Data Handling and Deletion Schedule

CloviAnalytics — Cookie Policy & Behavioral Tracking Disclosure

Effective date: draft — set on review
Contact: legal@clovitek.com
Generated: 2026-06-10

This document was machine-generated from a template and IS NOT LEGAL ADVICE. It is a starting draft that requires review by a qualified attorney before publication.

Review required before publication. Consult qualified legal counsel.
This document supplements the CloviAnalytics Terms of Service and Privacy Policy. It details retention periods, deletion methods, cookie practices, and behavioral tracking disclosures specific to the analytics platform context.

Part A — Data Retention Schedule

CloviTek AI retains personal data only as long as necessary to fulfill the purposes described in our Privacy Policy or as required by applicable law. The table below lists retention periods for each category of personal data we process as data controller (i.e., data about you as a platform customer).

Data Category Retention Period Trigger for Deletion Notes
Account & Profile Data (name, email, company, hashed password) Duration of account + 30 days post-closure Account closure + 30-day export window Hashed passwords deleted immediately on account closure request
Billing & Transaction Records 7 years from transaction date Statutory retention period expiry Required for tax and accounting compliance; payment method tokens deleted on account closure
Platform Usage / Session Logs (your account activity within the dashboard) 24 months from event date Rolling 24-month window Used for security audit trails and product improvement; anonymized after retention period
Customer Support Records (tickets, emails, chat logs) 3 years from last interaction 3 years from last support contact Retained for quality assurance and legal defense; may be anonymized earlier upon request
Marketing Communications Records (consent, opt-out logs) 3 years from consent or opt-out event 3 years rolling Consent records retained as evidence of lawful marketing; email removed from send lists immediately on opt-out
Authentication & Security Logs (login events, IP, 2FA, access changes) 12 months from event date Rolling 12-month window Used for fraud detection and security investigations
Contract & Legal Records (agreements, DPAs, terms acceptance logs) 7 years from contract end date 7 years from account closure Required for legal compliance and dispute resolution
Data Subject Rights Request Records (DSARs, deletion confirmations) 5 years from request date 5 years rolling Required to demonstrate GDPR/CCPA compliance
Aggregated/Anonymized Analytics (no individual attribution) Indefinite No scheduled deletion Fully anonymized; not personal data; used for product benchmarking
Session Replay Data (opt-in behavioral recording within the platform dashboard) 90 days from session date Rolling 90-day window Only collected where customer has explicitly opted in; deleted automatically after 90 days
Cookie Consent Records (consent logs from the CloviAnalytics consent banner) 3 years from consent event 3 years rolling Required as evidence of valid consent under GDPR Art. 7

A.1 — End-User Behavioral Data (You as Data Controller)

When you use the CloviAnalytics tracking code to collect behavioral data about your end users, you are the data controller and CloviTek AI is the data processor. Default retention periods for end-user data processed on your behalf are:

Data CategoryDefault RetentionConfigurable?Notes
Raw event stream (page views, clicks, custom events)24 monthsYes (1–36 months)Configurable per property in dashboard settings
Session-level aggregates (session counts, duration, bounce rate)36 monthsYesLess granular; used for trend analysis
Funnel and conversion data36 monthsYesAggregated; may contain pseudonymous user IDs
Audience segment membershipDuration of active segment + 30 daysSegment-levelDeleted when segment is archived or account closes
Heatmap and click-map data12 monthsYesStored as aggregated density maps; not linked to individual users
Session recordings (if enabled by you)90 daysYes (7–365 days)You are responsible for obtaining end-user consent before enabling; PII masking enabled by default
Individual user profiles (if you enable user identification)12 months of inactivityYesPseudonymous identifier; link to real identity controlled by you; deletion API available

You may configure retention periods in your property settings. You may also submit deletion requests for specific end-user identifiers via the deletion API or by contacting legal@clovitek.com. CloviTek AI will process deletion requests within 30 days.

Part B — Cookie Policy

This Cookie Policy covers cookies set on the CloviAnalytics platform itself (your customer account and dashboard). It does not govern cookies that the CloviAnalytics tracking code places on your own digital properties — those are subject to your own cookie policy, which you are responsible for maintaining.

B.1 — What Are Cookies?

Cookies are small text files placed on your device by a web server. They allow the platform to recognize your browser, maintain your session, remember preferences, and collect usage information. We also use similar technologies including local storage, session storage, pixel tags, and device fingerprinting signals for specific purposes described below.

B.2 — Categories of Cookies We Use

B.3 — Managing Cookies

You can manage your cookie preferences at any time by:

Withdrawal of consent for non-essential cookies takes effect prospectively and does not affect processing that occurred before withdrawal.

B.4 — Third-Party Cookies

Some cookies may be placed by our approved sub-processors (listed in Part D). Those sub-processors' privacy practices are governed by their own policies, but we require all sub-processors to comply with applicable data protection law and to process data only per our instructions.

Part C — Behavioral Tracking Disclosure

CloviAnalytics is fundamentally a behavioral intelligence tool. This section provides comprehensive transparency about behavioral tracking practices at every layer of the Service.

C.1 — Behavioral Tracking Within the CloviAnalytics Platform (Your Account)

As a platform customer, your interactions within the CloviAnalytics dashboard are subject to the following behavioral data collection:

Tracking TypeData CollectedDefault StateBasisRetention
Platform Usage AnalyticsFeature clicks, navigation paths, time on page, report exports, API calls madeActive (with consent)Consent + Legitimate Interests24 months
Error & Performance MonitoringJavaScript errors, page load times, API response times, anonymized stack tracesActive (essential for service quality)Legitimate Interests12 months
Security Event LoggingLogin attempts, IP addresses, 2FA events, permission changes, API key usageAlways activeLegal Obligation + Legitimate Interests12 months
Session Replay (UX Research)Mouse movements, click coordinates, scroll behavior, form interactions (PII masked)OFF — explicit opt-in onlyConsent90 days
Heatmap AnalysisAggregated click density maps on dashboard pages (no individual attribution)OFF — explicit opt-in onlyConsent90 days (aggregated, indefinite)

C.2 — Behavioral Tracking of Your End Users (You as Data Controller)

The following tracking capabilities are available for you to deploy on your digital properties via the CloviAnalytics tracking code. You are the data controller for all end-user data collected through these features. You must ensure compliance with applicable law, including obtaining valid consent where required.

FeatureData Collected from Your End UsersYour Compliance Responsibility
Page View TrackingURL, referrer, timestamp, anonymized IP (last octet masked by default), browser/OS, screen resolutionDisclose in your cookie/privacy policy; obtain consent in ePrivacy/GDPR jurisdictions before activating
Custom Event TrackingEvent name, properties you define (e.g., button clicks, form submissions, purchases)Ensure events do not inadvertently capture PII; document all tracked events in your privacy policy
User IdentificationPseudonymous user ID you provide (e.g., hashed email or internal user ID); associates events to a user profileDo not send unhashed PII as user ID; obtain appropriate consent; provide users with right to deletion
Session RecordingMouse movements, clicks, scrolls, form interactions (PII masking enabled by default)Explicit consent required in most jurisdictions; must disclose in cookie policy; must enable PII masking for sensitive fields
Funnel AnalysisSequence of events leading to conversion; drop-off pointsBased on aggregated event data; same consent as underlying event tracking
Audience SegmentationGrouping of pseudonymous users by behavioral attributes (e.g., high-value visitors, churned users)Disclose segmentation logic if used for consequential decisions; do not discriminate unlawfully
Heatmaps & Click MapsAggregated interaction density maps per pageAggregated data; lower consent threshold in many jurisdictions; still disclose in cookie policy
Cross-Domain TrackingLinking a single user session across multiple domains you ownRequires explicit configuration; disclose in your privacy policy; obtain appropriate consent
UTM / Campaign AttributionUTM parameters from URLs; links sessions to marketing campaignsGenerally low privacy risk; disclose in privacy policy

C.3 — What CloviTek AI Does and Does Not Do with End-User Behavioral Data

We do NOT:
  • Cross-reference your end users' data with data from other CloviAnalytics customers
  • Build cross-customer behavioral profiles of individuals
  • Sell end-user data to any third party for advertising or other purposes
  • Use end-user data for ad targeting of any kind
  • Share end-user data with any party except sub-processors acting on your instructions
  • Make automated decisions with legal effects about your end users

We DO:

C.4 — Do Not Track and Global Privacy Control

CloviAnalytics supports the Global Privacy Control (GPC) signal. When your end user's browser sends a GPC signal to your property, the CloviAnalytics tracking code will, by default, suppress non-essential data collection for that session. You can configure GPC handling behavior in your property settings. Support for the Do Not Track (DNT) header is available as a configurable option.

Part D — Sub-Processor List

CloviTek AI engages the following categories of sub-processors. All are contractually required to process data only per our instructions and to maintain appropriate security measures. Current sub-processor details are available by contacting legal@clovitek.com.

CategoryProcessing PurposeData ProcessedTransfer Mechanism
Cloud Infrastructure / Object StoragePlatform hosting, data persistence, CDN deliveryAll platform and behavioral dataDPA, SCCs (where applicable)
Relational Database ServiceStructured data storage for account, billing, and configuration dataAccount data, event schema metadataDPA, encryption at rest
Time-Series / Event DatabaseHigh-volume behavioral event storage and queryingEnd-user behavioral eventsDPA, encryption at rest
Payment ProcessingBilling, subscription managementBilling info, transaction recordsPCI DSS Level 1, DPA
Transactional Email ServiceAccount notifications, billing receipts, support correspondenceEmail address, name, message contentDPA, TLS in transit
Error MonitoringBug detection and performance diagnosticsAnonymized error logs, stack tracesDPA, data minimization
Customer Support SoftwareHelpdesk ticketing and live chatAccount info, support messagesDPA

Part E — Deletion Methods and Procedures

E.1 — Standard Deletion Process

Upon expiry of a retention period or a verified deletion request, CloviTek AI deletes personal data using the following methods:

E.2 — How to Submit a Deletion Request

E.3 — Deletion Audit and Verification

All deletion actions are logged with a timestamp, the deletion method used, the data categories deleted, and confirmation of sub-processor deletion propagation. These audit logs are retained for 5 years as evidence of compliance. Deletion confirmations are available to you upon request.

Part F — Data Export and Portability

You may export your data and your end users' aggregated data at any time via the export tools available in the platform dashboard. Export formats include CSV, JSON, and PDF reports. Exports include:

After account closure, you have 30 days to complete your export. Export tools remain accessible for that window. Contact legal@clovitek.com if you require assistance with a bulk export or a format not listed above.

Contact

For data handling inquiries, deletion requests, or sub-processor questions: legal@clovitek.com.

Governing law: Delaware, USA. EU/EEA/UK data subjects retain all rights under applicable data protection law.