This document is a working draft prepared for legal review. It has not been reviewed by a qualified lawyer, is not a binding legal instrument in its current form, and must not be relied upon as legal advice. Do not publish, present to clients, or execute this agreement until a qualified attorney has reviewed and approved it.
The Customer
The legal entity or individual that has accepted the ClearAI HQ Terms of Service and is using the platform to process personal data of their own customers or employees.
Referred to in this DPA as "Controller".
ClearAI HQ
[LEGAL ENTITY NAME — TO BE CONFIRMED]
Stockholm, Sweden
Referred to in this DPA as "Processor".
2.1 The Processor shall process Personal Data on behalf of the Controller for the purpose of providing the Services under the Terms of Service.
2.2 This DPA commences on the date the Controller first accepts the Terms of Service (or the date of execution if separately executed) and continues until the termination of the Terms of Service. Obligations regarding data deletion and confidentiality survive termination.
3.1 The Processor processes Personal Data solely on the documented instructions of the Controller, which are provided through the Controller's use of the Services, including:
3.2 The Processor shall not process Personal Data for any purpose other than to provide the Services unless required to do so by Union or Member State law.
The types of personal data processed depend on what the Controller inputs into the Services. They may include:
| Category | Examples |
|---|---|
| Identity data | Name, job title, company name |
| Contact data | Email address, phone number, postal address |
| Engagement data | CRM notes, deal status, interaction history |
| Social media data | Social media handles or profiles connected by the Controller |
| Content data | Text, images, or other content referencing identifiable individuals |
The Processor does not process special categories of data (as defined in GDPR Article 9) unless the Controller explicitly provides such data, in which case the Controller warrants it has a valid legal basis to do so.
In accordance with GDPR Article 28(3), the Processor shall:
6.1 The Controller provides a general written authorisation for the Processor to engage sub-processors. The current list of sub-processors is maintained in the ClearAI HQ Privacy Policy — Sub-Processors section.
6.2 The Processor shall notify the Controller of any intended addition or replacement of sub-processors by updating the Privacy Policy and, where the change materially affects data processing, by emailing the Controller at least 14 days in advance.
6.3 The Controller may object to a new sub-processor on reasonable, documented grounds by notifying the Processor in writing within 14 days of notification. If the Processor cannot accommodate the objection, the Controller may terminate the relevant services on written notice without penalty.
6.4 The Processor shall impose data protection obligations on each sub-processor equivalent to those imposed on the Processor under this DPA, by contract. The Processor remains liable to the Controller for the performance of sub-processors' obligations.
7.1 The Processor shall not transfer Personal Data outside the European Economic Area (EEA) except:
7.2 Where SCCs are required for transfers to sub-processors, the Processor ensures those are in place. The current sub-processors and their transfer mechanisms are listed in the Privacy Policy.
7.3 The Controller may request evidence of the transfer mechanisms in place for specific sub-processors by contacting privacy@clearaihq.com.
The Processor implements appropriate technical and organisational measures to ensure a level of security appropriate to the risk, including:
9.1 The Processor shall assist the Controller in fulfilling its obligation to respond to Data Subject requests under GDPR Articles 15–22 (access, rectification, erasure, restriction, portability, objection, automated decision-making).
9.2 If the Processor receives a Data Subject request relating to Personal Data processed on behalf of the Controller, the Processor shall promptly forward the request to the Controller and shall not respond to it directly except on the Controller's instruction or as required by law.
9.3 The Processor shall provide reasonable assistance in extracting or deleting Personal Data to facilitate the Controller's response to Data Subject requests, within the technical capabilities of the platform.
10.1 The Processor shall notify the Controller of a Security Incident affecting Personal Data processed under this DPA without undue delay and, where feasible, within 48 hours of becoming aware of the incident.
10.2 The notification shall include, to the extent available: (a) the nature of the incident; (b) the categories and approximate number of Data Subjects and Personal Data records concerned; (c) likely consequences of the incident; and (d) measures taken or proposed to address the incident.
10.3 The Processor acknowledges that the Controller may have an obligation to notify the supervisory authority within 72 hours under GDPR Article 33. The Processor shall provide timely cooperation to support this obligation.
10.4 Breach notifications to the Controller shall be sent to the email address associated with the Controller's account, unless the Controller specifies otherwise in writing.
11.1 Upon termination of the Services, the Processor shall, at the Controller's election, either:
11.2 The Controller shall make this election within 30 days of termination. If no election is made, the Processor will delete the data.
11.3 The Processor may retain Personal Data where required by Union or Member State law (e.g. financial records required under Swedish accounting law for 7 years). In such cases, the Processor shall inform the Controller of the legal basis and scope of retention.
11.4 Deletion shall be completed within 30 days of termination or of the Controller's request, except where legal retention obligations apply.
12.1 The Processor shall make available to the Controller all information reasonably necessary to demonstrate compliance with GDPR Article 28 and this DPA.
12.2 The Processor shall allow the Controller, or an independent auditor appointed by the Controller, to audit the Processor's data processing activities, subject to the following conditions:
12.3 As an alternative to an on-site audit, the Processor may provide written responses to reasonable security questionnaires submitted by the Controller. The Processor shall share relevant security certifications (e.g. SOC 2, ISO 27001) held by itself or its sub-processors where available.
13.1 Each party shall be liable for damage caused to Data Subjects as a result of that party's breach of this DPA or of the GDPR, in accordance with GDPR Articles 82 and 83.
13.2 As between the parties, the liability of each party under or in connection with this DPA (including any indemnity obligations) is subject to the limitations and exclusions set out in the Terms of Service.
13.3 The Processor is not liable for damage caused by processing where the Processor has acted in compliance with documented instructions from the Controller and those instructions were in breach of GDPR.
This DPA is governed by the laws of Sweden and subject to the jurisdiction of the courts of Stockholm, Sweden, without prejudice to the rights of Data Subjects to bring claims before any competent supervisory authority or court in their jurisdiction.
Data protection and DPA enquiries: privacy@clearaihq.com
Registered address: [TO BE CONFIRMED BY LEGAL], Stockholm, Sweden.
| Field | Details |
|---|---|
| Subject matter | Provision of the ClearAI HQ platform as described in the Terms of Service |
| Duration | For the term of the Terms of Service agreement between the parties |
| Nature of processing | Collection, storage, retrieval, use, disclosure, and erasure of Personal Data through the platform |
| Purpose of processing | To deliver the ClearAI HQ Services to the Controller, including CRM, content generation, social publishing, and analytics |
| Type of personal data | As specified in Article 4 of this DPA |
| Categories of data subjects | Controller's customers, leads, team members, and recipients of published content |
| Primary storage location | EU-West (Frankfurt, Germany) via Supabase |
The following is a high-level summary. Full technical documentation available on request.
| Control area | Measure |
|---|---|
| Encryption in transit | TLS 1.2+ (HTTPS) on all endpoints |
| Encryption at rest | Database and token encryption at rest; managed by Supabase |
| Access control | Role-based access; least-privilege principle; production access restricted to authorised personnel |
| Authentication | Password hashing (bcrypt); MFA available for all accounts |
| Availability | Hosted on Netlify and Supabase with redundant infrastructure; uptime SLA per provider agreements |
| Audit logging | Access logs maintained for security and compliance |
| Vulnerability management | Periodic security reviews; dependency updates applied promptly |
| Incident response | Documented incident response procedure; breach notification within 48 hours (Art. 10) |
| Sub-processor oversight | Security evaluation before engagement; DPA in place with each sub-processor |
See the Privacy Policy — Sub-Processors section for the current list. This list is updated when sub-processors are added or changed, with 14 days' notice to Controllers.