Scope and application
This Privacy Policy (the "Policy") describes how Cloverfield ("Cloverfield", "we", "us" or "our") collects, uses, discloses, transfers, retains and protects personal data in connection with the Cloverfield website, web application, application programming interfaces, analysis pipelines and any related products or support channels (together, the "Service").
This Policy applies to visitors of our website, individuals who register an account, individuals who submit imagery or other material for analysis, and individuals whose personal data may be contained within material submitted by a user. It forms part of, and is incorporated by reference into, the Cloverfield Terms of Service.
This Policy does not apply to third-party websites, products or services that are linked from or integrated with the Service and that are operated by parties other than Cloverfield. Your interactions with those parties are governed by their own privacy notices.
Controller and processor roles
For personal data relating to your account, your billing relationship and your use of the Service, Cloverfield acts as a controller (or business). For personal data contained within imagery and other material that you upload and instruct us to analyse, Cloverfield acts as a processor (or service provider) on your behalf, and you act as the controller. Where you upload material that contains personal data, you are responsible for having a valid legal basis for that processing.
Definitions
| Term | Meaning |
|---|---|
| Personal data | Any information relating to an identified or identifiable natural person, as defined under applicable data-protection law. |
| Processing | Any operation performed on personal data, including collection, storage, structuring, analysis, transmission, erasure or destruction. |
| User Content | Imagery, files, coordinates, case names, notes, labels and other material submitted to the Service by or on behalf of a user. |
| Analysis Output | Estimates, coordinates, confidence values, similarity scores, candidate matches, reasoning summaries and other results generated by the Service from User Content. |
| Sub-processor | A third party engaged by Cloverfield to process personal data in the course of providing the Service. |
| Applicable Data Protection Law | Any law governing the processing of personal data that applies to Cloverfield or to you, including the EU and UK GDPR and applicable US state privacy statutes. |
Categories of data we collect
We collect the categories of data set out below. Not every category applies to every user; the data actually collected depends on the features you use and the choices you make.
3.1 Account and identity data
- Email address and, where you choose to provide one, a display name.
- Authentication identifiers, including a unique account identifier, hashed credential material and, where you use a federated identity provider, the subject identifier issued by that provider.
- Session and security data, including sign-in timestamps, refresh-token metadata, and records of password or credential changes.
- Account state, including plan tier, entitlements, usage allowances consumed, and administrative flags such as suspension status.
3.2 User Content submitted for analysis
Cloverfield accepts imagery and related material for visual-intelligence analysis. Depending on the feature invoked, submitted material may be processed for image-based geolocation, terrain and environmental inference, vehicle identification or similarity comparison, street-level and landmark matching, visual similarity retrieval, or other analytical functions that you expressly request.
Submitted imagery may contain embedded metadata, including EXIF fields such as capture time, camera model and, in some cases, GPS coordinates. Where such metadata is present it may be read as an analytical input and stored alongside the file. You may strip metadata before upload if you do not wish it to be processed.
Imagery may contain personal data, including images of identifiable individuals, vehicle registration plates, residential property and other sensitive detail. You must not submit material that you are not lawfully entitled to process, disclose or transfer to a processor.
3.3 Analysis Output and case data
- Geographic estimates, candidate coordinates, bounding regions and administrative-region labels.
- Vehicle attributes, candidate makes, models and similarity scores.
- Street, landmark and scene-match candidates and their supporting evidence.
- Confidence values, ranking positions, model version identifiers and derived reasoning summaries.
- Case names, folder structures, notes, labels, tags and any other annotation you create.
- Derived thumbnails, crops and preview renderings generated for display in your workspace.
3.4 Technical and device data
- Internet protocol address and the coarse geographic region inferred from it.
- Browser family and version, operating system, device class, language and display characteristics.
- Request logs, including timestamps, requested routes, response status codes, latency and referrer.
- Diagnostic and error telemetry, including stack traces and unhandled-exception reports.
- Aggregate feature-usage counters used to measure reliability and capacity.
3.5 Billing data
Where the Service is offered on a paid basis, payment instruments are collected and processed by a third-party payment processor operating under its own privacy notice and under PCI-DSS obligations. Cloverfield does not store complete primary account numbers. We receive and retain only limited billing records such as the transaction identifier, amount, currency, timestamp, outcome, card brand, last four digits and billing country.
3.6 Correspondence
When you contact us, we retain the content of your message, the address you contacted us from, and any material you attach, for the purpose of responding, maintaining a support record, and evidencing how a request was handled.
Purposes of processing and legal bases
Where the EU or UK GDPR (or a materially equivalent law) applies, we process personal data only where a lawful basis exists. The table below maps each purpose to its basis.
| Purpose | Categories | Legal basis |
|---|---|---|
| Creating and maintaining your account; authenticating you | Account and identity data | Performance of a contract |
| Executing the analyses you request and returning Analysis Output | User Content; Analysis Output | Performance of a contract; instructions of the controller |
| Storing your analyses, cases and history so you can return to them | User Content; Analysis Output | Performance of a contract |
| Billing, invoicing, dunning and tax record-keeping | Billing data | Performance of a contract; legal obligation |
| Detecting, investigating and preventing fraud, abuse and security incidents | Technical data; account data | Legitimate interests; legal obligation |
| Maintaining reliability, capacity planning and debugging | Technical data | Legitimate interests |
| Improving and developing features | Aggregated and de-identified data | Legitimate interests |
| Responding to support requests | Correspondence | Performance of a contract; legitimate interests |
| Non-essential analytics and optional cookies | Technical data | Consent |
| Responding to lawful requests from competent authorities | Any relevant category | Legal obligation |
Legitimate-interests balancing
Where we rely on legitimate interests, we have assessed that our interest in operating a secure, reliable and improving service is not overridden by your interests, rights and freedoms, taking into account the limited scope of the data used, the safeguards applied, and your ability to object. You may request a summary of the relevant balancing assessment.
How uploaded imagery is handled
Uploaded imagery is processed for the sole purpose of producing the analysis you have requested and of storing the result in your workspace. Analysis may involve transmitting the image, a derived representation of it, or a numerical embedding to a model-inference provider engaged as a sub-processor.
- 01We do not use your private uploads to train general-purpose models without your separate, freely given and specific consent.
- 02We do not make private uploads publicly searchable, indexable or accessible unless you deliberately invoke a sharing feature.
- 03We do not sell, rent or license uploaded imagery or Analysis Output to data brokers, advertisers or list vendors.
- 04We do not use uploaded imagery for advertising, profiling for advertising purposes, or cross-context behavioural advertising.
- 05Access to stored objects is enforced at the storage layer by per-user access rules in addition to application-level controls.
Should we ever propose a materially different use of submitted material, we will update this Policy, provide advance notice through the Service, and where the change requires consent we will obtain it before the new use begins.
Automated processing and the nature of results
The Service is inherently automated: results are produced by statistical and machine-learning systems operating on visual evidence. Analysis Output is probabilistic. It expresses a modelled likelihood, not an established fact, and may be incorrect, incomplete, outdated or ambiguous.
Cloverfield must not be used as the sole basis for any decision producing legal effects concerning an individual, or similarly significantly affecting an individual, including decisions relating to law enforcement, employment, credit, housing, insurance, safety or emergency response. Meaningful human review and independent corroboration are required.
Cloverfield does not itself carry out automated decision-making within the meaning of Article 22 of the GDPR in relation to data subjects whose imagery you submit. Where you use Analysis Output as an input to your own decision-making about individuals, you are the controller of that decision and are responsible for the safeguards that law requires of you.
Disclosure and sub-processors
We disclose personal data only where necessary to operate the Service, where required by law, or where you direct us to do so. We do not disclose personal data for monetary or other valuable consideration.
| Category of recipient | Function | Data involved |
|---|---|---|
| Cloud infrastructure and database providers | Application hosting, managed database, object storage | Account data, User Content, Analysis Output, logs |
| Authentication provider | Credential verification and session issuance | Account and identity data |
| Model-inference providers | Execution of visual-analysis models | Imagery or derived representations submitted for analysis |
| Mapping and geospatial data providers | Base maps, reverse geocoding, imagery references | Coordinates and query parameters |
| Payment processor | Payment authorisation, settlement and refunds | Billing data |
| Transactional email provider | Delivery of account and security notices | Email address and message content |
| Error-monitoring and observability tooling | Fault diagnosis and reliability | Technical data and diagnostic context |
Each sub-processor is engaged under a written contract that restricts processing to our documented instructions, imposes confidentiality obligations, requires appropriate technical and organisational measures, and provides for deletion or return of data on termination. A current list of sub-processors is available on request.
7.1 Legal and safety disclosures
We may disclose personal data where we reasonably believe disclosure is necessary to comply with applicable law, regulation, legal process or an enforceable governmental request; to enforce our agreements; to detect, prevent or address fraud, abuse or security or technical issues; or to protect the rights, property or safety of Cloverfield, our users or the public. Where lawful and practicable, we will notify the affected account before responding to a compelled disclosure and will seek to narrow requests that are overbroad.
7.2 Corporate transactions
If Cloverfield is involved in a merger, acquisition, financing, reorganisation, sale of assets, insolvency or similar transaction, personal data may be transferred as part of that transaction. Any acquirer will remain bound by this Policy in respect of transferred data until it is superseded by a notice that is no less protective, and material changes will be notified in advance.
International transfers
Cloverfield and its sub-processors may process personal data in jurisdictions other than the one in which you reside, including the United States and the European Union.
Where personal data is transferred out of the European Economic Area, the United Kingdom or Switzerland to a jurisdiction not benefiting from an adequacy decision, we rely on the European Commission's Standard Contractual Clauses (and, for UK transfers, the UK International Data Transfer Addendum), supplemented where necessary by a transfer impact assessment and additional technical measures including encryption in transit and at rest and strict access controls. A copy of the relevant clauses may be requested at the contact address below.
Retention
We retain personal data only for as long as necessary for the purposes for which it was collected, and thereafter for the period required to comply with legal obligations, resolve disputes and enforce our agreements.
| Data | Retention period |
|---|---|
| Account record | For the life of the account, then deleted or de-identified within 30 days of account deletion |
| Uploaded imagery and derived thumbnails | Until you delete the analysis or case, or until account deletion |
| Analysis Output and case metadata | Until you delete it, or until account deletion |
| Application and access logs | Typically up to 90 days, extended only where an active security investigation requires it |
| Security and abuse records | Up to 24 months where necessary to prevent recurrence |
| Billing and tax records | As required by applicable accounting and tax law, typically 6 to 10 years |
| Support correspondence | Up to 24 months from resolution |
| Encrypted backups | Rolling window, typically not exceeding 35 days |
Deletion from active systems is initiated promptly on request. Residual copies may persist in encrypted backups until the relevant backup generation expires on its normal rotation schedule, during which time the data remains isolated from production access and is not used for any purpose other than disaster recovery.
Security measures
We maintain technical and organisational measures designed to protect personal data against unauthorised or unlawful processing and against accidental loss, destruction or damage. These measures include, as applicable:
- Encryption of data in transit using current TLS versions, and encryption of stored objects and database volumes at rest.
- Row-level authorisation rules enforced at the database and object-storage layers so that records are readable only by their owning account.
- Least-privilege administrative access, with privileged operations restricted to a limited number of personnel and logged.
- Segregation of production credentials, managed secret storage and periodic credential rotation.
- Automated dependency and configuration scanning, and remediation of identified issues on a risk-prioritised basis.
- Logging and monitoring of authentication events and anomalous access patterns.
- Backup and restoration procedures designed to limit the impact of data-loss events.
No method of transmission or storage is completely secure, and we cannot guarantee absolute security. You are responsible for safeguarding your credentials, for using a unique password, and for notifying us promptly if you suspect unauthorised access to your account.
Breach notification
Where a personal data breach is likely to result in a risk to the rights and freedoms of natural persons, we will notify the competent supervisory authority without undue delay and, where feasible, within 72 hours of becoming aware of it, and will notify affected individuals where the breach is likely to result in a high risk to them.
Your rights
Subject to the conditions and exemptions in Applicable Data Protection Law, you may have the following rights in relation to personal data we hold about you:
- Access — to obtain confirmation of whether we process your personal data and a copy of it.
- Rectification — to have inaccurate personal data corrected and incomplete data completed.
- Erasure — to have personal data deleted where one of the statutory grounds applies.
- Restriction — to have processing restricted while accuracy or a legitimate-interests objection is examined.
- Objection — to object to processing based on legitimate interests, and at any time to direct marketing.
- Portability — to receive personal data you provided in a structured, commonly used and machine-readable format and to have it transmitted to another controller where technically feasible.
- Withdrawal of consent — to withdraw consent at any time, without affecting the lawfulness of processing carried out before withdrawal.
- Complaint — to lodge a complaint with your supervisory authority or another competent regulator.
Many of these rights can be exercised directly in the product: analyses, cases and uploaded imagery can be deleted from your dashboard, and account deletion removes the associated records. For anything else, contact us at the address in section 16. We will respond within one month of receipt, extendable by a further two months where the request is complex, and we will tell you if an extension applies. We may ask for information reasonably necessary to verify your identity, and we will not use that information for any other purpose. We do not charge a fee unless a request is manifestly unfounded or excessive.
Requests concerning third parties
If you are an individual whose personal data may be contained in material uploaded by a Cloverfield user, we generally act as a processor for that material and are not able to identify it from a name alone. Please direct your request to the user who submitted the material where known; if you contact us, we will make reasonable efforts to refer the request to the relevant controller.
United States state privacy disclosures
This section applies to residents of US states with comprehensive privacy statutes, including California, Colorado, Connecticut, Virginia, Utah, Texas, Oregon and Montana, to the extent those statutes apply to us.
- Categories of personal information collected in the preceding twelve months: identifiers; commercial information; internet or other electronic network activity information; approximate geolocation data; visual information contained in uploaded imagery; and inferences drawn from that information.
- Sources: directly from you; automatically from your device; and from service providers acting on our behalf.
- Business purposes: those listed in section 4 of this Policy.
- Sensitive personal information: we do not use or disclose sensitive personal information for purposes other than those permitted without a right to limit under applicable law.
- Sale and sharing: we do not sell personal information and do not share it for cross-context behavioural advertising.
- Rights: to know, access, delete, correct, obtain a portable copy, opt out of sale, sharing and targeted advertising, limit use of sensitive personal information, and appeal a refused request.
- Non-discrimination: we will not deny goods or services, charge different prices or provide a different level of quality because you exercised a privacy right.
You may exercise these rights through the contact address in section 16, and you may use an authorised agent where permitted, subject to proof of authorisation. If we decline a request, you may appeal by replying to our response; we will inform you of the outcome and of your right to contact your state Attorney General.
Children
The Service is not directed to children. We do not knowingly collect personal data from any person under 16 years of age, or under such higher age as applicable local law may require for the processing to be lawful without parental authorisation. If we become aware that we hold such data without a valid basis, we will delete it promptly. If you believe a child has provided personal data to us, contact us using the details in section 16.
Changes to this Policy
We may amend this Policy to reflect changes in our practices, technology, legal requirements or the Service itself. The version identifier and "last updated" date at the head of this document indicate when it was last revised.
Where a change is material, we will provide reasonable advance notice through the Service or by email before it takes effect, and where the change requires consent under Applicable Data Protection Law we will obtain that consent. Continued use of the Service after the effective date of a revised Policy constitutes acknowledgement of the revision to the extent permitted by law.
Contact and complaints
Questions, privacy requests, sub-processor list requests and copies of transfer safeguards may be directed to contact@buildingnew.life. Please include enough detail for us to locate the relevant records and, where you are exercising a statutory right, tell us which right you are invoking.
If you are located in the European Economic Area or the United Kingdom and you believe we have not handled your personal data lawfully, you may lodge a complaint with your local supervisory authority. We would appreciate the opportunity to address your concern first.