Data Processing Addendum
Last updated: July 20, 2026
1. Roles
For personal information contained in Customer Data, Customer is the controller (or processor) and ClearDCAA is the processor (or subprocessor). Each party will comply with applicable data protection laws, including GDPR, UK GDPR, and CCPA where relevant.
2. Scope and Purpose
ClearDCAA processes personal information solely to provide the Service described in the Terms of Service and per Customer's documented instructions.
3. Subprocessors
Customer authorizes ClearDCAA to use subprocessors. Current subprocessors include:
- Lovable Cloud (Supabase) — application backend, database, storage
- Cloudflare — hosting, CDN, DDoS protection
- Email delivery provider — transactional email
We will provide notice of new subprocessors and give Customer a reasonable opportunity to object.
4. Security Measures
ClearDCAA maintains technical and organizational measures including encryption in transit (TLS 1.2+) and at rest (AES-256), role-based access control, tenant isolation via row-level security, audit logging, MFA support, and least-privilege access for personnel. Additional detail is available on our Trust page.
5. Personnel
Personnel with access to personal information are bound by confidentiality obligations and receive security training.
6. Data Subject Requests
ClearDCAA will provide reasonable assistance to Customer in responding to data subject access, deletion, and other rights requests, taking into account the nature of the processing.
7. Breach Notification
ClearDCAA will notify Customer without undue delay after becoming aware of a personal data breach affecting Customer Data, and will cooperate on investigation and remediation.
8. International Transfers
Where transfers of personal information occur out of the EEA, UK, or Switzerland, the parties agree to rely on Standard Contractual Clauses or other lawful transfer mechanisms.
9. Deletion and Return
Upon termination, Customer may export Customer Data for 30 days. After that period ClearDCAA will delete or anonymize Customer Data within a reasonable time, subject to backup retention cycles and legal obligations.
10. Audits
Upon reasonable request and no more than once per year, ClearDCAA will provide summaries of relevant third-party audits and reasonable information necessary to demonstrate compliance with this DPA.
11. Contact
Data protection contact: privacy@cleardcaa.com.