Client Confidentiality & Data Protection
Client Confidentiality & Data Protection
Effective Date: August 18, 2026 | Last Updated: August 18, 2026
CleverXEL LLC is committed to protecting confidential, proprietary, personal, and sensitive information entrusted to us through client relationships, business operations, and digital services. We seek to handle such information responsibly and only for legitimate business purposes.
1. Our Commitment
We aim to use administrative, organizational, technical, and contractual safeguards appropriate to the nature of the information, the service being provided, and the associated risk.
• confidentiality;
• limited and appropriate access;
• responsible data use and data minimization;
• security and accountability;
• appropriate retention; and
• secure disposal.
2. Information We May Handle
Depending on the engagement, we may receive or access business records, workforce or human-resources information, policies and internal documentation, financial or performance information, contact information, project files and communications, analytics and reporting data, technical information, and information relating to employees, contractors, customers, or other individuals.
3. Confidential Client Information
We seek to use confidential client information only for purposes reasonably related to the engagement, authorized business activities, contractual obligations, or legal requirements. Confidentiality obligations may also be governed by client agreements, Statements of Work, nondisclosure agreements, data-protection terms, or other written contracts.
4. Access Controls
Access to confidential or sensitive information should be limited to personnel and service providers who reasonably require access for an authorized purpose. Depending on the engagement, access may be subject to role-based permissions, confidentiality obligations, authentication, contractual requirements, and other appropriate safeguards.
5. Data Minimization
We seek to collect, use, and retain only information reasonably necessary and proportionate to the relevant business purpose, service, or engagement, and to avoid unnecessary collection or use of sensitive information.
6. Information Security
We seek to maintain safeguards appropriate to the nature of the information and the risks of unauthorized access, use, disclosure, alteration, loss, or destruction.
• access controls and secure authentication;
• secure file-sharing and storage practices;
• encryption or other technical protections where appropriate;
• account and endpoint protections;
• vendor and service-provider review;
• confidentiality requirements;
• incident-response procedures; and
• security awareness for personnel and contractors.
7. Third-Party Service Providers
We may use technology providers, contractors, consultants, cloud services, professional advisers, and other service providers in connection with our operations or client engagements. Where such parties may access confidential or personal information, we seek to apply appropriate confidentiality, security, privacy, and contractual protections based on the nature of the service and information involved.
8. AI and Automated Technologies
Where AI or automated technologies are used in connection with client work, we seek to apply appropriate safeguards to confidential and sensitive information, consistent with our Responsible AI Use Statement and applicable contractual requirements.
9. Disclosure of Client Information
We may disclose confidential client information when authorized by the client, reasonably necessary to provide agreed services, made to an authorized service provider or professional adviser, required to protect legitimate rights or interests, required by contract, or required or permitted by applicable law, regulation, legal process, or governmental authority.
10. Retention and Secure Disposal
Information may be retained for periods reasonably necessary to provide services, maintain business records, meet contractual or legal obligations, resolve disputes, protect legitimate interests, or maintain operational records. When no longer reasonably required, information may be deleted, destroyed, anonymized, or otherwise disposed of in accordance with applicable requirements and internal retention practices.
11. Client Responsibilities
Clients are responsible for determining what information they provide and for notifying us when information requires special handling, heightened security, regulatory restrictions, or specific contractual safeguards. Clients should avoid providing information that is unnecessary for the engagement.
12. Privacy Rights
This statement describes our general approach to client confidentiality and data protection. Personal-information practices and applicable privacy rights are addressed in our Privacy Notice.
13. Security Incidents
If we become aware of a suspected or confirmed security incident involving information under our control, we intend to assess the matter and take steps appropriate to the circumstances, contractual requirements, and applicable law. Such steps may include containment, investigation, remediation, documentation, and legally required notifications.
14. Contractual Terms Control
Specific client agreements may impose confidentiality, data protection, security, retention, ownership, or information-handling requirements that differ from or supplement this statement. Where an applicable written agreement establishes specific obligations, that agreement governs the relevant engagement according to its terms.
15. Contact
Questions about this policy may be directed to:
CleverXEL LLC
Address: 2443 Fair Oaks Blvd, #306, Sacramento, CA 95825, United States
Email: clients@cleverxel.com
Phone: +1 916 999 0904