This policy explains how ZioMark (“we”, “us”) handles personal data when you use the ClavisDB website and app, purchase a Pro plan, or access the customer portal.
1. Data we process
- Account and purchase data: email, display name, customer and order identifiers, plan, payment status, subscription, invoice, and license keys.
- License data: key, validity, expiry, activation status, and a hardware identifier where needed to activate or validate a license.
- Technical data: IP address, browser or device type, network requests, and security or error logs ordinarily processed by our hosting infrastructure.
- Session data: an essential signed cookie containing the portal email and session expiry.
- Communications: information you provide when requesting support.
2. Why we use data and our legal bases
- To create and administer orders, deliver and validate licenses, and provide the customer portal: performance of our contract with you.
- For security, abuse prevention, error diagnosis, and product improvement: our legitimate interests, balanced against your rights.
- For tax, accounting, and other legal requirements: compliance with legal obligations.
- For promotional email or optional analytics: your consent, which you may withdraw at any time.
3. Cookies, sessions, and analytics
The portal uses the essential clavis_customer cookie to keep you signed in after email verification. It is HttpOnly, Secure, SameSite=Lax, and expires after seven days. It is not used for advertising or cross-site tracking.
Only after you consent, we use Google Analytics 4 to measure visits, page views, interactions, technical device information, and approximate geographic area. Google Analytics may set analytics cookies or identifiers. Google Signals, advertising storage, and ad personalisation are disabled. You can reject or revisit your choice through “Cookie preferences” in the footer.
4. Providers and sharing
We share data only as needed with providers that help operate the service, principally Shoppex for checkout, payments, orders, profiles, and licenses, Cloudflare for hosting, network delivery, and security, and, with consent, Google Analytics for aggregate usage analytics. GitHub hosts public download files. These providers may process data under their own terms and privacy notices. We may also disclose data where legally required or necessary to protect users and the service.
We do not sell or license personal information or session details to third parties.
5. Retention and security
We retain data only as long as needed for the stated purposes, to manage our commercial relationship, and to meet legal obligations. Order and billing records may be retained for legally required periods; the portal session expires after seven days. We use reasonable technical and organisational safeguards, but no online system can guarantee absolute security.
6. International transfers
Some providers may process data outside the European Economic Area. Where applicable, we rely on safeguards recognised by relevant data-protection law and measures offered by the provider.
7. Your rights
Depending on applicable law, you may request access, correction, deletion, restriction, or portability of your data, or object to processing. You may withdraw consent without affecting earlier processing and lodge a complaint with your competent data-protection authority. Legal retention duties may limit some requests.
8. Contact and changes
For privacy requests, contact ZioMark through ziomark.xyz. We may update this policy and will publish the revised version here with a new effective date.
