Clemion Legal
Terms, privacy and information about how Clemion handles your data.
Terms of Service
- Effective date
- 25 August 2026
- Last updated
- 6 September 2026
These Terms of Service explain the rules that apply when you create an account, access or use Clemion.
Please read them carefully. By creating a Clemion account, purchasing a subscription or continuing to use Clemion, you agree to these Terms.
If you do not agree to these Terms, you should not use Clemion.
Some rights and obligations may depend on the country in which you live. Nothing in these Terms is intended to remove or restrict any consumer or other legal right that cannot lawfully be excluded.
1. ABOUT CLEMION AND WHO OPERATES IT
Clemion is a digital platform for business and client management designed to help professionals and businesses organise clients, projects, documents, payments and related work.
Clemion provides tools such as client management, projects, quotes and estimates, contracts and electronic signatures, invoices and receipts, expenses, questionnaires, consent forms, files and documents, Client Hub, scheduling, tasks, reports, AI-assisted features and related business-management functionality. Features vary by plan, device, platform and region.
Certain features or plans previously offered under other Clemion product labels may no longer be available to new customers. Existing subscriptions and entitlements remain subject to the applicable purchase and subscription terms.
Clemion is operated by:
Clemion LTD
A company registered in England and Wales
Company number: 17423709
Registered office: Pollard Street East, Manchester, M40 7FS, United Kingdom
Email: support@clemion.app
In these Terms, "Clemion", "we", "us" and "our" refer to Clemion LTD, the legal entity operating Clemion.
"User", "you" and "your" refer to the person or organisation using Clemion.
If you create or use an account on behalf of a business or other organisation, you confirm that you have authority to accept these Terms on its behalf.
2. WHO MAY USE CLEMION
You must be at least 16 years old to create a Clemion account.
If the law where you live requires you to be older to create an account, consent to the processing of your personal information, or enter into an agreement with us, you must meet that higher age requirement.
If you are under the age of legal majority where you live, you may need permission from a parent, legal guardian or another person authorised by law.
You must provide accurate information when creating and maintaining your account.
You must not use Clemion where applicable law prevents you from receiving or using the service.
We may apply additional age or eligibility requirements to particular features where required by law, an app store, a payment provider or the nature of the feature.
3. CREATING AND SECURING YOUR ACCOUNT
You are responsible for your Clemion account and for keeping your sign in details secure.
You must not knowingly allow another person to access your account using your credentials unless the feature is specifically designed for shared or authorised access.
If you believe that your account has been accessed without permission, you should change your credentials and contact us as soon as reasonably possible.
You are responsible for keeping your account information accurate and up to date.
Clemion may support different sign in methods, including email and password, Apple and Google. The availability of individual sign in methods may vary by platform.
You are responsible for ensuring that any third party account you use to sign in remains under your control.
4. CLEMION SERVICE AND FEATURES
Clemion is a business and client-management platform.
Depending on your plan, device, platform and region, Clemion may include functionality for managing clients and business information, projects, quotes and estimates, contracts and agreements, electronic signatures, invoices, receipts, expenses, questionnaires, consent forms, files and documents, Client Hub, scheduling and tasks, reports and exports, AI-assisted features, and related business-management tools.
If you use Clemion for business activities, contracts, invoicing, payments or other commercial transactions, you are responsible for ensuring that you have the legal capacity and any permissions required to carry out those activities.
Being eligible to create a Clemion account does not mean that you are automatically legally permitted to enter every type of contract or conduct every type of business activity.
The availability of features may differ between platforms, plans and regions. Some features may be available through the Clemion mobile application but not through the Web application, or may contain different functionality depending on the platform.
A subscription or entitlement provides access to the features included in that subscription for as long as it remains active, subject to these Terms. The features included in your plan will be shown before you purchase or activate the relevant plan.
Clemion is not a school, university, teaching service or tutoring service. Clemion does not teach courses, provide formal instruction, assess academic work or guarantee academic results.
5. FREE PLANS AND USAGE LIMITS
Clemion may provide certain features without requiring a paid subscription.
Free access may be subject to limits. These limits may include the number of clients, workflows, documents, AI generations, storage capacity or other usage allowances.
The limits that apply to your account will be shown within Clemion or in the relevant plan information.
Where Clemion provides a lifetime free allowance, that allowance does not automatically reset each month, each year, when you reinstall the application or when you use Clemion on another device.
Usage limits are associated with your Clemion account and may apply across Web, iOS and Android.
We may change free allowances in the future. Where a change would materially affect existing users, we will provide reasonable notice where appropriate.
We will not deliberately charge you simply because you have reached a free usage limit. If a paid plan is required to continue using a feature, Clemion will ask you to upgrade.
6. PAID SUBSCRIPTIONS
Some Clemion features require a paid subscription.
The price, billing period, included features and any applicable taxes will be shown before you subscribe.
Subscriptions may be offered monthly, annually or on another billing period clearly disclosed before purchase.
Prices may vary by country, currency, platform, taxes and purchasing channel.
By purchasing a subscription, you authorise the applicable payment provider to charge the amount shown to you.
A subscription gives you access to the features included in that subscription for as long as the subscription remains active and subject to these Terms.
Clemion may offer promotional pricing, introductory offers, free trials or other promotions from time to time. Additional conditions may apply to those offers and will be disclosed when the offer is made.
Certain features or plans previously offered by Clemion may no longer be available to new customers. Existing subscriptions, renewals, cancellations and entitlements remain subject to the applicable purchase and subscription terms and the platform through which they were purchased.
7. AUTOMATIC RENEWALS
Unless clearly stated otherwise when you subscribe, paid subscriptions renew automatically at the end of each billing period.
A monthly subscription will normally renew each month.
An annual subscription will normally renew each year.
The applicable renewal price will be disclosed in accordance with the requirements that apply to your purchase.
You can prevent future renewal by cancelling your subscription before the next renewal is processed.
Where applicable law requires a renewal reminder, cooling off period or other renewal protection, we will provide it.
Nothing in these Terms limits any mandatory renewal or cancellation right available to you under applicable law.
8. CANCELLING A SUBSCRIPTION
You can cancel your subscription at any time using the subscription management method available for your purchase.
Cancellation normally prevents your subscription from renewing for another billing period.
Unless applicable law, an app store decision or another specific circumstance provides otherwise, you will continue to have access to your paid subscription until the end of the billing period you have already paid for.
For example, if you purchase a monthly subscription and cancel before the end of that month, your paid access will normally continue until the subscription expiry date.
After the paid period ends, your account may return to the features and limits available without that subscription.
Cancelling your subscription does not delete your Clemion account.
If you want your account and associated Clemion data permanently deleted, you must use the account deletion feature.
9. REFUNDS AND STATUTORY RIGHTS
Payments for Clemion subscriptions are generally non refundable once charged.
However, circumstances can vary.
We may provide a full or partial refund where we consider it appropriate. This may include a duplicate charge, a billing error, a significant service issue or another exceptional circumstance.
Any discretionary refund will be considered based on the circumstances of the request.
Cancelling part way through a billing period does not automatically entitle you to a refund or credit for the unused part of that period.
Nothing in these Terms limits any right to a refund, cancellation, cooling off period or other remedy that you are entitled to under applicable law.
Where your purchase was processed by Apple, Google or another third party marketplace, refund decisions may also be governed by that provider's rules and procedures.
10. APP STORE AND GOOGLE PLAY PURCHASES
Subscriptions purchased through the Apple App Store are billed and managed through Apple.
Subscriptions purchased through Google Play are billed and managed through Google.
If you purchase through one of these platforms, your purchase may also be subject to the terms and policies of the relevant app store.
Cancellation and refund requests for an app store purchase may need to be submitted directly to that app store.
Subscriptions purchased directly from Clemion through the Web are managed through Clemion and its payment provider.
Access to an eligible Clemion subscription may be recognised across supported platforms when you use the same Clemion account, subject to the plan and entitlement rules that apply to that subscription.
11. CLEMION AI
Clemion includes features powered by artificial intelligence.
Clemion AI is a tool designed to assist users with drafting, organising, rewriting, summarising and generating content within supported parts of Clemion.
Depending on the feature, Clemion AI may help with business documents, emails, questionnaires, consent forms, invoices, receipts and other supported tasks.
Clemion AI is intended to help you work or organise information more efficiently.
It does not replace your own judgement, professional expertise, teacher, tutor, adviser or other qualified professional.
Access to Clemion AI may depend on your plan or usage allowance.
AI functionality may change as the technology and Clemion develop.
Clemion does not guarantee that AI generated content will always be available, complete, accurate or suitable for your particular circumstances.
12. AI GENERATED CONTENT AND YOUR RESPONSIBILITY
AI generated content can contain mistakes.
It may be inaccurate, incomplete, outdated, misleading or unsuitable for your particular circumstances.
You must review AI generated content carefully before you use it, send it to another person, publish it, rely on it or incorporate it into a business, academic or legal process.
Clemion AI is an assistance tool. It does not replace your own judgement or the advice of an appropriately qualified professional.
AI generated contracts, consent forms, clauses, explanations or other content are not legal advice.
AI generated financial, tax or business information is not accounting, tax, financial or other regulated professional advice.
Clemion AI does not guarantee that an answer is correct or suitable for your particular circumstances.
You remain responsible for checking AI generated content and for complying with any academic integrity rules, assessment requirements and other policies that apply to your school, university or educational institution, where relevant.
You are responsible for determining whether AI generated content is appropriate for your circumstances and complies with any laws, professional rules, academic rules and contractual obligations that apply to you.
Where content has legal, financial, medical, academic or other significant consequences, you should obtain appropriate professional guidance where necessary.
Clemion does not guarantee that AI generated content is original, error free, legally enforceable or suitable for a particular jurisdiction or purpose.
You must not intentionally use Clemion AI to generate unlawful, fraudulent, harmful or infringing material.
13. CLIENTS AND CLIENT INFORMATION
Clemion users may add information about their own clients to Clemion.
You are responsible for ensuring that you have a lawful reason to collect, upload, store and use information about your clients.
You must only add information that is reasonably necessary for your professional activities and that you are legally permitted to process.
Clemion does not determine whether you are legally entitled to collect particular client information.
Where Clemion processes client information on your behalf, additional provisions in our Privacy Policy and Data Processing Terms may apply.
You are responsible for keeping client information accurate where accuracy is relevant to your use of Clemion.
14. CLIENT HUB
Client Hub allows Clemion users to share selected information, documents, files and other content with their clients.
You are responsible for choosing what you share and who receives access.
You should take reasonable care when sharing Client Hub links or other access credentials.
If you believe a Client Hub link has been shared with the wrong person or accessed without permission, you should revoke or replace access where the feature allows you to do so.
Clients may be able to upload or submit information through Client Hub. You are responsible for how you use information received from your clients.
Clemion may apply storage, file type and other usage limits to Client Hub.
Paid Clemion plans may include a stated Client Hub storage allowance. The current allowance applicable to your plan will be displayed within Clemion or in the relevant plan information.
15. QUOTES, ESTIMATES, INVOICES AND RECEIPTS
Clemion provides tools that allow users to create and manage business documents such as quotes, estimates, invoices and receipts.
These tools are provided to assist with business administration.
You are responsible for the contents of documents you create.
You are also responsible for ensuring that your invoices, receipts, taxes, payment details, business information and other commercial documents comply with the legal and tax requirements that apply to your business.
Clemion may adapt terminology based on your region or preferences. For example, Clemion may use "Quote" or "Estimate" depending on your selected terminology or region.
Clemion does not act as your accountant, tax adviser or financial adviser.
Unless expressly provided through a separate payment service, Clemion does not become a party to a transaction between you and your client simply because you record or manage that transaction in Clemion.
16. CONTRACTS AND ELECTRONIC SIGNATURES
Clemion provides tools for creating, sharing and electronically signing documents.
You are responsible for deciding which documents require signatures and whether electronic signing is appropriate for your circumstances.
You are responsible for ensuring that the people signing a document have the necessary authority and capacity to do so.
Laws relating to electronic signatures and contract formation vary between countries and can also depend on the type of document.
Clemion does not guarantee that every document or electronic signature created through the service will be legally valid, admissible or enforceable in every jurisdiction or circumstance.
Clemion does not provide legal advice.
Where the legal effect of a contract or signature is important, you should obtain appropriate legal advice.
17. QUESTIONNAIRES AND CONSENT FORMS
Clemion allows users to create and send questionnaires and consent forms.
These tools help you collect information, acknowledgements, choices and signatures from clients.
You are responsible for deciding what questions to ask and what consent you need.
Clemion does not determine whether a particular consent form is legally sufficient for your profession, jurisdiction or intended purpose.
A response, checkbox, signature or acknowledgement collected through Clemion does not automatically prove that every legal requirement for consent has been satisfied.
You are responsible for complying with any industry specific rules that apply to your work.
Where appropriate, you should obtain professional legal, regulatory or medical advice when designing consent processes.
18. FILES, UPLOADS AND STORAGE
Clemion may allow you and, where applicable, your clients to upload documents, photographs, videos and other files.
Storage limits may depend on your plan and account.
You must not upload content that is unlawful, malicious, infringes another person's rights or violates these Terms.
We may restrict individual file sizes, file types or storage usage for security, performance or technical reasons.
You are responsible for maintaining your own copies of important files and records where appropriate.
Clemion is not intended to be your only archival or backup system.
If you reach a storage limit, you may need to delete files or increase your available storage where an upgrade option is offered.
19. USER CONTENT AND INTELLECTUAL PROPERTY
This section explains how Clemion treats content that users upload, create, store, process or share through the service.
User ownership
You retain ownership of content you upload, create or share through Clemion. Clemion does not claim ownership of your user content.
This includes, for example:
- Images, videos, documents, PDFs and other files.
- Logos, branding assets and attachments.
- Project files and uploaded source material.
- Client Hub content and client-facing shared material.
- Questionnaire, consent and other user-provided responses.
- Other content you provide through Clemion.
Limited licence to Clemion
You grant Clemion a limited, non-exclusive licence to use your content only to the extent reasonably necessary to operate, maintain, protect and provide Clemion.
This may include hosting, storing, processing, technically reproducing, displaying, transmitting, backing up, securing and making content available according to your sharing settings, including converting or generating technical representations needed to provide features.
This licence does not transfer ownership to Clemion and does not permit Clemion to use your content independently for its own commercial purposes outside operating the service.
Your responsibility
You are responsible for ensuring that you have the necessary rights, licences, permissions, consents and authority to upload, store, process, use and share content through Clemion.
Third-party rights
You must not knowingly use Clemion to upload or distribute content that infringes or violates applicable copyright, trademark, privacy, confidentiality, image, likeness, personality, publicity or other third-party rights, or that breaches contractual restrictions or is otherwise unlawful.
Clemion's response to reports
Clemion may investigate reports concerning content hosted or shared through the service. Where reasonably appropriate, Clemion may restrict access, disable sharing, temporarily make content unavailable, remove content, preserve information where legally appropriate, contact the relevant user, request additional information or take account-level action in serious or repeated substantiated cases.
Nothing in these Terms limits any responsibility Clemion may have under applicable law, and Clemion does not provide absolute immunity from liability for user content.
Serious or repeated misuse
Where appropriate, Clemion may issue warnings, restrict sharing, restrict uploads, suspend service access or terminate an account for serious or repeated substantiated misuse. Pending or rejected complaints do not automatically count as infringements, and Clemion does not apply a fixed automatic "three strikes" rule.
Reporting
If you believe content on Clemion infringes copyright, intellectual property or other rights, you may submit a report through Clemion's reporting process at https://clemion.app/en/legal/report-content.
False or abusive reports
Reports should be submitted honestly and based on information you reasonably believe to be accurate. Clemion may take reasonable measures against intentionally abusive or fraudulent use of the reporting system.
20. ACCEPTABLE USE
You must use Clemion lawfully and responsibly.
You must not use Clemion to:
- Commit, facilitate or promote unlawful activity.
- Defraud, deceive or impersonate another person or organisation.
- Upload malware, malicious code or content intended to compromise another system.
- Access another user's account or data without permission.
- Infringe intellectual property, privacy, confidentiality or other legal rights.
- Send unlawful spam or abusive communications.
- Harass, threaten or deliberately harm another person.
- Store or distribute content that you are not legally entitled to possess or share.
- Circumvent subscription, security, storage or usage limits.
- Interfere with the normal operation, security or integrity of Clemion.
- Use automated systems to place unreasonable load on Clemion's infrastructure.
- Reverse engineer or attempt to extract protected parts of Clemion except where applicable law expressly permits it.
- Use Clemion AI in a way that violates law, these Terms or the rights of another person.
We may take reasonable action where we believe Clemion is being misused.
21. THIRD PARTY SERVICES
Clemion relies on third party technology and service providers to provide parts of the service.
These may include hosting and database providers, authentication services, payment processors, app stores, email delivery services, artificial intelligence providers and other infrastructure services.
Some Clemion features may also allow you to enter links or information relating to services such as payment providers or communication platforms.
Your use of a third party service may be subject to that provider's own terms and privacy practices.
We are not responsible for services that are operated independently by third parties.
Where a third party processes personal information on our behalf, our Privacy Policy and Data Processing Terms explain the relevant arrangements in more detail.
22. AVAILABILITY AND CHANGES TO CLEMION
We aim to keep Clemion reliable and available, but we cannot guarantee uninterrupted access at all times.
Clemion may occasionally be unavailable because of maintenance, upgrades, security work, technical problems, third party outages or circumstances outside our reasonable control.
We may add, improve, modify or remove features as Clemion develops.
Where a change materially reduces a paid service that you have already purchased, we will take reasonable steps to communicate the change and will respect any rights you have under applicable law.
We may release features gradually or make some functionality available only on particular platforms, plans or regions.
23. ACCOUNT SUSPENSION
We may temporarily restrict or suspend access to an account where reasonably necessary.
This may happen if:
- We reasonably believe the account has been compromised.
- There is a significant security risk.
- You seriously or repeatedly breach these Terms.
- Your use of Clemion is unlawful.
- We are required to take action by law or a competent authority.
- Payment for a paid subscription remains unresolved where suspension is permitted.
- Your activity threatens the security or operation of Clemion or other users.
Where appropriate, we will try to explain the reason for suspension and provide an opportunity to resolve the issue.
We may act immediately where necessary to protect users, data, Clemion or third parties.
24. ACCOUNT DELETION AND DATA DELETION
You can permanently delete your Clemion account using the account deletion feature available in your account settings.
Account deletion is different from subscription cancellation.
Cancelling a subscription stops future renewal but does not delete your Clemion account.
Deleting your account permanently closes the account.
When account deletion is completed, we delete the account and associated content from Clemion's active systems.
Depending on how you use Clemion, this may include:
- Profile and account information.
- Business and client-management information.
- Historical account content from previously offered Clemion features, where applicable.
- Client information.
- Projects.
- Quotes and estimates.
- Contracts.
- Invoices and receipts.
- Expenses.
- Questionnaires.
- Consent forms.
- Client Hub information.
- Uploaded documents, photographs, videos and other stored files.
- Schedules, tasks and other account content.
You should download or export anything you need before deleting your account.
Once deletion has been completed, your account and its contents may not be recoverable.
Some information may remain temporarily in secure technical backups until those backups are overwritten or expire through our normal backup cycle.
We may also retain limited information where retention is required by law or is reasonably necessary for the establishment, exercise or defence of legal claims.
Any information retained for those limited purposes will not be kept longer than necessary.
Our Privacy Policy explains account deletion and retention in more detail.
25. INTELLECTUAL PROPERTY
Clemion, including its software, design, interface, branding, logos, graphics, original content and underlying technology, is owned by us or licensed to us and is protected by intellectual property laws.
These Terms give you permission to use Clemion for its intended purpose while your account is active.
They do not transfer ownership of Clemion or its intellectual property to you.
You must not copy, sell, sublicense, distribute or commercially exploit Clemion or its protected components except where we have given written permission or applicable law expressly allows it.
Clemion names, logos and branding must not be used in a way that falsely suggests sponsorship, endorsement or affiliation.
26. DISCLAIMERS
Clemion is a business, productivity and organisation tool.
It is not a law firm, accounting practice, financial adviser, tax adviser, medical provider, school, university, teacher, tutor or other regulated professional adviser.
Templates, AI generated content, document structures, explanations, study assistance and other information provided through Clemion are intended to assist you with organisation and productivity.
They should not be treated as a substitute for professional advice, formal education or qualified instruction where those are required.
You remain responsible for your business decisions, documents, client relationships, taxes, regulatory obligations, professional responsibilities, study decisions, assignments and academic obligations.
To the extent permitted by law, Clemion is provided without a guarantee that every feature will always be uninterrupted, error free or suitable for every particular business, profession, educational setting or jurisdiction.
Nothing in this section affects warranties, guarantees or other rights that applicable law does not allow us to exclude.
27. LIMITATION OF LIABILITY
Nothing in these Terms excludes or limits liability where it would be unlawful to do so.
This includes liability for fraud or fraudulent misrepresentation and any other liability that applicable law does not permit us to exclude or restrict.
Nothing in these Terms limits your mandatory consumer rights.
If you use Clemion as a consumer, we are responsible for losses that are a foreseeable result of our breach of these Terms or our failure to use reasonable care and skill where applicable law requires that responsibility.
We are not responsible for losses that were not reasonably foreseeable when you agreed to these Terms.
If you use Clemion primarily for business purposes, then, to the fullest extent permitted by law, we will not be liable for indirect or consequential loss, loss of profits, loss of business opportunity, loss of anticipated savings or loss arising solely from your failure to keep appropriate copies of important business records.
For business users, our total aggregate liability arising out of or relating to Clemion during any twelve month period will not exceed the greater of:
The amount you paid to Clemion for the relevant service during the twelve months immediately before the event giving rise to the claim.
£100.
This limitation does not apply where applicable law does not permit it.
28. RESPONSIBILITY FOR CLAIMS ARISING FROM BUSINESS USE
If you use Clemion for business or professional purposes, you are responsible for the content, documents and information you choose to create, upload, send or share through your account.
To the extent permitted by law, you are responsible for losses or claims caused by your unlawful use of Clemion, your deliberate infringement of another person's rights, or content you provide where you did not have the legal right to provide it.
We will not require you to compensate us for a claim to the extent that the claim was caused by our own breach of these Terms, negligence or unlawful conduct.
Nothing in this section removes protections that apply to you under mandatory consumer law.
29. GOVERNING LAW AND DISPUTES
These Terms are governed by the laws of England and Wales, except where mandatory law in your country of residence gives you protections or rights that cannot lawfully be displaced by this choice of law.
If you are a consumer, you may also have the right to bring proceedings in the courts of the country or region where you normally live.
If you use Clemion for business purposes, the courts of England and Wales will have jurisdiction over disputes arising from these Terms, unless applicable law requires otherwise.
Before starting formal proceedings, we encourage you to contact us so that we can try to resolve the matter directly.
Nothing in this section prevents either party from seeking urgent legal relief where necessary.
30. CHANGES TO THESE TERMS
We may update these Terms as Clemion develops, our business changes or legal requirements change.
When we make a material change, we will provide reasonable notice where required.
The updated Terms will show the date on which they were last revised.
Where applicable law requires your consent to a change, we will request it.
If you do not agree to a material change, you may stop using Clemion and, where appropriate, cancel your subscription before the change takes effect.
Changes will not remove rights that applicable law gives you.
31. CONTACT DETAILS
If you have questions about these Terms, your subscription, your account or Clemion generally, you can contact us at:
Clemion
Operated by:
Clemion LTD
Registered office:
Pollard Street East, Manchester, M40 7FS, United Kingdom
Company number:
17423709
Support:
support@clemion.app
Legal enquiries:
support@clemion.app
Website:
https://clemion.app
Privacy related requests will also be explained in the Privacy Policy and Data Protection & GDPR sections of the Clemion Legal page.
Privacy Policy
- Effective date
- 25 August 2026
- Last updated
- 6 September 2026
Your privacy matters to us.
This Privacy Policy explains what personal information Clemion collects when you create an account, use Clemion, interact with Client Hub or otherwise communicate with us, how we use that information, and the choices available to you.
We want you to understand what happens to your information and how you can control it.
Please read this Privacy Policy together with our Terms of Service, Data Protection & GDPR section, and Data Processing Terms where those documents apply to you.
The privacy laws that apply to you may depend on where you live and how you use Clemion.
Nothing in this Privacy Policy is intended to remove or restrict any privacy, data protection or consumer right that applicable law gives you.
1. WHO WE ARE AND WHAT THIS POLICY COVERS
This Privacy Policy explains how Clemion handles personal information.
Clemion is a digital platform for business and client management designed to help professionals and businesses organise clients, projects, documents, payments and related work.
Clemion provides tools such as client management, projects, quotes and estimates, contracts and electronic signatures, invoices and receipts, expenses, questionnaires, consent forms, files and documents, Client Hub, scheduling, tasks, reports, AI-assisted features and related business-management functionality. Features vary by plan, device, platform and region.
If your account includes content from Clemion features or plans previously offered under other product labels, this Privacy Policy also applies to that historical account content for as long as Clemion continues to store or process it.
This Privacy Policy applies to personal information processed when you use Clemion through the Web application, mobile applications and related services.
It also applies to personal information processed through Client Hub, public document flows such as questionnaires, consent forms and contract signing, and when you contact us.
Clemion is operated by:
Clemion LTD
A company registered in England and Wales
Company number: 17423709
Registered office: Pollard Street East, Manchester, M40 7FS, United Kingdom
In this Privacy Policy, "Clemion", "we", "us" and "our" refer to Clemion LTD, the legal entity operating Clemion.
"User", "you" and "your" refer to the person using Clemion or otherwise interacting with our services.
2. HOW TO READ THIS POLICY WITH OTHER DOCUMENTS
Clemion legal documents work together.
Our Terms of Service explain the rules for using Clemion.
This Privacy Policy explains how we handle personal information.
Our Data Protection & GDPR section provides additional information for users in the European Economic Area, the United Kingdom and other regions where similar laws apply.
Our Data Processing Terms explain how Clemion processes personal information on behalf of Clemion users when those users add client or other third party information to Clemion.
Our Cookies & Similar Technologies section provides more detail about cookies and similar technologies used on the Clemion website.
If there is a conflict between documents, the document most specific to the activity will normally apply to that activity.
3. ROLES: CONTROLLER AND PROCESSOR
Data protection law distinguishes between a controller, who decides why and how personal information is processed, and a processor, who processes personal information on behalf of a controller.
When you create and use your own Clemion account, Clemion generally acts as a controller of the personal information needed to provide your account and the Clemion features you use.
When a Clemion user adds information about their clients, contractors, signatories or other individuals to Clemion, that user is normally the controller of that information.
In those situations, Clemion generally acts as a processor and processes that information on the Clemion user's instructions to provide the service.
Our Data Processing Terms explain those processor arrangements in more detail.
Some processing may involve both roles depending on the feature, the information involved and the circumstances.
4. INFORMATION WE COLLECT
The personal information Clemion collects depends on how you use Clemion, your account, your plan, your device and the features you choose to use.
We may collect information that you provide directly, information generated through your use of Clemion, information from your device or browser, and limited information from third parties such as payment providers or sign-in services.
We do not need every category of information for every user.
We aim to collect only what is reasonably necessary for the relevant feature, security, billing, support or legal compliance.
5. ACCOUNT, PROFILE AND AUTHENTICATION INFORMATION
When you create a Clemion account, we collect information such as your name, email address and password or other sign in credentials.
If you sign in with Apple or Google, we receive information from that provider as permitted by your settings and the provider's policies. This may include your name, email address and an identifier linked to your third party account.
We may also collect profile and account settings such as your preferred language, region, account preferences, notification settings and subscription status.
Authentication and session management are handled through Supabase Auth.
Supabase Auth also sends authentication related emails such as sign up confirmation, password reset and email change messages.
You are responsible for keeping your sign in details secure and for ensuring that any third party account you use to sign in remains under your control.
6. CLIENT HUB AND CLIENT-FACING FEATURES
Client Hub allows Clemion users to share selected information, documents, files and other content with their clients through a secure link.
Clients do not need a Clemion account to access Client Hub.
When a client uses Client Hub, Clemion may process information such as the client's name, email address, uploaded files, submitted responses, activity related to shared documents and technical information needed to deliver the service securely.
Clemion users decide what they share and who receives access.
Some Client Hub features may allow a client to upload files, complete questionnaires, sign documents or submit other information.
Clemion users may optionally enable Protect Client Hub for a specific Client Hub.
When protection is enabled, a client may need to verify access using a one time code sent to the email address associated with that client record before Client Hub content is shown.
If the client successfully verifies on a browser and the Clemion user has enabled remembered verified devices, Clemion may store a Client Hub specific trusted browser session for up to 30 days so the client does not need to verify on every visit from that browser during that period.
Client Hub protection is designed to add an optional security layer. It does not create a full Clemion account for the client.
Public document flows such as questionnaires, consent forms, contract review and signing may also process personal information submitted by clients or other recipients.
The Clemion user who created or sent the document is normally responsible for deciding what information to collect and for having a lawful basis to do so.
7. BUSINESS AND CLIENT MANAGEMENT INFORMATION
If you use Clemion for business and client management, we process information you add to manage your business activities.
This may include client records, contact details, project information, schedules, tasks, notes, quotes, estimates, invoices, receipts, expenses, contracts, questionnaires, consent forms, mailing activity, branding assets, signatures, uploaded documents, photographs, videos and other files.
It may also include business profile information, payment details you choose to display on documents, tax or registration information you enter, and internal documents marked as not shared with clients.
Clemion users remain responsible for ensuring that they have a lawful basis to collect and use information about their clients and other individuals.
8. HISTORICAL STUDENT ACCOUNT CONTENT
If your Clemion account includes content from previously offered study-organisation features, we may continue to process that historical information for as long as it remains associated with your account.
This may include schedules, tasks, goals, notes, study related documents, uploaded files and other information you previously stored in Clemion.
Clemion is not a school, university or teaching service.
Clemion does not require educational institutions to provide student records directly to Clemion for ordinary use of those features.
9. HISTORICAL PERSONAL ACCOUNT CONTENT
If your Clemion account includes content from previously offered personal-organisation features, we may continue to process that historical information for as long as it remains associated with your account.
This may include routines, plans, goals, journal entries, wardrobe information, personal finance records, uploaded media and other information you previously stored in Clemion.
The categories of information depend on the features you choose to use.
10. FILES, UPLOADS AND USER CONTENT
Clemion allows you, and in some cases your clients or other recipients, to upload or create documents, images, videos and other content.
We process the content you upload or create so that Clemion can store it, display it, share it where you choose, generate documents from it, and provide related features such as search, synchronisation, previews and downloads.
You should not upload content that you are not legally permitted to share with Clemion or that contains unnecessary sensitive information.
Storage limits may depend on your plan and account.
Rights and infringement reports
If a person submits a copyright, intellectual property or other rights complaint through Clemion's reporting process, Clemion may process information such as the reporter's name, email address, organisation if supplied, relationship to the rights holder, the reported Clemion URL or resource, a description of the protected work or right, complaint details, supporting information or evidence, correspondence, relevant uploader or account information, relevant resource metadata and internal investigation or action records.
Clemion may use this information to investigate reports, protect rights, enforce its Terms, prevent misuse, communicate with involved parties, comply with applicable legal obligations and establish, exercise or defend legal claims.
The legal bases for this processing are explained in section 19 of this Privacy Policy and, where applicable, in the Data Protection & GDPR section of the Clemion Legal page. Clemion retains this information only for as long as reasonably necessary for those purposes, consistent with the retention principles in this Privacy Policy.
11. INFORMATION WE COLLECT AUTOMATICALLY
When you use Clemion, we automatically collect limited technical and usage information needed to operate, secure and maintain the service.
This may include device type, operating system, app version, browser type, IP address, general location derived from IP address, log information, timestamps, feature usage events, error reports, security signals and identifiers associated with your account or session.
We may also collect information about how you interact with Clemion, such as pages viewed, actions taken, subscription status, storage usage and AI usage allowances.
We use this information to provide Clemion, prevent abuse, troubleshoot problems, improve reliability and understand how features are used.
12. HOW WE USE PERSONAL INFORMATION
We use personal information to provide, operate, maintain, secure and improve Clemion.
This includes creating and managing accounts, authenticating users, synchronising data across devices, delivering Clemion features, generating and sharing documents, operating Client Hub, sending service communications, providing support, enforcing our Terms, complying with law and protecting Clemion, our users and others.
We may use personal information to process subscriptions, manage billing, apply usage limits, detect fraud or misuse, and maintain audit records where appropriate.
We do not use your private account content to train public AI models through Clemion's own systems.
We do not sell personal information.
13. CLEMION AI
Clemion includes features powered by artificial intelligence.
Clemion AI is designed to help users draft, organise, rewrite, summarise and generate content within supported parts of Clemion.
Clemion AI uses OpenAI to generate responses through OpenAI's Responses API.
Clemion AI requests are handled through a Supabase Edge Function called clemion-ai.
When you use Clemion AI, Clemion sends OpenAI the information reasonably needed for the requested task. Depending on the feature, this may include user prompts, client names, business context, document excerpts and account settings.
This means personal or business information can be included when it is relevant to the task you request. Clemion does not represent that no personal information is sent to OpenAI.
Where covered by Clemion's AI context scrubber, sensitive fields such as client email addresses, phone numbers, IBANs, raw PDF objects, authentication tokens and other blocked fields are removed or redacted before the request is sent.
You should only submit information that is reasonably necessary for the requested task.
Do not submit unnecessary sensitive personal information through Clemion AI unless you have decided that doing so is appropriate for your circumstances.
Clemion does not store full AI prompts or full generated responses in its own database as standard long term records.
Clemion may retain limited AI usage metadata needed for plan enforcement, idempotency, abuse prevention or service operation. This may include user or account association, workspace, idempotency key, billing period, action type, timestamp and usage counters.
OpenAI receives the request content necessary to generate the response. Clemion's production integration explicitly sets store to false for Responses API requests, so OpenAI is instructed not to retain the response object for Clemion's stateless requests.
Clemion's OpenAI organisation settings currently have API input and output sharing for model improvement disabled.
OpenAI may process information internationally. OpenAI's handling of API data is subject to OpenAI's applicable API terms, data handling practices and contractual safeguards.
Clemion does not use OpenAI conversation state, stored response retrieval, response ID chaining, threads, Assistants, OpenAI Files, Vector Stores or Batches for Clemion AI.
You should review AI generated content carefully before relying on it or sharing it.
14. PAYMENTS AND SUBSCRIPTIONS
If you purchase a paid Clemion subscription, we process information needed to manage billing and entitlements.
If you subscribe through the Clemion website, payment processing is handled by Stripe.
Clemion receives subscription and billing metadata from Stripe, such as customer identifiers, subscription status, billing period, product or plan information and limited contact details.
Clemion does not necessarily receive your full payment card number from Stripe.
If you subscribe through the Apple App Store or Google Play, the purchase is handled by Apple or Google.
Clemion receives subscription entitlement information from those platforms so that your Clemion account can reflect the subscription you purchased.
Clemion does not receive your full payment card details from Apple or Google.
Payment providers process personal information according to their own privacy policies and terms.
If a Clemion user adds payment links from third party services to invoices or other documents, Clemion stores the link information but does not process the underlying payment transaction.
15. COMMUNICATIONS, EMAILS AND NOTIFICATIONS
We use personal information to send service related communications.
This may include account notices, security alerts, document notifications, onboarding messages, product tips where permitted, billing messages, support responses and Client Hub verification codes.
Transactional and product emails are generally sent through Resend.
Authentication emails such as sign up confirmation and password reset are sent through Supabase Auth.
You can manage some email preferences within Clemion, including product email preferences where available.
Some service communications are necessary for security, billing or account operation and cannot be fully switched off while you maintain an account.
If you use Clemion mobile applications and enable notifications, Clemion may process device push tokens and send push notifications through the Expo push notification service.
Push notifications are used for reminders and service messages according to your settings and the features you use.
16. SHARING WITH CLIENTS, SIGNATORIES AND OTHER RECIPIENTS
Clemion is designed to help you share information with others when you choose to do so.
If you share a Client Hub link, send a questionnaire, request a signature, share a contract or send a business document, Clemion processes and delivers the information you choose to share to the intended recipient.
You control what you share in these flows.
Recipients may be able to view, download, respond to or sign content depending on the feature.
If you include personal information about another person in content you share, you are responsible for ensuring that you are permitted to share that information.
17. ANALYTICS AND TECHNICAL DATA
The current Clemion web application does not use third party analytics services or advertising trackers.
We do not currently use tools such as Google Analytics, Meta Pixel or similar advertising analytics products in the Clemion web app.
We may still collect limited technical information needed to operate, secure and maintain Clemion.
This includes server logs, authentication events, error information, security monitoring signals and first party product events stored in our own systems.
We use this information to keep Clemion secure, diagnose problems, understand feature usage at an aggregate level and improve reliability.
If we introduce additional analytics in the future, we will update this Privacy Policy and, where required, provide appropriate choices or notices.
18. MARKETING
Clemion is primarily a productivity and business tool.
We do not sell personal information for third party marketing.
We may send product updates, feature announcements or onboarding tips by email where permitted by law and your preferences.
You can manage product email preferences using the email preference controls provided in Clemion emails or account settings where available.
We do not currently use third party advertising cookies on the Clemion web app.
19. LEGAL BASES FOR PROCESSING
Where data protection law requires a legal basis, Clemion relies on one or more of the following, depending on the activity:
- Performance of a contract with you, including providing Clemion, your subscription and the features you request.
- Legitimate interests, such as securing Clemion, preventing misuse, improving the service, supporting users and communicating about the service in a proportionate way.
- Compliance with legal obligations.
- Consent, where required, for example for certain optional communications or where you choose to enable a feature that requires consent.
If you are a Clemion user processing client information in Clemion, you are responsible for identifying and documenting the legal basis that applies to your own use of that information.
Our Data Protection & GDPR section explains these concepts in more detail for users in relevant regions.
20. WHEN WE SHARE INFORMATION WITH OTHERS
We share personal information with service providers that help us operate Clemion.
We may also share information with other users, clients or recipients when you choose to use sharing features.
We may share information within our corporate group if Clemion reorganises its business structure in the future.
We require service providers to handle personal information appropriately and only for authorised purposes.
We do not authorise service providers to use personal information for their own unrelated marketing.
A list of key service providers is included later in this Privacy Policy.
21. LEGAL DISCLOSURES AND SECURITY INCIDENTS
We may disclose personal information where we reasonably believe disclosure is necessary to:
- Comply with applicable law, regulation, legal process or a lawful request from a public authority.
- Enforce our Terms or protect the rights, property or safety of Clemion, our users or others.
- Detect, prevent or address fraud, security or technical issues.
- Protect Clemion against misuse or unlawful activity.
Where permitted by law, we will take reasonable steps to ensure disclosures are limited to what is necessary.
If we become aware of a personal data breach that is likely to require notification under applicable law, we will take appropriate steps, which may include notifying affected users and relevant authorities.
22. SERVICE PROVIDERS AND SUB-PROCESSORS
Clemion uses carefully selected service providers to deliver the service.
Depending on the features you use, these providers may process personal information on our behalf.
Key providers used in Clemion's current production environment include:
- Supabase for database hosting, authentication, file storage, edge functions and related infrastructure.
- Vercel for web hosting and server side application delivery.
- Stripe for web subscription payments.
- Apple App Store and Google Play for mobile subscription purchases and entitlement management.
- Resend for transactional and product email delivery.
- Supabase Auth for authentication related emails.
- Expo push notification service for mobile push notifications.
- Google and Apple, through Supabase Auth, for optional OAuth sign in.
- OpenAI for Clemion AI response generation.
Clemion AI requests are processed through the clemion-ai Supabase Edge Function, which uses OpenAI to generate responses.
PDF rendering for supported documents is performed server side on Vercel using Clemion controlled rendering infrastructure. It is not outsourced to a separate PDF SaaS provider for ordinary document generation.
Service providers may change as Clemion develops, but we aim to work with providers that maintain appropriate security and contractual protections.
23. INTERNATIONAL DATA TRANSFERS
Clemion is used internationally.
Personal information may be processed in countries other than the country where you live.
Those countries may have data protection laws that differ from the laws where you are located.
Some core Clemion infrastructure is hosted in the European Union. Clemion's primary Supabase project region is North EU (Stockholm).
Some service providers may process personal information in other locations according to their infrastructure and service design. For example, OpenAI's project residency for Clemion AI is Global.
We do not represent that all personal information remains in the United Kingdom or the European Economic Area at all times.
Where required by applicable law, we use appropriate safeguards for international transfers, such as contractual protections approved for that purpose.
More information about international processing and related rights may be found in our Data Protection & GDPR section.
24. DATA RETENTION
We keep personal information only for as long as reasonably necessary for the purposes described in this Privacy Policy.
Retention periods depend on the type of information, how you use Clemion, legal requirements and operational needs.
Account content is generally kept while your account remains active.
If you delete your account, we delete the account and associated content from Clemion's active systems, subject to limited exceptions.
Clemion uses scheduled daily Supabase database backups. Point in Time Recovery is currently not enabled.
Supabase database backups do not include Storage API objects. Files you delete from Clemion Storage are therefore not restored merely by restoring an older database backup.
Database records deleted from active systems may remain temporarily in historical database backups until those backups expire according to the production backup retention schedule.
We may retain limited information where retention is required by law or is reasonably necessary for the establishment, exercise or defence of legal claims, billing records, fraud prevention or security.
Security records and billing records may be kept for longer where necessary for legitimate business, security or legal reasons.
25. SECURITY
We use administrative, technical and organisational measures designed to protect personal information.
These measures include access controls, encryption in transit, secure authentication, monitoring, hashing of sensitive verification values and service provider security requirements.
No online service can guarantee absolute security.
You also play an important role in security by protecting your account credentials, using secure devices and taking care when sharing links or documents.
If you believe your account or a Client Hub link has been accessed without permission, contact us and take any available recovery steps promptly.
26. YOUR CHOICES AND SETTINGS
You can make certain choices about your personal information within Clemion.
You can update account and profile information, manage notification settings, change language or appearance preferences, and manage product email preferences where available.
Clemion users can choose what client information to store, what to share through Client Hub, and whether to enable optional Client Hub email verification.
You can cancel subscriptions using the method available for your purchase channel.
Some information is required to provide Clemion. If you choose not to provide required information, certain features may not be available.
27. YOUR RIGHTS
Depending on where you live, you may have rights over your personal information.
These may include the right to access, correct, delete, restrict, object to or port certain personal information, and the right to withdraw consent where processing is based on consent.
You may also have the right to complain to a data protection authority.
To exercise your rights, contact us using the details in this Privacy Policy.
We may need to verify your identity before responding.
We will respond within the time limits required by applicable law.
Our Data Protection & GDPR section explains these rights in more detail for users in relevant regions.
If you are a client whose information was added to Clemion by a Clemion user, you may need to contact that Clemion user directly. Clemion may also respond where applicable law requires us to do so.
28. ACCOUNT DELETION
You can permanently delete your Clemion account using the account deletion feature available in your account settings.
Account deletion is different from subscription cancellation.
When account deletion is completed, we delete the account and associated content from Clemion's active systems.
Account erasure also removes known user owned active Storage content through Clemion's existing cleanup process.
Depending on how you use Clemion, this may include profile information, business and client-management information, historical account content from previously offered Clemion features, client information, projects, documents, uploaded files, schedules, tasks and other account content.
You should download or export anything you need before deleting your account.
Some information may remain temporarily in secure database backups, with external service providers, or where retention is required by law or for legitimate legal, billing or security purposes.
If you cannot access the app, you may contact support for help with account deletion requests.
29. CHILDREN
Clemion is intended for users aged 16 and over.
We do not knowingly intend the service for children under 16.
If the law where you live requires a higher age for you to consent to the processing of your personal information, that higher age requirement applies.
Where parental or guardian consent is required by applicable law, the required permission must be obtained.
Clemion is not a school, university, teaching service or tutoring service.
Clemion does not assess users academically or determine grades.
30. BUSINESS USERS AND CLIENT PERSONAL DATA
If you are a Clemion user, you may add personal information about your clients and other individuals to Clemion.
You are responsible for ensuring that you have a lawful basis to collect, upload, store, use and share that information.
You must provide appropriate privacy information to your clients and other individuals where required by law.
When Clemion processes that information to provide Clemion to you, Clemion generally acts as a processor on your instructions.
Our Data Processing Terms explain those arrangements.
If an individual contacts Clemion about information you control as a Clemion user, we may direct them to you unless applicable law requires us to respond directly.
31. PUBLIC PAGES, LINKS AND THIRD-PARTY CONTENT
Some Clemion features allow you to share links or make content accessible to recipients through secure public pages.
Anyone with a valid link may be able to access the content you share, subject to any security settings you apply.
You should take care when sharing links and should revoke or replace access where the feature allows you to do so.
Public pages may display business branding where configured.
Third party websites or services linked from Clemion are governed by their own privacy practices.
32. COOKIES AND SIMILAR TECHNOLOGIES
The Clemion website and Web application use cookies and similar technologies where necessary to operate the service.
In the current Clemion web app, these are functional rather than non essential analytics or advertising cookies.
Examples include cookies used for authentication sessions, appearance or theme preferences, locale preferences, promotional attribution where applicable, and Client Hub trusted device recognition when Protect Client Hub is enabled.
The Client Hub trusted device cookie is designed to remember a successfully verified browser for up to 30 days for a specific protected Client Hub.
We do not currently use non essential analytics cookies in the Clemion web app.
More information is available in our Cookies & Similar Technologies section.
33. LINKS TO OTHER WEBSITES AND SERVICES
Clemion may contain links to third party websites, payment pages, app stores or other services.
If you follow a link to a third party service or sign in through Apple or Google, that third party's privacy policy and terms apply to their handling of your information.
Clemion is not responsible for the privacy practices of independent third parties.
If you add third party payment links or external references to your documents, those third parties handle any payment or interaction according to their own policies.
34. CHANGES TO THIS POLICY
We may update this Privacy Policy as Clemion develops, our business changes or legal requirements change.
When we make a material change, we will provide reasonable notice where required by law.
The updated Privacy Policy will show the date on which it was last revised.
If you do not agree with a material change, you may stop using Clemion and, where appropriate, delete your account.
Changes will not remove rights that applicable law gives you.
36. DATA PROTECTION AUTHORITY
If you are located in the European Economic Area, the United Kingdom or another region with a supervisory authority for data protection, you may have the right to lodge a complaint with that authority.
We encourage you to contact us first so that we can try to resolve your concern directly.
You can find contact details for your local authority through the official resources available in your country or region.
Our contact details are set out below if you wish to reach us about a privacy matter.
35. HOW TO CONTACT US
If you have questions about this Privacy Policy, your personal information, or how Clemion handles data, you can contact us at:
Clemion
Operated by:
Clemion LTD
Registered office:
Pollard Street East, Manchester, M40 7FS, United Kingdom
Company number:
17423709
Privacy:
support@clemion.app
Support:
support@clemion.app
Website:
https://clemion.app
For data protection requests, please include enough information for us to identify your account or request and to verify your identity where necessary.
Additional information about data protection rights may be found in the Data Protection & GDPR section of the Clemion Legal page.
Data Protection & GDPR
- Effective date
- 25 August 2026
- Last updated
- 6 September 2026
This section explains how UK and European data protection law applies to Clemion and the rights that may be available to you.
It should be read together with the Clemion Privacy Policy and Data Processing Terms.
Depending on where you live and how Clemion is used, the UK GDPR, EU GDPR or other applicable privacy laws may apply.
Nothing in this section is intended to limit any right that cannot legally be restricted.
1. DATA PROTECTION FRAMEWORK
Clemion is designed to operate in accordance with applicable data protection law.
For users in the United Kingdom, this includes the UK General Data Protection Regulation and the Data Protection Act 2018 where applicable.
For users in the European Economic Area, this includes the EU General Data Protection Regulation where applicable.
Other local privacy laws may also apply depending on where you live or where personal information is processed.
This section focuses on UK and European data protection rights.
2. WHEN CLEMION IS THE CONTROLLER
Clemion generally acts as a data controller for personal information relating to:
- account creation
- authentication
- subscription management
- service communications
- security
- support
- product operation
- Clemion's own legal obligations
- other processing where Clemion determines the purpose and means
As controller, Clemion is responsible for deciding why and how that information is processed.
The Privacy Policy explains these activities in more detail.
3. WHEN CLEMION IS A PROCESSOR
When a Clemion user uses Clemion to store or manage personal information about their own clients, the Clemion user may act as the data controller and Clemion may act as the data processor.
In that situation, the Clemion user decides why the client information is processed.
Clemion processes the information to provide the service on the Clemion user's behalf and in accordance with the applicable Data Processing Terms.
If you are a client of a Clemion user and your request concerns information that Clemion user has placed into Clemion, you should normally contact the Clemion user first.
Clemion will assist the Clemion user with valid data protection requests where required by law and the Data Processing Terms.
4. OUR LEGAL BASES
Where UK GDPR or EU GDPR applies, Clemion relies on one or more lawful bases depending on the processing activity.
These may include:
Contract
Processing necessary to create and operate your account, provide requested features, manage subscriptions or otherwise perform our agreement with you.
Legitimate interests
Processing necessary for legitimate interests such as protecting Clemion, preventing misuse, maintaining security, improving reliability, responding to support issues and operating the service.
We rely on legitimate interests only where those interests are not overridden by your rights and interests.
Legal obligation
Processing necessary to comply with laws, regulatory obligations, lawful requests or legal requirements.
Consent
Processing based on your consent where consent is the appropriate legal basis.
Where we rely on consent, you may withdraw that consent at any time.
Legal claims
Processing necessary to establish, exercise or defend legal claims where permitted by law.
5. RIGHT OF ACCESS
Where applicable law gives you this right, you may ask us whether we process personal information about you and request a copy of that information.
You may also be entitled to information about why the information is processed, the categories of information involved, who receives or may receive it, how long it is expected to be retained, the source of the information where it was not obtained directly from you, and other information required by law.
Some information may be subject to lawful exemptions or restrictions.
6. RIGHT TO CORRECTION
You may ask us to correct personal information that is inaccurate.
You may also ask us to complete information that is incomplete where appropriate.
Many account details can be updated directly within Clemion.
Where information is controlled by a Clemion user rather than Clemion, you may need to contact that Clemion user.
7. RIGHT TO ERASURE
In certain circumstances, you may ask for personal information to be deleted.
Clemion also provides a self-service account deletion feature.
Deleting a Clemion account removes the account and associated user-owned content from active systems through the account-erasure process described in the Privacy Policy.
The right to erasure is not absolute.
Some information may need to be retained where required by law, for security, billing, legal claims, dispute handling or another lawful purpose.
Historical database backups may temporarily contain records until those backups expire.
Storage objects deleted through account erasure are not included in Supabase database backups.
8. RIGHT TO RESTRICTION
In certain circumstances, you may ask us to restrict the processing of your personal information.
This can apply, for example, while the accuracy of information is being disputed, the lawfulness of processing is being considered, you need information preserved for a legal claim, or an objection to processing is being assessed.
Where processing is restricted, we will handle the information in accordance with applicable law.
9. RIGHT TO OBJECT
You may have the right to object to certain processing based on legitimate interests.
Where a valid objection applies, we will stop the relevant processing unless we have compelling legitimate grounds to continue or the processing is required for legal claims.
You may also have the right to object to direct marketing.
Where applicable, optional product communications can be disabled through available email preference controls or unsubscribe mechanisms.
10. RIGHT TO DATA PORTABILITY
Where the legal requirements are met, you may have the right to receive personal information you provided to us in a structured, commonly used and machine-readable format.
You may also have the right to ask us to transmit that information to another organisation where technically feasible.
This right generally applies to certain processing based on consent or contract and carried out by automated means.
It does not apply to every category of information held by Clemion.
11. WITHDRAWING CONSENT
Where we rely on your consent to process personal information, you may withdraw that consent at any time.
Withdrawing consent does not make earlier processing unlawful if that processing was lawful before consent was withdrawn.
If consent is required for a feature and you withdraw it, that feature may no longer be available to you.
12. AUTOMATED DECISION MAKING
Clemion AI provides assistive output.
Clemion does not currently use Clemion AI to make solely automated decisions that produce legal effects or similarly significant effects about users.
Clemion AI does not determine:
- whether you receive a subscription
- whether you may create an account
- your academic grade
- your legal rights
- your eligibility for financial services
- employment decisions
- other comparable high-impact decisions
AI generated content must be reviewed by the user before use.
If Clemion introduces automated decision-making that is legally significant in the future, we will update our privacy information and provide any safeguards required by applicable law.
13. INTERNATIONAL TRANSFERS
Clemion is used internationally and some service providers may process information outside the country where you live.
Some core Clemion infrastructure is hosted in the European Union.
Clemion's primary Supabase project is hosted in North EU, Stockholm.
Other providers may process information internationally. For example, Clemion AI uses OpenAI and the relevant OpenAI project currently has Global residency.
Where UK or EU data protection law requires safeguards for international transfers, we use an appropriate legal mechanism.
Depending on the circumstances, this may include:
- an adequacy decision
- Standard Contractual Clauses
- the UK International Data Transfer Agreement
- the UK Addendum to Standard Contractual Clauses
- another lawful transfer mechanism
The exact mechanism depends on the provider and processing activity.
14. REQUESTS INVOLVING CLIENT DATA CONTROLLED BY CLEMION USERS
If you are a client of a Clemion user using Clemion, the Clemion user may be responsible for the personal information they store about you.
For example, a Clemion user may control information contained in client records, projects, contracts, quotes or estimates, invoices, questionnaires, consent forms, Client Hub, files and communications.
If your request concerns that information, you should normally contact the Clemion user first.
Where Clemion acts as processor, we will assist the Clemion user where required by applicable law.
15. IDENTITY VERIFICATION
We may need to confirm your identity before responding to certain privacy requests.
This is intended to prevent personal information from being disclosed, changed or deleted at the request of someone who is not authorised to act for you.
We will only request information that is reasonably necessary to verify the request.
Where we already have sufficient information to verify your identity, we should not ask for unnecessary additional identification.
16. AUTHORISED REPRESENTATIVES
Where permitted by law, you may authorise another person to submit a privacy request on your behalf.
We may ask for reasonable evidence that the person is authorised to act for you.
We may also need to verify your identity directly where appropriate.
17. RESPONSE TIMES
We aim to respond to valid privacy requests within the timeframe required by applicable law.
Under UK GDPR and EU GDPR, this will generally be within one month after receiving a valid request and any information reasonably required to verify it.
In certain circumstances, the response period may be extended where the request is complex or where multiple requests have been made.
Where an extension is permitted and required, we will inform you in accordance with applicable law.
18. FEES
We do not normally charge a fee for exercising data protection rights.
Where permitted by law, a reasonable fee may apply if a request is manifestly unfounded, excessive or repetitive.
In appropriate circumstances, we may also refuse to act on such a request where the law permits.
19. WHEN A REQUEST MAY BE LIMITED
Data protection rights are not absolute.
A request may be restricted or refused where an exemption or other lawful reason applies.
This may include situations involving the rights and freedoms of another person, confidential information, legal privilege, fraud prevention, security, legal obligations, legal claims or records that must lawfully be retained.
Where required, we will explain why we cannot fully comply with a request.
20. COMPLAINTS
If you have concerns about how Clemion handles your personal information, we encourage you to contact us first so we can try to resolve the issue.
You may also have the right to complain to a data protection supervisory authority.
For users in the United Kingdom, the supervisory authority is the Information Commissioner's Office.
Users in the European Economic Area may have the right to complain to the supervisory authority in the country where they live, work or where they believe an infringement occurred.
You are not required to contact us before exercising a right to complain to a supervisory authority.
22. CHANGES TO THIS SECTION
We may update this Data Protection & GDPR section when Clemion changes, our processing activities change, data protection law changes or regulatory guidance changes.
Where required, we will provide appropriate notice of material changes.
The current version will display its effective date and last updated date.
21. HOW TO EXERCISE YOUR RIGHTS
To exercise a data protection right relating to information controlled by Clemion, contact:
Clemion
Privacy:
support@clemion.app
Website:
https://clemion.app
You should provide enough information for us to understand your request and identify the relevant account or information.
Do not send unnecessary sensitive information when making a request.
If the request concerns information controlled by a Clemion user using Clemion, we may direct you to that Clemion user.
Data Processing Terms
- Effective date
- 25 August 2026
- Last updated
- 6 September 2026
These Data Processing Terms apply where Clemion processes personal data on behalf of a user of Clemion, particularly where a Clemion user uses Clemion to manage information about clients or other individuals.
They form part of the agreement governing use of Clemion.
Where applicable data protection law requires a contract between a controller and processor, including Article 28 of the UK GDPR or EU GDPR, these terms are intended to provide that contract.
These terms should be read together with the Clemion Terms of Service, the Clemion Privacy Policy and the Clemion Data Protection & GDPR section.
If there is a conflict concerning the processing of personal data on behalf of a customer, these Data Processing Terms should govern that processing to the extent required by applicable data protection law.
1. SCOPE
These Data Processing Terms apply when a Clemion user determines the purposes and means of processing personal data and Clemion processes that personal data on the user's behalf in providing the service.
This will most commonly apply to Clemion users who use Clemion to manage personal information relating to their clients.
These terms do not apply to processing for which Clemion independently determines the purposes and means. That processing is governed by the Clemion Privacy Policy and applicable law.
2. ROLES OF THE PARTIES
Where these terms apply, the Clemion user is generally the controller and Clemion is generally the processor.
If the user processes personal data on behalf of another controller, the user may instead act as a processor and Clemion may act as a subprocessor.
References to "controller" in these terms should therefore include a user acting with authority from another controller where appropriate.
Each party is responsible for complying with the obligations that apply to its role under applicable data protection law.
3. PROCESSING INSTRUCTIONS
Clemion will process personal data on the controller's documented instructions unless processing is required by applicable law.
The controller's instructions include using Clemion, configuring the workspace, creating and managing records, uploading information, sharing documents, using Client Hub, using questionnaires and consent forms, using contracts and electronic signatures, using Clemion AI where selected, using other features that process client information, and instructions provided through support or other authorised channels.
Clemion will not intentionally process controller data for unrelated purposes.
Where Clemion is legally required to process personal data outside the controller's instructions, Clemion will inform the controller before doing so where the law permits.
4. CONTROLLER RESPONSIBILITIES
The controller is responsible for ensuring that it has a lawful basis for processing the personal data, the personal data was collected lawfully, appropriate privacy information has been provided to individuals, any required consent has been obtained where consent is relied upon, its instructions to Clemion comply with applicable law, it does not use Clemion to process information unlawfully, people authorised to use its Clemion account are appropriately permitted to access the information, and client information entered into Clemion is relevant and appropriate for the intended purpose.
The controller is responsible for deciding whether Clemion is suitable for the nature of the personal data it chooses to process.
Clemion does not determine the controller's legal basis for processing its own client information.
5. NATURE AND PURPOSE OF PROCESSING
Clemion processes personal data to provide the features selected and used by the controller.
Depending on the Clemion user's use of Clemion, processing may include collecting, recording, organising, structuring, storing, retrieving, viewing, editing, sharing, transmitting, generating documents, receiving responses, managing files, creating backups, protecting information, deleting information and other processing necessary to provide the service.
The purpose is to provide Clemion's business management, client management, document, communication, productivity and related functionality.
6. DURATION OF PROCESSING
Clemion processes controller data for as long as necessary to provide the service and while the relevant account or data remains active, subject to the Terms, Privacy Policy and these Data Processing Terms.
Processing may continue for a limited period where information must be retained for backup cycles, security, fraud prevention, legal obligations, billing, legal claims or other lawful purposes.
Account deletion and data deletion are handled as described in the Privacy Policy.
7. CATEGORIES OF DATA SUBJECTS
Depending on how Clemion is used, controller data may relate to clients, prospective clients, client representatives, client contacts, project participants, contract signatories, questionnaire respondents, consent form respondents, Client Hub users and other people whose information the controller chooses to manage through Clemion.
Clemion does not require the controller to upload information about every person in these categories. The actual categories depend on the controller's use of the service.
8. TYPES OF PERSONAL DATA
Controller data may include, depending on the features used, name, email address, telephone number, postal or business address, company or organisation information, project information, appointment or scheduling information, quotes and estimates, contract information, signatures, invoice and receipt information, payment-related references, questionnaire responses, consent form responses, files, photographs, videos, documents, communications, Client Hub information and other information entered or uploaded by the controller or an authorised client.
Clemion does not need or request all of these categories. The exact data processed depends on what the controller chooses to use.
9. SPECIAL CATEGORY AND SENSITIVE DATA
Clemion is not designed as a specialist platform for storing highly sensitive regulated information such as medical records.
However, some features, particularly questionnaires, consent forms, files and free-text fields, may allow a controller or client to enter information that is sensitive or may qualify as special category personal data under applicable law.
The controller is responsible for determining whether it is lawful and appropriate to process that information through Clemion and for satisfying any additional legal requirements that apply.
10. CONFIDENTIALITY
Clemion will ensure that people authorised to process controller data on Clemion's behalf are subject to appropriate confidentiality obligations.
Access to controller data should be limited to people and systems that need it for authorised purposes.
Clemion will not intentionally disclose controller data except on the controller's instructions, as necessary to provide the service, to authorised subprocessors, where required by law, or as otherwise permitted under these terms.
11. SECURITY
Clemion will maintain appropriate technical and organisational measures designed to protect controller data against unauthorised access, unauthorised disclosure, accidental loss, unlawful destruction, alteration, misuse and other unlawful processing.
Measures may include, where appropriate, authentication, access controls, row level security, encryption in transit, provider-managed encryption at rest, private Storage controls, secure account deletion, logging and monitoring, backup and recovery measures, restricted service credentials, separation of user-owned data, Client Hub protection features and software and infrastructure security practices.
Security measures may evolve as technology, risks and Clemion change. No online service can guarantee absolute security.
12. SUBPROCESSORS
The controller authorises Clemion to use subprocessors where reasonably necessary to provide, secure and operate the service.
Subprocessors may provide services such as cloud infrastructure, database hosting, authentication, Storage, hosting, email delivery, AI processing, payments, mobile push delivery and other technical services.
Providers currently relevant to Clemion, depending on the feature used, may include Supabase, Vercel, Stripe, Resend, OpenAI, Expo, Apple and Google.
Not every provider acts as an Article 28 subprocessor in every context. Some providers may act as an independent controller, a processor or a subprocessor depending on the service and processing activity involved.
Clemion uses providers in the role appropriate to the relevant processing and applicable data protection law.
13. CHANGES TO SUBPROCESSORS
Clemion may add or replace subprocessors as the service evolves.
Where required by applicable data protection law, Clemion will provide reasonable notice of a material change involving a subprocessor that processes controller data.
Where applicable law gives the controller a right to object, the controller may raise a reasonable data protection objection. Clemion and the controller will attempt in good faith to address the concern.
If a reasonable solution is not available, the controller may stop using the affected feature or terminate the affected service in accordance with the Terms.
14. SUBPROCESSOR OBLIGATIONS
Where Clemion appoints a subprocessor to process controller data, Clemion will impose data protection obligations appropriate to the services being provided and as required by applicable law.
Clemion remains responsible for its obligations concerning subprocessors to the extent required by applicable data protection law.
15. INTERNATIONAL TRANSFERS
Controller data may be processed in countries other than the country where the controller or data subject is located.
Some core Clemion infrastructure is hosted in the European Union. The primary Clemion Supabase project is hosted in North EU, Stockholm.
Other providers may process information internationally. Clemion AI uses OpenAI and the relevant OpenAI project currently has Global residency.
Where UK or EU data protection law restricts international transfers, Clemion will use an appropriate lawful transfer mechanism where required. This may include an adequacy decision, Standard Contractual Clauses, the UK International Data Transfer Agreement, the UK Addendum to Standard Contractual Clauses or another mechanism recognised by applicable law.
16. DATA SUBJECT REQUESTS
Where Clemion receives a request from an individual concerning controller data and Clemion acts as processor, Clemion may direct the individual to the controller.
Taking into account the nature of the processing, Clemion will provide reasonable assistance to enable the controller to respond to valid requests where required by applicable law.
This may include requests involving access, correction, erasure, restriction, objection, data portability and other applicable rights. The controller remains responsible for determining how to respond to the request.
17. SECURITY INCIDENTS AND PERSONAL DATA BREACHES
If Clemion becomes aware of a personal data breach affecting controller data, Clemion will notify the controller without undue delay where required by applicable data protection law.
The notification will provide information reasonably available to Clemion that is relevant to the controller's legal obligations. This may include, where available, the nature of the incident, categories of information affected, likely consequences, measures taken or proposed and relevant contact information.
Information may be provided in stages where it is not all available at the same time.
Clemion's notification of an incident does not by itself constitute an admission of fault or liability.
18. CONTROLLER BREACH RESPONSIBILITIES
The controller is responsible for determining whether it must notify affected individuals, a supervisory authority or another organisation of a personal data breach involving data it controls.
Clemion will provide reasonable assistance where required by applicable law and where the relevant information is available to Clemion.
19. DATA PROTECTION IMPACT ASSESSMENTS
Taking into account the nature of processing and information available to Clemion, Clemion will provide reasonable assistance where a controller is required to conduct a Data Protection Impact Assessment relating to its use of Clemion.
The controller remains responsible for determining whether a DPIA is required and for completing it.
20. REGULATORY CONSULTATION
Where applicable law requires prior consultation with a supervisory authority concerning processing carried out through Clemion, Clemion will provide reasonable assistance relating to its processing activities where required and reasonably available.
21. RETURN AND DELETION OF CONTROLLER DATA
During active use of Clemion, available product features may allow the controller to access, export, download or delete certain information.
When an account is permanently deleted, Clemion's account-erasure process removes the account and known user-owned content from active systems as described in the Privacy Policy. Known private user-owned Storage is included in the account-erasure cleanup process.
Historical database backups may temporarily contain deleted database records until those backups expire. Supabase database backups do not include Storage API objects.
Clemion may retain limited information where required for legal obligations, billing or tax requirements, security, fraud prevention, legal claims or other lawful purposes.
Where applicable data protection law requires return or deletion of controller data at the end of processing, Clemion will comply subject to lawful retention requirements.
22. AUDITS AND COMPLIANCE INFORMATION
Clemion will make available information reasonably necessary to demonstrate compliance with applicable processor obligations where required by data protection law.
Where a controller has a legally applicable audit right, the parties should first use available documentation, security information and other reasonable evidence.
If an additional audit is legally required, it should be reasonable in scope, protect the security and confidentiality of other users, avoid unnecessary disruption and comply with reasonable security requirements.
Clemion does not have to provide access that would compromise another user's data, security controls, confidential information belonging to another person or trade secrets beyond what the law requires.
23. COSTS OF ASSISTANCE
Ordinary assistance reasonably required under applicable data protection law is provided as part of Clemion's processor responsibilities.
Where a request requires exceptional, repetitive or unusually extensive work beyond what is reasonably required to provide the service, Clemion may discuss reasonable costs with the controller where permitted by law.
24. UNLAWFUL INSTRUCTIONS
If Clemion reasonably believes an instruction from the controller infringes applicable data protection law, Clemion may inform the controller and may suspend the affected processing where necessary while the issue is addressed.
Clemion is not required to follow an instruction that would require unlawful processing.
25. CLEMION AI AND CONTROLLER DATA
Where a controller chooses to use Clemion AI with controller data, the controller instructs Clemion to process the relevant information for the requested AI task.
Clemion AI currently uses OpenAI through the Responses API. Only information relevant to the requested task should be sent through the Clemion AI processing flow. Depending on the feature, this may include prompts, client names, business context, document excerpts and workspace information.
Clemion applies its existing AI context scrubbing controls to covered sensitive fields.
Production OpenAI Responses API requests explicitly use store set to false. Clemion's OpenAI organisation settings currently have API input and output sharing for model improvement disabled.
OpenAI may process controller data internationally as necessary to provide the requested AI output. The controller is responsible for deciding whether it is appropriate and lawful to submit particular controller data to an AI feature.
26. CLIENT HUB AND PUBLIC LINKS
Where a Clemion user uses Client Hub or another client-facing link, Clemion processes information necessary to make the selected information available to the intended recipient.
The Clemion user is responsible for choosing what information to share, ensuring the recipient information is appropriate, using available protection features where appropriate and revoking access when it is no longer required.
Where Protect Client Hub is enabled, Clemion may use email verification and a trusted-browser mechanism as described in the Privacy Policy. No security feature removes the controller's responsibility to share information carefully.
27. RECORDS OF PROCESSING AND COOPERATION
Clemion will maintain records relating to its processing activities where required by applicable law.
Each party will reasonably cooperate with the other where necessary to demonstrate compliance with applicable data protection obligations concerning the services.
28. LIABILITY
Liability relating to these Data Processing Terms is subject to the liability provisions in the Clemion Terms of Service except where applicable law requires otherwise.
Nothing in these Data Processing Terms excludes or limits liability where doing so would be unlawful.
29. ORDER OF PRECEDENCE
If these Data Processing Terms conflict with another part of the Clemion Terms concerning Clemion's processing of controller data on behalf of the controller, these Data Processing Terms prevail to the extent of that conflict.
For processing where Clemion acts independently as controller, the Privacy Policy applies.
30. CHANGES TO THESE DATA PROCESSING TERMS
Clemion may update these Data Processing Terms where the service changes, subprocessors change, security practices evolve, data protection law changes or regulatory guidance changes.
Where required by law or contract, Clemion will provide appropriate notice of material changes.
The current version will display its effective date and last updated date.
ANNEX 1. DETAILS OF PROCESSING
Subject matter: provision of Clemion features selected by the controller, including client management, projects, business documents, Client Hub, questionnaires, consent forms, files, communications and related functionality.
Duration: for the duration of the controller's use of the relevant Clemion services and any limited lawful retention period described in the Terms, Privacy Policy and these Data Processing Terms.
Nature and purpose: processing necessary to host, organise, retrieve, display, transmit, secure, support, delete and otherwise operate controller-selected Clemion functionality.
Data subjects may include clients, prospective clients, client representatives, project participants, signatories, questionnaire respondents, consent form respondents, Client Hub users and other individuals whose information the controller lawfully processes through Clemion.
Personal data may include identity and contact information, business information, project information, appointments, communications, contract information, signatures, quotes and estimates, invoice and receipt information, questionnaire responses, consent responses, files and media, Client Hub information and other information supplied through the service.
Special category data is not required as a general condition of using Clemion. It may be entered by controllers or clients through flexible fields, questionnaires, consent forms, files or other user-controlled content. The controller is responsible for ensuring any such processing is lawful.
Processing operations may include collection, recording, organisation, storage, retrieval, consultation, use, transmission, sharing at the controller's direction, security, backup, deletion and other operations necessary to provide the service.
ANNEX 2. TECHNICAL AND ORGANISATIONAL MEASURES
Access control: authentication and authorisation controls, row level security and user-scoped access where implemented, and restricted administrative or service credentials.
Data protection in transit and storage: encrypted network transport using provider-supported secure connections and provider-managed encryption at rest where applicable, with private Storage for user-owned sensitive files where appropriate.
Tenant and user separation: user-scoped database and Storage controls, with ownership-aware paths and access policies.
Account security: secure authentication infrastructure, OAuth where selected, session management and available Client Hub email verification protection.
Data deletion: fail-closed account erasure for known user-owned Storage, database deletion and cascade processes, and public link revocation.
Backup and resilience: scheduled database backups, Storage objects treated separately from database backups, and infrastructure resilience provided through relevant hosting providers.
Application security: input validation, access controls, secret management, restricted server-side operations, and logging and monitoring where appropriate.
AI data minimisation: AI context scrubbing for covered sensitive fields, OpenAI Responses API requests configured with store set to false, and no OpenAI persistent conversation state used by Clemion.
Organisational measures: access limited to authorised purposes, confidentiality obligations where applicable, and security and privacy practices reviewed as Clemion evolves.
31. CONTACT
Questions concerning these Data Processing Terms can be sent to:
Clemion
Privacy:
support@clemion.app
Legal:
support@clemion.app
Website:
https://clemion.app