Privacy Policy

CloviReach

Effective date: draft — set on review
Contact: enable JavaScript to view
Generated: 2026-06-10T00:00:00.000000+00:00

This document was machine-generated from a template and IS NOT LEGAL ADVICE. It is a starting draft that requires review by a qualified attorney before publication.

1. Introduction and Controller Identity

This Privacy Policy ("Policy") is issued by CloviTek AI ("we," "us," "our"), the operator of CloviReach. It explains how we collect, use, disclose, and protect personal data in connection with the CloviReach platform and its related services. For privacy inquiries or to exercise your rights, contact us at enable JavaScript to view. We may update this Policy from time to time; material changes will be communicated to you, and where required by law, we will seek renewed consent. Detailed retention periods for each data category are set out in our Data Handling and Deletion Schedule.

2. Definitions

3. Data We Collect and Why

We collect personal data through your interactions with CloviReach. Retention periods for each category are detailed in our Data Handling and Deletion Schedule.

CategoryExamplesPurposeLawful Basis
Contact & Identity InformationName, email address, job title, companyAccount creation, authentication, supportContract, Legitimate Interests
Account & Profile DataUsername, hashed password, subscription tier, user IDAccount management, security, personalizationContract, Legitimate Interests
Billing & Payment DataBilling address, payment method last four digits, transaction historyPayment processing, invoicing, tax complianceContract, Legal Obligation
Usage & Activity DataLogin timestamps, IP address, browser/device info, features accessed, campaign metricsAnalytics, security monitoring, service improvementLegitimate Interests, Consent (analytics)
Contact Data (User-Uploaded)Recipient names, email addresses, phone numbers, custom fieldsEnabling outreach campaigns on your behalfContract (we act as Processor for this data; you are Controller)
Campaign ContentMessage templates, subject lines, sequences, attachmentsService delivery, campaign execution and historyContract
AI-Generated OutputsAI-suggested copy, personalization tokens, engagement summariesService delivery, output historyContract, Legitimate Interests
Support & CommunicationsSupport tickets, email correspondence, chat transcriptsSupport delivery, dispute resolution, service qualityContract, Legitimate Interests
Marketing & PreferencesEmail opt-in status, campaign interactions, subscription preferencesMarketing (with consent), preference managementConsent, Legitimate Interests
Cookies & Tracking DataSession cookies, analytics identifiers, referral sourcesSite functionality, analytics, securityConsent (non-essential), Legitimate Interests (essential)
Legal & Compliance DataConsent records, data subject requests, audit logsRegulatory compliance, legal defenseLegal Obligation, Legitimate Interests

4. User-Uploaded Contact Data — Dual Role Notice

When you upload contact lists or import recipient data into CloviReach, you act as the data Controller for that Contact Data, and CloviTek AI acts as a Processor on your behalf. You are responsible for ensuring you have a lawful basis (e.g., consent, legitimate interest) for processing each recipient's personal data and for honoring all applicable rights and obligations under data protection law. Our processing of Contact Data is governed by the data processing terms incorporated into our Terms of Service.

5. How We Use Your Information

We process your personal data only for the purposes described in this Policy and in accordance with applicable law:

6. International Data Transfers

CloviTek AI is based in the United States. Your personal data may be transferred to and processed in countries outside your country of residence, including the United States. For users in the EU, EEA, or UK, transfers to third countries rely on Standard Contractual Clauses (SCCs) adopted by the European Commission, adequacy decisions, or other appropriate safeguards as required by applicable law. Details of transfer mechanisms for individual sub-processors are available upon request at enable JavaScript to view.

7. Data Security

We implement industry-standard technical and organizational security measures to protect your personal data, including encryption of data in transit (TLS) and at rest, strict access controls and authentication requirements, regular security assessments and vulnerability management, contractual security and data processing requirements imposed on all sub-processors, and incident response procedures compliant with applicable breach notification laws. No transmission over the internet is completely secure; while we work to protect your data, we cannot guarantee absolute security.

8. Data Retention and Deletion

We retain personal data only as long as necessary for the purposes described in this Policy or as required by law. Full retention periods for each category are specified in our Data Handling and Deletion Schedule. Upon expiry of the applicable retention period or upon a verified deletion request, personal data is securely deleted or irreversibly anonymized. Deletion actions are logged and periodically audited. To submit a deletion request, contact enable JavaScript to view.

9. Sharing Your Information

We share personal data only as described below. We do not sell personal data to third parties.

CategoryPurposeSafeguards
Cloud Hosting and StorageInfrastructure, file storage, content deliveryEncryption at rest and in transit; DPA in place
AI and Language ProcessingAI-assisted copy generation and personalizationNo-training terms; DPA in place; minimal data shared
Payment ProcessingSubscription billing, invoicing, refundsPCI DSS compliant; DPA in place; card data not stored by us
Email and Notification DeliveryTransactional emails, system notificationsEncryption; DPA in place
Analytics and Error MonitoringPlatform performance, error diagnosticsAggregated or pseudonymized data; DPA in place
Legal and Regulatory AuthoritiesCompliance with legal obligations, law enforcement requestsDisclosed only as required by law or valid legal process
Business TransfersMerger, acquisition, or sale of assetsSuccessor bound by terms at least as protective as this Policy

10. Children's Privacy

CloviReach is not directed to individuals under the age of 13 (or 16 in the EU/EEA). We do not knowingly collect personal data from children. If you believe a child has provided us with personal data, please contact enable JavaScript to view immediately and we will take steps to delete such data.

11. Cookies and Tracking Technologies

We use essential cookies necessary for the Service to function, as well as functional and (with your consent) analytics cookies. Essential cookies do not require consent; non-essential cookies are set only following your affirmative consent through our cookie consent banner. You may withdraw consent or manage cookie preferences at any time through your browser settings or our consent interface. See our Cookie Policy for full details.

12. Your Rights

Depending on your jurisdiction, you may have the following rights regarding your personal data. To exercise any right, contact enable JavaScript to view. We will verify your identity and respond within the legally required timeframe (30 days for GDPR; 45 days for CCPA).

13. Governing Law

This Privacy Policy is governed by the laws of the State of Delaware, USA. For users in the EU, EEA, or UK, applicable data protection law (including GDPR and UK GDPR) also governs our processing activities to the extent required.

14. Contact

For privacy inquiries, data subject requests, or to reach our data protection contact, write to: enable JavaScript to view. We aim to acknowledge all requests within 5 business days.