Last updated · June 2026

Data Processing Agreement

Customer-as-Controller, Claivi-as-Processor. GDPR Art. 28 compliant with Standard Contractual Clauses for international transfers.

1. Parties & effective date

This Data Processing Agreement ("DPA") forms part of the Terms of Service between:

  • Customer ("Controller")
    The entity that subscribes to Claivi and determines the purposes and means of processing personal data.
  • Claivi Technologies Inc. ("Processor")
    200 Bay Street, Toronto, ON M5J 2J2, Canada.
    Privacy Officer: dpo@claivi.com

This DPA is effective as of the date you accept the Terms of Service or begin using the Claivi platform, whichever is earlier. By using Claivi, you agree to be bound by this DPA.

2. Definitions

Unless otherwise defined, capitalized terms have the meanings given in the Terms of Service. In addition:

  • "Personal Data" has the meaning given in applicable Data Protection Laws.
  • "Data Protection Laws" means all applicable laws relating to data protection, privacy, and security, including: PIPEDA (Canada); GDPR (EU) and UK GDPR; California Consumer Privacy Act as amended (CCPA/CPRA); Quebec Law 25; and all implementing regulations.
  • "Controller", "Processor", "Data Subject", "Processing", "Personal Data Breach" have the meanings given in applicable Data Protection Laws.
  • "SCCs" means the Standard Contractual Clauses adopted by the European Commission Decision 2021/914 (Modules 2 and 3), as amended or replaced.
  • "Sub-processor" means any third party engaged by Processor to Process Personal Data on behalf of Controller.
  • "Supplementary Measures" means additional safeguards beyond SCCs that address third-country surveillance risks, including encryption, data minimization, and pseudonymization.
  • "Transfer Impact Assessment" means the assessment required under Article 46 GDPR and the UK GDPR to evaluate the level of protection afforded to Personal Data in the importing country.
  • "ROPA" means the Record of Processing Activities required under Article 30 GDPR.

3. Roles & scope

Controller: Customer determines the purposes and means of processing Personal Data. Customer is the Controller of Personal Data relating to its end customers and team members.

Processor: Claivi Processes Personal Data only on behalf of and on documented instructions from Controller, as described in this DPA and the Terms of Service. Claivi processes as a Processor within the meaning of Article 28 GDPR and applicable Data Protection Laws.

GDPR Art. 28 compliance: Processor is committed to complying with Article 28 GDPR and shall: (a) process Personal Data only on Controller's documented instructions; (b) ensure persons authorized to process are subject to confidentiality; (c) implement security measures as set out in Section 10; (d) engage Sub-processors as set out in Section 9; (e) assist Controller with data subject requests as set out in Section 12; (f) assist Controller with data protection impact assessments and prior consultation obligations; (g) return or delete data on termination as set out in Section 15; and (h) make available all information necessary to demonstrate compliance as set out in Section 14.

Scope: This DPA applies to all Processing of Personal Data by Claivi in connection with the Claivi platform, regardless of the channel (Instagram, Telegram, WhatsApp, web chat, email) through which data is collected.

4. Subject matter & duration

Subject matter: Automated and human-assisted handling of customer conversations, including message storage, AI-assisted draft generation, FAQ matching, and routing to support operators.

Duration: This DPA takes effect on the effective date and continues until termination of the Terms of Service, plus the post-termination data deletion period (30 days unless extended by legal hold requirements).

5. Nature & purpose of processing

Processor shall Process Personal Data for the following purposes:

  • Receiving, storing, and organizing messages from Connected Channels.
  • Running deterministic FAQ matching, embedding vector search, and confidence scoring against the Controller's private knowledge base.
  • Generating AI-assisted draft replies using zero-retention LLM APIs.
  • Routing conversations to human operators through the dashboard.
  • Maintaining audit logs for security and compliance.
  • Generating aggregated, anonymized analytics for service improvement.
  • Billing the Controller based on Resolved Conversation volume.

Processor shall not Process Personal Data for any purpose other than those described in this DPA and the Terms of Service, except on Controller's documented instructions. Processor shall not sell or otherwise monetize Personal Data pursuant to any Data Protection Laws, including CCPA/CPRA.

6. Categories of data subjects

  • End customers of Controller who initiate conversations through Connected Channels (Instagram, Telegram, WhatsApp, web chat, email).
  • Team members of Controller (operators, admins, viewers) who access the Claivi dashboard.
  • Prospective customers of Controller who inquire through web chat or email.

7. Categories of personal data

  • Contact identifiers: social media handle, email address, name, phone number (when provided by the end customer or channel).
  • Conversation content: full text of messages, message timestamps, file attachments and metadata, channel-specific identifiers.
  • Operational metadata: IP address, timestamps, channel source, user-agent, audit trail entries.
  • Account data (team members): name, email, role, login history, hashed password.
  • Derived data: AI confidence scores, embedding vectors (non-reversible), conversation routing decisions, resolution status.

Controller represents and warrants that it will not (and will ensure its end customers do not) submit special categories of personal data (data revealing racial or ethnic origin, political opinions, religious or philosophical beliefs, trade union membership, genetic data, biometric data, health data, sex life or sexual orientation) or criminal conviction data to the Claivi platform. If Controller nevertheless submits such data, Controller acknowledges that Claivi's security measures may not be appropriate for such data and Controller assumes all associated risk.

8. Processing instructions

By using the Claivi platform and configuring workspace settings, Controller provides Processor with documented instructions to Process Personal Data. The initial instructions are:

  • Process messages from Connected Channels as they arrive.
  • Apply Controller's configured matching and routing rules.
  • Store, retrieve, and delete data according to Controller's retention settings.
  • Provide dashboard access to Controller's authorized team members.

Controller may issue additional written instructions (including suspension, restriction, or deletion of data) through the dashboard or by email to privacy@claivi.com. Processor shall comply within 5 business days unless compliance would violate applicable law.

If Processor believes that an instruction violates Data Protection Laws, Processor shall promptly inform Controller and may suspend execution of the instruction until Controller confirms or modifies it.

9. Sub-processors

General written authorization: Controller grants Processor a general written authorization to engage Sub-processors. Processor maintains an up-to-date list of authorized Sub-processors.

Sub-processorProcessing activityLocationTransfer safeguard
Amazon Web ServicesCompute, RDS PostgreSQL (pgvector), S3 storage, networkingca-central-1 (Canada)N/A (data stays in Canada)
OpenAIAI LLM inference (zero-retention, no training)United StatesSCCs + DPA + zero-retention contractual commitment
StripePayment processing, subscription management, invoicingUnited StatesSCCs + DPA + PCI DSS
CloudflareCDN, DDoS protection, WAF, DNS (no persistent storage)Global edgeSCCs + DPA, ephemeral processing only
ResendTransactional email (magic links, invites, alerts)European Union (Frankfurt)SCCs + DPA

Sub-processor changes: Processor shall notify Controller by email at least 30 days before authorizing any new Sub-processor. Controller may object in writing within 14 days of notice on reasonable grounds relating to data protection. If the parties cannot resolve the objection within 30 days, Controller may terminate the affected services without penalty.

Processor shall enter into written agreements with each Sub-processor that impose data protection obligations equivalent to those in this DPA. Processor remains fully liable for Sub-processors' compliance.

10. Security measures

Processor shall implement and maintain appropriate technical and organizational security measures to protect Personal Data against accidental or unlawful destruction, loss, alteration, unauthorized disclosure, or access. These measures are mapped to ISO 27001:2022 controls and include:

10.1 Access control (ISO 27001: A.9)

  • Role-based access control (RBAC) with least-privilege defaults: admin, agent, viewer roles.
  • Multi-factor authentication required for workspace owners; available for all users.
  • Automated session timeout after 24 hours of inactivity.
  • Quarterly access review; immediate revocation on termination.
  • Unique user IDs for all personnel with system access.

10.2 Encryption & supplementary measures (ISO 27001: A.10)

  • Encryption at rest: AES-256 for all data in PostgreSQL, S3, and backups. Keys managed via AWS KMS with automatic rotation (maximum 1 year). Processor contractually commits to maintaining AES-256 encryption at rest as a supplementary measure for transfer safeguard.
  • Encryption in transit: TLS 1.2+ for all external connections. HSTS preloading. mTLS for inter-service communication within infrastructure. Processor contractually commits to TLS 1.2+ as a supplementary measure for transfer safeguard.
  • Token encryption: OAuth tokens and API keys encrypted at rest using a dedicated TOKEN_ENCRYPTION_KEY, separate from database encryption.
  • Data minimization: Processor collects and retains only the Personal Data necessary for the processing purposes described in this DPA, as a supplementary measure.
  • Pseudonymization: Where technically feasible, Processor applies pseudonymization to reduce linkability to specific data subjects. Embedding vectors are non-reversible and constitute a form of pseudonymization for conversation data.

10.3 Network security (ISO 27001: A.13)

  • All infrastructure within isolated VPC with no public database access.
  • Web Application Firewall (Cloudflare WAF) with OWASP Top 10 rule sets.
  • DDoS protection always-on (Cloudflare).
  • Rate limiting per IP (6 requests/second), per workspace (12 requests/second), and per magic-link endpoint (5 requests/minute).
  • Intrusion detection and automated threat response.

10.4 Input & output control (ISO 27001: A.12, A.14)

  • PII redaction pipeline: automatic detection and masking of email, phone, credit card, passport, SNILS, INN, and IBAN patterns before AI processing.
  • Input sanitization: control character stripping, length capping (8KB), prompt-injection marker removal.
  • Output guardrails: canary-token leakage detection, system-prompt fragment detection, off-topic code block filtering, knowledge-base exfiltration prevention.
  • Immutable audit logging of all state-changing operations with actor, action, target, timestamp, and IP address.

10.5 Operational security (ISO 27001: A.12, A.16)

  • Automated vulnerability scanning of dependencies (Go mod, npm), containers (Docker image scan), and infrastructure (CSPM).
  • SAST in CI/CD pipeline; DAST performed quarterly.
  • Annual independent third-party penetration test covering all external surfaces. Summary reports available to Controller on request.
  • 24-hour patch SLA for critical vulnerabilities; 7-day for high severity.
  • Incident response plan documented and tested quarterly.

10.6 Personnel security (ISO 27001: A.7)

  • Background checks for all employees with access to Personal Data.
  • Signed confidentiality agreements and data handling policies.
  • Data protection and security awareness training upon hire and annually.
  • Strict need-to-know principle: access to production data granted only for support or engineering purposes with documented approval.

10.7 Business continuity (ISO 27001: A.17)

  • Automated daily encrypted backups to separate region.
  • Backup retention: 30 days with point-in-time recovery (PITR) for PostgreSQL.
  • Disaster recovery plan tested semi-annually with RTO of 4 hours and RPO of 15 minutes.
  • Infrastructure deployed across multiple availability zones.

10.8 Data breach insurance

Processor maintains a data breach insurance policy with coverage of at least $5,000,000 CAD per occurrence. Coverage includes: incident response costs, forensic investigation, legal defense, regulatory fines (where insurable by law), notification costs, and credit monitoring for affected data subjects. Processor shall notify Controller of any material change to this coverage.

11. Personal data breach

Processor maintains a documented incident response plan and shall:

  • Notification: Notify Controller without undue delay and in any event within 48 hours of becoming aware of a Personal Data Breach. Notification shall include: (a) nature of the breach; (b) categories and approximate number of data subjects and records concerned; (c) likely consequences; (d) measures taken or proposed; (e) contact details of Processor's Privacy Officer.
  • Investigation: Investigate the breach, conduct root cause analysis, and provide a detailed written report to Controller within 10 business days of initial notification.
  • Cooperation: Cooperate fully with Controller in meeting Controller's obligations under Data Protection Laws, including notification to supervisory authorities and data subjects within applicable timelines (72 hours under GDPR, as soon as feasible under PIPEDA and Quebec Law 25).
  • Remediation: Take all reasonably necessary steps to mitigate the effects of the breach and prevent recurrence.

Notification is not required for breaches that are unlikely to result in a risk to data subjects (e.g., successful login from unexpected geographic location after 2FA verification). Processor shall log and review such events quarterly.

12. Data subject requests

Processor shall provide reasonable assistance to Controller in fulfilling Controller's obligations to respond to data subject requests under Data Protection Laws.

  • Self-service tools: Controller may use dashboard features to export, correct, restrict, or delete personal data for any data subject.
  • Forwarding requests: If Processor receives a direct request from a data subject, Processor shall forward it to Controller within 48 hours and shall not respond to the data subject except to confirm receipt and redirect to Controller.
  • Assistance: Processor shall assist Controller in responding to data subject requests, including access, portability, rectification, restriction, objection, and erasure, within the timelines required by applicable law.
  • DPIA support: Processor shall provide reasonable assistance to Controller with data protection impact assessments and prior consultation with supervisory authorities, as required under Articles 35-36 GDPR.

13. International transfers & SCCs

Data localization: Primary data storage is in Canada (AWS ca-central-1). Processor may transfer Personal Data to countries where Sub-processors operate, as listed in Section 9, subject to the safeguards below.

Transfer mechanisms:

Transfer pathSafeguard
Canada → Canada (AWS)No transfer; data remains in Canada
EEA/UK → Canada (AWS)EU Adequacy Decision (Art. 45 GDPR — Canada is adequate)
Canada/EEA/UK → US (OpenAI, Stripe)SCCs Module 3 (2021/914) + Transfer Impact Assessment + supplementary measures (AES-256, TLS 1.2+, data minimization, pseudonymization)
Canada/EEA/UK → EU (Resend)EU Adequacy Decision or SCCs as applicable
Canada/EEA/UK → Global edge (Cloudflare)SCCs + DPA + contractual commitment to ephemeral processing only

Standard Contractual Clauses: By entering into this DPA, the parties are deemed to have signed the EU Standard Contractual Clauses (European Commission Decision 2021/914) as follows:

  • Module 2 (Controller-to-Processor transfers) applies where Controller is established in the EEA/UK and transfers data to Processor outside the EEA/UK.
  • Module 3 (Processor-to-Processor transfers) applies where Processor transfers data to Sub-processors outside the EEA/UK.
  • The SCCs are completed as follows: (a) Clause 7 (docking clause): OPTED IN; (b) Clause 11 (redress): OPTED OUT; (c) Clause 13 (supervisory authority): Ontario Privacy Commissioner for Canada, competent EU supervisory authority for EEA; (d) Annex I.A: Parties as identified in Section 1 of this DPA; (e) Annex I.B: Description of transfer as described in Sections 4-7 of this DPA; (f) Annex I.C: Competent supervisory authority as determined under Clause 13; (g) Annex II: Technical and organizational measures as described in Section 10 of this DPA.

To the extent that any transfer of Personal Data is subject to the UK GDPR, the UK International Data Transfer Agreement (IDTA) shall apply in place of the EU SCCs, with equivalent effect. Controller may request a fully executed copy by emailing dpo@claivi.com.

Transfer Impact Assessment: Processor shall maintain a current Transfer Impact Assessment (TIA) for each transfer destination and shall provide a copy to Controller on request (with confidential information redacted). Processor reviews and updates the TIA at least annually or whenever there is a material change in the legal framework of the importing country.

Supplementary measures: For transfers to third countries that are not subject to an adequacy decision, Processor implements the following supplementary measures in addition to SCCs: (a) AES-256 encryption at rest with key material held in Canada; (b) TLS 1.2+ encryption in transit; (c) data minimization commitments limiting collection to necessary data only; (d) pseudonymization of embedding vectors and derived data such that they are non-reversible; (e) contractual commitments from Sub-processors that Personal Data will not be used for purposes beyond the specified processing.

14. Audit & compliance

Processor shall make available to Controller all information reasonably necessary to demonstrate compliance with this DPA:

  • Audit reports: Processor shall provide a summary of the most recent independent penetration test and SOC 2 Type II report (or equivalent) upon Controller's written request, no more than once per calendar year.
  • Annual security assessment: Processor conducts an independent third-party penetration test annually. A summary of findings (with remediation status) is available to Controller on request.
  • ROPA: Processor maintains a Record of Processing Activities (ROPA) as required under Article 30 GDPR. Processor shall provide a copy to Controller on request (with confidential information redacted).
  • On-site audits: Controller or its authorized representative may conduct an on-site audit of Processor's facilities with 30 days' written notice, no more than once per calendar year, during normal business hours, and subject to Processor's security policies. The parties shall agree on scope, duration, and security protocols in advance.
  • Alternative: If Processor believes an on-site audit would compromise security or operations, Processor may instead provide a detailed written response and supporting evidence addressing the audit scope.
  • Costs: Each party bears its own audit costs. If Controller's audit identifies a material finding, Processor shall bear the reasonable costs of the audit.

15. Return & deletion

Upon termination of the Terms of Service or upon Controller's written request:

  • Right to export: Controller may export Personal Data in a structured, commonly used, machine-readable format (JSON) from the dashboard at any time during the active term and for 30 days after termination.
  • Deletion: Within 30 days of termination or Controller's request, Processor shall delete all Personal Data from production systems and sub-processor systems, unless applicable law requires retention.
  • Billing records: Processor may retain billing records containing limited Personal Data (name, email, billing address, transaction history) for up to 7 years as required by Canadian tax law.
  • Certification: Within 60 days of deletion, Processor shall provide Controller with a written certification that deletion has been completed.
  • Backups: Personal Data in backups shall be deleted when the backup reaches its natural rotation cycle (maximum 30 days). Processor shall not restore backups containing Controller's data except for legitimate business continuity purposes or at Controller's request.

16. Liability

Processor liability: Processor shall be liable to Controller for damages arising from Processor's breach of this DPA, provided that Processor's total liability under this DPA shall be subject to the liability cap in the Terms of Service (Section 13). Processor's liability for data protection obligations shall not be limited or excluded by the Terms of Service cap to the extent prohibited by applicable law.

Controller liability: Controller shall be liable to Processor for damages arising from Controller's breach of this DPA, including: (a) processing instructions that violate Data Protection Laws; (b) submission of special categories of data in violation of Section 7; (c) failure to obtain necessary consents or provide required notices to data subjects.

Each party's liability to the other under this DPA shall be reduced to the extent that the other party's acts or omissions contributed to the damage.

17. Assignment & termination

Assignment: Processor may not assign its rights or delegate its obligations under this DPA without Controller's prior written consent, except in connection with a merger, acquisition, or sale of all or substantially all assets (with 30 days' notice). Controller may not assign this DPA without Processor's consent, except in connection with the assignment of the underlying Terms of Service.

Termination: This DPA terminates automatically with the underlying Terms of Service. Either party may terminate this DPA if the other party materially breaches its data protection obligations and fails to cure within 30 days. If a change in Data Protection Laws prevents Processor from complying with this DPA, Processor shall notify Controller and either party may terminate.

18. Governing law

This DPA is governed by the laws of the Province of Ontario and the federal laws of Canada applicable therein, provided that Data Protection Laws of the Controller's jurisdiction shall prevail to the extent they impose stricter requirements on the processing of Personal Data.

Disputes arising from this DPA shall be resolved in accordance with the arbitration and dispute resolution provisions in the Terms of Service (Sections 18-19).