Privacy Policy
Last updated: 1 September 2026
1. Who this policy covers
This policy explains how Cloudvieve collects, uses and protects personal data when you visit this website, contact us, or use the Cloudvieve product. We operate in line with the UK GDPR and, where applicable, the California Consumer Privacy Act (CCPA/CPRA). If you have questions or want to exercise a right, contact us at hello@cloudvieve.com — we respond to all data subject requests within one month of receipt.
2. Our roles: controller and processor
We act as a controller for the data you give us directly (for example, when you contact us or manage an account). For the contract, spend and supplier data processed through the Cloudvieve product, we act as a processor on behalf of the organisation using the product, which remains the controller of that data.
3. Information we collect
- Information you give us directly. Your name, email address, and anything else you share with us.
- Product data. Where an organisation uses Cloudvieve, we process the contract, spend and supplier data that organisation provides or connects, to deliver supplier exposure analysis, action plans and negotiation briefs.
- Data embedded in documents. Contracts and related documents may contain personal data about individuals named within them (signatories, directors, guarantors, contact persons). We process this solely to provide the analysis you have requested. This data belongs to the organisation using the product.
4. Automated processing and AI
Cloudvieve uses automated and AI-assisted processing to analyse supplier, contract and spend data and generate outputs such as exposure summaries, prioritisation, action plans and negotiation briefs. These outputs are decision support: they help a human user make a better-informed decision and are not used to make decisions with legal or similarly significant effect on an individual without human involvement. Analysis is generated with the assistance of third-party AI models. Your data is not used to train our models or third-party foundation models, and is not sold or shared for model training.
5. Why we process information
We process personal data:
- to respond to enquiries you send us (legitimate interest / steps taken at your request);
- to provide the Cloudvieve product to organisations that use it (performance of a contract with that organisation, as a processor on their instruction);
- to meet legal obligations where relevant.
6. How we share information
We do not sell personal data. We may share information with service providers who help us operate the website and product (for example, hosting, infrastructure and AI-assistance providers), under obligations to protect that data. We may disclose information where required by law. Where data is processed in the EU/UK or the US, cross-border transfers are protected by appropriate safeguards.
7. Data ownership and retention
You retain full ownership of all uploaded contracts and supplier records. How long we keep data depends on its type, and you control the default:
- Raw documents (contracts and related files) are retained for the live contract term plus a 90-day buffer after expiry. This window is user-configurable.
- Derived insights (renewal tracking, supplier risk, action plans, spend analysis) persist beyond the raw-file purge so your dashboard keeps working, held as encrypted, non-identifiable metadata.
- Financial and invoice data is retained as a longer-lived record in line with accounting and record-keeping requirements.
- Enquiry and account data is kept as long as needed for our relationship, then deleted.
- Zero third-party sale — your commercial evidence and contract details are never sold, shared, or used to train public AI models.
Deleting or purging raw files does not disable your dashboard. Derived insights continue to power renewal tracking, risk prediction and negotiation playbooks.
8. Security and incident management
We implement appropriate technical and organisational measures including encryption in transit and at rest to protect personal data against unauthorised access, loss or misuse, taking into account the state of the art and the risks involved.
In the event of a confirmed personal data breach affecting your data, we will notify you, as the Data Controller, without undue delay after becoming aware of the incident. Where required by applicable law, we will assist you in fulfilling your obligations to notify the ICO within 72 hours and to inform affected individuals.
For personal data we process as a controller (such as enquiry and account data), we will notify the ICO and affected individuals where required under UK GDPR.
9. Your rights
- UK and EU: the right to access, rectify, erase, restrict and object to processing, and data portability. If you are in the UK and dissatisfied with our response, you may complain to the ICO.
- California (CCPA/CPRA): the right to know, delete, correct, opt out of sale or sharing, and limit use of sensitive personal data, all without discrimination. We do not sell or share personal data.
To exercise any right, contact hello@cloudvieve.com — we respond within one month of receipt.
10. Cookies
This website does not use non-essential tracking or advertising cookies. If this changes, this policy will be updated accordingly.
11. Changes to this policy
We may update this policy from time to time. The date at the top of this page shows when it was last revised. Continued use of our products after any update constitutes your acceptance of the revised policy.
12. Contact us
Questions about this policy or your data can be sent to hello@cloudvieve.com.