Data Handling and Deletion Schedule

CloviSEO

Effective date: draft — set on review
Contact: [email protected]
Generated: 2026-09-11T16:27:10.848599+00:00
Inventory rows satisfied: A, E

This document was machine-generated from a template and IS NOT LEGAL ADVICE. It is a starting draft that requires review by a qualified attorney before publication, especially for high-stakes terms.

1. Overview

CloviTek Inc. maintains this Data Handling and Deletion Schedule as a component of our broader Privacy Policy and Terms of Service. It outlines our retention periods for each category of personal information, the justification for maintaining such data, and the secure deletion or anonymization protocols executed upon schedule expiration or a valid user request. We evaluate and refresh this document annually, or sooner if significant updates are made to our data management practices.

2. Retention Periods by Data Category

The following framework details how long we store each type of personal information, the conditions that initiate deletion, and the specific methods used to securely destroy or anonymize the records once they are no longer needed.

Data CategoryRetention PeriodDeletion / Anonymization MethodRetention Purpose
Contact & Identity InformationAccount duration + 2 yearsSecure erasure on verified request or 2 years post-closeAccount management, support, legal compliance
Account & Profile DataAccount duration + 2 yearsSecure erasure on verified request or 2 years post-closeAccount security, personalization
Billing & Payment Data7 years after transactionAnonymization after tax-retention periodTax, accounting, regulatory compliance
Usage & Activity Data2 years from collectionRolling deletion; anonymized after 2 yearsAnalytics, security, service improvement
Uploaded Content / FilesAccount duration + 30 days post-closeSecure multi-pass overwrite + third-party confirmationService delivery, user access
Support / Communications2 years after last interactionSecure erasure; anonymized summaries retainedSupport, dispute resolution, quality assurance
AI-Generated OutputsAccount duration + 90 daysSecure erasure on account closeService delivery, output history
Marketing & PreferencesUntil opt-out or 2 years inactivityImmediate erasure on opt-outMarketing, preference management
Cookies & Analytics Data13 months (analytics); session (essential)Auto-expired; browser deletion on consent withdrawalSite performance, analytics
Third-Party Integration DataIntegration duration + 1 yearCoordinated with third-party provider; confirmation obtainedWorkflow automation, integrations
Legal & Compliance Data7 years or as required by lawLegal hold review before any deletionLegal, audit, regulatory compliance
Data Subject Requests2 years from request resolutionSecure erasure after retention periodCompliance documentation, audit trail

3. Deletion Methods

Our deletion protocols vary based on the nature of the information and where it is stored. We employ industry-standard techniques to ensure irretrievable removal of digital records, including secure overwriting, cryptographic erasure, and safe physical destruction of hardware media when necessary.

4. Third-Party Processor Deletion Coordination

Upon removing information from our primary infrastructure, we mandate corresponding deletions across all external service providers that handle our data. We maintain documented agreements with these partners to guarantee compliance, tracking each engagement and verifying the completion of cross-system data removal through formal audits and written confirmations.

CategoryProvider(s)Deletion Procedure
Cloud Hosting / CDNAWS S3 / CloudFront, CloudflareDeletion request sent via provider API or DPA process; written confirmation obtained within 30 days
AI / GenerationCloviAIDeletion request sent via provider API or DPA process; written confirmation obtained within 30 days
Text-to-SpeechElevenLabsDeletion request sent via provider API or DPA process; written confirmation obtained within 30 days
PaymentsCloviPayDeletion request sent via provider API or DPA process; written confirmation obtained within 30 days
Email / MessagingEmailItDeletion request sent via provider API or DPA process; written confirmation obtained within 30 days
Media / VideoGumletDeletion request sent via provider API or DPA process; written confirmation obtained within 30 days

5. Data Subject Deletion Requests

Users seeking to remove their personal information should email [email protected]. Upon receipt, we will authenticate your identity, execute deletion or anonymization procedures across all applicable systems, instruct downstream processors accordingly, and issue a written confirmation once complete. Processing occurs within the timeframe mandated by applicable regulations. Certain information, such as transaction records required for accounting or tax obligations, may be preserved beyond standard limits to satisfy legal mandates.

6. Audit and Review

Every deletion and anonymization event is recorded within our internal compliance logs to ensure full traceability. We conduct mandatory reviews of this Schedule on an annual basis, following any substantial adjustments to our data lifecycle, and promptly after security incidents or regulatory examinations. For inquiries or clarification, please direct communications to [email protected]. Document versions track the most recent review date.