Effective date: July 14, 2025 Vital Webmaster LLC (doing business as CloviCFO)
A note on this document: This Privacy Policy was prepared using CloviLegal, an AI-assisted drafting tool operated by Vital Webmaster LLC. It reflects the Company's actual data practices as of the Effective Date. This document does not constitute legal advice. Vital Webmaster LLC recommends that you seek review by qualified privacy counsel before relying on this Policy for compliance purposes, particularly with respect to jurisdiction-specific obligations that may apply to your business or your use of our Services.
Controller / Operator: Vital Webmaster LLC, a limited liability company organized under the laws of [Utah / State of formation — reviewer to confirm], doing business as CloviCFO ("Company," "we," "us," or "our").
We operate the CloviTek fleet of products, which currently includes:
| Product | Description |
|---|---|
| CloviCFO | AI-assisted bookkeeping and financial reporting |
| CloviShell | Sandboxed code-execution environment (paid SaaS) |
| CloviLegal | AI-assisted legal drafting and knowledge tool |
| CloviTrade | Market and financial research platform |
| CloviCrypto | Cryptocurrency research and information platform |
Collectively, these are referred to in this Policy as the "Services."
Privacy inquiries: Email: [email protected]
Legal and compliance inquiries: Email: [email protected]
Mailing address: [Registered address — to be inserted]
We do not currently have a designated EU Data Protection Officer ("DPO") as a formal appointment. Privacy inquiries from EU/EEA data subjects should be directed to [email protected]. We will respond to GDPR-related requests within the timelines described in Section 15.
This Privacy Policy ("Policy") describes how Vital Webmaster LLC collects, uses, stores, discloses, and protects personal information in connection with your access to and use of the Services.
GDPR applicability. Our primary application servers and databases are hosted in the European Union (France). Accordingly, personal data processed on those servers is subject to Regulation (EU) 2016/679 ("GDPR") to the extent applicable to our processing activities. We treat the GDPR's standards as our baseline data-protection floor for all users, regardless of location.
CCPA/CPRA applicability. To the extent we meet the applicable thresholds, we comply with the California Consumer Privacy Act of 2018, as amended by the California Privacy Rights Act of 2020 (collectively, "CCPA"). Section 16 provides California-specific disclosures.
What this Policy does NOT cover. This Policy does not apply to: (a) information that has been de-identified or aggregated such that it cannot reasonably be used to identify you; (b) third-party websites or services linked from our Services, which are governed by their own privacy policies; or (c) our employees or contractors in their employment/engagement context.
We collect personal information in the following categories, depending on which Service(s) you use:
| Category | Examples |
|---|---|
| Account and identity data | Full name, email address, username, password (stored as a one-way hash — never in plaintext), business name, phone number |
| Billing and subscription data | Subscription tier, billing address, payment method type (e.g., card brand, last four digits); full payment card numbers are never stored by us — they are handled exclusively by our billing processor, Chargebee, and its underlying payment network |
| Business and financial documents | Receipts, invoices, statements, and other documents you upload manually to CloviCFO |
| Communications | Messages, support tickets, and feedback you send to us |
| CloviShell usage data | Code you enter, execute, and store within sandboxed environments |
| Category | Examples |
|---|---|
| Usage and log data | Pages or features accessed, timestamps, session duration, clicks, search queries within the Service |
| Device and technical data | IP address, browser type and version, operating system, device identifiers, time zone |
| Cookies and similar technologies | Session and preference cookies, analytics identifiers (see Section 14) |
When you choose to connect a bank or credit card account through Plaid Inc. ("Plaid"), we receive — with your explicit consent — the financial data described in Section 4. This is a distinct and sensitive category of data governed by heightened protections described in that Section.
| Category | Examples |
|---|---|
| Account identification data | Account holder name, institution name, account type, masked account number |
| Transaction data | Transaction amounts, dates, merchant names, transaction descriptions, categories |
| Balance data | Current and available account balances |
| Card and payment data | Credit/debit card transaction records imported via the Plaid connection |
| Category | Examples |
|---|---|
| Categorizations and labels | AI-generated transaction categories and tags applied to your financial records |
| Draft reports and outputs | Bookkeeping summaries, financial reports, and other AI-assisted outputs generated on the basis of your data |
This Section governs our most sensitive data processing activity: the aggregation of your financial account data through Plaid. Please read it carefully.
CloviCFO integrates with Plaid Inc. (www.plaid.com) to allow you to connect your bank accounts, credit card accounts, and other financial institutions directly within the Service. The connection uses an OAuth-style authorization flow: you authenticate directly with your financial institution through Plaid's interface, and you grant explicit, informed consent before any data is transferred. We do not receive or store your bank login credentials.
Upon your consent, we receive the financial account data described in Section 3.3 above, specifically:
Lawful basis (GDPR): Consent (Article 6(1)(a)). We process your financial account data solely on the basis of your freely given, specific, informed, and unambiguous consent, provided through the Plaid authorization flow. Where financial account data constitutes special-category data under applicable law, your explicit consent also satisfies any heightened legal requirement.
Purpose limitation. Your financial account data received via Plaid is used exclusively to provide you with bookkeeping, transaction categorization, and financial reporting services within CloviCFO — and only on your behalf. We do not use Plaid-sourced data for any purpose beyond the delivery of those Services to you, the account holder who authorized the connection.
We do not sell, rent, license, share, or otherwise disclose your financial account data — including any data received via Plaid — to any third party for marketing, advertising, lead generation, or resale purposes. Period.
This commitment applies regardless of the definition of "sale" or "sharing" under any applicable law, including the CCPA.
You have the following rights with respect to your Plaid connection at any time:
| Right | How to Exercise |
|---|---|
| Disconnect a linked account | Within the CloviCFO account settings, navigate to "Connected Accounts" and select "Disconnect." This immediately terminates the ongoing data connection. |
| Request deletion of imported financial data | Submit a deletion request to [email protected]. We will delete your imported financial data from our systems within 30 days, subject to any retention required by applicable law (see Section 11). |
| Revoke consent | You may revoke consent for Plaid data processing at any time by disconnecting your account as described above, or by contacting [email protected]. Revocation does not affect the lawfulness of processing carried out before revocation. |
You may also manage your Plaid connections directly through Plaid's own data-management portal at my.plaid.com.
Plaid processes your data as a data processor acting on our behalf, and also in accordance with Plaid's Privacy Policy (available at https://plaid.com/legal/). By using the Plaid connection feature, you also agree to Plaid's End User Privacy Policy. We encourage you to review Plaid's privacy documentation.
We use the personal information we collect for the following purposes:
| Purpose | Data Used | Lawful Basis (GDPR) |
|---|---|---|
| Providing and operating the Services (account creation, authentication, feature delivery) | Account data, usage data, financial data | Contract (Art. 6(1)(b)) |
| Financial bookkeeping, categorization, and reporting (CloviCFO) | Financial account data (Plaid), uploaded documents | Contract; Consent (for Plaid data) |
| Billing and subscription management | Billing data, account data | Contract (Art. 6(1)(b)) |
| AI-assisted processing (categorization, report drafts) | Financial data, uploaded documents | Contract; Consent |
| Security, fraud detection, and abuse prevention | Log data, usage data, account data | Legitimate interests (Art. 6(1)(f)); Legal obligation |
| Customer support and responding to inquiries | Communications, account data | Contract; Legitimate interests |
| Service improvement (aggregate analytics, bug fixes) | Anonymized/aggregated usage data | Legitimate interests |
| Compliance with legal obligations | As required | Legal obligation (Art. 6(1)(c)) |
| Sending transactional and service communications (e.g., billing notices, security alerts) | Email address | Contract; Legitimate interests |
| Sending marketing communications (if you have opted in) | Email address | Consent (Art. 6(1)(a)) |
We do not use your personal information for purposes incompatible with those listed above without first obtaining your consent or otherwise establishing a lawful basis.
For users whose personal data is processed subject to the GDPR, we rely on the following lawful bases:
6.1 Consent (Article 6(1)(a)). We rely on consent for: (a) Plaid financial account data (see Section 4.3); (b) optional marketing communications; and (c) any other processing for which we specifically request your consent. You may withdraw consent at any time without affecting the lawfulness of prior processing.
6.2 Performance of a Contract (Article 6(1)(b)). We rely on contractual necessity to process data required to deliver the Services you have subscribed to, including account management, feature delivery, and billing.
6.3 Compliance with a Legal Obligation (Article 6(1)(c)). We process data as necessary to comply with applicable laws, including tax, accounting, fraud prevention, and law enforcement obligations.
6.4 Legitimate Interests (Article 6(1)(f)). We rely on legitimate interests for: (a) security monitoring and abuse prevention; (b) improving our Services through aggregated, de-identified analytics; and (c) internal administrative functions. Where we rely on legitimate interests, we have assessed that our interests are not overridden by your fundamental rights and freedoms. You have the right to object to legitimate-interests processing (see Section 15.7).
We share personal information only as described below. We do not sell personal information. We do not share personal information with third parties for their own marketing, advertising, or promotional purposes.
We share personal information with third-party vendors and service providers who process data on our behalf to help us deliver the Services. These entities are bound by data processing agreements that prohibit them from using your data for purposes beyond providing services to us. See Section 8 for the full sub-processor list.
We may disclose personal information if we believe in good faith that disclosure is necessary to:
(a) comply with a valid legal process, court order, subpoena, or binding governmental request; (b) enforce our Terms of Service or other agreements; (c) protect the rights, property, or safety of Vital Webmaster LLC, our users, or the public; or (d) detect, investigate, or prevent fraud or security incidents.
Where permitted by law, we will provide reasonable notice to you before disclosing your data in response to legal process.
If Vital Webmaster LLC undergoes a merger, acquisition, asset sale, financing, or reorganization, your personal information may be transferred as part of that transaction. We will provide notice (via email and/or a prominent notice on our website) prior to any such transfer and prior to your data becoming subject to a materially different privacy policy. In the event of a change of control, the acquirer will be required to honor the commitments in this Policy or obtain your fresh consent.
We may share aggregated, anonymized, or de-identified data — which cannot reasonably be used to identify you — for business, research, or analytics purposes. We do not attempt to re-identify de-identified data.
We may share your information for any other purpose with your prior consent.
The following is our current list of sub-processors and service providers who may process personal information on our behalf. We maintain data processing agreements with each of them.
| Sub-Processor | Purpose | Data Processed | Location |
|---|---|---|---|
| Plaid Inc. | Financial account data aggregation | Financial account data, transaction data, balance data | United States |
| Amazon Web Services (AWS) — S3 | Document and receipt storage | Uploaded receipts, invoices, and other documents | United States |
| Contabo GmbH | Primary application and database hosting | All application data processed on our servers | EU — France |
| Anthropic PBC | AI language model processing (categorization, report generation) | Transaction descriptions, document content submitted for processing | United States (contractually: no-training / zero-retention basis where available) |
| OpenAI, LLC | AI language model processing | As above | United States (contractually: no-training / zero-retention basis where available) |
| Google LLC | AI language model processing | As above | United States (contractually: no-training / zero-retention basis where available) |
| Chargebee Inc. | Subscription billing and invoicing | Billing address, subscription data, payment method type (card numbers are handled by Chargebee's payment network — not us) | United States |
| [Email delivery provider — e.g., Postmark / SendGrid — insert name] | Transactional and notification email delivery | Email address, name, notification content | [Location] |
AI sub-processor data handling note. When your data (such as transaction descriptions or document text) is submitted to Anthropic, OpenAI, or Google for AI processing, we contractually require — to the extent available under those providers' enterprise or API terms — that such providers do not use your data to train or improve their general-purpose models and do not retain your data beyond the scope of processing your request. You acknowledge that the contractual scope of these no-training commitments is determined by each provider's applicable terms, which may be updated independently.
We will update this sub-processor list when we add or remove sub-processors and will provide notice as described in Section 19.
CloviCFO uses AI language models (provided by the sub-processors listed in Section 8) to:
Other Services in the CloviTek fleet use AI in similar ways: CloviLegal uses AI to assist with legal document drafting and review; CloviTrade and CloviCrypto use AI to assist with research and information delivery.
AI-generated categorizations, entries, reports, and other outputs are not guaranteed to be accurate, complete, or current. All AI outputs require your review. You — the user — are responsible for verifying the accuracy of any output before relying on it.
CloviCFO is a bookkeeping and financial reporting tool. It is not tax advice, accounting advice, financial advice, investment advice, or legal advice. It is not a substitute for a licensed CPA, accountant, financial advisor, attorney, or other qualified professional. You should consult a licensed CPA or accountant for tax preparation, financial planning, and other professional services.
Similarly: CloviTrade and CloviCrypto provide research tools and informational content only. They are not investment advice and are not operated by a registered broker-dealer or investment adviser. You make your own investment decisions.
We do not make decisions about you that produce legal effects or similarly significant effects based solely on automated processing, within the meaning of GDPR Article 22. AI outputs in CloviCFO are recommendations presented to you for your review and override.
When content is submitted to an AI sub-processor for processing, only the minimum data necessary to generate the requested output is sent. We do not send unnecessary personal identifiers to AI sub-processors. The data submitted may include transaction descriptions, document text, and contextual metadata. It does not routinely include full account numbers, passwords, or payment card numbers.
Your data is stored and processed in the following locations:
| Data Type | Storage Location | Provider |
|---|---|---|
| Application data (account data, transaction records, bookkeeping records, AI outputs) | EU — France | Contabo |
| Uploaded documents (receipts, invoices, attachments) | United States | AWS S3 |
This means there is a cross-border transfer of personal data from the EU to the United States when you upload documents and when data is processed by US-based sub-processors (Plaid, AWS, Anthropic, OpenAI, Google, Chargebee).
When we transfer personal data from the EU/EEA to the United States or other countries not recognized by the European Commission as providing an adequate level of protection, we rely on one or more of the following transfer mechanisms:
(a) EU Standard Contractual Clauses ("SCCs"). We rely on the European Commission's approved Standard Contractual Clauses (Commission Implementing Decision (EU) 2021/914) as our primary transfer mechanism for EU-to-US transfers. We incorporate SCCs (or require our sub-processors to incorporate SCCs) for all relevant EU-to-US data transfers.
(b) EU-U.S. Data Privacy Framework. Where a US sub-processor is certified under the EU-U.S. Data Privacy Framework ("DPF") (and its UK and Swiss extensions, as applicable), we may rely on that certification as a supplementary or alternative transfer mechanism.
(c) Supplementary Technical Measures. In addition to contractual safeguards, we apply technical measures including encryption in transit (TLS) and encryption at rest for data stored on US infrastructure.
Data submitted to Anthropic, OpenAI, and Google for AI processing is transferred to the United States. Such transfers are governed by SCCs and/or applicable DPF certifications as between us and those providers, supplemented by the contractual no-training and zero-retention commitments described in Section 8.
If you are an EU/EEA data subject and have questions about the safeguards applicable to international transfers of your data, you may request a copy of the relevant transfer mechanism documents by contacting [email protected].
We retain personal information only for as long as necessary to fulfill the purposes for which it was collected, or as required or permitted by law.
| Data Category | Retention Period | Basis |
|---|---|---|
| Account and identity data | Duration of your active account, plus [2 years] after account closure or last activity | Operational necessity; legal compliance |
| Financial account data (Plaid-imported transactions, balances) | Duration of active account; deleted within 30 days of a verified deletion request or account closure, unless retention is required by law | Consent; legal obligation |
| Uploaded documents (receipts, invoices stored in AWS S3) | Duration of active account; deleted within 30 days of a verified deletion request | Consent; contract |
| Billing and subscription records | 7 years from the relevant transaction date | Legal obligation (tax and accounting records) |
| Security and audit logs | [90 days to 1 year] — rolling retention | Legitimate interests; legal obligation |
| Marketing consent records | Until consent is withdrawn, plus a reasonable period to evidence the consent | Legal obligation (consent records) |
| Support communications | [2 years] from resolution | Legitimate interests |
| AI-generated outputs stored in your account | Duration of active account; deleted upon account closure or verified deletion request | Contract |
Account closure. When you close your account, we will initiate deletion of your personal data within 30 days, subject to any legal holds or retention obligations described above. Data subject to mandatory retention will be stored in a restricted-access archive and deleted promptly upon expiration of the applicable retention period.
Aggregated data. De-identified or aggregated data derived from your information may be retained indefinitely, as it no longer constitutes personal data.
We implement a layered security program designed to protect personal information from unauthorized access, disclosure, alteration, and destruction. Our current technical and organizational measures include:
| Measure | Description |
|---|---|
| Encryption in transit | All data transmitted between your browser/client and our servers is encrypted using TLS (Transport Layer Security) |
| Encryption at rest | Data stored on our servers and in AWS S3 is encrypted at rest using industry-standard encryption |
| Password security | Passwords are stored exclusively as one-way cryptographic hashes; we do not store plaintext passwords |
| Role-based access control (RBAC) | Access to systems and data is restricted based on employee/contractor role and need-to-know |
| Least-privilege access | System permissions are scoped to the minimum level required for each role or service |
| Audit logging | Access to and modifications of sensitive data are logged for security monitoring and incident response |
| Payment card security | We do not store payment card numbers; all card processing is handled by Chargebee and its payment network |
| Sandboxing (CloviShell) | User code execution in CloviShell occurs in isolated, sandboxed environments |
No absolute guarantee. No security system is impenetrable. While we maintain these measures, we cannot guarantee that unauthorized third parties will never be able to defeat our security measures. You are responsible for maintaining the security of your own account credentials and for notifying us promptly at [email protected] if you suspect unauthorized access to your account.
In the event of a personal data breach, we will take prompt action to contain, investigate, and remediate the incident, and to notify affected parties in accordance with applicable law.
We will notify affected users of a personal data breach that is likely to result in a high risk to their rights and freedoms without undue delay and, in any event, as promptly as feasible given the circumstances. Notification will be provided via the email address associated with your account and/or a prominent notice within the Service. The notification will include, to the extent known at the time: (a) a description of the nature of the breach; (b) the categories and approximate number of individuals and records affected; (c) likely consequences; and (d) measures taken or proposed to address the breach.
Where a personal data breach is likely to result in a risk to the rights and freedoms of natural persons, and where GDPR Article 33 applies, we will notify the competent supervisory authority within 72 hours of becoming aware of the breach. If notification is not made within 72 hours, we will provide the reasons for the delay. Where applicable under GDPR Article 34, we will also notify affected data subjects without undue delay.
For the purposes of GDPR, given that our primary servers are hosted in France, the competent lead supervisory authority is the Commission Nationale de l'Informatique et des Libertés (CNIL), unless a different authority has jurisdiction for a specific matter. We will assess the applicable supervisory authority on a case-by-case basis.
| Cookie Type | Purpose | Duration |
|---|---|---|
| Essential / strictly necessary | Required for the Service to function (authentication sessions, security tokens) | Session or persistent (as required) |
| Preference / functional | Remember your settings and preferences (e.g., language, display settings) | Persistent |
| Analytics | Aggregate, anonymized usage data to help us understand how the Service is used and improve it | Persistent |
| Marketing / advertising | We do not currently use marketing or advertising tracking cookies | N/A |
You can control cookies through your browser settings. Disabling essential cookies may impair the functionality of the Service. For analytics cookies, we [describe opt-out mechanism, e.g., honor browser "Do Not Track" signals / provide an in-product cookie preference center — to be confirmed by operator].
Depending on your location and applicable law, you have the following rights regarding your personal information. We honor these rights for all users to the maximum extent practicable, regardless of whether GDPR or CCPA technically applies to your jurisdiction.
You have the right to request confirmation of whether we process your personal data, and to receive a copy of the personal data we hold about you, along with information about how it is used and shared.
You have the right to request correction of inaccurate personal data we hold about you, and to have incomplete data completed.
You have the right to request deletion of your personal data where: (a) the data is no longer necessary for the purposes for which it was collected; (b) you withdraw consent and there is no other lawful basis for processing; (c) you object to processing and there are no overriding legitimate grounds; or (d) the data has been unlawfully processed. We will honor erasure requests within 30 days, subject to legal retention obligations described in Section 11.
You have the right to receive your personal data that you have provided to us in a structured, commonly used, machine-readable format (e.g., CSV or JSON), and to transmit it to another controller, where technically feasible. This right applies to data processed on the basis of consent or contract.
You have the right to request that we restrict the processing of your personal data in certain circumstances, including where you contest the accuracy of the data or where you have objected to processing pending verification of our legitimate grounds.
Where processing is based on consent, you may withdraw your consent at any time. Withdrawal does not affect the lawfulness of processing carried out before withdrawal. To withdraw consent for Plaid data processing, disconnect your linked account (Section 4.5). To withdraw consent for marketing communications, use the unsubscribe link in any marketing email or contact [email protected].
You have the right to object at any time to processing of your personal data where we rely on legitimate interests as the lawful basis. We will cease processing unless we can demonstrate compelling legitimate grounds that override your interests, or unless processing is necessary for the establishment, exercise, or defense of legal claims.
As described in Section 9.3, we do not make solely automated decisions that produce legal or similarly significant effects about you.
If you are an EU/EEA data subject and believe that our processing of your personal data violates the GDPR, you have the right to lodge a complaint with the competent supervisory authority in your EU/EEA member state of habitual residence, place of work, or place of the alleged infringement. The CNIL (France) contact page is available at www.cnil.fr. UK residents may contact the ICO at www.ico.org.uk.
To exercise any of the rights above, contact us at [email protected] with the subject line "Privacy Rights Request." Please include: (a) your name and the email address associated with your account; (b) the specific right(s) you wish to exercise; and (c) sufficient information to allow us to verify your identity and locate your data.
Response timeline. We will acknowledge your request within 5 business days and respond substantively within 30 days of receipt. We may extend this period by an additional 60 days where necessary for complex requests, in which case we will provide notice of the extension and reasons within the initial 30-day window (consistent with GDPR Art. 12(3)).
Identity verification. We will take reasonable steps to verify your identity before fulfilling a request to access, export, or delete your data. We will not use verification data for any purpose beyond verifying your identity.
Authorized agents. Where permitted by applicable law, you may submit a rights request through an authorized agent by providing written authorization to [email protected].
DRAFT — NOT YET PUBLISHED. This document was generated by the CloviLegal DraftAgent engine (model claude-sonnet-4-6) on 2026-06-24 from the controlling facts supplied. AI drafting/review assistant — not legal advice. Consult a licensed attorney. It is an AI-generated starting draft and is not legal advice; have a licensed attorney review before publishing — especially the GDPR, Plaid, and international-transfer clauses.