Last updated 7 October 2026
Cloverr is run by Kyle Kozlowski, a sole trader based in Dundee, Scotland, United Kingdom ("we", "us"). This policy explains how we handle personal data when you use Cloverr at cloverr.co.uk and its subdomains, including the app, booking pages, forms, the community forum, the status and legal pages, and the API.
Who is responsible for your data
For your account (your name, email address, sign-in and billing details), and for running and protecting the service, we are the controller under the UK GDPR and the Data Protection Act 2018.
For what an organisation puts into its workspace (mail, chat, documents, files, tasks, calendars, calls, forms, contacts and so on), the organisation is the controller and we process it on its behalf as its processor. If you're asking about something inside an organisation's workspace, contact that organisation first; we'll help them answer you. See Data handling for how we process workspace data.
You can contact us about anything in this policy at kyle@imkylejk.me.
What we collect
Account details. Your name, email address, password (stored only as a one-way hash), profile photo, job title, time zone, notification and display settings, and whether you've turned on login verification.
Sign-in and security information. The IP address and browser or app details of each signed-in session, a fingerprint of devices you've signed in from (so we can warn you about new ones), and records of failed sign-ins and rate limits.
Workspace content. Whatever you and your organisation add: emails sent and received through Cloverr addresses, chat messages and reactions, documents and their history, uploaded files, tasks, calendar events, bookings, forms and their responses, contacts and companies, automations, and calls. For calls this includes live captions and transcripts when transcription is on, chat sent during the call, and recordings when someone in the call starts one (everyone in the call is shown that it's being recorded).
People who aren't Cloverr users. When someone books time on a booking page, fills in a form, joins a call as a guest, or emails a Cloverr address, we receive what they provide (for example name, email address, message or answers) on behalf of the organisation they're dealing with.
AI features. The requests you give Cloverr's AI teammates ("Bees"), what they produce, and a log of what they did. If your organisation turns on memories, short notes summarised from chats and documents (for example "the launch moved to Friday") are stored so Bees can use them; organisation owners can review and delete them.
Integrations you choose to connect. For example a GitHub account (an access token, stored encrypted), calendar subscription links and their credentials (encrypted), or your organisation's own AI provider key (encrypted).
Community and public content. Posts and replies on the community forum, public forms, booking pages, an organisation's public profile and anything else you choose to publish. These are visible to anyone.
Messages to us. If you email us or report a problem, we keep that conversation.
We don't use advertising or analytics trackers, and we don't buy data about you from anyone.
Why we use it, and our lawful bases
- To provide Cloverr (create your account, run your workspace, deliver email, run calls and AI features you ask for): performance of a contract with you or your organisation.
- To keep Cloverr secure and stop misuse (sign-in protection, new-device alerts, rate limits, automated screening of outgoing emails, forms and community posts for scams, phishing and abuse): our legitimate interests in protecting users, the people they contact and the service.
- To send service messages (sign-in codes, security alerts, invitations, booking confirmations and reminders, summaries you've chosen): contract and legitimate interests.
- To support you and improve the service (answering questions, fixing faults): legitimate interests.
- Push notifications on your devices: your consent, which you can withdraw in your browser or in Settings.
- To meet legal obligations (for example keeping records, or responding to lawful requests): legal obligation.
We never sell personal data, and workspace content is not used to train AI models.
Automated decisions
Some safety checks are automated:
- Before an email leaves an organisation, an AI reviewer checks it. Emails that look harmful (for example phishing, leaked passwords or abuse) are held for a person in that organisation to look at, not sent.
- Patterns that strongly suggest scams or abuse can automatically pause an account while we review it.
Neither is the final word. A person reviews held emails and suspended accounts, and you can ask us to look again at any decision by emailing kyle@imkylejk.me.
Who we share it with
We use a small number of providers to run Cloverr. They act on our instructions and may only use the data to provide their service to us:
- Hosting: Oracle Cloud Infrastructure hosts our servers. Cloverr runs in an isolated container on an isolated private network.
- Network security and delivery: a provider that protects the site from attacks and delivers pages quickly. It sees connection details such as your IP address.
- Email delivery: a provider that sends and receives email for Cloverr addresses.
- Push notifications: if you turn them on, your browser's push service (for example Apple, Google or Mozilla) carries the notification.
Other parties only receive data when you or your organisation choose: for example GitHub when you connect a repository, an AI provider your organisation connects with its own key, calendar services you subscribe to, people you email or share links with, and anyone viewing what you publish.
We may also disclose information if the law requires it, to protect people from harm, or as part of selling or transferring the business (in which case this policy continues to apply).
International transfers
Our main servers are hosted with Oracle Cloud Infrastructure. Some providers (for example email delivery and network security) may process data outside the UK, including in the United States. When that happens we make sure there is protection in place: UK adequacy regulations (including the UK Extension to the EU–US Data Privacy Framework), or the ICO's International Data Transfer Agreement or Addendum.
How long we keep it
- Your account: for as long as you have it. When an account is closed, we delete or anonymise its personal data within 30 days, except where we need to keep something longer (below).
- Workspace content: until the organisation deletes it or closes its workspace. Then it is deleted from our live systems within 30 days, and from backups when they cycle out.
- Sign-in sessions: until they expire or you sign out. Security records such as new-device alerts are kept for up to 12 months.
- Safety records (for example a record of why an account was suspended): for up to 2 years, so repeated misuse can be recognised.
- Emails to us: for up to 2 years after the conversation ends.
Your rights
Under the UK GDPR you have the right to:
- access your data and get a copy of it;
- correct it;
- have it deleted;
- restrict or object to how we use it;
- receive it in a portable format;
- not be subject to solely automated decisions with significant effects;
- withdraw consent where we rely on it.
See Your UK GDPR rights for how to use them. Email kyle@imkylejk.me; we'll reply within one month.
If you're unhappy with how we've handled your data, please tell us first. You can also complain to the Information Commissioner's Office at ico.org.uk/make-a-complaint or on 0303 123 1113.
Security
How we protect data is described in Security and Data handling.
Children
Cloverr is a tool for work and organisations. It isn't intended for anyone under 16, and we don't knowingly collect data from children.
Changes
If we change this policy in a way that matters, we'll update the date above and tell account holders by email or in the app before the change takes effect.