CloviSEO
This Privacy Policy is published by CloviTek Inc. It outlines how we collect, use, share, and safeguard your personal information. Please direct any privacy-related inquiries to [email protected]. We may update this Policy from time to time and will notify you of material changes; significant updates may require your renewed consent. Specific retention periods for collected data categories are outlined in our Data Handling and Deletion Schedule.
To ensure clarity, the following terms are defined: 'Personal Information' refers to any data that can identify you individually. 'Processing' encompasses any operation performed on Personal Information, including collection, storage, use, and deletion. 'Service' refers to the websites, applications, and platforms provided by CloviTek Inc. 'Third-Party Service Provider' means an external company engaged to perform functions on our behalf. 'Data Handling and Deletion Schedule' is our internal framework detailing retention timelines and secure destruction methods for each data category.
Depending on how you interact with our services, we may collect several categories of personal data. These typically include account and contact details, communication records, technical and usage information, and transaction data where applicable. We maintain detailed retention schedules for each data category in our Data Handling and Deletion Schedule.
| Category | Examples | Purpose | Lawful Basis |
|---|---|---|---|
| Contact & Identity Information | Name, business, email, phone, address | Account creation, communication, support | Contract, Legitimate Interests, Consent |
| Account & Profile Data | Username, hashed password, company, user ID | Account management, security, personalization | Contract, Legitimate Interests |
| Billing & Payment Data | Billing address, payment method (last 4), transactions, tax/VAT ID | Payments, invoicing, compliance | Contract, Legal Obligation |
| Usage & Activity Data | Logins, IP, device/browser info, features used | Analytics, security, troubleshooting | Legitimate Interests, Consent (analytics) |
| Uploaded Content | Files, documents, recordings, business data, AI outputs | Service delivery, storage, AI features | Contract, Legitimate Interests, Consent |
| Cookies, Tracking & Analytics | Cookies, device IDs, geolocation, analytics | Site functionality, analytics, personalization | Consent (non-essential), Legitimate Interests |
| Support & Communications | Support tickets, chat transcripts, email correspondence | Support delivery, dispute resolution, service quality | Contract, Legitimate Interests |
| Marketing & Preferences | Email opt-in/out, campaign interactions, subscription preferences | Marketing (with consent), preference management | Consent, Legitimate Interests |
| AI-Generated Outputs | Generated text, audio narrations, images, video, reports | Service delivery, output history | Contract, Legitimate Interests |
| Third-Party Integration Data | Data exchanged with connected services (CRMs, APIs, webhooks) | Workflow automation, integrations | Contract, Legitimate Interests, Consent |
| Legal & Compliance Data | Consent records, data subject requests, audit logs, deletion records | Compliance, legal defense, regulatory audits | Legal Obligation, Legitimate Interests |
We process your personal information solely for the specific purposes disclosed throughout this Policy and strictly in compliance with applicable data protection regulations. Processing activities include providing and maintaining our services, managing customer accounts, communicating service updates, and ensuring platform security.
Personal information may be transferred to and processed in jurisdictions outside your country of residence. Where required by applicable law, we implement appropriate international data transfer safeguards, such as contractual clauses or adequacy determinations, to ensure continuous protection standards. Specific transfer arrangements for each third-party provider are documented in our Data Handling and Deletion Schedule.
We employ industry-standard technical and organizational safeguards to prevent unauthorized access, accidental loss, or misuse of your personal information. Security measures include encryption during transmission and at rest, strict role-based access controls, routine vulnerability assessments, and enforceable security obligations for all subcontractors. Additional details regarding secure deletion techniques and internal audit protocols are maintained in our Data Handling and Deletion Schedule.
We retain personal information only for as long as necessary to fulfill the stated purposes or comply with legal obligations. Comprehensive retention timelines for each data type are specified in our Data Handling and Deletion Schedule. When retention periods expire or upon receipt of a verified deletion request, data is securely destroyed or irreversibly anonymized using recognized industry standards. All deletion and anonymization activities are logged and subject to periodic review. For data held by third-party vendors, we coordinate removal efforts and obtain written confirmation of completion. To initiate a deletion request, please contact [email protected].
We disclose personal information exclusively to vetted third-party service providers who assist in operating our business, delivering services, or conducting ancillary operations. All sharing is governed by binding data processing agreements and stringent security protocols. Under no circumstances will we sell your personal data to third parties.
| Category | Provider(s) | Data Shared | Security Measures |
|---|---|---|---|
| Cloud Hosting / CDN | AWS S3 / CloudFront, Cloudflare | Stored user data, delivery | Encryption, DPA |
| AI / Generation | CloviAI | Prompted content (as needed) | No-train terms, DPA |
| Text-to-Speech | ElevenLabs | Narration text / voice config | Voice/likeness terms, DPA |
| Payments | CloviPay | Billing info, transactions | PCI DSS, DPA |
| Email / Messaging | EmailIt | Email, name, message content | Encryption, DPA |
| Media / Video | Gumlet | Uploaded media | DPA |
Our services are not intended for individuals under the age of 13. We do not knowingly solicit or retain personal information from minors. Should you become aware that a child has voluntarily submitted personal data to us, please notify [email protected] immediately so that we may promptly remove the information from our systems.
We utilize cookies and similar tracking technologies to support platform functionality, deliver a seamless user experience, and gather usage insights. Essential and strictly necessary cookies operate automatically, while analytical and marketing cookies are deployed only after obtaining your explicit consent. Detailed preferences can be adjusted through our consent management interface or directly via your web browser settings. For comprehensive specifications, please refer to our separate Cookie Policy.
Depending on your applicable jurisdiction, you may hold certain rights regarding your personal information, including the ability to access, rectify, erase, or port your data, as well as to restrict processing or withdraw previously given consent. You also retain the right to submit complaints to the relevant data protection authority. To exercise any of these rights, please reach out to [email protected]. We will authenticate your identity and process your request within the timeframe mandated by governing regulations.
Depending on your geographic location, supplementary disclosures and regulatory notices may apply. These supplemental provisions address region-specific obligations and operational practices tailored to local data protection frameworks.
DB research unavailable: 1045 (28000): Access denied for user 'root'@'localhost' (using password: NO)
Should you have questions regarding this Privacy Policy, wish to exercise your data rights, or need to communicate with our designated privacy representative, please direct all correspondence to [email protected].