CloviAnalytics — Cookie Policy & Behavioral Tracking Disclosure
CloviTek AI retains personal data only as long as necessary to fulfill the purposes described in our Privacy Policy or as required by applicable law. The table below lists retention periods for each category of personal data we process as data controller (i.e., data about you as a platform customer).
| Data Category | Retention Period | Trigger for Deletion | Notes |
|---|---|---|---|
| Account & Profile Data (name, email, company, hashed password) | Duration of account + 30 days post-closure | Account closure + 30-day export window | Hashed passwords deleted immediately on account closure request |
| Billing & Transaction Records | 7 years from transaction date | Statutory retention period expiry | Required for tax and accounting compliance; payment method tokens deleted on account closure |
| Platform Usage / Session Logs (your account activity within the dashboard) | 24 months from event date | Rolling 24-month window | Used for security audit trails and product improvement; anonymized after retention period |
| Customer Support Records (tickets, emails, chat logs) | 3 years from last interaction | 3 years from last support contact | Retained for quality assurance and legal defense; may be anonymized earlier upon request |
| Marketing Communications Records (consent, opt-out logs) | 3 years from consent or opt-out event | 3 years rolling | Consent records retained as evidence of lawful marketing; email removed from send lists immediately on opt-out |
| Authentication & Security Logs (login events, IP, 2FA, access changes) | 12 months from event date | Rolling 12-month window | Used for fraud detection and security investigations |
| Contract & Legal Records (agreements, DPAs, terms acceptance logs) | 7 years from contract end date | 7 years from account closure | Required for legal compliance and dispute resolution |
| Data Subject Rights Request Records (DSARs, deletion confirmations) | 5 years from request date | 5 years rolling | Required to demonstrate GDPR/CCPA compliance |
| Aggregated/Anonymized Analytics (no individual attribution) | Indefinite | No scheduled deletion | Fully anonymized; not personal data; used for product benchmarking |
| Session Replay Data (opt-in behavioral recording within the platform dashboard) | 90 days from session date | Rolling 90-day window | Only collected where customer has explicitly opted in; deleted automatically after 90 days |
| Cookie Consent Records (consent logs from the CloviAnalytics consent banner) | 3 years from consent event | 3 years rolling | Required as evidence of valid consent under GDPR Art. 7 |
When you use the CloviAnalytics tracking code to collect behavioral data about your end users, you are the data controller and CloviTek AI is the data processor. Default retention periods for end-user data processed on your behalf are:
| Data Category | Default Retention | Configurable? | Notes |
|---|---|---|---|
| Raw event stream (page views, clicks, custom events) | 24 months | Yes (1–36 months) | Configurable per property in dashboard settings |
| Session-level aggregates (session counts, duration, bounce rate) | 36 months | Yes | Less granular; used for trend analysis |
| Funnel and conversion data | 36 months | Yes | Aggregated; may contain pseudonymous user IDs |
| Audience segment membership | Duration of active segment + 30 days | Segment-level | Deleted when segment is archived or account closes |
| Heatmap and click-map data | 12 months | Yes | Stored as aggregated density maps; not linked to individual users |
| Session recordings (if enabled by you) | 90 days | Yes (7–365 days) | You are responsible for obtaining end-user consent before enabling; PII masking enabled by default |
| Individual user profiles (if you enable user identification) | 12 months of inactivity | Yes | Pseudonymous identifier; link to real identity controlled by you; deletion API available |
You may configure retention periods in your property settings. You may also submit deletion requests for specific end-user identifiers via the deletion API or by contacting legal@clovitek.com. CloviTek AI will process deletion requests within 30 days.
Cookies are small text files placed on your device by a web server. They allow the platform to recognize your browser, maintain your session, remember preferences, and collect usage information. We also use similar technologies including local storage, session storage, pixel tags, and device fingerprinting signals for specific purposes described below.
You can manage your cookie preferences at any time by:
Withdrawal of consent for non-essential cookies takes effect prospectively and does not affect processing that occurred before withdrawal.
Some cookies may be placed by our approved sub-processors (listed in Part D). Those sub-processors' privacy practices are governed by their own policies, but we require all sub-processors to comply with applicable data protection law and to process data only per our instructions.
CloviAnalytics is fundamentally a behavioral intelligence tool. This section provides comprehensive transparency about behavioral tracking practices at every layer of the Service.
As a platform customer, your interactions within the CloviAnalytics dashboard are subject to the following behavioral data collection:
| Tracking Type | Data Collected | Default State | Basis | Retention |
|---|---|---|---|---|
| Platform Usage Analytics | Feature clicks, navigation paths, time on page, report exports, API calls made | Active (with consent) | Consent + Legitimate Interests | 24 months |
| Error & Performance Monitoring | JavaScript errors, page load times, API response times, anonymized stack traces | Active (essential for service quality) | Legitimate Interests | 12 months |
| Security Event Logging | Login attempts, IP addresses, 2FA events, permission changes, API key usage | Always active | Legal Obligation + Legitimate Interests | 12 months |
| Session Replay (UX Research) | Mouse movements, click coordinates, scroll behavior, form interactions (PII masked) | OFF — explicit opt-in only | Consent | 90 days |
| Heatmap Analysis | Aggregated click density maps on dashboard pages (no individual attribution) | OFF — explicit opt-in only | Consent | 90 days (aggregated, indefinite) |
The following tracking capabilities are available for you to deploy on your digital properties via the CloviAnalytics tracking code. You are the data controller for all end-user data collected through these features. You must ensure compliance with applicable law, including obtaining valid consent where required.
| Feature | Data Collected from Your End Users | Your Compliance Responsibility |
|---|---|---|
| Page View Tracking | URL, referrer, timestamp, anonymized IP (last octet masked by default), browser/OS, screen resolution | Disclose in your cookie/privacy policy; obtain consent in ePrivacy/GDPR jurisdictions before activating |
| Custom Event Tracking | Event name, properties you define (e.g., button clicks, form submissions, purchases) | Ensure events do not inadvertently capture PII; document all tracked events in your privacy policy |
| User Identification | Pseudonymous user ID you provide (e.g., hashed email or internal user ID); associates events to a user profile | Do not send unhashed PII as user ID; obtain appropriate consent; provide users with right to deletion |
| Session Recording | Mouse movements, clicks, scrolls, form interactions (PII masking enabled by default) | Explicit consent required in most jurisdictions; must disclose in cookie policy; must enable PII masking for sensitive fields |
| Funnel Analysis | Sequence of events leading to conversion; drop-off points | Based on aggregated event data; same consent as underlying event tracking |
| Audience Segmentation | Grouping of pseudonymous users by behavioral attributes (e.g., high-value visitors, churned users) | Disclose segmentation logic if used for consequential decisions; do not discriminate unlawfully |
| Heatmaps & Click Maps | Aggregated interaction density maps per page | Aggregated data; lower consent threshold in many jurisdictions; still disclose in cookie policy |
| Cross-Domain Tracking | Linking a single user session across multiple domains you own | Requires explicit configuration; disclose in your privacy policy; obtain appropriate consent |
| UTM / Campaign Attribution | UTM parameters from URLs; links sessions to marketing campaigns | Generally low privacy risk; disclose in privacy policy |
We DO:
CloviAnalytics supports the Global Privacy Control (GPC) signal. When your end user's browser sends a GPC signal to your property, the CloviAnalytics tracking code will, by default, suppress non-essential data collection for that session. You can configure GPC handling behavior in your property settings. Support for the Do Not Track (DNT) header is available as a configurable option.
CloviTek AI engages the following categories of sub-processors. All are contractually required to process data only per our instructions and to maintain appropriate security measures. Current sub-processor details are available by contacting legal@clovitek.com.
| Category | Processing Purpose | Data Processed | Transfer Mechanism |
|---|---|---|---|
| Cloud Infrastructure / Object Storage | Platform hosting, data persistence, CDN delivery | All platform and behavioral data | DPA, SCCs (where applicable) |
| Relational Database Service | Structured data storage for account, billing, and configuration data | Account data, event schema metadata | DPA, encryption at rest |
| Time-Series / Event Database | High-volume behavioral event storage and querying | End-user behavioral events | DPA, encryption at rest |
| Payment Processing | Billing, subscription management | Billing info, transaction records | PCI DSS Level 1, DPA |
| Transactional Email Service | Account notifications, billing receipts, support correspondence | Email address, name, message content | DPA, TLS in transit |
| Error Monitoring | Bug detection and performance diagnostics | Anonymized error logs, stack traces | DPA, data minimization |
| Customer Support Software | Helpdesk ticketing and live chat | Account info, support messages | DPA |
Upon expiry of a retention period or a verified deletion request, CloviTek AI deletes personal data using the following methods:
All deletion actions are logged with a timestamp, the deletion method used, the data categories deleted, and confirmation of sub-processor deletion propagation. These audit logs are retained for 5 years as evidence of compliance. Deletion confirmations are available to you upon request.
You may export your data and your end users' aggregated data at any time via the export tools available in the platform dashboard. Export formats include CSV, JSON, and PDF reports. Exports include:
After account closure, you have 30 days to complete your export. Export tools remain accessible for that window. Contact legal@clovitek.com if you require assistance with a bulk export or a format not listed above.
For data handling inquiries, deletion requests, or sub-processor questions: legal@clovitek.com.
Governing law: Delaware, USA. EU/EEA/UK data subjects retain all rights under applicable data protection law.