Last updated: July 12, 2026
Privacy Policy
This Privacy Policy describes how Dolutech.ai OÜ ("we", "us", "our") processes personal data when you visit the Clavio website, create an account, or use the Clavio Credential Vault service (the "Service"). We comply with the EU General Data Protection Regulation (GDPR) and applicable national data protection laws.
1. Data controller
The data controller for Clavio is Dolutech.ai OÜ. For privacy-related requests, contact us at [email protected].
2. Personal data we process
Depending on how you use the Service, we may process the following categories of personal data:
- Account data: name, email address, password hash, locale preference, MFA configuration metadata, and billing identifiers when you subscribe to Pro.
- Vault metadata: secret labels, types, tags, audit log entries (action, timestamp, IP address, user agent, result), and MCP token names and scopes.
- Encrypted secret payloads: credentials you store are encrypted at rest. We do not access plaintext secret values except when you explicitly reveal them through authenticated actions.
- Technical data: server logs, session identifiers, CSRF tokens, cookie consent preferences, and security-related events.
- Payment data: if you upgrade to Pro, payment processing is handled by Stripe. We receive subscription status and customer identifiers, not full card numbers.
3. Purposes and legal bases
We process personal data only when a valid legal basis applies under GDPR:
- Contract (Art. 6(1)(b)): to provide the Service, authenticate users, enforce plan limits, and deliver support.
- Legal obligation (Art. 6(1)(c)): to comply with tax, accounting, and security incident reporting obligations where applicable.
- Legitimate interests (Art. 6(1)(f)): to secure the platform, prevent abuse, maintain audit trails, and improve reliability — balanced against your rights.
- Consent (Art. 6(1)(a)): for non-essential cookies and optional analytics, where enabled. You may withdraw consent at any time via cookie preferences.
4. Data retention
We retain personal data only as long as necessary for the purposes described above. Account data is kept while your account is active and for a limited period after deletion to meet legal and backup requirements. Audit logs may be retained longer where required for security and compliance. Cookie consent records are stored according to our Cookie Policy.
5. Recipients and international transfers
We may share data with infrastructure providers, email delivery services, and Stripe for billing. Where processors are located outside the European Economic Area, we rely on appropriate safeguards such as Standard Contractual Clauses or adequacy decisions.
6. Security measures
Clavio uses envelope encryption for secrets, mandatory MFA for accounts, scoped MCP tokens, rate limiting, and comprehensive audit logging. Despite these measures, no system is completely secure; please use strong passwords and protect your MFA devices.
7. Your rights
Under GDPR, you may have the right to access, rectify, erase, restrict processing, object, and data portability regarding your personal data. You may also lodge a complaint with your local supervisory authority. To exercise your rights, email [email protected]. We will respond within the timeframe required by law.
8. Children
The Service is not directed at children under 16. We do not knowingly collect personal data from children.
9. Changes to this policy
We may update this Privacy Policy to reflect legal or product changes. Material updates will be indicated by revising the "Last updated" date. Continued use of the Service after changes constitutes acknowledgment where permitted by law.