Clovert ("Clovert", "we", "us") is a performance management platform operated from Croatia. This policy explains how we handle personal data when you visit clovert.eu, create an account, or use the Clovert application.
An important distinction: when your organisation enters employee data into Clovert, your organisation is the data controller and Clovert acts as the data processor on your behalf. That relationship is governed by our Data Processing Agreement.
Jump to section
Data we process How we use it Employee data Storage & security International transfers Retention Your rights Cookies Subprocessors ContactWhen an organisation creates a Clovert account, we process the account holder's name, work email address, company name, job title, and authentication information. Passwords are stored as a one-way cryptographic hash and are never stored in plain text.
Customers may enter information about their employees, including name, work email address, employee ID, job title, department, manager relationship, performance reviews and ratings, goals and goal progress, development plans, skills and competency data, 360° and peer feedback, and 9-Box ratings.
The customer organisation decides what is entered and is responsible for ensuring an appropriate legal basis exists for that processing.
Login timestamps, session information, audit logs, and records of actions performed within the platform — used to maintain security, investigate incidents, and meet compliance obligations.
Email addresses used to send account verification, password resets, review reminders and other transactional messages.
On our marketing website (clovert.eu) we use PostHog to understand how visitors use the site. Analytics only run if you accept them through the cookie banner — see section 8.
We do not collect payment card data directly; payments are handled by third-party payment providers.
Legal basis: performance of a contract, or steps taken at your request before entering into one.
To create and manage accounts, operate review cycles, manage goals, skills and development plans, provide 360° feedback, generate dashboards and reports, and provide support.
Legal basis: our legitimate interests in keeping the service secure.
To protect accounts, detect and prevent abuse, investigate security incidents, maintain system integrity, and enforce our Terms of Service.
Legal basis: compliance with a legal obligation.
Where required, we retain information to meet legal, accounting or tax requirements.
Legal basis: your consent, given through the cookie banner.
To understand how visitors use clovert.eu so we can improve it.
We do not sell personal data. We do not use customer or employee data for advertising. We do not use identifiable customer data to train general-purpose AI models.
When an organisation uses Clovert to manage employee information, the organisation is the data controller and Clovert is the data processor.
As the controller, the customer organisation is responsible for:
Clovert processes employee data only to provide the service, in accordance with the customer's documented instructions and our Data Processing Agreement.
Location. Application data is stored on servers within the European Union (Frankfurt, Germany).
Encryption. Data is encrypted in transit using TLS, and at rest where supported by our infrastructure providers.
Passwords. Stored using one-way cryptographic hashing. We cannot recover your password.
Tenant isolation. Data is isolated per company at the application layer. Every database query is scoped to the requesting company, and this is covered by automated tests that run on every code change.
Access control. Role-based permissions within the application, and restricted administrative access on our side.
Audit logging. Security-relevant actions are logged.
Backups. Backups are performed regularly through our infrastructure provider, with retention according to the applicable service tier.
Our infrastructure is configured to keep application data within the European Union.
Where a service provider processes personal data outside the European Economic Area, we ensure an appropriate transfer mechanism is in place — an adequacy decision, Standard Contractual Clauses, or another safeguard recognised under applicable law.
Customers may request current information about subprocessors and transfer safeguards.
Active accounts. Data is retained for the duration of the subscription.
Inactive accounts. Where an account has been unused for an extended period, we may contact the account holder and, after giving reasonable notice, close the account and delete the associated data.
Closed accounts. Personal data is deleted within 30 days of account closure. Backup copies may persist for a short period before being overwritten through normal backup cycles.
Audit and security logs. Retained for as long as reasonably necessary for security, troubleshooting, dispute resolution and compliance purposes.
Specific retention arrangements may be agreed in the Data Processing Agreement.
Depending on your circumstances you may have the right to:
You can also contact us at privacy@clovert.eu. We respond within the timeframe required by applicable law, normally within one month.
You have the right to lodge a complaint with a supervisory authority. In Croatia, this is the Croatian Personal Data Protection Agency (AZOP), azop.hr.
The application uses a single session cookie (talent_session) for authentication. It is HttpOnly and Secure, so it cannot be read by JavaScript, and it expires after a period of inactivity. This cookie is strictly necessary for the service to function.
We use PostHog (EU-hosted) to understand how visitors use our website. These analytics cookies are disabled by default and only load if you choose "Accept all" in the cookie banner. If you select "Reject all", no analytics are collected.
You can change your choice at any time by clearing your browser's site data for clovert.eu, which will cause the banner to appear again.
We do not use advertising cookies, retargeting pixels, or third-party advertising trackers.
We use a small number of service providers to operate Clovert. Each is engaged under a data processing agreement with appropriate safeguards.
We require subprocessors to provide appropriate data protection safeguards through contractual arrangements. This list may change as the service develops; customers may request current information at any time, and we will inform customers of intended changes where required.
We do not use Google Analytics, Facebook Pixel, or comparable advertising trackers.
We may update this policy as the service develops. Where changes are material, we will give notice as required by applicable law. The "last updated" date above shows when this policy was last revised.
Full legal entity details, including registered name and tax identification number, will be published here once business registration is complete.