that every feature, integration, model, or API will be available at all times or operate without interruption. We may maintain, change, suspend, or discontinue features when reasonably necessary for security, legal compliance, operations, provider changes, or service improvement. We will use reasonable notice where required by contract or law and practical under the circumstances.
We may suspend or limit access if reasonably necessary to protect the Services, users, data, a provider, or the public; to investigate a suspected breach of these Terms; to comply with law; or for nonpayment after any required notice. We will restore access when the issue is resolved where appropriate.
During the applicable subscription period, Customers may use available export tools and support channels to retrieve Customer Data, subject to plan, permissions, security, and legal restrictions. On termination, access may be disabled and Customer Data may be returned, deleted, archived, or de-identified in accordance with the applicable agreement, Customer configuration, retention schedule, legal hold, and law.
Deletion from a live workspace does not necessarily mean immediate destruction from archives or backups. We may retain limited information for tax, accounting, security, fraud prevention, dispute resolution, legal hold, audit, and enforcement purposes. Customers must obtain required records before termination and must not request deletion that conflicts with a legal hold or mandatory retention obligation.
Each party will use the other party’s non-public confidential information only to perform under the applicable agreement and will protect it with reasonable care. This does not apply to information that is public through no breach, independently developed, lawfully received without confidentiality duty, or required to be disclosed by law (subject to lawful notice where possible).
We and our licensors retain all rights in the Services, software, documentation, branding, and platform materials. Subject to these Terms and payment of applicable fees, we grant the Customer a limited, non-exclusive, non-transferable right for its Authorized Users to access and use the Services during the subscription. Feedback is voluntary; we may use it without restriction or compensation, provided we do not identify the Customer as the source without permission.
To the maximum extent permitted by law and except as expressly stated in a signed agreement, the Services are provided “as is” and “as available”. We disclaim all warranties, express, implied, and statutory, including merchantability, fitness for a particular purpose, non-infringement, uninterrupted availability, and error-free operation. We do not warrant third-party services, Customer-selected integrations, external recipients, AI outputs, or Customer Data. Some jurisdictions do not allow the exclusion of certain warranties, so parts of this paragraph may not apply to you.
To the maximum extent permitted by law, neither party is liable for indirect, incidental, special, consequential, exemplary, or punitive damages, or lost profits, revenue, goodwill, data, or business opportunity. Any additional liability cap, exclusions, or indemnity obligations are governed by the signed agreement or order, if any. A Customer will defend and indemnify ClearWorkSuite against third-party claims arising from the Customer Data, the Customer’s unlawful use of the Services, or the Customer’s breach of Sections 3, 4, 6, 7, 8, or 9, except to the extent caused by our breach.
Severability. If a provision is held unenforceable, it is limited or severed to the minimum extent necessary and the remaining provisions stay in force.
No waiver. A failure or delay in enforcing a provision is not a waiver of it or of any other provision.
Assignment. Neither party may assign these Terms without the other’s consent, except that either party may assign them in full to a successor in a merger, acquisition, reorganization, or sale of substantially all assets, on notice. Any other attempted assignment is void.
Force majeure. Neither party is liable for a delay or failure caused by events beyond its reasonable control, including infrastructure, network, provider, utility, or governmental failures. This does not excuse an obligation to pay amounts already due.
Notices. We may give notice through the Services, the account’s registered administrator address, or the contact address in an order. Customers must keep their administrator contact details current. Notices to us go to the contact address below unless an order specifies another address.
Survival. Sections 3, 4, 9, 12, 13, 14, this Section 15, and any accrued payment obligation survive termination.
Independent parties. These Terms create no partnership, agency, joint venture, employment, or fiduciary relationship, and no third-party beneficiary rights.
We may revise these Terms for product, provider, security, operational, or legal changes. Changes take effect for future use of the Services; for a material change, we will give notice and obtain any new acceptance required by law, contract, or a valid click-through process, and we will not apply a material change retroactively to a completed subscription period. The current version and its version number are always published on this page. The governing law, forum, notice address, and legal entity for a Customer contract are those identified in its signed order or other written agreement; mandatory rights, including consumer and worker protections, cannot be waived by these Terms.
Legal, contract, privacy, or data-processing questions can be directed to support@clearwork.email.