Data Handling Policy

Platform: CloviShield  |  Effective Date: June 22, 2026  |  Governing Law: State of Delaware, USA

This Data Handling Policy describes the technical and operational practices CloviShield uses to collect, process, store, protect, quarantine, and delete data within the CloviShield platform. It supplements our Privacy Policy and Terms of Service, and is intended to provide transparency for users, enterprise customers, and compliance reviewers.

Authorized Use Only: CloviShield may only be used to scan and remediate sites you own or for which you hold explicit written authorization both to control and to apply changes to the site. This policy applies exclusively to data generated through authorized use of the Service. Data generated through unauthorized access or modification is subject to immediate deletion and may be disclosed to affected parties or law enforcement authorities.
Remediation & Reversibility: CloviShield actively modifies connected sites. Its default policy is to quarantine, not delete: suspicious files are moved to a secure vault with a 30-day restore window. All remediation actions are logged in an audit trail and are designed to be reversible/roll-back-able where technically feasible. Customers remain responsible for maintaining current, working backups.

1. Data Categories and Sources

Data CategorySourcePurposeRetention
Account identity data (name, email, organization) User-provided at registration Authentication, communication, support Duration of account + 90 days post-closure
Payment and billing data User-provided; processed by payment processor Subscription and CloviRescue management 7 years (legal/financial compliance)
Connected-site credentials and connectors User-provided to enable access and remediation Site access, scanning, remediation Until site disconnected; deleted within 30 days
Authorization attestations User-provided or recorded at site connection Compliance, abuse investigation, legal 5 years from submission
Scan result data (SSL, headers, DNS, malware/vulnerability matches, scores) Automated scan of connected sites Security analysis, historical trending, reporting 24 months from scan date, then deleted or de-identified
Quarantined files Files removed from site during remediation Safe isolation with restore capability 30-day restore window, then purged
Remediation audit trail (actions, patches, hardening, rollbacks) Generated by remediation engine Transparency, recovery, rollback, dispute resolution 24 months, then deleted or de-identified
Third-party vulnerability and threat intelligence data Licensed databases and threat feeds Detection, vulnerability matching, risk scoring Per provider license terms; refreshed periodically
Usage and telemetry data Automatically collected from Service interaction Product improvement, performance monitoring 13 months, then aggregated/de-identified
Support and communication records User-initiated support channels Issue resolution, quality assurance 3 years from ticket closure

2. Data Processing Principles

CloviShield processes data in accordance with the following principles:

3. Site Access and Remediation Data Handling

3.1 Site Connection and Authorization

When a user connects a site, CloviShield records the site identifier, the initiating account, the credentials or connector used, and the timestamp. By connecting a site and enabling remediation, the user attests to ownership or written authorization to both control and apply changes to the site, consistent with the Terms of Service. CloviShield may capture explicit authorization attestation where required by the user's plan tier or organizational policy.

3.2 Remediation Execution

Remediation is performed by automated systems acting on your authorized site. Actions fall into three categories: (a) quarantine of suspicious or malicious files to a secure vault; (b) patching and updating of vulnerable components; and (c) configuration hardening. Every action is written to the remediation audit trail with the affected item, the change made, and a timestamp.

3.3 Quarantine Vault

Files identified as suspicious or malicious are moved — not deleted — into a secure, isolated quarantine vault that is encrypted and access-controlled. Quarantined items are retained for a 30-day restore window, during which a user may request restoration to the original location. After 30 days, quarantined items may be permanently purged.

3.4 Reversibility and Rollback

Where technically feasible, remediation actions can be rolled back to a prior state, and quarantined files can be restored within the restore window. The audit trail supports recovery and dispute resolution. Full reversibility cannot be guaranteed in all environments, particularly where a site was damaged by a pre-existing compromise or modified outside the Service.

3.5 No Cross-Customer Data Sharing

Connected-site credentials, contents, quarantine records, and remediation audit trails are treated as confidential account data and are logically isolated per account. CloviShield does not share individual site or remediation data with other users. Aggregate, anonymized signal data (e.g., prevalence of malware families across the user base) may be used internally for product improvement and never identifies individual accounts or sites.

4. Automated Processing and Algorithmic Analysis

CloviShield uses automated algorithms and, in some features, AI-assisted analysis to detect threats, generate security scores, and recommend or apply remediation. Key disclosures:

Users should engage qualified security professionals before making security decisions based solely on CloviShield output, and should maintain independent backups.

5. Data Security Measures

CloviShield implements the following security controls:

6. Sub-Processors and Third-Party Vendors

CloviShield engages the following categories of sub-processors. All sub-processors are bound by data processing agreements requiring data protection standards consistent with applicable law:

A current list of sub-processors is available upon request at privacy@clovishield.com.

7. Abuse Detection and Unauthorized Use Handling

CloviShield operates controls to detect patterns that may indicate unauthorized site access or modification, including anomalous connection volumes, patterns inconsistent with legitimate remediation, or sites flagged as not owned or authorized by the connecting account. Where unauthorized use is suspected:

8. Data Deletion and Erasure Requests

Users may request deletion of their personal data and account at any time. Upon a verified deletion request:

To submit a deletion request, contact privacy@clovishield.com from the email address associated with your account.

9. Data Portability

Upon request, CloviShield will provide a structured, machine-readable export of personal data associated with your account (e.g., account information, scan history, and remediation audit trail in JSON or CSV format). Requests will be fulfilled within 30 days.

10. International Transfers

CloviShield's primary infrastructure is located in the United States. For users in the European Economic Area, United Kingdom, or other regions with cross-border transfer restrictions, CloviShield relies on appropriate legal mechanisms (such as Standard Contractual Clauses) to authorize data transfers. Contact privacy@clovishield.com for transfer mechanism documentation.

11. Breach Notification

In the event of a data breach that is likely to result in a risk to the rights and freedoms of affected users, CloviShield will:

12. Compliance and Audit

Enterprise or business customers requiring data processing agreements (DPAs), security questionnaires, sub-processor lists, or audit documentation should contact legal@clovishield.com. CloviShield will work in good faith to accommodate reasonable compliance review requests.

13. Changes to This Policy

This Data Handling Policy may be updated from time to time to reflect changes in our practices, technology, legal requirements, or operational needs. Material changes will be communicated to registered users via email or in-Service notice at least 14 days before they take effect.

14. Contact

For questions, requests, or concerns relating to this Data Handling Policy:

CloviShield Legal & Privacy
privacy@clovishield.com