ClashWise

Legal

Data Processing Agreement

How we process personal data on your behalf and how to request a signed agreement.

This page is a summary of how ClashWise handles personal data when delivering the product and how to request a binding, signed Data Processing Agreement (DPA) for your organization. It is not itself a contract, and nothing on this page creates or modifies any legal obligation.

Our role

When you or your organization use ClashWise, we act as a data processor on your behalf for the personal data you or your team upload or generate while using the product (for example, names and contact details attached to clashes, or account and usage data). Your organization remains the data controller. Where we use other companies to help deliver the service, they act as our subprocessors. The full list, checked against the product code, is published on our subprocessors page, and we notify customers of material changes to that list. Where you connect a third-party application to ClashWise (for example, an AI client connected via MCP), we disclose data to it on your documented instruction. The connected vendor acts as your provider, not our subprocessor.

Security measures

The technical and organizational security measures we apply are described in detail at our security page, including authentication, access control, encryption in transit and audit logging. We have checked that page against the product code.

AI processing

Cloud features use Microsoft Azure OpenAI. The Azure OpenAI resource and data at rest are provisioned in Sweden, but the current GlobalStandard deployment may process prompts and responses in other Azure geographies. The Navisworks plug-in can also generate clash titles locally on the customer workstation using clash metadata rather than model geometry. Cloud fallback is optional and disabled by default; if enabled, or if the local provider cannot be created, a title-generation request may be sent to ClashWise. Local title modifications may synchronise limited audit metadata such as identifiers, naming settings, timestamps, and source-file names. Customer data is not used by ClashWise to train or fine-tune its AI models.

Data deletion

Accounts can request self-service deletion at any time. There is a 30-day recovery window after a deletion request, after which personal data is purged in a full cascade across every system that holds it. Certain records (for example, the admin audit log, retained for 7 years) are kept on legitimate-interest and legal grounds as the record that an action happened, not as personal content about you — this is described in full on /security.

Data access & export

You can export your own personal data at any time in a machine-readable format — a GDPR Article 15/20 data-subject access request ("DSAR"), available self-service from within the product.

Breach notification

If a personal-data breach occurs, we commit to notifying affected customers without undue delay, and in any case within 72 hours of becoming aware of the breach, consistent with GDPR Article 33/34 obligations.

Requesting a signed DPA

If your organization requires a signed DPA (for example, as part of a vendor security review), email support@clashwise.ai and we will send the current template for execution.

See also: our security controls, our subprocessor list, and our privacy policy.