How your data moves through our systems, how we protect and isolate it, how long we keep it, and exactly how to have it deleted.
This page explains, in plain terms, how CloviTek AI handles the data you and your users entrust to us, and how you can have it deleted. It complements our Privacy Policy.
Data enters our systems when you contact us or use a service, is processed only to provide and improve that service, and is removed when it is no longer needed or when you ask us to delete it. We aim to collect the minimum necessary at each stage and to avoid keeping data without a purpose.
For the personal data of our own account holders and enquirers, CloviTek AI LLC acts as a data controller. For data that a client uploads or directs us to process on its behalf — including its customers’, staff’s, and leads’ personal data — CloviTek AI acts as a data processor / service provider, and the client is the controller. Where we act as a processor, our processing is governed by our Terms of Service and a separate Data Processing Addendum (DPA) where required. See our Privacy Policy for full detail.
Data is stored on reputable cloud infrastructure. We apply encryption in transit (for example, TLS/HTTPS for data moving between you and our services) and, where applicable, encryption at rest for stored data. Access is restricted to those who need it to operate the service, and administrative access is controlled. We align our security practices with recognised standards.
Your data may be transferred to and processed in countries outside your home jurisdiction, including the United States, by us and our sub-processors. Data residency corresponds to the configured cloud storage region. Where required, we rely on Standard Contractual Clauses (SCCs), adequacy decisions, and supplementary technical and organisational measures (such as encryption and access controls) to protect transferred data.
Each customer’s data is scoped and isolated to that customer’s account. A new account starts empty, access is scoped to the authenticated user, and one customer’s data is never pooled with or exposed to another. This isolation is a core, non-negotiable rule across everything we build and run.
We keep data only as long as it is needed for the purpose it was collected for, or as required to meet legal, security, and record-keeping obligations. Contact-form information is retained for as long as needed to handle your enquiry and reasonable follow-up. Customer service data is retained for the life of the engagement and a limited period afterward, unless you request earlier deletion.
You can ask us to delete your personal information or your account data at any time.
We keep encrypted backups so we can recover from failure. When you delete data or we action a deletion request, it is removed from active systems promptly. Copies held in routine backups are overwritten or expire on our normal backup-rotation cycle, so deleted data is not retained indefinitely. Backups are not used to restore data you have asked us to delete.
We use a limited set of third-party providers to run our services. Each sub-processor acts on our instructions under an agreement that requires it to protect the data and use it only to provide its service to us. We do not sell data to them or anyone else, we update this list as our stack changes, and we will provide 30 days’ advance notice of material additions or changes to sub-processors that affect your data. A full named list is available on request at [email protected].
For any question about how we handle your data, or to make a deletion request, contact us below.
For any data-handling question or deletion request, Reach us at [email protected] and we’ll respond promptly.
CloviTek AI LLC · 3731 S Broughtyferry Cv., Salt Lake City, UT 84106, USA · contact [email protected] · Last updated 2026-07-22. This page may be revised as our practices and services evolve; the date above always reflects the current version.