How CloviTek AI LLC collects, uses, shares, and protects information — and the choices and rights you have over it, under the GDPR, CCPA/CPRA, and other applicable laws.
CloviTek AI ("CloviTek AI", "we", "us") builds and operates software and business-operations services. This policy explains what information we collect when you visit our website or use our services, how we use it, how we share and protect it, and the control and rights you have over it. We keep what we collect to a minimum and we do not sell personal data.
This Privacy Policy ("Policy") is issued by CloviTek AI LLC, with its principal place of business at 3731 S Broughtyferry Cv., Salt Lake City, UT 84106, USA. It applies to our website at clovitek.ai and to the services and engagements we provide, and is issued in compliance with the General Data Protection Regulation (GDPR), the California Consumer Privacy Act / CPRA (CCPA), and other applicable data protection laws.
Controller vs. processor. For the personal data of our own account holders, website visitors, and enquirers, CloviTek AI acts as a data controller. For data that a client uploads, imports, or directs us to process on its behalf — including its own customers’, staff’s, leads’, and prospects’ personal data — CloviTek AI acts as a data processor / service provider, and the client is the controller. Where we act as a processor, our processing is governed by our Terms of Service and any applicable Data Processing Addendum (DPA). We may update this Policy from time to time and will notify you of material changes by email and/or a notice on our site and by updating the "Last updated" date above.
We collect only what we need to respond to you and operate our services:
We do not intentionally collect special-category or sensitive personal information through our website, we do not knowingly collect data from children (see section 12), and we ask that you do not send sensitive information to us through contact forms.
We use the information above to:
We rely on contract performance, legitimate interests, legal obligations, and consent (where required) as our lawful bases. We do not sell your personal data, and we do not use contact-form submissions for unrelated marketing.
Data isolation is a core engineering rule across everything we build and run. Each client’s data is scoped and isolated to that client’s account — one client’s information is never pooled with, or made visible to, another. New accounts start empty, and access is scoped to the authenticated user.
Some of our services generate, review, or transform content using artificial intelligence. Where a feature does this, prompts and the content needed to produce your result may be sent to third-party AI and large-language-model ("LLM") providers — our AI sub-processor (Anthropic) — for processing. You should not submit sensitive personal data, regulated data, or confidential information you do not have the right to process through these AI features. That content is used solely to return your result and is not used to train third-party models; however, output ownership and "no-training" assurances vary by provider and are governed by each provider’s terms, and we do not warrant any provider’s training practices. AI voice / narration. Where text-to-speech features are used, synthetic-voice outputs are generated from text you provide, and you are responsible for ensuring you hold the rights to any voice, likeness, or script used. AI-generated output is a working draft that must be independently reviewed before you rely on it — see our Disclaimer.
We use a small set of cookies to run the site and to understand, in aggregate, how it is used. You can choose which non-essential categories to allow at any time through our Cookie Preferences panel, and full detail is in our Cookie Policy. Necessary cookies, required for basic functionality, are always active and do not store personal data. If analytics or marketing technologies are added in the future, this Policy and the Cookie Policy will be updated and, where required, consent obtained.
Your data may be transferred to and processed in countries outside your home jurisdiction, including the United States, by us and our sub-processors. Data residency for stored data corresponds to the configured cloud storage region. Where required, we rely on Standard Contractual Clauses (SCCs), adequacy decisions, and supplementary technical and organisational measures (such as encryption and access controls) to protect transferred data.
We share information only where necessary to run our services, and only with providers bound to protect it. These sub-processors are used for functions such as AI generation and review, cloud hosting and content delivery, email delivery, payment and subscription billing, and website analytics; the current named list is published on our Data Handling page, and a full named list is also available on request at [email protected]. We engage them to act on our instructions, not for their own purposes, and we will provide 30 days’ advance notice of material additions or changes to sub-processors that affect your data. We may also disclose information where required by law or to protect the rights, safety, and security of our users and services. We do not sell personal data.
Payment-card data. Where payments are processed, payment cards are captured and tokenised by our PCI-DSS-certified payment providers — Stripe (card processing) and, for subscription billing, Chargebee. CloviTek AI does not receive, process, or store full payment-card numbers on its own systems; we retain only non-sensitive billing records (such as transaction identifiers, amounts, plan, and card brand or last four digits where provided). We rely on these providers’ own PCI-DSS compliance for card handling; CloviTek AI itself does not represent that it holds PCI-DSS or SOC certification, which are maintained by our payment providers for the services they operate.
We protect your information with a layered security program, including encryption in transit (TLS/HTTPS) and at rest where supported, hashed credentials, role-based access controls scoped to those who need them, audit logs, secrets held in a secured vault (never exposed in outputs), and continuous monitoring with error tracking. No system is perfectly secure; we cannot guarantee absolute security.
We keep personal data only as long as needed for the purposes described here — to respond to you, to provide a service, or to meet legal and security obligations — after which it is deleted or anonymised. Client service data is retained for the life of the engagement and a limited period afterward, subject to legal-hold and backup-rotation periods, unless you request earlier deletion. For data held by sub-processors, we coordinate deletion and seek confirmation where feasible. Full detail, including how to request deletion, is in our Data Handling & Deletion policy.
Our website and services are intended for businesses and for adults. They are not directed to children, and we do not knowingly collect personal information from anyone under 18 (or the applicable age in your jurisdiction). If you believe a child has provided us information without required consent, contact us and we will delete it.
Subject to applicable law (GDPR, CCPA/CPRA, and others), you may:
Where CloviTek AI processes data as a processor on a client’s behalf, please direct your request to the relevant client (the controller); we will assist them in responding. To exercise rights as a CloviTek AI account holder, email [email protected]. We will verify your identity and respond within the legally required timeframe. For deletion specifically, see our Data Handling & Deletion page.
We may update this Policy. For material changes we will provide reasonable advance notice by email and/or a notice on our site and update the "Last updated" date. Continued use after the effective date constitutes acceptance.
For any privacy question, correction, or data request, reach our privacy team at [email protected] or reach us generally at [email protected], and we’ll respond promptly.
CloviTek AI LLC · 3731 S Broughtyferry Cv., Salt Lake City, UT 84106, USA · contact [email protected] · Last updated 2026-07-22. This page may be revised as our practices and services evolve; the date above always reflects the current version.