Privacy Policy
Last updated: 2026-07-27 (version 1.0)
1. Who we are
ClearPath is an AI-assisted proposal and bid management platform operated by [LEGAL ENTITY NAME], registered at [REGISTERED ADDRESS] (“ClearPath”, “we”, “us”).
For privacy questions, data-subject requests or security reports, contact [PRIVACY CONTACT EMAIL].
Where you use ClearPath as a member of an organisation’s workspace, that organisation is the controller of the content in its workspace and we act as its processor. For your own account details and our own operation of the service, we are the controller.
2. What we collect
| Category | Examples | Why |
|---|---|---|
| Account data | Name, email address, hashed password, job title, language and timezone preference, avatar | To create and secure your account and personalise the interface |
| Workspace content | Leads, opportunities, proposals, bills of quantities, contracts, tasks, comments, uploaded documents and images | To provide the service. This is your organisation’s data; we process it on its instructions |
| Authentication and security data | Session tokens, sign-in timestamps, failed-login counters, audit-log entries recording who changed what | To keep accounts secure and to give administrators an accountability record |
| Consent records | Your cookie choice per category, the date and time, your IP address and browser user agent | To evidence that consent was given or withdrawn, as data-protection law requires |
| Operational logs | Error diagnostics and request metadata | To keep the service running and investigate faults |
We do not sell personal data, and we do not use your workspace content to train our own models.
3. Artificial intelligence features
When you use an AI feature, the relevant content — for example the text of a proposal section or an uploaded document — is transmitted to a model provider. Which provider, and on whose account, depends on how your workspace is configured.
- Where your plan includes an AI allowance and your workspace has not required otherwise, we transmit that content to a model provider we contract with, on our account. We choose that provider and the models available for it. The provider processes the content in order to return the result and, under our agreement with it, does not use it to train its models.
- Where your workspace has configured its own provider key, we transmit the content to that provider under your organisation’s account and subject to that provider’s terms. Your organisation chooses the provider and the model.
A workspace administrator can require that only your organisation’s own key is used, in which case we never transmit your content on our own account. That setting is in the workspace’s AI configuration.
Your organisation remains responsible for ensuring that the transfer is lawful for the data the content contains. The providers we engage on your behalf are named in the sub-processor table below, and we will update it before engaging another.
We do not use your workspace content to train our own models, on either route.
4. Sub-processors
We use the following providers. Those marked optional are only engaged if your workspace enables that integration.
| Provider | Purpose | Engaged |
|---|---|---|
| OpenRouter | AI model routing for generation, scoring and extraction | Always, unless your workspace has required that only its own key is used |
| Cloudflare (R2) | Object storage for uploaded images and documents | Always |
| Brevo | Transactional email — verification, password reset, invitations | Always |
| [HOSTING PROVIDER] | Application and database hosting in [REGION] | Always |
| Publishing and page analytics | Optional | |
| Typefully | Social content scheduling | Optional |
| Microsoft (Graph / Entra) | Single sign-on and Teams integration | Optional |
| Payment processor | Subscription billing and invoicing | Optional, on paid plans |
We will update this list before engaging a new sub-processor. If you have a data processing agreement with us, we will give the notice period it specifies.
5. Cookies and similar technologies
We set a small number of strictly necessary cookies that the service cannot work without: a session cookie that keeps you signed in, and a cookie that remembers your language choice. These do not require consent.
Any analytics or marketing cookie is set only after you have explicitly allowed that category in our consent banner. If you decline, the relevant scripts are not loaded and no such cookie is set. If you later withdraw consent, we stop collection and delete the cookies already set for that category.
You can change or withdraw your choice at any time from the cookie settings available on this site and inside the application. See our Cookie Policy for the detail.
6. Legal bases
Where GDPR or equivalent law applies, we rely on:
- Contract — to provide the service to you and your organisation.
- Legitimate interests — to keep the service secure, prevent abuse, maintain audit records and improve reliability.
- Consent — for non-essential cookies and for optional marketing communications. You may withdraw consent at any time.
- Legal obligation — where we must retain records or respond to lawful requests.
7. Retention
| Data | Kept for |
|---|---|
| Workspace content | For as long as the workspace is active, then [RETENTION PERIOD] after closure |
| Account data | Until the account is deleted, then removed or anonymised within [PERIOD] |
| Audit and security logs | [PERIOD] — these exist to be reviewable after the fact |
| Consent records | Kept after withdrawal so we can evidence the choice, for [PERIOD] |
| AI usage records | A record of each AI request served on our account — workspace, timestamp, model and token counts, never the content of the request — is kept indefinitely as a billing and entitlement record. Short-term usage counters expire after 100 days. |
| Backups | Overwritten on a rolling [PERIOD] cycle |
8. International transfers
ClearPath is used by organisations in several countries, and some of our sub-processors operate outside the region where your data is hosted. Where personal data is transferred across borders, we rely on the transfer mechanism available for that route — such as standard contractual clauses or an adequacy decision — and on the terms of our agreement with the relevant provider.
9. Your rights
Depending on where you live, you may have the right to access your personal data, correct it, delete it, restrict or object to processing, receive it in a portable format, and withdraw consent. Residents of Saudi Arabia have equivalent rights under the Personal Data Protection Law (PDPL); residents of Quebec have rights under Law 25 including de-indexing; residents of the EU, UK and other GDPR-aligned jurisdictions have rights under GDPR.
To exercise a right, contact [PRIVACY CONTACT EMAIL]. We will respond within the period the applicable law requires and, where it is short — 30 days under PDPL — within that. If your data sits inside an organisation’s workspace, we may need to refer your request to that organisation as controller, and we will tell you if we do.
If you are unsatisfied with our response, you may complain to your local supervisory authority.
10. Security
We encrypt data in transit, encrypt sensitive credentials at rest, isolate each workspace’s data, enforce role-based access control, and record an audit trail of administrative and content changes. Access to production systems is limited to those who need it.
No system is perfectly secure. If we become aware of a breach affecting your personal data, we will notify the relevant authority and affected individuals as required by applicable law.
11. Children
ClearPath is a business tool and is not directed at children. We do not knowingly collect personal data from anyone under 16.
12. Changes
We will post any change to this policy on this page and update the date above. If a change materially affects how we handle your personal data, we will give notice in the application or by email before it takes effect.