Data Processing Addendum

Last updated: July 20, 2026

1. Roles

For personal information contained in Customer Data, Customer is the controller (or processor) and ClearDCAA is the processor (or subprocessor). Each party will comply with applicable data protection laws, including GDPR, UK GDPR, and CCPA where relevant.

2. Scope and Purpose

ClearDCAA processes personal information solely to provide the Service described in the Terms of Service and per Customer's documented instructions.

3. Subprocessors

Customer authorizes ClearDCAA to use subprocessors. Current subprocessors include:

  • Lovable Cloud (Supabase) — application backend, database, storage
  • Cloudflare — hosting, CDN, DDoS protection
  • Email delivery provider — transactional email

We will provide notice of new subprocessors and give Customer a reasonable opportunity to object.

4. Security Measures

ClearDCAA maintains technical and organizational measures including encryption in transit (TLS 1.2+) and at rest (AES-256), role-based access control, tenant isolation via row-level security, audit logging, MFA support, and least-privilege access for personnel. Additional detail is available on our Trust page.

5. Personnel

Personnel with access to personal information are bound by confidentiality obligations and receive security training.

6. Data Subject Requests

ClearDCAA will provide reasonable assistance to Customer in responding to data subject access, deletion, and other rights requests, taking into account the nature of the processing.

7. Breach Notification

ClearDCAA will notify Customer without undue delay after becoming aware of a personal data breach affecting Customer Data, and will cooperate on investigation and remediation.

8. International Transfers

Where transfers of personal information occur out of the EEA, UK, or Switzerland, the parties agree to rely on Standard Contractual Clauses or other lawful transfer mechanisms.

9. Deletion and Return

Upon termination, Customer may export Customer Data for 30 days. After that period ClearDCAA will delete or anonymize Customer Data within a reasonable time, subject to backup retention cycles and legal obligations.

10. Audits

Upon reasonable request and no more than once per year, ClearDCAA will provide summaries of relevant third-party audits and reasonable information necessary to demonstrate compliance with this DPA.

11. Contact

Data protection contact: privacy@cleardcaa.com.