clerim
Privacy Policy
Last updated: August 6, 2026
Clerim ("we", "us") is a building-operations platform for residential buildings, operated from
Ontario, Canada. This policy explains what personal information we collect through
clerim.com and app.clerim.com, how we use it, and the choices you have.
We handle personal information in accordance with the Personal Information Protection and
Electronic Documents Act (PIPEDA). Questions or requests:
hello@clerim.com.
What we collect
- Account information. Name, email address, role, and the building or company
you're associated with. Passwords are stored only as salted cryptographic hashes — we cannot
read them.
- Building-operations records. Clerim's purpose is keeping a reliable record of
what happens at a building. Depending on how you interact with a building that uses Clerim,
that record can include: vendor visit details (company, technician name and phone number,
destination, purpose, arrival and departure times), work reports, photos taken for reports
(with technical metadata such as capture time), voice dictations and their transcripts,
insurance and compliance certificates, and maintenance requests emailed to a building's
intake address.
- Technical information. An essential session cookie for signing in, and
security logs (such as sign-in events). We do not use advertising trackers or sell data to
anyone, and we do not use third-party analytics on the app.
How we use it
- To provide the service: recording visits and work, verifying vendor insurance and
compliance, and giving building staff and managers an accurate operational history.
- To secure the service: authentication, permissions, and audit records.
- To communicate: service emails (invitations, account setup) and — only with consent —
text messages such as a link to your own visit record. You can opt out of texts at any time.
AI-assisted features
Some features use artificial-intelligence services: transcribing voice dictations, drafting
structured reports from them, and categorizing intake emails. Content sent to these providers can
include personal information. We use providers under contractual terms that prohibit training on
our data and limit retention to what processing requires. AI output is a draft — a person reviews
and confirms it before it becomes part of the record, and the record shows what was AI-drafted and
human-edited.
Where data is stored
Clerim runs on cloud infrastructure (including Cloudflare and Neon) with data processed and
stored in United States data centers, under contractual protections with those
providers. Information we handle may therefore be subject to the laws of the United States. PIPEDA
permits cross-border processing with comparable protection and transparency — this notice is that
transparency.
How long we keep it
- Operational records are kept as an append-only history for the building —
that permanence is the product. Corrections are recorded as amendments rather than deletions,
so the record stays trustworthy.
- Voice recordings: the audio itself is deleted 36 months after
capture. The transcript and a cryptographic fingerprint of the recording remain part
of the record.
- Account credentials and session data are kept only while needed and are
deleted or expire on their own schedule.
Who we share it with
- The building you interact with. If you visit or work at a building that
uses Clerim, your visit and work records are part of that building's operational log and are
visible to its authorized staff and managers.
- Service providers that host and operate the platform (cloud hosting,
database, email delivery, SMS delivery, AI processing), bound by agreements limiting their use
of the data to providing the service.
- Legal requirements. We may disclose information when required by law.
We do not sell personal information, and we do not share it for advertising.
How we protect it
Encryption in transit, encryption at rest on our storage providers, salted password hashing,
hashed single-use tokens for emailed links, private media storage accessible only through
short-lived signed URLs, strict per-building access isolation, and an append-only audit trail of
access changes.
Your rights
You may request access to, or correction of, personal information we hold about you by writing
to hello@clerim.com. We'll respond within a reasonable time
and may need to verify your identity. Note that some records belong to the building's operational
history (for example, that a visit occurred) and may be retained in amended rather than deleted
form. If you're unsatisfied with our response, you may contact the Office of the Privacy
Commissioner of Canada.
Changes
We'll post any changes to this policy here and update the date above. Material changes will be
communicated to account holders.