⚠️
REVIEW REQUIRED BY LEGAL COUNSEL BEFORE PUBLISHING

This document is a working draft prepared for legal review. It has not been reviewed by a qualified lawyer, is not a binding legal instrument in its current form, and must not be relied upon as legal advice. Do not publish, present to clients, or execute this agreement until a qualified attorney has reviewed and approved it.

Data Processing Agreement

Version: 1.0 (Draft) Last updated: 22 July 2026 Draft — Not Executed
This Data Processing Agreement ("DPA") supplements the ClearAI HQ Terms of Service and governs the processing of personal data by ClearAI HQ on behalf of business customers, as required by Article 28 of the General Data Protection Regulation (EU) 2016/679 ("GDPR"). If there is a conflict between this DPA and the Terms of Service, this DPA prevails with respect to data processing.

Contents

  1. Definitions
  2. Subject Matter and Duration
  3. Nature and Purpose of Processing
  4. Data Types and Data Subjects
  5. Processor Obligations
  6. Sub-Processors
  7. International Transfers
  8. Security Measures
  9. Data Subject Rights
  10. Personal Data Breaches
  11. Deletion and Return of Data
  12. Audit Rights
  13. Liability
  14. Governing Law
  15. Contact

Parties

Data Controller

The Customer

The legal entity or individual that has accepted the ClearAI HQ Terms of Service and is using the platform to process personal data of their own customers or employees.

Referred to in this DPA as "Controller".

Data Processor

ClearAI HQ

[LEGAL ENTITY NAME — TO BE CONFIRMED]
Stockholm, Sweden

Referred to in this DPA as "Processor".

Article 1 — Definitions

Article 2 — Subject Matter and Duration

2.1 The Processor shall process Personal Data on behalf of the Controller for the purpose of providing the Services under the Terms of Service.

2.2 This DPA commences on the date the Controller first accepts the Terms of Service (or the date of execution if separately executed) and continues until the termination of the Terms of Service. Obligations regarding data deletion and confidentiality survive termination.

Article 3 — Nature and Purpose of Processing

3.1 The Processor processes Personal Data solely on the documented instructions of the Controller, which are provided through the Controller's use of the Services, including:

3.2 The Processor shall not process Personal Data for any purpose other than to provide the Services unless required to do so by Union or Member State law.

Article 4 — Types of Personal Data and Categories of Data Subjects

4.1 Categories of data subjects

4.2 Types of personal data

The types of personal data processed depend on what the Controller inputs into the Services. They may include:

CategoryExamples
Identity data Name, job title, company name
Contact data Email address, phone number, postal address
Engagement data CRM notes, deal status, interaction history
Social media data Social media handles or profiles connected by the Controller
Content data Text, images, or other content referencing identifiable individuals

The Processor does not process special categories of data (as defined in GDPR Article 9) unless the Controller explicitly provides such data, in which case the Controller warrants it has a valid legal basis to do so.

Article 5 — Processor Obligations

In accordance with GDPR Article 28(3), the Processor shall:

Article 6 — Sub-Processors

6.1 The Controller provides a general written authorisation for the Processor to engage sub-processors. The current list of sub-processors is maintained in the ClearAI HQ Privacy Policy — Sub-Processors section.

6.2 The Processor shall notify the Controller of any intended addition or replacement of sub-processors by updating the Privacy Policy and, where the change materially affects data processing, by emailing the Controller at least 14 days in advance.

6.3 The Controller may object to a new sub-processor on reasonable, documented grounds by notifying the Processor in writing within 14 days of notification. If the Processor cannot accommodate the objection, the Controller may terminate the relevant services on written notice without penalty.

6.4 The Processor shall impose data protection obligations on each sub-processor equivalent to those imposed on the Processor under this DPA, by contract. The Processor remains liable to the Controller for the performance of sub-processors' obligations.

Article 7 — International Data Transfers

7.1 The Processor shall not transfer Personal Data outside the European Economic Area (EEA) except:

7.2 Where SCCs are required for transfers to sub-processors, the Processor ensures those are in place. The current sub-processors and their transfer mechanisms are listed in the Privacy Policy.

7.3 The Controller may request evidence of the transfer mechanisms in place for specific sub-processors by contacting privacy@clearaihq.com.

Article 8 — Security Measures

The Processor implements appropriate technical and organisational measures to ensure a level of security appropriate to the risk, including:

[NOTE FOR LEGAL REVIEW: Confirm whether the security measures listed meet the standard required by GDPR Art. 32 for the risk profile of this processing. Additional technical controls (e.g. penetration testing schedule, SOC 2 status) should be documented if available.]

Article 9 — Data Subject Rights Assistance

9.1 The Processor shall assist the Controller in fulfilling its obligation to respond to Data Subject requests under GDPR Articles 15–22 (access, rectification, erasure, restriction, portability, objection, automated decision-making).

9.2 If the Processor receives a Data Subject request relating to Personal Data processed on behalf of the Controller, the Processor shall promptly forward the request to the Controller and shall not respond to it directly except on the Controller's instruction or as required by law.

9.3 The Processor shall provide reasonable assistance in extracting or deleting Personal Data to facilitate the Controller's response to Data Subject requests, within the technical capabilities of the platform.

Article 10 — Personal Data Breach Notification

10.1 The Processor shall notify the Controller of a Security Incident affecting Personal Data processed under this DPA without undue delay and, where feasible, within 48 hours of becoming aware of the incident.

10.2 The notification shall include, to the extent available: (a) the nature of the incident; (b) the categories and approximate number of Data Subjects and Personal Data records concerned; (c) likely consequences of the incident; and (d) measures taken or proposed to address the incident.

10.3 The Processor acknowledges that the Controller may have an obligation to notify the supervisory authority within 72 hours under GDPR Article 33. The Processor shall provide timely cooperation to support this obligation.

10.4 Breach notifications to the Controller shall be sent to the email address associated with the Controller's account, unless the Controller specifies otherwise in writing.

Article 11 — Deletion and Return of Data

11.1 Upon termination of the Services, the Processor shall, at the Controller's election, either:

11.2 The Controller shall make this election within 30 days of termination. If no election is made, the Processor will delete the data.

11.3 The Processor may retain Personal Data where required by Union or Member State law (e.g. financial records required under Swedish accounting law for 7 years). In such cases, the Processor shall inform the Controller of the legal basis and scope of retention.

11.4 Deletion shall be completed within 30 days of termination or of the Controller's request, except where legal retention obligations apply.

Article 12 — Audit Rights

12.1 The Processor shall make available to the Controller all information reasonably necessary to demonstrate compliance with GDPR Article 28 and this DPA.

12.2 The Processor shall allow the Controller, or an independent auditor appointed by the Controller, to audit the Processor's data processing activities, subject to the following conditions:

12.3 As an alternative to an on-site audit, the Processor may provide written responses to reasonable security questionnaires submitted by the Controller. The Processor shall share relevant security certifications (e.g. SOC 2, ISO 27001) held by itself or its sub-processors where available.

Article 13 — Liability

13.1 Each party shall be liable for damage caused to Data Subjects as a result of that party's breach of this DPA or of the GDPR, in accordance with GDPR Articles 82 and 83.

13.2 As between the parties, the liability of each party under or in connection with this DPA (including any indemnity obligations) is subject to the limitations and exclusions set out in the Terms of Service.

13.3 The Processor is not liable for damage caused by processing where the Processor has acted in compliance with documented instructions from the Controller and those instructions were in breach of GDPR.

Article 14 — Governing Law

This DPA is governed by the laws of Sweden and subject to the jurisdiction of the courts of Stockholm, Sweden, without prejudice to the rights of Data Subjects to bring claims before any competent supervisory authority or court in their jurisdiction.

Article 15 — Contact

Data protection and DPA enquiries: privacy@clearaihq.com

Registered address: [TO BE CONFIRMED BY LEGAL], Stockholm, Sweden.

Annex I — Details of Processing Activities
FieldDetails
Subject matter Provision of the ClearAI HQ platform as described in the Terms of Service
Duration For the term of the Terms of Service agreement between the parties
Nature of processing Collection, storage, retrieval, use, disclosure, and erasure of Personal Data through the platform
Purpose of processing To deliver the ClearAI HQ Services to the Controller, including CRM, content generation, social publishing, and analytics
Type of personal data As specified in Article 4 of this DPA
Categories of data subjects Controller's customers, leads, team members, and recipients of published content
Primary storage location EU-West (Frankfurt, Germany) via Supabase
Annex II — Technical and Organisational Security Measures (Summary)

The following is a high-level summary. Full technical documentation available on request.

Control areaMeasure
Encryption in transitTLS 1.2+ (HTTPS) on all endpoints
Encryption at restDatabase and token encryption at rest; managed by Supabase
Access controlRole-based access; least-privilege principle; production access restricted to authorised personnel
AuthenticationPassword hashing (bcrypt); MFA available for all accounts
AvailabilityHosted on Netlify and Supabase with redundant infrastructure; uptime SLA per provider agreements
Audit loggingAccess logs maintained for security and compliance
Vulnerability managementPeriodic security reviews; dependency updates applied promptly
Incident responseDocumented incident response procedure; breach notification within 48 hours (Art. 10)
Sub-processor oversightSecurity evaluation before engagement; DPA in place with each sub-processor
Annex III — Authorised Sub-Processors

See the Privacy Policy — Sub-Processors section for the current list. This list is updated when sub-processors are added or changed, with 14 days' notice to Controllers.

[NOTES FOR LEGAL REVIEW]