Privacy Policy
How ClearVault protects, handles, and respects your data.
Last Updated: April 2026
1. Introduction
ClearVault ("Company," "we," "our," or "us") is committed to protecting personal data and maintaining the highest standards of privacy, security, and regulatory compliance.
This Privacy Policy describes how we collect, use, disclose, and safeguard personal data in connection with our website, platform, and related services (collectively, the "Services").
This Policy is designed to align with applicable privacy laws and frameworks, including but not limited to the General Data Protection Regulation (GDPR) and the California Consumer Privacy Act, as amended by the California Privacy Rights Act (CCPA/CPRA).
By using our Services, you acknowledge and agree to the practices described in this Policy.
2. Scope and Role
ClearVault operates as:
- A Data Controller with respect to personal data collected through our website and direct interactions
- A Data Processor / Service Provider with respect to data stored and processed on behalf of our customers
Where we act as a processor, we process personal data solely on documented instructions from the customer (the "Controller").
3. Information We Collect
3.1 Information You Provide
We may collect:
- Full name
- Business email address
- Company name
- Job title
- Phone number
- Any information submitted via forms or communications
3.2 Automatically Collected Data
We may collect:
- IP address
- Device identifiers
- Browser and operating system
- Usage patterns and session data
- Referring URLs and interaction data
3.3 Cookies and Tracking Technologies
We use cookies and similar technologies for site functionality, analytics and performance monitoring, and user experience optimization. Users may manage cookie preferences via browser settings or consent banners where required by law.
4. Legal Bases for Processing (GDPR)
Where the GDPR applies, we rely on the following legal bases:
- Consent — where you have given clear consent
- Contractual Necessity — to perform a contract or pre-contractual steps
- Legitimate Interests — including service improvement, security, and business operations
- Legal Obligation — where processing is required by law
5. How We Use Personal Data
We process personal data to:
- Respond to inquiries and demo requests
- Provide, maintain, and improve our Services
- Communicate with users and customers
- Ensure platform security and integrity
- Perform analytics and performance monitoring
- Comply with legal and regulatory obligations
6. Disclosure of Information
We do not sell personal data.
We may disclose data to:
- Infrastructure providers (hosting, storage, cloud services)
- Analytics providers
- Communication and CRM platforms
- Legal and regulatory authorities
- Successors in the event of a merger, acquisition, or asset sale
All third parties are contractually obligated to implement appropriate safeguards.
7. Data Security
We implement enterprise-grade safeguards, including:
- Encryption in transit (TLS 1.2+)
- Encryption at rest
- Department-Level Access and Table-Level Access
- Activity logging and monitoring
- Incident response procedures
We are SOC 2 compliant and actively progressing toward formal certification.
8. Data Retention
We retain personal data only for as long as necessary to:
- Fulfill contractual obligations
- Meet legal and regulatory requirements
- Resolve disputes and enforce agreements
Retention periods may vary based on data type and applicable laws.
9. GDPR — Data Subject Rights (EU/EEA)
If you are located in the European Economic Area, you have the following rights:
- Right of access
- Right to rectification
- Right to erasure ("right to be forgotten")
- Right to restrict processing
- Right to data portability
- Right to object to processing
- Right to withdraw consent
Requests may be submitted to: privacy@clearvault.tech
You also have the right to lodge a complaint with your local supervisory authority.
10. International Data Transfers (GDPR)
Personal data may be transferred outside the EEA, including to the United States.
Where applicable, we rely on:
- Standard Contractual Clauses (SCCs)
- Other legally recognized transfer mechanisms
We implement safeguards to ensure an equivalent level of data protection.
11. CCPA / CPRA — California Privacy Rights
If you are a California resident, you have the following rights:
- Right to know what personal information is collected
- Right to access personal information
- Right to correct inaccurate information
- Right to delete personal information
- Right to opt-out of sale or sharing (we do not sell data)
- Right to limit use of sensitive personal information
- Right to non-discrimination
To exercise your rights, contact: privacy@clearvault.tech
We will verify requests in accordance with applicable law.
12. Do Not Sell or Share (California)
ClearVault does not sell or share personal information as defined under CCPA/CPRA.
13. Children's Privacy
Our Services are not directed to individuals under 13 years of age. We do not knowingly collect personal data from children.
14. Third-Party Links
Our Services may contain links to third-party websites. We are not responsible for their privacy practices.
15. Data Processing Addendum (DPA) — Enterprise Clients
For customers subject to GDPR or other data protection laws, ClearVault offers a Data Processing Addendum ("DPA") governing the processing of personal data.
The DPA includes:
- Processing subject matter and duration
- Nature and purpose of processing
- Types of personal data and categories of data subjects
- Obligations and rights of the controller
- Confidentiality obligations
- Security measures
- Subprocessors and approval mechanisms
- Breach notification obligations
- Audit and inspection rights
- Data return or deletion upon termination
The DPA is available upon request or executed as part of enterprise agreements.
16. Changes to This Policy
We may update this Privacy Policy periodically. Updates will be posted with a revised "Last Updated" date.
17. Contact Information
For questions, requests, or concerns:
Email: privacy@clearvault.tech