The processor terms that apply where CloviTek AI processes personal data on a customer’s behalf.
This Data Processing Addendum (“DPA”) forms part of the agreement between CloviTek AI LLC (“Processor”) and the customer (“Controller”) for the provision of the Services, and applies where CloviTek AI processes personal data on the Controller’s behalf. It supplements our Terms of Service and Privacy Policy. Where a separately signed DPA exists between the parties, that signed DPA controls.
For personal data that the Controller uploads or directs us to process, the Controller is the controller (or, under CCPA/CPRA, the business) and CloviTek AI is the processor (or service provider). For personal data of our own account holders and enquirers, CloviTek AI is the controller, as described in our Privacy Policy.
We process personal data for the duration of the agreement, for the purpose of providing and supporting the Services. The nature of processing includes hosting, storage, transmission, AI generation and review, and related operations. The categories of data subjects and personal data are those the Controller chooses to submit, which may include the Controller’s staff, customers, and prospects, and identifiers, contact details, commercial information, and content.
We process personal data only on the Controller’s documented instructions, including as set out in the agreement and this DPA, unless required to do otherwise by applicable law, in which case we will inform the Controller unless the law prohibits it. We do not sell personal data or process it for our own independent purposes.
We ensure that personnel authorised to process personal data are bound by appropriate confidentiality obligations.
We implement appropriate technical and organisational measures to protect personal data, as described in our Security Statement, including encryption in transit and at rest where supported, access controls on a least-privilege basis, network protection, monitoring, and encrypted backups.
The Controller authorises CloviTek AI to engage the sub-processors listed on our Sub-processors page. Each sub-processor is bound by data-protection obligations no less protective than this DPA. We give 30 days’ advance notice of material additions or changes to sub-processors affecting the Controller’s data, and the Controller may raise a reasonable objection within that period.
Taking into account the nature of processing, we assist the Controller by appropriate technical and organisational measures, insofar as possible, to respond to data-subject requests (such as access, correction, deletion, and objection) and to meet the Controller’s obligations regarding security, breach notification, and data-protection impact assessments. Where a data subject contacts us directly, we refer the request to the Controller.
We notify the Controller without undue delay after becoming aware of a personal-data breach affecting the Controller’s data, and provide the information reasonably needed for the Controller to meet its own notification obligations.
Where processing involves transferring personal data across borders, including to the United States, we rely on appropriate safeguards, including the Standard Contractual Clauses (SCCs) and the UK International Data Transfer Addendum, adequacy decisions where applicable, and supplementary technical and organisational measures. See our GDPR Notice and Data Handling page.
On termination of the Services, and at the Controller’s choice, we delete or return the personal data we process on the Controller’s behalf, and delete existing copies unless applicable law requires storage. Copies in routine encrypted backups expire on our normal rotation cycle. See our Data Handling page.
We make available information reasonably necessary to demonstrate compliance with this DPA and, subject to confidentiality and reasonable notice and scope, allow for and contribute to audits conducted by the Controller or an agreed independent auditor.
To request a signed DPA or ask a question about processing, email [email protected].
See also our Terms of Service, Privacy Policy, and full legal center.
For any question about this policy, reach us at [email protected] and we’ll respond promptly.
CloviTek AI LLC · 3731 S Broughtyferry Cv., Salt Lake City, UT 84106, USA · contact [email protected] · Last updated 2026-07-22. This page may be revised as our practices and services evolve; the date above always reflects the current version.