1. Definitions
- "Controller"
- The entity that determines the purposes and means of processing personal data (the Customer).
- "Processor"
- Clario Finance, which processes personal data on behalf of the Controller.
- "Personal Data"
- Any information relating to an identified or identifiable natural person.
- "Processing"
- Any operation performed on personal data, including collection, storage, analysis, and deletion.
- "GDPR"
- General Data Protection Regulation (EU) 2016/679.
2. Scope and Purpose
This Data Processing Agreement ("DPA") forms part of the Terms of Service between Clario Finance ("Processor") and the Customer ("Controller") and governs the processing of personal data in connection with the Clario platform.
2.1 Processing Activities
The Processor will process personal data for the following purposes:
- Providing AI-powered financial analysis services
- Processing and analyzing financial documents and data
- Generating insights, reports, and recommendations
- Maintaining and improving the platform functionality
- Providing customer support and technical assistance
2.2 Categories of Personal Data
The following categories of personal data may be processed:
- Identity data (name, email address, user ID)
- Contact data (email address, phone number, business address)
- Financial data (account information, transaction records, financial statements)
- Technical data (IP address, browser type, device information)
- Usage data (platform interactions, feature usage, session data)
3. Processor Obligations
3.1 Processing Instructions
The Processor shall:
- Process personal data only on documented instructions from the Controller
- Not process personal data for any purpose other than those specified in this DPA
- Immediately inform the Controller if any instruction violates applicable data protection law
- Ensure that persons authorized to process personal data are bound by confidentiality obligations
3.2 Security Measures
The Processor shall implement appropriate technical and organizational measures to ensure:
- Confidentiality of personal data
- Integrity of personal data
- Availability of personal data and the services
- Resilience of processing systems and services
- Regular testing, assessing, and evaluating of security measures
3.3 Specific Security Measures
- Encryption: AES-256 encryption at rest, TLS 1.3 in transit
- Access Controls: Role-based access control, multi-factor authentication
- Network Security: Firewalls, intrusion detection, DDoS protection
- Data Isolation: Logical separation of customer data
- Monitoring: 24/7 security monitoring and logging
- Backup Security: Encrypted backups with secure key management
4. Sub-Processors
4.1 Authorized Sub-Processors
The Controller authorizes the Processor to engage the following sub-processors:
Google Cloud Platform
Purpose: Infrastructure hosting, database services, AI processing
Location: United States, European Union
Firebase (Google)
Purpose: Authentication, real-time database, file storage
Location: United States, European Union
Stripe
Purpose: Payment processing
Location: United States
SendGrid
Purpose: Email delivery services
Location: United States
4.2 Sub-Processor Obligations
The Processor shall:
- Ensure sub-processors are bound by the same data protection obligations
- Inform the Controller of any intended changes to sub-processors
- Allow the Controller to object to new sub-processors
- Remain fully liable for sub-processor compliance
5. Data Subject Rights
5.1 Assistance with Data Subject Requests
The Processor shall assist the Controller in responding to data subject requests:
- Right of access to personal data
- Right to rectification of inaccurate data
- Right to erasure ("right to be forgotten")
- Right to restriction of processing
- Right to data portability
- Right to object to processing
5.2 Response Timeframes
The Processor shall respond to data subject requests within:
- 24 hours for urgent requests (data breaches, immediate harm)
- 72 hours for standard requests
- 30 days for complex requests (with possibility of extension)
6. Data Breach Notification
6.1 Breach Detection and Assessment
The Processor shall:
- Implement systems to detect personal data breaches
- Assess the likelihood and severity of risks to data subjects
- Document all breaches, including facts, effects, and remedial actions
6.2 Notification Requirements
The Processor shall notify the Controller without undue delay and, where feasible, within 24 hours of becoming aware of a personal data breach, providing:
- Description of the nature of the breach
- Categories and approximate number of data subjects affected
- Categories and approximate number of personal data records affected
- Likely consequences of the breach
- Measures taken or proposed to address the breach
7. Data Protection Impact Assessments
The Processor shall assist the Controller in carrying out data protection impact assessments and prior consultations with supervisory authorities where required by GDPR Article 35 and 36.
8. Audit and Compliance
8.1 Audit Rights
The Processor shall:
- Make available to the Controller all information necessary to demonstrate compliance
- Allow for and contribute to audits conducted by the Controller or its authorized representative
- Provide access to premises, systems, and personnel for audit purposes
- Maintain detailed records of processing activities
8.2 Compliance Certifications
The Processor maintains the following certifications and compliance standards:
- SOC 2 Type II (in progress)
- ISO 27001 (through cloud providers)
- PCI DSS Level 1 (through Stripe)
- GDPR compliance program
9. Data Retention and Deletion
9.1 Retention Periods
Personal data shall be retained for the following periods:
- Active accounts: Duration of the service agreement
- Inactive accounts: 2 years after last activity
- Deleted accounts: 30 days after deletion request
- Backup data: 90 days after account deletion
9.2 Secure Deletion
Upon expiration of retention periods, the Processor shall:
- Securely delete personal data from all systems
- Ensure deletion from backup systems within 90 days
- Provide certification of deletion to the Controller
- Maintain deletion logs for audit purposes
10. International Transfers
Where personal data is transferred outside the European Economic Area, the Processor shall ensure appropriate safeguards are in place, including:
- Standard Contractual Clauses (SCCs) approved by the European Commission
- Adequacy decisions by the European Commission
- Binding corporate rules
- Certification schemes and codes of conduct
11. Liability and Indemnification
11.1 Processor Liability
The Processor shall be liable for any damage caused by processing that infringes this DPA or applicable data protection law.
11.2 Limitation of Liability
The Processor's total liability shall not exceed the total amount paid by the Controller for the services in the 12 months preceding the event giving rise to the claim.
12. Termination and Data Return
12.1 Termination
This DPA shall terminate automatically upon termination of the main service agreement, unless the parties agree otherwise in writing.
12.2 Data Return or Deletion
Upon termination, the Processor shall:
- Return all personal data to the Controller in a structured, commonly used format
- Delete all copies of personal data unless required by law
- Provide certification of deletion
- Ensure sub-processors also delete the data
13. Governing Law and Jurisdiction
This DPA shall be governed by the laws of [Your Jurisdiction] and any disputes shall be resolved in the courts of [Your Jurisdiction]. In case of conflicts between this DPA and the main service agreement, this DPA shall prevail with respect to data protection matters.
14. Contact Information
Data Protection Officer
Email: dpo@clario.finance
Phone: +1 (555) 123-4567
Legal Department
Email: legal@clario.finance
Address: [Your Business Address]