Privacy Policy
Last updated: 17 August 2026
Cloventa ("Cloventa", "we", "us", or "our") respects your privacy and is committed to protecting personal data.

This Privacy Policy explains how we collect, use, store, disclose, and protect personal data when you visit our website, create an account, use the Cloventa platform, communicate with us, or otherwise interact with our Services.

For the purposes of applicable data protection legislation, including the EU General Data Protection Regulation ("GDPR"), Cloventa may act as either a data controller or a data processor, depending on how the Services are used.

1. Who We Are
Cloventa provides software for cybersecurity compliance and continuous compliance monitoring.
Our Services may help organisations monitor their infrastructure, identify potential compliance gaps, collect evidence, and prepare for security audits and assessments.
Company: Cloventa
Website: https://cloventa.eu/
Email: [privacy@cloventa.eu]
Registered office: [Company address]
Company registration number: [Registration number]
VAT number: [VAT number, if applicable]
Where required by applicable law, Cloventa will designate a Data Protection Officer or other privacy contact.

2. What Personal Data We Collect
Depending on how you interact with Cloventa, we may collect the following categories of personal data.
2.1 Account Information
When you create or manage an account, we may collect:
  • name;
  • business email address;
  • company name;
  • job title or role;
  • username and authentication information;
  • account preferences;
  • account and subscription information.
2.2 Contact and Communication Information
When you contact us, request a demo, communicate with our team, or participate in a pilot, we may collect:
  • name;
  • email address;
  • company information;
  • job title;
  • information contained in your communications with us;
  • meeting and scheduling information.
2.3 Technical and Usage Information
When you use our website or platform, we may automatically collect information such as:
  • IP address;
  • browser type and version;
  • operating system;
  • device information;
  • approximate location derived from IP address;
  • pages and features accessed;
  • timestamps;
  • referral information;
  • logs and diagnostic information;
  • information about interactions with the Services.
2.4 Customer and Infrastructure Data
When an organisation connects its systems to Cloventa, the platform may process technical information from those systems.
Depending on the integrations and configuration, this may include:
  • cloud infrastructure configuration;
  • identity and access-management information;
  • security configurations;
  • source-code repository information;
  • configuration and policy information;
  • vulnerability or security findings;
  • compliance evidence;
  • audit logs;
  • system metadata;
  • information associated with users, employees, or administrators.
The exact information processed depends on the integrations enabled by the customer.
Customers are responsible for configuring integrations appropriately and ensuring that they have the necessary rights and permissions to provide this information to Cloventa.

3. How We Use Personal Data
We may use personal data for the following purposes:
Providing the Services
We use information to:
  • create and manage accounts;
  • provide Cloventa's functionality;
  • operate integrations;
  • monitor compliance controls;
  • generate compliance-related results and reports;
  • provide customer support;
  • maintain and troubleshoot the platform.
Security
We may process information to:
  • detect and prevent unauthorised access;
  • investigate security incidents;
  • protect Cloventa, customers, and users;
  • detect fraud, abuse, and malicious activity;
  • maintain the security and integrity of our Services.
Communication
We may use contact information to:
  • respond to inquiries;
  • provide customer support;
  • communicate about accounts and subscriptions;
  • provide important service notifications;
  • communicate about security or technical matters.
Where permitted by applicable law, we may also send marketing communications. You can unsubscribe from marketing communications at any time.
Product Improvement
We may use information to:
  • understand how our Services are used;
  • identify technical problems;
  • improve features and functionality;
  • develop new products and services;
  • analyse product performance.
Where practical, we use aggregated, anonymised, or otherwise de-identified information for these purposes.
Legal Compliance
We may process personal data when necessary to:
  • comply with applicable laws;
  • respond to lawful requests from authorities;
  • establish, exercise, or defend legal claims;
  • enforce our agreements;
  • protect our legal rights and interests.

4. Legal Bases for Processing
Where GDPR applies, we process personal data based on one or more of the following legal bases:
Contract
We may process personal data where necessary to enter into or perform a contract with you or your organisation.
Legitimate Interests
We may process personal data where necessary for our legitimate interests, provided those interests do not override your fundamental rights and freedoms.
Examples include:
  • securing our Services;
  • preventing fraud and abuse;
  • improving our products;
  • managing business relationships;
  • communicating with business customers;
  • protecting our legal interests.
Consent
Where required, we may rely on your consent, for example, for certain marketing activities or non-essential cookies.
You may withdraw consent at any time.
Legal Obligation
We may process personal data where required to comply with a legal obligation.

5. Cookies and Similar Technologies
We may use cookies and similar technologies on our website and Services.
Cookies may be used to:
  • operate essential website functionality;
  • remember preferences;
  • understand website usage;
  • measure performance;
  • improve the user experience;
  • support marketing activities where permitted.
Where required by law, we will ask for your consent before using non-essential cookies.
You can manage cookies through your browser or, where available, our cookie-consent mechanism.

6. Artificial Intelligence
Some Cloventa features may use artificial intelligence or machine-learning technologies.
Depending on the feature, information may be processed to:
  • analyse compliance-related information;
  • identify potential issues;
  • generate recommendations;
  • summarize information;
  • assist with compliance-related workflows.
Cloventa does not use customer data to train publicly available AI models unless this is expressly agreed with the customer.
Where AI providers or other subprocessors are used to provide a feature, information may be processed by those providers on Cloventa's behalf and subject to appropriate contractual and security safeguards.
AI-generated results may contain errors and should not be treated as definitive legal, regulatory, security, or compliance advice.

7. Customer Data and Our Role as a Processor
When a business customer uses Cloventa to process personal data contained within its systems or infrastructure, Cloventa generally acts as a data processor, and the customer acts as the data controller.
In such cases:
  • the customer determines the purposes and means of processing;
  • Cloventa processes personal data according to the customer's instructions;
  • Cloventa applies appropriate technical and organisational measures;
  • Cloventa assists the customer with applicable data-protection obligations where required;
  • Processing may be governed by a separate Data Processing Agreement ("DPA").
The DPA will take precedence over this Privacy Policy where there is a conflict concerning processor activities.

8. Data Sharing
We may share personal data with the following categories of recipients.
Service Providers
We may use third-party providers that help us operate Cloventa, such as:
  • cloud infrastructure providers;
  • hosting providers;
  • analytics providers;
  • authentication providers;
  • communication and email providers;
  • customer-support platforms;
  • payment providers;
  • security providers;
  • AI and machine-learning service providers.
These providers may process personal data only as necessary to provide their services to Cloventa and subject to appropriate contractual safeguards.
Professional Advisers
We may share information with lawyers, accountants, auditors, insurers, and other professional advisers where reasonably necessary.
Authorities and Legal Requirements
We may disclose information where required by applicable law, regulation, court order, or lawful governmental request.
Business Transactions
Personal data may be transferred as part of a merger, acquisition, financing, restructuring, sale of assets, or similar corporate transaction, subject to applicable legal requirements.
We do not sell personal data.

9. International Data Transfers
Cloventa may use service providers located outside the European Economic Area ("EEA").
Where personal data is transferred outside the EEA, we will implement appropriate safeguards required by applicable data-protection law.
These safeguards may include:
  • European Commission adequacy decisions;
  • Standard Contractual Clauses ("SCCs");
  • appropriate supplementary technical and organisational measures;
  • other legally recognised transfer mechanisms.

10. Data Retention
We retain personal data only for as long as reasonably necessary for the purposes described in this Privacy Policy, unless a longer retention period is required by law.
Retention periods may depend on:
  • the nature of the information;
  • the purpose for which it was collected;
  • the duration of the customer relationship;
  • legal and regulatory obligations;
  • security and fraud-prevention requirements;
  • the need to establish or defend legal claims.
When personal data is no longer required, we may delete, anonymise, or securely dispose of it.
For customer data processed on behalf of a customer, retention and deletion may be governed by the applicable customer agreement or DPA.

11. Data Security
We implement reasonable technical and organisational measures designed to protect personal data against:
  • unauthorized access;
  • accidental loss;
  • destruction;
  • alteration;
  • disclosure;
  • unauthorized processing.
Depending on the nature of the information and Services, security measures may include:
  • access controls;
  • authentication mechanisms;
  • encryption;
  • logging and monitoring;
  • infrastructure security controls;
  • vulnerability management;
  • backup and recovery procedures;
  • employee security practices;
  • incident-response procedures.
No internet-based service can be guaranteed to be completely secure.

12. Your Data Protection Rights
Where GDPR or other applicable data-protection laws apply, you may have rights including:
  • the right to access your personal data;
  • the right to correct inaccurate personal data;
  • the right to request deletion;
  • the right to restrict processing;
  • the right to object to certain processing;
  • the right to data portability;
  • the right to withdraw consent where processing is based on consent;
  • the right to lodge a complaint with a supervisory authority.
Some rights are subject to legal limitations and exceptions.
If you are using Cloventa through your organisation, your organisation may be the controller of your personal data. In that case, you may need to exercise certain rights directly with your organisation.

13. How to Exercise Your Rights
To exercise your privacy rights or ask a question about our processing of personal data, contact:
Email: [privacy@cloventa.eu]
We may need to verify your identity before responding to a request.
We aim to respond within the time period required by applicable law.

14. Children's Privacy
Cloventa is a business-oriented service and is not intended for children.
We do not knowingly collect personal data from children where prohibited by applicable law.
If you believe that a child has provided personal data to Cloventa, please contact us so that we can investigate and take appropriate action.

15. Third-Party Websites and Services
Our website or Services may contain links to third-party websites or services.
Cloventa is not responsible for the privacy practices of third parties.
We recommend reviewing the privacy policies of third-party websites and services before providing them with personal information.

16. Marketing Communications
We may send you marketing communications where permitted by applicable law.
You can unsubscribe from marketing emails by:
  • clicking the unsubscribe link in the relevant communication; or
  • contacting us at [privacy@cloventa.eu].
Even if you unsubscribe from marketing communications, we may continue to send important transactional, security, account, or service-related communications.

17. Automated Decision-Making
Cloventa may use automated processing to analyze information and generate compliance-related findings, recommendations, scores, or alerts.
These outputs are intended to support human decision-making.
Unless expressly stated otherwise, Cloventa does not make decisions producing legal or similarly significant effects on individuals solely through automated processing.
Where applicable law provides rights concerning automated decision-making or profiling, we will comply with those requirements.

18. Changes to This Privacy Policy
We may update this Privacy Policy from time to time.
When we make material changes, we may provide notice through the website, Services, email, or another appropriate method.
The updated Privacy Policy will indicate its effective date.
We encourage you to review this Privacy Policy periodically.

19. Contact Us
If you have questions, concerns, or requests relating to this Privacy Policy or Cloventa's processing of personal data, please contact us:
Cloventa
Website: https://cloventa.eu/
Privacy email: [privacy@cloventa.eu]
Registered office: [Company address]
Company registration number: [Registration number]
VAT number: [VAT number, if applicable]

Made on
Tilda