CloviCFO
This document was prepared with AI assistance and reflects our current practices. It is being reviewed by counsel; for questions email [email protected].

Privacy Policy

Effective date: July 14, 2025 Vital Webmaster LLC (doing business as CloviCFO)


A note on this document: This Privacy Policy was prepared using CloviLegal, an AI-assisted drafting tool operated by Vital Webmaster LLC. It reflects the Company's actual data practices as of the Effective Date. This document does not constitute legal advice. Vital Webmaster LLC recommends that you seek review by qualified privacy counsel before relying on this Policy for compliance purposes, particularly with respect to jurisdiction-specific obligations that may apply to your business or your use of our Services.


Table of Contents

  1. Who We Are and How to Contact Us
  2. Scope of This Policy
  3. Categories of Personal Information We Collect
  4. Plaid and Financial Account Data
  5. How We Use Your Information
  6. Lawful Bases for Processing (GDPR)
  7. How We Share Your Information
  8. Sub-Processors and Third-Party Service Providers
  9. AI and Automated Processing
  10. Data Residency and International Transfers
  11. Data Retention
  12. Security Measures
  13. Breach Notification
  14. Cookies and Tracking Technologies
  15. Your Data-Subject Rights
  16. California Privacy Rights (CCPA / CPRA)
  17. Children and Minimum Age
  18. Third-Party Links and Services
  19. Changes to This Policy
  20. Governing Law

1. Who We Are and How to Contact Us

Controller / Operator: Vital Webmaster LLC, a limited liability company organized under the laws of [Utah / State of formation — reviewer to confirm], doing business as CloviCFO ("Company," "we," "us," or "our").

We operate the CloviTek fleet of products, which currently includes:

Product Description
CloviCFO AI-assisted bookkeeping and financial reporting
CloviShell Sandboxed code-execution environment (paid SaaS)
CloviLegal AI-assisted legal drafting and knowledge tool
CloviTrade Market and financial research platform
CloviCrypto Cryptocurrency research and information platform

Collectively, these are referred to in this Policy as the "Services."

Privacy inquiries: Email: [email protected]

Legal and compliance inquiries: Email: [email protected]

Mailing address: [Registered address — to be inserted]

We do not currently have a designated EU Data Protection Officer ("DPO") as a formal appointment. Privacy inquiries from EU/EEA data subjects should be directed to [email protected]. We will respond to GDPR-related requests within the timelines described in Section 15.


2. Scope of This Policy

This Privacy Policy ("Policy") describes how Vital Webmaster LLC collects, uses, stores, discloses, and protects personal information in connection with your access to and use of the Services.

GDPR applicability. Our primary application servers and databases are hosted in the European Union (France). Accordingly, personal data processed on those servers is subject to Regulation (EU) 2016/679 ("GDPR") to the extent applicable to our processing activities. We treat the GDPR's standards as our baseline data-protection floor for all users, regardless of location.

CCPA/CPRA applicability. To the extent we meet the applicable thresholds, we comply with the California Consumer Privacy Act of 2018, as amended by the California Privacy Rights Act of 2020 (collectively, "CCPA"). Section 16 provides California-specific disclosures.

What this Policy does NOT cover. This Policy does not apply to: (a) information that has been de-identified or aggregated such that it cannot reasonably be used to identify you; (b) third-party websites or services linked from our Services, which are governed by their own privacy policies; or (c) our employees or contractors in their employment/engagement context.


3. Categories of Personal Information We Collect

We collect personal information in the following categories, depending on which Service(s) you use:

3.1 Information You Provide Directly

Category Examples
Account and identity data Full name, email address, username, password (stored as a one-way hash — never in plaintext), business name, phone number
Billing and subscription data Subscription tier, billing address, payment method type (e.g., card brand, last four digits); full payment card numbers are never stored by us — they are handled exclusively by our billing processor, Chargebee, and its underlying payment network
Business and financial documents Receipts, invoices, statements, and other documents you upload manually to CloviCFO
Communications Messages, support tickets, and feedback you send to us
CloviShell usage data Code you enter, execute, and store within sandboxed environments

3.2 Information Collected Automatically

Category Examples
Usage and log data Pages or features accessed, timestamps, session duration, clicks, search queries within the Service
Device and technical data IP address, browser type and version, operating system, device identifiers, time zone
Cookies and similar technologies Session and preference cookies, analytics identifiers (see Section 14)

3.3 Financial Account Data (via Plaid)

When you choose to connect a bank or credit card account through Plaid Inc. ("Plaid"), we receive — with your explicit consent — the financial data described in Section 4. This is a distinct and sensitive category of data governed by heightened protections described in that Section.

Category Examples
Account identification data Account holder name, institution name, account type, masked account number
Transaction data Transaction amounts, dates, merchant names, transaction descriptions, categories
Balance data Current and available account balances
Card and payment data Credit/debit card transaction records imported via the Plaid connection

3.4 AI-Generated and Derived Data

Category Examples
Categorizations and labels AI-generated transaction categories and tags applied to your financial records
Draft reports and outputs Bookkeeping summaries, financial reports, and other AI-assisted outputs generated on the basis of your data

4. Plaid and Financial Account Data

This Section governs our most sensitive data processing activity: the aggregation of your financial account data through Plaid. Please read it carefully.

4.1 How the Connection Works

CloviCFO integrates with Plaid Inc. (www.plaid.com) to allow you to connect your bank accounts, credit card accounts, and other financial institutions directly within the Service. The connection uses an OAuth-style authorization flow: you authenticate directly with your financial institution through Plaid's interface, and you grant explicit, informed consent before any data is transferred. We do not receive or store your bank login credentials.

4.2 What Data We Receive via Plaid

Upon your consent, we receive the financial account data described in Section 3.3 above, specifically:

4.3 Lawful Basis for Processing Financial Account Data

Lawful basis (GDPR): Consent (Article 6(1)(a)). We process your financial account data solely on the basis of your freely given, specific, informed, and unambiguous consent, provided through the Plaid authorization flow. Where financial account data constitutes special-category data under applicable law, your explicit consent also satisfies any heightened legal requirement.

Purpose limitation. Your financial account data received via Plaid is used exclusively to provide you with bookkeeping, transaction categorization, and financial reporting services within CloviCFO — and only on your behalf. We do not use Plaid-sourced data for any purpose beyond the delivery of those Services to you, the account holder who authorized the connection.

4.4 No Sale or Marketing Use of Financial Data

We do not sell, rent, license, share, or otherwise disclose your financial account data — including any data received via Plaid — to any third party for marketing, advertising, lead generation, or resale purposes. Period.

This commitment applies regardless of the definition of "sale" or "sharing" under any applicable law, including the CCPA.

4.5 Your Rights Regarding Plaid-Connected Accounts

You have the following rights with respect to your Plaid connection at any time:

Right How to Exercise
Disconnect a linked account Within the CloviCFO account settings, navigate to "Connected Accounts" and select "Disconnect." This immediately terminates the ongoing data connection.
Request deletion of imported financial data Submit a deletion request to [email protected]. We will delete your imported financial data from our systems within 30 days, subject to any retention required by applicable law (see Section 11).
Revoke consent You may revoke consent for Plaid data processing at any time by disconnecting your account as described above, or by contacting [email protected]. Revocation does not affect the lawfulness of processing carried out before revocation.

You may also manage your Plaid connections directly through Plaid's own data-management portal at my.plaid.com.

4.6 Plaid's Own Privacy Practices

Plaid processes your data as a data processor acting on our behalf, and also in accordance with Plaid's Privacy Policy (available at https://plaid.com/legal/). By using the Plaid connection feature, you also agree to Plaid's End User Privacy Policy. We encourage you to review Plaid's privacy documentation.


5. How We Use Your Information

We use the personal information we collect for the following purposes:

Purpose Data Used Lawful Basis (GDPR)
Providing and operating the Services (account creation, authentication, feature delivery) Account data, usage data, financial data Contract (Art. 6(1)(b))
Financial bookkeeping, categorization, and reporting (CloviCFO) Financial account data (Plaid), uploaded documents Contract; Consent (for Plaid data)
Billing and subscription management Billing data, account data Contract (Art. 6(1)(b))
AI-assisted processing (categorization, report drafts) Financial data, uploaded documents Contract; Consent
Security, fraud detection, and abuse prevention Log data, usage data, account data Legitimate interests (Art. 6(1)(f)); Legal obligation
Customer support and responding to inquiries Communications, account data Contract; Legitimate interests
Service improvement (aggregate analytics, bug fixes) Anonymized/aggregated usage data Legitimate interests
Compliance with legal obligations As required Legal obligation (Art. 6(1)(c))
Sending transactional and service communications (e.g., billing notices, security alerts) Email address Contract; Legitimate interests
Sending marketing communications (if you have opted in) Email address Consent (Art. 6(1)(a))

We do not use your personal information for purposes incompatible with those listed above without first obtaining your consent or otherwise establishing a lawful basis.


6. Lawful Bases for Processing (GDPR)

For users whose personal data is processed subject to the GDPR, we rely on the following lawful bases:

6.1 Consent (Article 6(1)(a)). We rely on consent for: (a) Plaid financial account data (see Section 4.3); (b) optional marketing communications; and (c) any other processing for which we specifically request your consent. You may withdraw consent at any time without affecting the lawfulness of prior processing.

6.2 Performance of a Contract (Article 6(1)(b)). We rely on contractual necessity to process data required to deliver the Services you have subscribed to, including account management, feature delivery, and billing.

6.3 Compliance with a Legal Obligation (Article 6(1)(c)). We process data as necessary to comply with applicable laws, including tax, accounting, fraud prevention, and law enforcement obligations.

6.4 Legitimate Interests (Article 6(1)(f)). We rely on legitimate interests for: (a) security monitoring and abuse prevention; (b) improving our Services through aggregated, de-identified analytics; and (c) internal administrative functions. Where we rely on legitimate interests, we have assessed that our interests are not overridden by your fundamental rights and freedoms. You have the right to object to legitimate-interests processing (see Section 15.7).


7. How We Share Your Information

We share personal information only as described below. We do not sell personal information. We do not share personal information with third parties for their own marketing, advertising, or promotional purposes.

7.1 Service Providers and Sub-Processors

We share personal information with third-party vendors and service providers who process data on our behalf to help us deliver the Services. These entities are bound by data processing agreements that prohibit them from using your data for purposes beyond providing services to us. See Section 8 for the full sub-processor list.

7.2 Legal Requirements and Protection of Rights

We may disclose personal information if we believe in good faith that disclosure is necessary to:

(a) comply with a valid legal process, court order, subpoena, or binding governmental request; (b) enforce our Terms of Service or other agreements; (c) protect the rights, property, or safety of Vital Webmaster LLC, our users, or the public; or (d) detect, investigate, or prevent fraud or security incidents.

Where permitted by law, we will provide reasonable notice to you before disclosing your data in response to legal process.

7.3 Business Transfers

If Vital Webmaster LLC undergoes a merger, acquisition, asset sale, financing, or reorganization, your personal information may be transferred as part of that transaction. We will provide notice (via email and/or a prominent notice on our website) prior to any such transfer and prior to your data becoming subject to a materially different privacy policy. In the event of a change of control, the acquirer will be required to honor the commitments in this Policy or obtain your fresh consent.

7.4 Aggregated and De-Identified Data

We may share aggregated, anonymized, or de-identified data — which cannot reasonably be used to identify you — for business, research, or analytics purposes. We do not attempt to re-identify de-identified data.

7.5 With Your Consent

We may share your information for any other purpose with your prior consent.


8. Sub-Processors and Third-Party Service Providers

The following is our current list of sub-processors and service providers who may process personal information on our behalf. We maintain data processing agreements with each of them.

Sub-Processor Purpose Data Processed Location
Plaid Inc. Financial account data aggregation Financial account data, transaction data, balance data United States
Amazon Web Services (AWS) — S3 Document and receipt storage Uploaded receipts, invoices, and other documents United States
Contabo GmbH Primary application and database hosting All application data processed on our servers EU — France
Anthropic PBC AI language model processing (categorization, report generation) Transaction descriptions, document content submitted for processing United States (contractually: no-training / zero-retention basis where available)
OpenAI, LLC AI language model processing As above United States (contractually: no-training / zero-retention basis where available)
Google LLC AI language model processing As above United States (contractually: no-training / zero-retention basis where available)
Chargebee Inc. Subscription billing and invoicing Billing address, subscription data, payment method type (card numbers are handled by Chargebee's payment network — not us) United States
[Email delivery provider — e.g., Postmark / SendGrid — insert name] Transactional and notification email delivery Email address, name, notification content [Location]

AI sub-processor data handling note. When your data (such as transaction descriptions or document text) is submitted to Anthropic, OpenAI, or Google for AI processing, we contractually require — to the extent available under those providers' enterprise or API terms — that such providers do not use your data to train or improve their general-purpose models and do not retain your data beyond the scope of processing your request. You acknowledge that the contractual scope of these no-training commitments is determined by each provider's applicable terms, which may be updated independently.

We will update this sub-processor list when we add or remove sub-processors and will provide notice as described in Section 19.


9. AI and Automated Processing

9.1 How AI Is Used

CloviCFO uses AI language models (provided by the sub-processors listed in Section 8) to:

Other Services in the CloviTek fleet use AI in similar ways: CloviLegal uses AI to assist with legal document drafting and review; CloviTrade and CloviCrypto use AI to assist with research and information delivery.

9.2 AI Outputs Are Not Guaranteed — User Responsibility

AI-generated categorizations, entries, reports, and other outputs are not guaranteed to be accurate, complete, or current. All AI outputs require your review. You — the user — are responsible for verifying the accuracy of any output before relying on it.

CloviCFO is a bookkeeping and financial reporting tool. It is not tax advice, accounting advice, financial advice, investment advice, or legal advice. It is not a substitute for a licensed CPA, accountant, financial advisor, attorney, or other qualified professional. You should consult a licensed CPA or accountant for tax preparation, financial planning, and other professional services.

Similarly: CloviTrade and CloviCrypto provide research tools and informational content only. They are not investment advice and are not operated by a registered broker-dealer or investment adviser. You make your own investment decisions.

9.3 No Solely Automated Decisions with Legal or Significant Effects

We do not make decisions about you that produce legal effects or similarly significant effects based solely on automated processing, within the meaning of GDPR Article 22. AI outputs in CloviCFO are recommendations presented to you for your review and override.

9.4 Data Submitted to AI Sub-Processors

When content is submitted to an AI sub-processor for processing, only the minimum data necessary to generate the requested output is sent. We do not send unnecessary personal identifiers to AI sub-processors. The data submitted may include transaction descriptions, document text, and contextual metadata. It does not routinely include full account numbers, passwords, or payment card numbers.


10. Data Residency and International Transfers

10.1 Where Your Data Is Stored

Your data is stored and processed in the following locations:

Data Type Storage Location Provider
Application data (account data, transaction records, bookkeeping records, AI outputs) EU — France Contabo
Uploaded documents (receipts, invoices, attachments) United States AWS S3

This means there is a cross-border transfer of personal data from the EU to the United States when you upload documents and when data is processed by US-based sub-processors (Plaid, AWS, Anthropic, OpenAI, Google, Chargebee).

10.2 Transfer Mechanisms for EU/EEA Personal Data

When we transfer personal data from the EU/EEA to the United States or other countries not recognized by the European Commission as providing an adequate level of protection, we rely on one or more of the following transfer mechanisms:

(a) EU Standard Contractual Clauses ("SCCs"). We rely on the European Commission's approved Standard Contractual Clauses (Commission Implementing Decision (EU) 2021/914) as our primary transfer mechanism for EU-to-US transfers. We incorporate SCCs (or require our sub-processors to incorporate SCCs) for all relevant EU-to-US data transfers.

(b) EU-U.S. Data Privacy Framework. Where a US sub-processor is certified under the EU-U.S. Data Privacy Framework ("DPF") (and its UK and Swiss extensions, as applicable), we may rely on that certification as a supplementary or alternative transfer mechanism.

(c) Supplementary Technical Measures. In addition to contractual safeguards, we apply technical measures including encryption in transit (TLS) and encryption at rest for data stored on US infrastructure.

10.3 Transfers to AI Sub-Processors

Data submitted to Anthropic, OpenAI, and Google for AI processing is transferred to the United States. Such transfers are governed by SCCs and/or applicable DPF certifications as between us and those providers, supplemented by the contractual no-training and zero-retention commitments described in Section 8.

10.4 Transfers Outside the EU/EEA — Your Rights

If you are an EU/EEA data subject and have questions about the safeguards applicable to international transfers of your data, you may request a copy of the relevant transfer mechanism documents by contacting [email protected].


11. Data Retention

We retain personal information only for as long as necessary to fulfill the purposes for which it was collected, or as required or permitted by law.

Data Category Retention Period Basis
Account and identity data Duration of your active account, plus [2 years] after account closure or last activity Operational necessity; legal compliance
Financial account data (Plaid-imported transactions, balances) Duration of active account; deleted within 30 days of a verified deletion request or account closure, unless retention is required by law Consent; legal obligation
Uploaded documents (receipts, invoices stored in AWS S3) Duration of active account; deleted within 30 days of a verified deletion request Consent; contract
Billing and subscription records 7 years from the relevant transaction date Legal obligation (tax and accounting records)
Security and audit logs [90 days to 1 year] — rolling retention Legitimate interests; legal obligation
Marketing consent records Until consent is withdrawn, plus a reasonable period to evidence the consent Legal obligation (consent records)
Support communications [2 years] from resolution Legitimate interests
AI-generated outputs stored in your account Duration of active account; deleted upon account closure or verified deletion request Contract

Account closure. When you close your account, we will initiate deletion of your personal data within 30 days, subject to any legal holds or retention obligations described above. Data subject to mandatory retention will be stored in a restricted-access archive and deleted promptly upon expiration of the applicable retention period.

Aggregated data. De-identified or aggregated data derived from your information may be retained indefinitely, as it no longer constitutes personal data.


12. Security Measures

We implement a layered security program designed to protect personal information from unauthorized access, disclosure, alteration, and destruction. Our current technical and organizational measures include:

Measure Description
Encryption in transit All data transmitted between your browser/client and our servers is encrypted using TLS (Transport Layer Security)
Encryption at rest Data stored on our servers and in AWS S3 is encrypted at rest using industry-standard encryption
Password security Passwords are stored exclusively as one-way cryptographic hashes; we do not store plaintext passwords
Role-based access control (RBAC) Access to systems and data is restricted based on employee/contractor role and need-to-know
Least-privilege access System permissions are scoped to the minimum level required for each role or service
Audit logging Access to and modifications of sensitive data are logged for security monitoring and incident response
Payment card security We do not store payment card numbers; all card processing is handled by Chargebee and its payment network
Sandboxing (CloviShell) User code execution in CloviShell occurs in isolated, sandboxed environments

No absolute guarantee. No security system is impenetrable. While we maintain these measures, we cannot guarantee that unauthorized third parties will never be able to defeat our security measures. You are responsible for maintaining the security of your own account credentials and for notifying us promptly at [email protected] if you suspect unauthorized access to your account.


13. Breach Notification

13.1 Our Commitment

In the event of a personal data breach, we will take prompt action to contain, investigate, and remediate the incident, and to notify affected parties in accordance with applicable law.

13.2 Notification to Affected Users

We will notify affected users of a personal data breach that is likely to result in a high risk to their rights and freedoms without undue delay and, in any event, as promptly as feasible given the circumstances. Notification will be provided via the email address associated with your account and/or a prominent notice within the Service. The notification will include, to the extent known at the time: (a) a description of the nature of the breach; (b) the categories and approximate number of individuals and records affected; (c) likely consequences; and (d) measures taken or proposed to address the breach.

13.3 Regulatory Notification — GDPR (72-Hour Rule)

Where a personal data breach is likely to result in a risk to the rights and freedoms of natural persons, and where GDPR Article 33 applies, we will notify the competent supervisory authority within 72 hours of becoming aware of the breach. If notification is not made within 72 hours, we will provide the reasons for the delay. Where applicable under GDPR Article 34, we will also notify affected data subjects without undue delay.

13.4 Competent Supervisory Authority

For the purposes of GDPR, given that our primary servers are hosted in France, the competent lead supervisory authority is the Commission Nationale de l'Informatique et des Libertés (CNIL), unless a different authority has jurisdiction for a specific matter. We will assess the applicable supervisory authority on a case-by-case basis.


14. Cookies and Tracking Technologies

14.1 Types of Cookies We Use

Cookie Type Purpose Duration
Essential / strictly necessary Required for the Service to function (authentication sessions, security tokens) Session or persistent (as required)
Preference / functional Remember your settings and preferences (e.g., language, display settings) Persistent
Analytics Aggregate, anonymized usage data to help us understand how the Service is used and improve it Persistent
Marketing / advertising We do not currently use marketing or advertising tracking cookies N/A

14.2 Managing Cookies

You can control cookies through your browser settings. Disabling essential cookies may impair the functionality of the Service. For analytics cookies, we [describe opt-out mechanism, e.g., honor browser "Do Not Track" signals / provide an in-product cookie preference center — to be confirmed by operator].


15. Your Data-Subject Rights

Depending on your location and applicable law, you have the following rights regarding your personal information. We honor these rights for all users to the maximum extent practicable, regardless of whether GDPR or CCPA technically applies to your jurisdiction.

15.1 Right of Access (GDPR Art. 15)

You have the right to request confirmation of whether we process your personal data, and to receive a copy of the personal data we hold about you, along with information about how it is used and shared.

15.2 Right to Rectification (GDPR Art. 16)

You have the right to request correction of inaccurate personal data we hold about you, and to have incomplete data completed.

15.3 Right to Erasure / Deletion ("Right to Be Forgotten") (GDPR Art. 17)

You have the right to request deletion of your personal data where: (a) the data is no longer necessary for the purposes for which it was collected; (b) you withdraw consent and there is no other lawful basis for processing; (c) you object to processing and there are no overriding legitimate grounds; or (d) the data has been unlawfully processed. We will honor erasure requests within 30 days, subject to legal retention obligations described in Section 11.

15.4 Right to Data Portability (GDPR Art. 20)

You have the right to receive your personal data that you have provided to us in a structured, commonly used, machine-readable format (e.g., CSV or JSON), and to transmit it to another controller, where technically feasible. This right applies to data processed on the basis of consent or contract.

15.5 Right to Restriction of Processing (GDPR Art. 18)

You have the right to request that we restrict the processing of your personal data in certain circumstances, including where you contest the accuracy of the data or where you have objected to processing pending verification of our legitimate grounds.

15.6 Right to Withdraw Consent (GDPR Art. 7(3))

Where processing is based on consent, you may withdraw your consent at any time. Withdrawal does not affect the lawfulness of processing carried out before withdrawal. To withdraw consent for Plaid data processing, disconnect your linked account (Section 4.5). To withdraw consent for marketing communications, use the unsubscribe link in any marketing email or contact [email protected].

15.7 Right to Object (GDPR Art. 21)

You have the right to object at any time to processing of your personal data where we rely on legitimate interests as the lawful basis. We will cease processing unless we can demonstrate compelling legitimate grounds that override your interests, or unless processing is necessary for the establishment, exercise, or defense of legal claims.

15.8 Right Not to Be Subject to Solely Automated Decision-Making (GDPR Art. 22)

As described in Section 9.3, we do not make solely automated decisions that produce legal or similarly significant effects about you.

15.9 Right to Lodge a Complaint

If you are an EU/EEA data subject and believe that our processing of your personal data violates the GDPR, you have the right to lodge a complaint with the competent supervisory authority in your EU/EEA member state of habitual residence, place of work, or place of the alleged infringement. The CNIL (France) contact page is available at www.cnil.fr. UK residents may contact the ICO at www.ico.org.uk.

15.10 How to Exercise Your Rights

To exercise any of the rights above, contact us at [email protected] with the subject line "Privacy Rights Request." Please include: (a) your name and the email address associated with your account; (b) the specific right(s) you wish to exercise; and (c) sufficient information to allow us to verify your identity and locate your data.

Response timeline. We will acknowledge your request within 5 business days and respond substantively within 30 days of receipt. We may extend this period by an additional 60 days where necessary for complex requests, in which case we will provide notice of the extension and reasons within the initial 30-day window (consistent with GDPR Art. 12(3)).

Identity verification. We will take reasonable steps to verify your identity before fulfilling a request to access, export, or delete your data. We will not use verification data for any purpose beyond verifying your identity.

Authorized agents. Where permitted by applicable law, you may submit a rights request through an authorized agent by providing written authorization to [email protected].



DRAFT — NOT YET PUBLISHED. This document was generated by the CloviLegal DraftAgent engine (model claude-sonnet-4-6) on 2026-06-24 from the controlling facts supplied. AI drafting/review assistant — not legal advice. Consult a licensed attorney. It is an AI-generated starting draft and is not legal advice; have a licensed attorney review before publishing — especially the GDPR, Plaid, and international-transfer clauses.