Privacy Policy
Last updated: 9 September 2026
This policy explains how CleverUpps CommV ("CleverUpps", "we", "us") collects, uses and protects personal data when you use CleverMarketer at clever-marketer.com and apps.clever-marketer.com (the "Service").
1. Who is the data controller?
BTW / VAT: BE0724738765
Email: [email protected]
2. What personal data we collect
2.1 Early-access list
The email address you submit on the landing page, and the time you submitted it. Nothing else — there is no tracking pixel, no analytics script and no advertising cookie on this site.
2.2 Account and workspace data (once the Service is available)
- Name, email address and profile picture, via Kinde sign-in.
- Workspace details you enter: business name, markets, languages, brand voice, claims, audiences and the other Brand Brain content.
- Images and files you upload to the asset library.
2.3 Connected social and advertising accounts
When you connect an account (Facebook Page, Instagram professional account, LinkedIn organisation, TikTok, Meta or Google Ads), we store the access and refresh tokens that let us publish on your behalf, the account's public identifiers and name, and which permissions were granted. Tokens are encrypted at rest and are never shown to your browser or to another workspace.
2.4 Content and measurement data
- The posts, captions and creative briefs generated for you, together with the record of which model and which version of your Brand Brain produced each one.
- Metrics returned by the platforms you connected (reach, engagement, clicks), attached to the posts they belong to.
- Events you choose to send us from your own site — for example a signup or a purchase — so a post can be traced to an outcome. You decide what to send; see section 6.
2.5 Usage and technical data
IP address, browser and device information, and application logs used for debugging and security. Logs are scrubbed of access tokens, keys and authorisation headers before they are written.
3. Why we process your data (legal basis)
- Contract — to provide the Service you signed up for.
- Legitimate interest — to keep the Service secure, prevent abuse and improve the product.
- Legal obligation — Belgian and EU law, such as invoicing and tax.
- Consent — the early-access list, and any optional marketing email. You can withdraw at any time.
4. How long we keep your data
| Data | Kept for |
|---|---|
| Early-access email address | Until you ask us to remove it, or the list is retired |
| Account and workspace data | While the account is active, and up to 12 months after deletion |
| Tokens of a disconnected account | Erased within 7 days of the connection being revoked |
| Debugging traces of AI generations | 30 days |
| Identifiers in conversion events | 13 months, then removed (configurable per workspace) |
| Invoicing and accounting data | 7 years (Belgian tax law) |
| Backups | Rotated within 30 days |
5. Sub-processors we use
To deliver the Service we share data with:
- Kinde — authentication.
- Anthropic and OpenAI — generating drafts from the brand context you provide. Your content is sent to produce your drafts; it is not used to train their models.
- OpenArt — image generation, when you use it.
- Cloudflare — hosting, and storage of uploaded media.
- Hostinger — the servers the application runs on.
- Formspree — the early-access form on this page.
- Meta, LinkedIn, TikTok and Google — only where you have connected an account, and only to publish and to read back the results of what was published.
6. Data you send us about your own customers
If you send conversion events from your website, you are the controller of that data and we act as your processor. Send the minimum that makes the measurement work: an event name, a time and an opaque identifier are enough. The Service supports a consent flag, and when it says consent was not given, the identifiers are dropped rather than stored.
7. International transfers
We host in the EU. Some sub-processors above are established in the United States; where data reaches them it is transferred under the European Commission's Standard Contractual Clauses or an equivalent mechanism.
8. Your rights under the GDPR
You have the right to access, rectify, erase, restrict and port your data, and to object to processing based on legitimate interest. Write to [email protected] and we will answer within 30 days. You may also complain to the Belgian Data Protection Authority (gegevensbeschermingsautoriteit.be).
9. Cookies
This landing page sets no cookies and runs no analytics. The application at apps.clever-marketer.com uses only what is needed to keep you signed in.
10. Security
Access tokens and other provider credentials are encrypted at rest with per-record binding, so a value cannot be moved between records. Logs redact tokens, keys and authorisation headers. Access to production is limited to the people who operate it.
11. Children
The Service is for businesses and is not directed at anyone under 18.
12. Changes to this policy
We will update this page when the Service changes, and move the date at the top. Material changes will be sent to account holders by email.
13. Contact
Questions about this policy: [email protected], or write to the address in section 1.