This Data Handling Policy describes the technical and operational practices CloviShield uses to collect, process, store, protect, quarantine, and delete data within the CloviShield platform. It supplements our Privacy Policy and Terms of Service, and is intended to provide transparency for users, enterprise customers, and compliance reviewers.
| Data Category | Source | Purpose | Retention |
|---|---|---|---|
| Account identity data (name, email, organization) | User-provided at registration | Authentication, communication, support | Duration of account + 90 days post-closure |
| Payment and billing data | User-provided; processed by payment processor | Subscription and CloviRescue management | 7 years (legal/financial compliance) |
| Connected-site credentials and connectors | User-provided to enable access and remediation | Site access, scanning, remediation | Until site disconnected; deleted within 30 days |
| Authorization attestations | User-provided or recorded at site connection | Compliance, abuse investigation, legal | 5 years from submission |
| Scan result data (SSL, headers, DNS, malware/vulnerability matches, scores) | Automated scan of connected sites | Security analysis, historical trending, reporting | 24 months from scan date, then deleted or de-identified |
| Quarantined files | Files removed from site during remediation | Safe isolation with restore capability | 30-day restore window, then purged |
| Remediation audit trail (actions, patches, hardening, rollbacks) | Generated by remediation engine | Transparency, recovery, rollback, dispute resolution | 24 months, then deleted or de-identified |
| Third-party vulnerability and threat intelligence data | Licensed databases and threat feeds | Detection, vulnerability matching, risk scoring | Per provider license terms; refreshed periodically |
| Usage and telemetry data | Automatically collected from Service interaction | Product improvement, performance monitoring | 13 months, then aggregated/de-identified |
| Support and communication records | User-initiated support channels | Issue resolution, quality assurance | 3 years from ticket closure |
CloviShield processes data in accordance with the following principles:
When a user connects a site, CloviShield records the site identifier, the initiating account, the credentials or connector used, and the timestamp. By connecting a site and enabling remediation, the user attests to ownership or written authorization to both control and apply changes to the site, consistent with the Terms of Service. CloviShield may capture explicit authorization attestation where required by the user's plan tier or organizational policy.
Remediation is performed by automated systems acting on your authorized site. Actions fall into three categories: (a) quarantine of suspicious or malicious files to a secure vault; (b) patching and updating of vulnerable components; and (c) configuration hardening. Every action is written to the remediation audit trail with the affected item, the change made, and a timestamp.
Files identified as suspicious or malicious are moved — not deleted — into a secure, isolated quarantine vault that is encrypted and access-controlled. Quarantined items are retained for a 30-day restore window, during which a user may request restoration to the original location. After 30 days, quarantined items may be permanently purged.
Where technically feasible, remediation actions can be rolled back to a prior state, and quarantined files can be restored within the restore window. The audit trail supports recovery and dispute resolution. Full reversibility cannot be guaranteed in all environments, particularly where a site was damaged by a pre-existing compromise or modified outside the Service.
Connected-site credentials, contents, quarantine records, and remediation audit trails are treated as confidential account data and are logically isolated per account. CloviShield does not share individual site or remediation data with other users. Aggregate, anonymized signal data (e.g., prevalence of malware families across the user base) may be used internally for product improvement and never identifies individual accounts or sites.
CloviShield uses automated algorithms and, in some features, AI-assisted analysis to detect threats, generate security scores, and recommend or apply remediation. Key disclosures:
Users should engage qualified security professionals before making security decisions based solely on CloviShield output, and should maintain independent backups.
CloviShield implements the following security controls:
CloviShield engages the following categories of sub-processors. All sub-processors are bound by data processing agreements requiring data protection standards consistent with applicable law:
A current list of sub-processors is available upon request at privacy@clovishield.com.
CloviShield operates controls to detect patterns that may indicate unauthorized site access or modification, including anomalous connection volumes, patterns inconsistent with legitimate remediation, or sites flagged as not owned or authorized by the connecting account. Where unauthorized use is suspected:
Users may request deletion of their personal data and account at any time. Upon a verified deletion request:
To submit a deletion request, contact privacy@clovishield.com from the email address associated with your account.
Upon request, CloviShield will provide a structured, machine-readable export of personal data associated with your account (e.g., account information, scan history, and remediation audit trail in JSON or CSV format). Requests will be fulfilled within 30 days.
CloviShield's primary infrastructure is located in the United States. For users in the European Economic Area, United Kingdom, or other regions with cross-border transfer restrictions, CloviShield relies on appropriate legal mechanisms (such as Standard Contractual Clauses) to authorize data transfers. Contact privacy@clovishield.com for transfer mechanism documentation.
In the event of a data breach that is likely to result in a risk to the rights and freedoms of affected users, CloviShield will:
Enterprise or business customers requiring data processing agreements (DPAs), security questionnaires, sub-processor lists, or audit documentation should contact legal@clovishield.com. CloviShield will work in good faith to accommodate reasonable compliance review requests.
This Data Handling Policy may be updated from time to time to reflect changes in our practices, technology, legal requirements, or operational needs. Material changes will be communicated to registered users via email or in-Service notice at least 14 days before they take effect.
For questions, requests, or concerns relating to this Data Handling Policy:
CloviShield Legal & Privacy
privacy@clovishield.com