Skip to content
Security

Security and Data Retention Policy

Safeguards, retention periods, deletion, backups, account security, and incident handling.

Operational security language for platform trust and privacy compliance. · Last updated: July 4, 2026

Company

Mycleverly Services



Contact support
#

1. Security program

MyCleverly should maintain a security program appropriate to the size, nature, and risk of the service. Measures may include encryption in transit, access controls, logging, monitoring, vulnerability management, secure development, vendor review, backups, and incident response procedures.

Employees, contractors, and vendors should access personal data only when needed for authorized business purposes and should be subject to confidentiality obligations.

#

2. User account security

Users are responsible for maintaining strong passwords, protecting devices, avoiding credential sharing, and promptly reporting suspected compromise. MyCleverly may require password resets or additional verification where account risk is detected.

If available, users should enable multi-factor authentication, review active sessions, update recovery email addresses, and avoid reusing passwords from other services.

#

3. Payment security

Payment processing should be handled by reputable payment processors using industry-standard security controls. MyCleverly should avoid storing full payment card numbers unless specifically certified and necessary.

Fraud tools may review transaction signals, device data, IP address, billing information, velocity, chargeback history, and account behavior to protect users, creators, and the platform.

#

4. Retention schedule

Account data is generally retained while the account is active. Learning progress, certificates, purchases, and course access records may be retained so users can continue learning and prove completion.

Payment, invoice, tax, refund, chargeback, fraud, and accounting records may be retained for legally required periods. Security logs may be retained for a period appropriate to detect and investigate incidents.

Support tickets, legal correspondence, moderation records, and abuse reports may be retained as needed to resolve requests, enforce policies, defend claims, and comply with law.

#

5. Deletion, anonymization, and backups

Users may request deletion of personal data by contacting support@mycleverly.com. Deletion may not remove data that must be retained for legal, security, payment, tax, fraud, dispute, or legitimate business reasons.

Deleted data may remain in encrypted or access-controlled backups until the backup expires or is overwritten. MyCleverly should not restore deleted personal data into active systems except where necessary.

#

6. Security incidents

If MyCleverly discovers a security incident, it should investigate, contain, remediate, document, and notify affected users, regulators, customers, or partners where required by law or contract.

Security concerns should be reported to support@mycleverly.com with the subject Security Report and enough detail to reproduce or understand the issue.