Clausery OÜ

Terms of Use

1Service Description & Scope

1.1

These Terms of Use govern access to and use of the Clausery Documentation Engine ("the Service"), a document management and compliance check portal operated by Clausery OÜ ("Clausery", "we", "us"). The Service is provided exclusively to enterprise clients operating as organizations, and not to individual consumers. Any natural person accessing the Service does so as a representative of an organization that has entered into a subscription or account relationship with Clausery, and all rights granted under these Terms flow to that organization rather than to the individual personally.

1.2

The Service enables an organization to author, structure, version, and maintain compliance documentation as sets of numbered clauses, with supporting functionality for definitions, cross-references, and a shared glossary within the organization's own workspace. The Service supports multiple organizations on shared infrastructure, with each organization's documents and glossary presented only within that organization's own working context. Where a user is associated with more than one organization, access to each organization's content is contingent on that user having a valid role within that specific organization, and Clausery is responsible for maintaining the logical separation between organizations' data as part of the Service's access control model.

1.3

The Service maintains a version history for documents created and edited within the platform, allowing changes to be tracked over time and prior states to be referenced. Clausery retains organizational content, including document versions and associated metadata, for as long as the organization maintains an active account, and in accordance with the data retention practices communicated to the organization separately; retention and deletion of content upon termination are addressed further in this document. Clausery does not represent the Service as a substitute for an organization's own recordkeeping obligations under law or contract, and each organization remains responsible for determining whether the Service's retention behavior satisfies its own regulatory recordkeeping duties.

1.4

Certain features of the Service may incorporate automated or AI-assisted functionality to support drafting, consistency checking, or document analysis. Use of any such functionality is subject to the Artificial Intelligence & Automation Use section of these Terms, and does not relieve the organization of responsibility for reviewing and approving the final content of its own documents. The Service is not itself a certification body, auditor, or legal adviser, and any indication of compliance status, consistency, or coverage generated within the Service is a tool to assist the organization's own compliance work, not a substitute for independent legal, audit, or regulatory judgment.

1.5

The Service involves limited processing of user account data, such as names, organizational affiliations, and login credentials, necessary to operate accounts, roles, and access control across organizations. Clausery does not require or knowingly process special categories of personal data or other privileged data as part of the core Service, and organizations should not upload such data into document content unless expressly agreed with Clausery in writing. Scope and handling of personal data are addressed in more detail in the Data Protection & Personal Data Processing section of these Terms.

2Eligibility & User Account

2.1

The Service is provided on a business-to-business basis to enterprise clients acting in the course of their professional or organizational activities, and is not intended for consumer use. By registering for or accessing the Service, an individual represents that they are doing so on behalf of, and with the authority to bind, the organization that has entered into a subscription or engagement with Clausery, and that they are at least the age of majority in their jurisdiction of residence.

2.2

Access to the Service is granted through individual user accounts associated with one or more organizations within Clausery's multi-tenant environment. Each user account is uniquely tied to a person and is not intended to be shared among multiple individuals; credentials must be kept confidential and used only by the individual to whom they were issued. A user may belong to a single organization or to multiple organizations, but at any given time interacts with the Service within a single active organizational context, selected by the user, so that documents and glossary content of other organizations remain inaccessible during that session.

2.3

Account creation, role assignment, and the management of which individuals may access a given organization's workspace are governed by the roles and permissions structure of the Service. Organization administrators are responsible for determining which individuals are granted accounts within their organization and for promptly requesting removal or role changes when a person's need for access ends, such as upon departure from the client organization or a change in responsibilities. Clausery relies on the client organization to maintain the accuracy of this information and does not independently verify the employment or authorization status of individual users beyond the account and role data provided.

2.4

Registration requires limited account data, including name, organizational affiliation, and login credentials, which is used solely to operate accounts, enforce role-based access, and maintain the integrity of the multi-tenant environment. Users must provide accurate information when creating or updating their account and must notify their organization administrator or Clausery of any known unauthorized use of their credentials or account. Clausery may suspend or decline to activate an account where registration information appears false, incomplete, or where activation would conflict with an organization's existing access arrangements.

3Access Control & Multi-Tenant Security

3.1

The Service operates as a multi-tenant environment in which each enterprise client is provisioned as a distinct organization. A user may hold membership in one or multiple organizations, but at any given time works within a single active organization selected through the workspace switcher; documents, glossary entries, and other organizational content displayed to a user are scoped exclusively to that active organization. This design is intended to prevent inadvertent cross-organization visibility or editing and to ensure that each organization's compliance documentation remains logically segregated from that of other clients.

3.2

Access within an organization is governed by a role-based structure. Administrators of an organization are responsible for determining which individuals may access their organization's workspace and for assigning appropriate roles and permissions to those individuals, including contributors who author or edit documents and reviewers who require read or traceability access. A superadmin role exists at the platform level for the operation and administration of organizations generally, including the creation of new organizations; this role is limited to Clausery personnel or designated administrators and is not a substitute for an organization's own internal access governance.

3.3

Each user account is uniquely tied to an individual and is not intended for shared use across multiple people. Organizations are responsible for promptly updating role assignments and revoking access when a user's employment, engagement, or need for access ends, and for maintaining accurate records of who holds administrative privileges within their workspace. Clausery relies on organizations to manage the accuracy of their own user rosters and role assignments, as the Service does not independently verify the ongoing employment or authorization status of individual users.

3.4

Because the multi-tenant architecture is central to how the Service isolates client content, users must not attempt to access, probe, or interact with organizations, documents, or accounts other than those to which they have been granted access, and must not attempt to circumvent the role and permission controls governing their organization. Any suspected unauthorized access, compromised credentials, or misuse of access controls should be reported to Clausery promptly so that appropriate steps can be taken to protect the affected organization's content and other clients within the shared environment.

4Data Protection & Personal Data Processing

4.1

Clausery's processing of personal data in connection with the Service is limited in scope. The personal data involved consists of user account data necessary to operate the multi-tenant environment, including names, organizational affiliations, login credentials, and role assignments. Clausery does not require, and this Service is not designed to collect or process, special categories of personal data or other privileged or sensitive personal information. Organizations must not upload or embed such data within document content, and Clausery bears no responsibility for personal data submitted in violation of this restriction.

4.2

Where an enterprise client's personnel data is processed to provision accounts, assign roles, or enforce access control across organizations, Clausery acts in the capacity necessary to operate the Service on the client's instructions as reflected in these Terms. Organization administrators remain responsible for determining who may be granted an account, for the accuracy of the personal data submitted for that purpose, and for promptly instructing changes, such as revoking access, when a person's affiliation with the organization ends.

4.3

Personal data is retained only for as long as necessary to operate user accounts and maintain the associated version history of documents, consistent with the retention practices described elsewhere in these Terms. Account data tied to an organization is scoped to that organization's workspace within the multi-tenant environment and is not accessible to other organizations; access controls and role-based permissions are the primary safeguard applied to this data, consistent with Clausery's approach to access control under its ISO 27001-aligned practices.

4.4

Users and organizations remain responsible for ensuring that any personal data they choose to include within document content itself, as opposed to account data, is lawfully collected and appropriate for storage within a compliance documentation platform. Clausery processes such document content as instructed by the organization and does not review it for the presence of personal data. Questions regarding the categories of account data processed, applicable retention periods, or the exercise of individual rights in respect of account data should be directed to Clausery through the organization's administrators.

5Document Management: Versioning & History

5.1

The Service maintains a version history for documents authored and edited within the platform. As a document is structured into numbered clauses, changes to clause content, numbering, definitions, and cross-references are tracked over time so that prior states of a document can be referenced. This versioning function is intended to give organizations and their document owners a reliable record of how a document has evolved, and to support internal review and audit activities that depend on being able to demonstrate the history of a controlled document.

5.2

Version history is maintained at the document level within each organization's workspace and reflects edits made by users authorized to access that document under the organization's role-based access structure. Organizations remain responsible for ensuring that only appropriately authorized personnel make substantive edits to documents, and for reviewing version history where they need assurance that a document's content and structure have not been altered other than through authorized activity. Clausery does not warrant that version history constitutes a substitute for an organization's own internal change-approval or sign-off procedures; it is a supporting record, not a governance process in itself.

5.3

Clausery retains organizational document content, including associated version history, for as long as the organization maintains an active workspace within the Service, and for such further period as may be necessary to operate the Service, meet retention obligations described elsewhere in these Terms, or resolve disputes. Users and organizations should not treat the Service as a permanent archival system independent of their own record-keeping obligations, and are responsible for exporting or otherwise preserving document content where longer-term or independent retention is required for their compliance or regulatory purposes.

5.4

Because prior states of a document may be retained as part of version history, organizations should be mindful of the content they include in document text, consistent with the data protection commitments described elsewhere in these Terms. Clausery does not selectively purge individual historical versions on request outside of standard account or organization offboarding, and organizations should account for this when determining what information is appropriate to include within document content over time.

6Artificial Intelligence & Automation Use

6.1

Certain features of the Service may incorporate automated or AI-assisted functionality to support tasks such as drafting suggestions, consistency checking across clauses, definitions, and cross-references, or analysis of document structure. Such functionality operates on and within the structured clause framework that underlies the Service and is intended to support the organization's own authoring and review activities rather than to replace them. Any such functionality is provided as an aid to users who retain full authorship, decision-making, and approval responsibility over document content.

6.2

Output produced by automated or AI-assisted functionality is not warranted to be accurate, complete, or compliant with any particular regulatory, statutory, or contractual requirement applicable to the organization. Organizations and their authorized users remain solely responsible for reviewing, verifying, and approving any content, suggestion, or flagged inconsistency generated through such functionality before it is relied upon, incorporated into a governing version of a document, or presented to auditors, regulators, or other third parties.

6.3

Use of automated or AI-assisted functionality does not alter the access control, role-based permission, or multi-tenant isolation principles described elsewhere in these Terms. Any content processed through such functionality remains subject to the same organizational boundaries, version history retention, and data handling practices applicable to the document within which it is used, and no organization's content is used to influence or train functionality made available to another organization.

6.4

Organizations should not submit, and users should not include, sensitive personal data or privileged information within document content processed by automated or AI-assisted functionality beyond the limited account data necessary to operate the Service, as described in the Data Protection & Personal Data Processing section. Clausery may update, refine, or withdraw specific automated or AI-assisted features from time to time as part of the ordinary evolution of the Service, and continued use of the Service following such changes constitutes acceptance of the functionality as then made available.

7Acceptable Use & Prohibited Activities

7.1

Users and organizations must use the Service only for legitimate document management and compliance documentation purposes consistent with the multi-tenant, role-based structure described elsewhere in these Terms. Access rights granted to a user account are personal to that individual and tied to the organization or organizations to which the account belongs; users must not share login credentials, attempt to operate an account on behalf of another person, or use another user's session or credentials to access the Service.

7.2

Users must not attempt to access, probe, enumerate, or otherwise interact with organizations, documents, glossary entries, or account data belonging to an organization to which they have not been granted access. This includes attempting to bypass, circumvent, or test the boundaries of the access control and multi-tenant isolation mechanisms that keep each organization's documents and glossary separate from those of other organizations, whether by manipulating identifiers, exploiting misconfigured permissions, or any other means. Users must also not attempt to interfere with, disable, or degrade the version history functionality, including attempting to alter, delete, or falsify recorded prior states of a document outside of the normal editing and versioning functionality provided by the Service.

7.3

Where automated or AI-assisted functionality is used to support drafting, consistency checking, or document analysis, users must not submit sensitive personal data or privileged or otherwise inappropriate content to such functionality, and must not attempt to use that functionality for purposes unrelated to the organization's own compliance documentation, including attempting to extract, reverse engineer, or infer the underlying models, prompts, or configurations supporting such features. Organizations remain responsible for the content their users submit through the Service, whether entered directly into document clauses or processed through automated or AI-assisted features.

7.4

Users must not upload, store, or process content within the Service that is unlawful, infringes the rights of third parties, or that the organization is not authorized to include in its documentation, and must not use the Service to store or transmit malicious code, attempt unauthorized access to Clausery's infrastructure, or engage in activity that could disrupt the availability or integrity of the Service for other organizations. Organization administrators are responsible for ensuring that users under their organization comply with these obligations, and Clausery reserves the right to investigate suspected violations and to take action consistent with the suspension and termination provisions described elsewhere in these Terms.

8Term, Suspension & Termination

8.1

These Terms remain in effect for as long as an organization maintains an active subscription or account with Clausery, or until terminated in accordance with this section. Access to the Service is provisioned per organization within the multi-tenant environment, and an organization's term begins upon account provisioning and role assignment for its initial administrators and continues on the basis agreed between the organization and Clausery.

8.2

Clausery may suspend access to an organization's workspace, or to a specific user account, where necessary to protect the integrity of the multi-tenant environment, including where there is a reasonable basis to believe that a user is attempting to access, probe, or interact with organizations, documents, or accounts to which access has not been granted, or where use of automated or AI-assisted functionality involves submission of sensitive personal data or privileged content contrary to these Terms. Suspension is limited to what is reasonably necessary to address the underlying concern and, where practicable, Clausery will notify the affected organization's administrators of the reason for suspension.

8.3

An organization may terminate its use of the Service at any time by ceasing use and notifying Clausery, subject to any separate commercial agreement governing subscription terms, fees, or notice periods. Clausery may terminate an organization's access where the organization has materially breached these Terms, including the access control and acceptable use obligations described elsewhere, and such breach is not remedied within a reasonable period after notice, or where continued provision of the Service would expose Clausery or other organizations to security or legal risk.

8.4

Upon termination, Clausery will cease providing active access to the organization's workspace. Document content and associated version history are retained for as long as the organization maintains an active workspace, as described in the Document Management section, and Clausery will retain such content following termination only for such further period as may be necessary for legitimate business, legal, or archival purposes, consistent with the retention practices described elsewhere in these Terms. Organizations remain responsible, prior to termination, for exporting or otherwise preserving any document content or account data they wish to retain, as continued access to that content cannot be guaranteed once the workspace is no longer active.

8.5

Termination does not relieve either party of obligations accrued prior to termination, including obligations relating to account data, document content confidentiality, and any outstanding payment obligations under a separate commercial agreement. Provisions of these Terms that by their nature are intended to survive termination, including those addressing data protection, liability, and governing law, continue to apply after the term ends.

9Liability & Indemnification

9.1

The Service is provided to enterprise clients as a tool to support the authoring, structuring, versioning, and maintenance of compliance documentation. It does not constitute legal, regulatory, or compliance advice, and Clausery makes no warranty that use of the Service, including any document structure, clause numbering, glossary, cross-reference functionality, or automated or AI-assisted features, will satisfy any particular regulatory, statutory, contractual, or audit requirement applicable to an organization. Organizations remain solely responsible for the accuracy, adequacy, and regulatory sufficiency of the document content they create, edit, and maintain within the Service.

9.2

To the maximum extent permitted by applicable law, Clausery's aggregate liability arising out of or in connection with these Terms or use of the Service, whether in contract, tort, or otherwise, is limited to direct damages and shall not extend to indirect, incidental, special, consequential, or punitive damages, including loss of profits, loss of data, or loss of business opportunity, even where Clausery has been advised of the possibility of such damages. This limitation reflects the nature of the Service as a document management and compliance-check portal operating within a multi-tenant environment, rather than a guarantor of an organization's regulatory outcomes.

9.3

Clausery is not liable for consequences arising from an organization's own administration of its workspace, including its role-based access assignments, its determination of which individuals may hold access to the organization, its retention or deletion of document content, or its choice to include personal data, sensitive information, or privileged content within document text or within material submitted to automated or AI-assisted functionality. Clausery likewise is not liable for output produced by automated or AI-assisted functionality that an organization relies upon without independent review, consistent with the disclaimers set out in the Artificial Intelligence & Automation Use section.

9.4

Each organization agrees to indemnify and hold Clausery harmless from claims, losses, or liabilities arising from the organization's breach of these Terms, including unauthorized attempts to access, probe, or interact with other organizations' documents, glossary entries, or account data within the multi-tenant environment; the organization's inclusion of unlawful content or content it is not authorized to store within the Service; or the organization's mismanagement of its own account data, role assignments, or user access. This indemnification obligation is without prejudice to any separate commercial agreement between the parties addressing fees, service levels, or additional liability terms.

10Governing Law & Dispute Resolution

10.1

These Terms, and any dispute or claim arising out of or in connection with them or with use of the Service, including the Service's provision to enterprise clients as a document management and compliance check portal, are governed by the laws of Estonia, without regard to conflict of laws principles, reflecting the jurisdiction in which Clausery OÜ is established.

10.2

Before initiating formal proceedings, the parties will attempt in good faith to resolve any dispute arising under these Terms through direct negotiation between authorized representatives of the organization and Clausery. Either party may raise a dispute by written notice describing the issue with reasonable specificity, including, where relevant, matters concerning access control, role assignments within an organization's workspace, document versioning and retention, or the use of automated or AI-assisted functionality.

10.3

Where a dispute cannot be resolved through good-faith negotiation within a reasonable period, it will be submitted to the exclusive jurisdiction of the competent courts of Estonia, and each party consents to the personal jurisdiction and venue of those courts for this purpose. This applies regardless of the country from which an organization or its users access the Service, given its multi-tenant, cross-border operation.

10.4

Nothing in this section limits either party's ability to seek urgent injunctive or equivalent interim relief from a competent court where necessary to prevent unauthorized access to an organization's workspace, protect the integrity of the multi-tenant environment, or address an imminent risk to document content or account data, pending resolution of the underlying dispute through the mechanism described above.

10.5

This section does not create a different remedy or forum for matters otherwise addressed elsewhere in these Terms, including obligations relating to termination, liability, or indemnification, which remain governed by the terms of the corresponding sections and are subject to the same governing law and dispute resolution mechanism set out here.