Legal — Data protection notice

Privacy Policy

Cloverfield's Privacy Policy: the categories of data we collect, the legal bases we rely on, how uploaded imagery is processed, retention periods, sub-processors, and the rights available to you.

Version
2.0
Last updated
12 August 2026
Effective
12 August 2026
Operator
Cloverfield
01

Scope and application

This Privacy Policy (the "Policy") describes how Cloverfield ("Cloverfield", "we", "us" or "our") collects, uses, discloses, transfers, retains and protects personal data in connection with the Cloverfield website, web application, application programming interfaces, analysis pipelines and any related products or support channels (together, the "Service").

This Policy applies to visitors of our website, individuals who register an account, individuals who submit imagery or other material for analysis, and individuals whose personal data may be contained within material submitted by a user. It forms part of, and is incorporated by reference into, the Cloverfield Terms of Service.

This Policy does not apply to third-party websites, products or services that are linked from or integrated with the Service and that are operated by parties other than Cloverfield. Your interactions with those parties are governed by their own privacy notices.

Controller and processor roles

For personal data relating to your account, your billing relationship and your use of the Service, Cloverfield acts as a controller (or business). For personal data contained within imagery and other material that you upload and instruct us to analyse, Cloverfield acts as a processor (or service provider) on your behalf, and you act as the controller. Where you upload material that contains personal data, you are responsible for having a valid legal basis for that processing.

02

Definitions

TermMeaning
Personal dataAny information relating to an identified or identifiable natural person, as defined under applicable data-protection law.
ProcessingAny operation performed on personal data, including collection, storage, structuring, analysis, transmission, erasure or destruction.
User ContentImagery, files, coordinates, case names, notes, labels and other material submitted to the Service by or on behalf of a user.
Analysis OutputEstimates, coordinates, confidence values, similarity scores, candidate matches, reasoning summaries and other results generated by the Service from User Content.
Sub-processorA third party engaged by Cloverfield to process personal data in the course of providing the Service.
Applicable Data Protection LawAny law governing the processing of personal data that applies to Cloverfield or to you, including the EU and UK GDPR and applicable US state privacy statutes.
03

Categories of data we collect

We collect the categories of data set out below. Not every category applies to every user; the data actually collected depends on the features you use and the choices you make.

3.1 Account and identity data

  • Email address and, where you choose to provide one, a display name.
  • Authentication identifiers, including a unique account identifier, hashed credential material and, where you use a federated identity provider, the subject identifier issued by that provider.
  • Session and security data, including sign-in timestamps, refresh-token metadata, and records of password or credential changes.
  • Account state, including plan tier, entitlements, usage allowances consumed, and administrative flags such as suspension status.

3.2 User Content submitted for analysis

Cloverfield accepts imagery and related material for visual-intelligence analysis. Depending on the feature invoked, submitted material may be processed for image-based geolocation, terrain and environmental inference, vehicle identification or similarity comparison, street-level and landmark matching, visual similarity retrieval, or other analytical functions that you expressly request.

Submitted imagery may contain embedded metadata, including EXIF fields such as capture time, camera model and, in some cases, GPS coordinates. Where such metadata is present it may be read as an analytical input and stored alongside the file. You may strip metadata before upload if you do not wish it to be processed.

Imagery may contain personal data, including images of identifiable individuals, vehicle registration plates, residential property and other sensitive detail. You must not submit material that you are not lawfully entitled to process, disclose or transfer to a processor.

3.3 Analysis Output and case data

  • Geographic estimates, candidate coordinates, bounding regions and administrative-region labels.
  • Vehicle attributes, candidate makes, models and similarity scores.
  • Street, landmark and scene-match candidates and their supporting evidence.
  • Confidence values, ranking positions, model version identifiers and derived reasoning summaries.
  • Case names, folder structures, notes, labels, tags and any other annotation you create.
  • Derived thumbnails, crops and preview renderings generated for display in your workspace.

3.4 Technical and device data

  • Internet protocol address and the coarse geographic region inferred from it.
  • Browser family and version, operating system, device class, language and display characteristics.
  • Request logs, including timestamps, requested routes, response status codes, latency and referrer.
  • Diagnostic and error telemetry, including stack traces and unhandled-exception reports.
  • Aggregate feature-usage counters used to measure reliability and capacity.

3.5 Billing data

Where the Service is offered on a paid basis, payment instruments are collected and processed by a third-party payment processor operating under its own privacy notice and under PCI-DSS obligations. Cloverfield does not store complete primary account numbers. We receive and retain only limited billing records such as the transaction identifier, amount, currency, timestamp, outcome, card brand, last four digits and billing country.

3.6 Correspondence

When you contact us, we retain the content of your message, the address you contacted us from, and any material you attach, for the purpose of responding, maintaining a support record, and evidencing how a request was handled.

04

Purposes of processing and legal bases

Where the EU or UK GDPR (or a materially equivalent law) applies, we process personal data only where a lawful basis exists. The table below maps each purpose to its basis.

PurposeCategoriesLegal basis
Creating and maintaining your account; authenticating youAccount and identity dataPerformance of a contract
Executing the analyses you request and returning Analysis OutputUser Content; Analysis OutputPerformance of a contract; instructions of the controller
Storing your analyses, cases and history so you can return to themUser Content; Analysis OutputPerformance of a contract
Billing, invoicing, dunning and tax record-keepingBilling dataPerformance of a contract; legal obligation
Detecting, investigating and preventing fraud, abuse and security incidentsTechnical data; account dataLegitimate interests; legal obligation
Maintaining reliability, capacity planning and debuggingTechnical dataLegitimate interests
Improving and developing featuresAggregated and de-identified dataLegitimate interests
Responding to support requestsCorrespondencePerformance of a contract; legitimate interests
Non-essential analytics and optional cookiesTechnical dataConsent
Responding to lawful requests from competent authoritiesAny relevant categoryLegal obligation

Legitimate-interests balancing

Where we rely on legitimate interests, we have assessed that our interest in operating a secure, reliable and improving service is not overridden by your interests, rights and freedoms, taking into account the limited scope of the data used, the safeguards applied, and your ability to object. You may request a summary of the relevant balancing assessment.

05

How uploaded imagery is handled

Uploaded imagery is processed for the sole purpose of producing the analysis you have requested and of storing the result in your workspace. Analysis may involve transmitting the image, a derived representation of it, or a numerical embedding to a model-inference provider engaged as a sub-processor.

  1. 01We do not use your private uploads to train general-purpose models without your separate, freely given and specific consent.
  2. 02We do not make private uploads publicly searchable, indexable or accessible unless you deliberately invoke a sharing feature.
  3. 03We do not sell, rent or license uploaded imagery or Analysis Output to data brokers, advertisers or list vendors.
  4. 04We do not use uploaded imagery for advertising, profiling for advertising purposes, or cross-context behavioural advertising.
  5. 05Access to stored objects is enforced at the storage layer by per-user access rules in addition to application-level controls.

Should we ever propose a materially different use of submitted material, we will update this Policy, provide advance notice through the Service, and where the change requires consent we will obtain it before the new use begins.

06

Automated processing and the nature of results

The Service is inherently automated: results are produced by statistical and machine-learning systems operating on visual evidence. Analysis Output is probabilistic. It expresses a modelled likelihood, not an established fact, and may be incorrect, incomplete, outdated or ambiguous.

Cloverfield must not be used as the sole basis for any decision producing legal effects concerning an individual, or similarly significantly affecting an individual, including decisions relating to law enforcement, employment, credit, housing, insurance, safety or emergency response. Meaningful human review and independent corroboration are required.

Cloverfield does not itself carry out automated decision-making within the meaning of Article 22 of the GDPR in relation to data subjects whose imagery you submit. Where you use Analysis Output as an input to your own decision-making about individuals, you are the controller of that decision and are responsible for the safeguards that law requires of you.

07

Disclosure and sub-processors

We disclose personal data only where necessary to operate the Service, where required by law, or where you direct us to do so. We do not disclose personal data for monetary or other valuable consideration.

Category of recipientFunctionData involved
Cloud infrastructure and database providersApplication hosting, managed database, object storageAccount data, User Content, Analysis Output, logs
Authentication providerCredential verification and session issuanceAccount and identity data
Model-inference providersExecution of visual-analysis modelsImagery or derived representations submitted for analysis
Mapping and geospatial data providersBase maps, reverse geocoding, imagery referencesCoordinates and query parameters
Payment processorPayment authorisation, settlement and refundsBilling data
Transactional email providerDelivery of account and security noticesEmail address and message content
Error-monitoring and observability toolingFault diagnosis and reliabilityTechnical data and diagnostic context

Each sub-processor is engaged under a written contract that restricts processing to our documented instructions, imposes confidentiality obligations, requires appropriate technical and organisational measures, and provides for deletion or return of data on termination. A current list of sub-processors is available on request.

7.1 Legal and safety disclosures

We may disclose personal data where we reasonably believe disclosure is necessary to comply with applicable law, regulation, legal process or an enforceable governmental request; to enforce our agreements; to detect, prevent or address fraud, abuse or security or technical issues; or to protect the rights, property or safety of Cloverfield, our users or the public. Where lawful and practicable, we will notify the affected account before responding to a compelled disclosure and will seek to narrow requests that are overbroad.

7.2 Corporate transactions

If Cloverfield is involved in a merger, acquisition, financing, reorganisation, sale of assets, insolvency or similar transaction, personal data may be transferred as part of that transaction. Any acquirer will remain bound by this Policy in respect of transferred data until it is superseded by a notice that is no less protective, and material changes will be notified in advance.

08

International transfers

Cloverfield and its sub-processors may process personal data in jurisdictions other than the one in which you reside, including the United States and the European Union.

Where personal data is transferred out of the European Economic Area, the United Kingdom or Switzerland to a jurisdiction not benefiting from an adequacy decision, we rely on the European Commission's Standard Contractual Clauses (and, for UK transfers, the UK International Data Transfer Addendum), supplemented where necessary by a transfer impact assessment and additional technical measures including encryption in transit and at rest and strict access controls. A copy of the relevant clauses may be requested at the contact address below.

09

Retention

We retain personal data only for as long as necessary for the purposes for which it was collected, and thereafter for the period required to comply with legal obligations, resolve disputes and enforce our agreements.

DataRetention period
Account recordFor the life of the account, then deleted or de-identified within 30 days of account deletion
Uploaded imagery and derived thumbnailsUntil you delete the analysis or case, or until account deletion
Analysis Output and case metadataUntil you delete it, or until account deletion
Application and access logsTypically up to 90 days, extended only where an active security investigation requires it
Security and abuse recordsUp to 24 months where necessary to prevent recurrence
Billing and tax recordsAs required by applicable accounting and tax law, typically 6 to 10 years
Support correspondenceUp to 24 months from resolution
Encrypted backupsRolling window, typically not exceeding 35 days

Deletion from active systems is initiated promptly on request. Residual copies may persist in encrypted backups until the relevant backup generation expires on its normal rotation schedule, during which time the data remains isolated from production access and is not used for any purpose other than disaster recovery.

10

Security measures

We maintain technical and organisational measures designed to protect personal data against unauthorised or unlawful processing and against accidental loss, destruction or damage. These measures include, as applicable:

  • Encryption of data in transit using current TLS versions, and encryption of stored objects and database volumes at rest.
  • Row-level authorisation rules enforced at the database and object-storage layers so that records are readable only by their owning account.
  • Least-privilege administrative access, with privileged operations restricted to a limited number of personnel and logged.
  • Segregation of production credentials, managed secret storage and periodic credential rotation.
  • Automated dependency and configuration scanning, and remediation of identified issues on a risk-prioritised basis.
  • Logging and monitoring of authentication events and anomalous access patterns.
  • Backup and restoration procedures designed to limit the impact of data-loss events.

No method of transmission or storage is completely secure, and we cannot guarantee absolute security. You are responsible for safeguarding your credentials, for using a unique password, and for notifying us promptly if you suspect unauthorised access to your account.

Breach notification

Where a personal data breach is likely to result in a risk to the rights and freedoms of natural persons, we will notify the competent supervisory authority without undue delay and, where feasible, within 72 hours of becoming aware of it, and will notify affected individuals where the breach is likely to result in a high risk to them.

11

Your rights

Subject to the conditions and exemptions in Applicable Data Protection Law, you may have the following rights in relation to personal data we hold about you:

  • Access — to obtain confirmation of whether we process your personal data and a copy of it.
  • Rectification — to have inaccurate personal data corrected and incomplete data completed.
  • Erasure — to have personal data deleted where one of the statutory grounds applies.
  • Restriction — to have processing restricted while accuracy or a legitimate-interests objection is examined.
  • Objection — to object to processing based on legitimate interests, and at any time to direct marketing.
  • Portability — to receive personal data you provided in a structured, commonly used and machine-readable format and to have it transmitted to another controller where technically feasible.
  • Withdrawal of consent — to withdraw consent at any time, without affecting the lawfulness of processing carried out before withdrawal.
  • Complaint — to lodge a complaint with your supervisory authority or another competent regulator.

Many of these rights can be exercised directly in the product: analyses, cases and uploaded imagery can be deleted from your dashboard, and account deletion removes the associated records. For anything else, contact us at the address in section 16. We will respond within one month of receipt, extendable by a further two months where the request is complex, and we will tell you if an extension applies. We may ask for information reasonably necessary to verify your identity, and we will not use that information for any other purpose. We do not charge a fee unless a request is manifestly unfounded or excessive.

Requests concerning third parties

If you are an individual whose personal data may be contained in material uploaded by a Cloverfield user, we generally act as a processor for that material and are not able to identify it from a name alone. Please direct your request to the user who submitted the material where known; if you contact us, we will make reasonable efforts to refer the request to the relevant controller.

12

United States state privacy disclosures

This section applies to residents of US states with comprehensive privacy statutes, including California, Colorado, Connecticut, Virginia, Utah, Texas, Oregon and Montana, to the extent those statutes apply to us.

  • Categories of personal information collected in the preceding twelve months: identifiers; commercial information; internet or other electronic network activity information; approximate geolocation data; visual information contained in uploaded imagery; and inferences drawn from that information.
  • Sources: directly from you; automatically from your device; and from service providers acting on our behalf.
  • Business purposes: those listed in section 4 of this Policy.
  • Sensitive personal information: we do not use or disclose sensitive personal information for purposes other than those permitted without a right to limit under applicable law.
  • Sale and sharing: we do not sell personal information and do not share it for cross-context behavioural advertising.
  • Rights: to know, access, delete, correct, obtain a portable copy, opt out of sale, sharing and targeted advertising, limit use of sensitive personal information, and appeal a refused request.
  • Non-discrimination: we will not deny goods or services, charge different prices or provide a different level of quality because you exercised a privacy right.

You may exercise these rights through the contact address in section 16, and you may use an authorised agent where permitted, subject to proof of authorisation. If we decline a request, you may appeal by replying to our response; we will inform you of the outcome and of your right to contact your state Attorney General.

13

Cookies and similar technologies

CategoryPurposeBasis
Strictly necessarySession persistence, authentication, load balancing, security and abuse preventionNecessary for the service; no consent required
FunctionalRemembering interface preferences such as layout and unitsConsent where required
AnalyticsAggregate measurement of feature usage and performanceConsent where required

We do not use advertising or cross-site tracking cookies. Where consent is required, non-essential technologies are not set until consent is given, and consent may be withdrawn at any time. Most browsers allow cookies to be blocked or deleted; blocking strictly necessary cookies will prevent you from signing in.

14

Children

The Service is not directed to children. We do not knowingly collect personal data from any person under 16 years of age, or under such higher age as applicable local law may require for the processing to be lawful without parental authorisation. If we become aware that we hold such data without a valid basis, we will delete it promptly. If you believe a child has provided personal data to us, contact us using the details in section 16.

15

Changes to this Policy

We may amend this Policy to reflect changes in our practices, technology, legal requirements or the Service itself. The version identifier and "last updated" date at the head of this document indicate when it was last revised.

Where a change is material, we will provide reasonable advance notice through the Service or by email before it takes effect, and where the change requires consent under Applicable Data Protection Law we will obtain that consent. Continued use of the Service after the effective date of a revised Policy constitutes acknowledgement of the revision to the extent permitted by law.

16

Contact and complaints

Questions, privacy requests, sub-processor list requests and copies of transfer safeguards may be directed to contact@buildingnew.life. Please include enough detail for us to locate the relevant records and, where you are exercising a statutory right, tell us which right you are invoking.

If you are located in the European Economic Area or the United Kingdom and you believe we have not handled your personal data lawfully, you may lodge a complaint with your local supervisory authority. We would appreciate the opportunity to address your concern first.