CloviShield ("Company," "we," "us," or "our") respects your privacy. This Privacy Policy explains how we collect, use, disclose, and protect information when you use CloviShield (the "Service"). Please read this policy carefully. By using the Service, you agree to the practices described herein.
When you connect a site, CloviShield generates scan result data (SSL/TLS details, HTTP headers, DNS records, detected software versions, vulnerability and malware matches, security scores) and remediation data, including records of quarantined files, applied patches and updates, configuration-hardening changes, and a full audit trail of actions taken. Quarantined files themselves are stored in a secure, isolated vault for the restore window. This data is stored in association with your account.
We may query third-party vulnerability databases, malware signature feeds, threat intelligence, and certificate transparency logs to enrich detection and remediation. This data relates to publicly disclosed security information, not to your personal information.
| Purpose | Legal Basis |
|---|---|
| Provide, operate, and maintain the Service | Contract performance |
| Scan connected sites and deliver results | Contract performance |
| Perform remediation (quarantine, patching, hardening) on your authorized sites | Contract performance |
| Maintain quarantine vaults and remediation audit trails | Contract performance / Legitimate interest |
| Process subscriptions, CloviRescue purchases, and payments | Contract performance |
| Respond to support requests and communications | Contract performance / Legitimate interest |
| Send transactional notices (account activity, security alerts, remediation reports) | Contract performance |
| Analyze usage patterns to improve the Service | Legitimate interest |
| Detect and prevent fraud, abuse, unauthorized site access, and security threats | Legitimate interest / Legal obligation |
| Comply with applicable legal obligations and law enforcement requests | Legal obligation |
| Send marketing communications (with your consent) | Consent |
Data about your connected sites — credentials, file contents accessed during remediation, quarantine records, and audit logs — is treated as confidential account data. CloviShield does not share your connected-site data or remediation records with other users or customers of the Service. We will not disclose this data to third parties except:
CloviShield does not use your connected-site contents or remediation records to train shared models or to enrich data provided to other CloviShield users.
We do not sell your personal information. We may share your information in the following limited circumstances:
We retain personal account data for the duration of your account relationship with us, plus a reasonable period thereafter as required for legal, compliance, dispute resolution, or audit purposes. Account data is deleted within 90 days of account closure upon request. Quarantined files are retained for the 30-day restore window and may then be purged. Remediation audit trails and security reports may be retained for up to 24 months for trend analysis and recovery, after which they are deleted or de-identified. Authorization records may be retained for up to 5 years for compliance and legal purposes. See our Data Handling Policy for detail.
CloviShield uses strictly necessary cookies (authentication, session security), functional cookies (preferences such as theme), and privacy-respecting analytics cookies. You may control cookie preferences through your browser settings and our cookie banner. See our Cookie Policy for full detail. Disabling certain cookies may limit Service functionality.
Depending on your jurisdiction, you may have the following rights regarding your personal information:
To exercise any of these rights, contact us at privacy@clovishield.com. We will respond within 30 days. We may require identity verification before fulfilling requests. Note that we may be required to retain certain remediation or authorization records in connection with legal obligations or ongoing investigations, even following an erasure request.
We implement industry-standard technical and organizational measures to protect your information, including encrypted data transmission (TLS 1.2 or higher), encrypted data storage, role-based access controls, and regular security reviews. Site credentials, connected-site contents, quarantine vaults, and remediation records receive heightened access restrictions given their security-sensitive nature. No method of transmission or storage is 100% secure; we cannot guarantee absolute security. In the event of a data breach that affects your rights and freedoms, we will notify you as required by applicable law.
CloviShield operates primarily from the United States. If you access the Service from outside the US, your data may be transferred to and processed in the US or other countries. Where required by applicable law (e.g., transfers from the European Economic Area), we implement appropriate safeguards such as Standard Contractual Clauses or equivalent mechanisms.
The Service is not directed to individuals under the age of 18. We do not knowingly collect personal information from minors. If we become aware that we have collected data from a person under 18, we will delete it promptly. Contact us at privacy@clovishield.com if you believe we have inadvertently collected such data.
We may update this Privacy Policy from time to time. We will notify registered users of material changes by email or in-Service notice. The updated policy will be effective as of the date posted. Your continued use of the Service constitutes acceptance of the revised policy.
For privacy-related questions, requests, or complaints:
CloviShield Privacy
privacy@clovishield.com