Last updated 7 October 2026
This page is for organisations using Cloverr. It explains how we handle workspace data: everything your organisation and its people put into Cloverr. Together with the Terms of use, it forms the data processing terms between your organisation (the controller) and Kyle Kozlowski, trading as Cloverr (the processor), as required by Article 28 of the UK GDPR.
What we process, and why
- Subject matter: providing Cloverr to your organisation.
- Duration: while your organisation uses Cloverr, and until its data is deleted afterwards.
- Nature and purpose: storing, organising, displaying, transmitting, searching and analysing content, including with AI features, to provide the service your organisation and its people use.
- Types of personal data: names, email addresses, profile details, messages, emails, documents, files, calendar entries, call captions, transcripts and recordings, form answers, contact and company records, and anything else your organisation adds.
- Data subjects: your organisation's members, guests, customers, contacts, people who book time or fill in forms, and anyone else whose data you put into Cloverr.
Our commitments
As your processor we will:
- Process workspace data only on your documented instructions: your use and configuration of Cloverr, and these terms. We'll tell you if we believe an instruction breaks data protection law.
- Make sure anyone with access to it is bound by confidentiality.
- Protect it with appropriate technical and organisational measures (below).
- Use sub-processors only as described below. We'll give notice of changes so you can object.
- Help you respond to requests from data subjects, and with security, breach notification, impact assessments and consultations with the ICO, as far as is reasonable given what we process.
- Tell you without undue delay after becoming aware of a personal data breach affecting your data. We'll include what we know and what we're doing about it.
- Delete or return workspace data when you stop using Cloverr. Deletion from live systems happens within 30 days, and from backups when they cycle out, unless the law requires us to keep it.
- Make available the information needed to show we meet these obligations, and allow reasonable audits. These are normally met by written answers to your questions.
AI processing
- AI features process only the content your organisation gives each AI teammate access to.
- Your workspace data is never used to train AI models.
- AI features run on infrastructure we operate. If your organisation connects its own AI provider key, the content sent to that provider is processed under your organisation's agreement with them.
Where data is stored
- Hosting: Cloverr runs on servers hosted with Oracle Cloud Infrastructure.
- Isolation: it runs in an isolated container on an isolated private network that is separate from other systems. Only the web entry point is reachable from the internet. The database and internal services are not exposed.
- Transfers outside the UK: where a sub-processor processes data outside the UK, appropriate safeguards are in place (see the Privacy policy).
Security measures
- Encryption in transit: all traffic is encrypted with TLS (HTTPS) between your browser and Cloverr.
- Passwords: stored only as strong one-way hashes. Sign-in codes are hashed.
- Secrets: credentials for connected services (calendar subscriptions, GitHub, your own AI keys) are encrypted at rest.
- Sign-in protection: login verification, alerts for new devices, breached-password checks and rate limiting.
- Access control: a role-based permission model inside each organisation. Private mail and personal calendars are visible only to their owner. AI teammates are limited to the access they're given.
- Abuse prevention: automated review of outgoing email, and screening for scams and phishing.
- Least privilege: administrative access to production systems is restricted to the operator.
- Monitoring: health monitoring, with a public status page.
Sub-processors
| Sub-processor | Purpose |
|---|---|
| Oracle Cloud Infrastructure | Hosting of servers and storage |
| Network security and content delivery provider | Protecting and delivering the site |
| Email delivery provider | Sending and receiving email for Cloverr addresses |
Your organisation may also connect services itself (for example GitHub or its own AI provider). Those are your choice and under your agreement with them.
Questions
Email kyle@imkylejk.me.