Legal

Data Processing Agreement

Last updated: October 1, 2026

01Overview

This Data Processing Agreement ("DPA") forms part of the Terms of Service (the "Agreement") between Clementina Enterprises, LLC, a Delaware limited liability company with its principal place of business at 131 Continental Dr, Suite 305, Newark, DE 19713, United States ("CleverQA"), and the customer entity that has entered into the Agreement ("Customer"). It governs CleverQA's Processing of Customer Personal Data in providing the Service.

This DPA is incorporated into the Agreement by reference and takes effect when Customer accepts the Agreement, without separate signature. Customer may request a countersigned copy at privacy@cleverqa.com.

02Definitions

1.1 "Controller", "Processor", "Data Subject", "Personal Data", "Personal Data Breach", "Processing" and "Supervisory Authority" have the meanings given in the GDPR. Where the CCPA applies, "Business", "Service Provider", "Sell" and "Share" have the meanings given in the CCPA.

1.2 "Customer Personal Data" means Personal Data that CleverQA Processes on behalf of Customer in providing the Service, including Personal Data contained in data CleverQA retrieves from Customer's Connected Services.

1.3 "Connected Services" means third-party services Customer connects to the Service using its own credentials, such as Sentry, Firebase Crashlytics, GitHub, Jira, Linear or Azure DevOps.

1.4 "Data Protection Laws" means all data protection and privacy laws applicable to the Processing of Customer Personal Data under the Agreement, including, where applicable: the EU General Data Protection Regulation 2016/679 ("GDPR"); the GDPR as retained in UK law and the UK Data Protection Act 2018 ("UK GDPR"); the Swiss Federal Act on Data Protection; and the California Consumer Privacy Act as amended by the CPRA ("CCPA") and other U.S. state comprehensive privacy laws.

1.5 "EU SCCs" means the standard contractual clauses approved by European Commission Implementing Decision (EU) 2021/914. "UK Addendum" means the International Data Transfer Addendum to the EU SCCs issued by the UK Information Commissioner under section 119A of the Data Protection Act 2018.

1.6 "Service" has the meaning given in the Agreement. "Sub-processor" means any third party engaged by CleverQA to Process Customer Personal Data.

03Roles and scope

2.1 Customer is the Controller and CleverQA is the Processor of Customer Personal Data. Where Customer acts as a Processor on behalf of a third-party Controller, CleverQA is Customer's Sub-processor, and Customer warrants that its instructions have been authorized by that Controller.

2.2 CleverQA Processes Customer Personal Data only on Customer's documented instructions. The Agreement, this DPA and Customer's configuration and use of the Service constitute Customer's complete instructions. Any additional instruction requires written agreement. CleverQA may Process Customer Personal Data otherwise only where required by applicable law, in which case it will inform Customer before Processing unless that law prohibits it.

2.3 The subject matter, duration, nature, purpose, categories of Personal Data and categories of Data Subjects are set out in Annex I.

2.4 CleverQA's own Processing. CleverQA acts as an independent Controller, and not under this DPA, for Personal Data it Processes for its own legitimate business purposes: account creation and administration; billing and payments; fraud prevention and security of the Service; compliance with legal obligations; and creating aggregated or de-identified statistics about use of the Service, which do not identify Customer or any individual. That Processing is described in CleverQA's Privacy Policy at cleverqa.com/legal/privacy.

2.5 No model training. CleverQA will not use Customer Personal Data, or any content Customer submits, to train or fine-tune artificial intelligence models, and has configured its AI sub-processor so that such data is not used to train that sub-processor's models.

04CleverQA obligations

3.1 Instructions. CleverQA will Process Customer Personal Data only in accordance with Section 2.2, and will immediately inform Customer if, in its opinion, an instruction infringes Data Protection Laws.

3.2 Confidentiality. CleverQA will ensure that all persons it authorizes to Process Customer Personal Data are bound by written confidentiality obligations or an appropriate statutory duty of confidentiality, and access it only as needed to provide the Service.

3.3 Security. CleverQA will implement and maintain the technical and organizational measures in Annex II, appropriate to the risk. CleverQA may update those measures provided the overall level of protection is not reduced.

3.4 Assistance. Taking into account the nature of Processing and the information available to it, CleverQA will provide reasonable assistance to Customer with Customer's obligations regarding security of Processing, Personal Data Breach notification, data protection impact assessments and prior consultation with Supervisory Authorities (GDPR Articles 32 to 36).

3.5 Records. CleverQA will maintain the records of Processing required of a Processor under Data Protection Laws.

05Customer obligations

4.1 Customer is responsible for the lawfulness of the Processing it instructs, and warrants that it has a valid legal basis and has provided all notices and obtained all consents required by Data Protection Laws for CleverQA to Process Customer Personal Data under the Agreement.

4.2 Customer controls what data it sends to the Service, including the content of crash reports, logs, monitoring payloads and data in Connected Services. Customer will minimize Personal Data in that content and use the filtering, scrubbing and retention settings available in the Service and in its Connected Services.

4.3 Customer will not submit special categories of Personal Data (GDPR Article 9), Personal Data relating to criminal convictions, payment card data, government identification numbers or protected health information to the Service without CleverQA's prior written agreement.

4.4 Customer is responsible for the security of its accounts and credentials, including credentials for Connected Services, and for configuring access within its workspace.

06Sub-processors

5.1 Customer grants CleverQA general written authorization to engage Sub-processors. The Sub-processors in Annex III are authorized as of the effective date.

5.2 CleverQA will enter into a written agreement with each Sub-processor imposing data protection obligations no less protective than those in this DPA, to the extent applicable to the services provided. CleverQA remains liable to Customer for each Sub-processor's performance of those obligations.

5.3 CleverQA will notify Customer of any intended addition or replacement of a Sub-processor at least 30 days in advance, by email to Customer's account owner and an update to cleverqa.com/legal/subprocessors. Customer may object on reasonable data protection grounds by written notice within 14 days of the notice.

5.4 If Customer objects, the parties will discuss the objection in good faith. If it is not resolved within 30 days, Customer may terminate the affected part of the Service by written notice, and CleverQA will refund any prepaid fees for the terminated period after termination.

5.5 Connected Services are not CleverQA Sub-processors. When Customer connects a Connected Service, CleverQA accesses it on Customer's behalf and instruction, using Customer's credentials, and that provider's Processing is governed by Customer's own agreement with it. Customer Personal Data that CleverQA retrieves from, or writes to, a Connected Service is Processed by CleverQA under this DPA while in CleverQA's systems.

07Data Subject requests

6.1 Taking into account the nature of Processing, CleverQA will assist Customer by appropriate technical and organizational measures, insofar as possible, to respond to requests from Data Subjects to exercise their rights under Data Protection Laws. Customer can access, export, correct and delete Customer Personal Data through the Service's features; where Customer cannot do so itself, CleverQA will provide reasonable assistance on request.

6.2 If CleverQA receives a request directly from a Data Subject relating to Customer Personal Data, it will forward the request to Customer without undue delay and will not respond to it other than to direct the Data Subject to Customer, unless required by law.

08Audits

7.1 CleverQA will make available to Customer all information reasonably necessary to demonstrate compliance with this DPA and GDPR Article 28. CleverQA will first meet audit requests by providing written responses to reasonable security questionnaires, its current security documentation and, where available, third-party audit reports or certifications.

7.2 If that information is insufficient to demonstrate compliance, or a Supervisory Authority requires it, or following a Personal Data Breach, Customer may conduct an audit, including an inspection, itself or through an independent auditor bound by confidentiality who is not a competitor of CleverQA.

7.3 Audits under Section 7.2 are limited to once in any 12-month period (except where required by a Supervisory Authority or following a Personal Data Breach), require at least 30 days' written notice, take place during normal business hours, must not unreasonably disrupt CleverQA's operations or compromise other customers' data, and are at Customer's cost.

09Deletion and return

8.1 During the term, Customer may export Customer Personal Data using the Service's export features.

8.2 On expiry or termination of the Agreement, Customer may export Customer Personal Data for 30 days. After that period, CleverQA will delete Customer Personal Data from its active systems within 30 days, unless applicable law requires further retention, in which case CleverQA will keep it confidential and Process it only for that purpose.

8.3 Residual copies in backups, including point-in-time restore and cross-region backup copies, will be overwritten or deleted in the ordinary course of the backup cycle, which is currently no longer than 35 days, and will not be actively Processed in the meantime.

8.4 On Customer's written request, CleverQA will confirm deletion in writing.

10International transfers

9.1 Location. CleverQA is established in the United States. CleverQA and its Sub-processors Process Customer Personal Data in the United States, primarily in Microsoft Azure's US West region, and in the other locations stated in Annex III. CleverQA will not change the primary hosting region outside the United States without notice under Section 5.3.

9.2 EU transfers. To the extent Customer Personal Data subject to the GDPR is transferred to CleverQA, the EU SCCs are incorporated into this DPA and apply as follows: Module 2 (controller to processor) where Customer is a Controller, and Module 3 (processor to processor) where Customer is a Processor. They are completed as set out in Annex IV.

9.3 UK transfers. To the extent Customer Personal Data subject to the UK GDPR is transferred to CleverQA, the EU SCCs apply as amended by the UK Addendum, which is incorporated into this DPA and completed as set out in Annex IV.

9.4 Swiss transfers. To the extent Customer Personal Data subject to the Swiss Federal Act on Data Protection is transferred to CleverQA, the EU SCCs apply with the adaptations set out in Annex IV.

9.5 Onward transfers. CleverQA will ensure that any onward transfer to a Sub-processor outside the EEA, UK or Switzerland is covered by a valid transfer mechanism, such as the Sub-processor's standard contractual clauses.

9.6 Government access requests. If CleverQA receives a legally binding request from a public authority for access to Customer Personal Data, it will: (a) promptly notify Customer, unless legally prohibited; (b) assess the legality of the request and challenge it where there are reasonable grounds to consider it unlawful; (c) disclose only the minimum data required to comply; and (d) on Customer's request, provide information reasonably available to help Customer assess the transfer. As of the effective date, CleverQA has not received any such request.

11Personal Data Breach

10.1 CleverQA will notify Customer without undue delay, and in any event within 48 hours, after becoming aware of a Personal Data Breach affecting Customer Personal Data.

10.2 The notice will include, to the extent then known: the nature of the breach, including the categories and approximate number of Data Subjects and records concerned; the likely consequences; the measures taken or proposed to address it and mitigate its effects; and a contact point for further information. Where information is not available at once, CleverQA will provide it in phases without undue further delay.

10.3 CleverQA will take reasonable steps to contain, investigate and mitigate the breach, and will reasonably cooperate with Customer's own notification obligations. CleverQA will not notify Supervisory Authorities or Data Subjects about a breach of Customer Personal Data on Customer's behalf unless Customer instructs it or the law requires it.

10.4 CleverQA's notification of or response to a Personal Data Breach is not an acknowledgment of fault or liability.

12U.S. state privacy laws

11.1 To the extent the CCPA or another U.S. state comprehensive privacy law applies, CleverQA acts as Customer's Service Provider (or Processor, as that law defines it). Customer discloses Customer Personal Data to CleverQA only for the limited and specified business purpose of providing the Service described in the Agreement and Annex I.

11.2 CleverQA will not: (a) Sell or Share Customer Personal Data; (b) retain, use or disclose it for any purpose, including any commercial purpose, other than the business purpose in Section 11.1 or as otherwise permitted by the CCPA; (c) retain, use or disclose it outside the direct business relationship between Customer and CleverQA; or (d) combine it with Personal Data CleverQA receives from or on behalf of another person, or collects from its own interactions with consumers, except as permitted by the CCPA.

11.3 CleverQA will comply with the CCPA's obligations applicable to it and provide the same level of privacy protection the CCPA requires. CleverQA will notify Customer if it determines it can no longer meet those obligations.

11.4 Customer may, on notice, take reasonable and appropriate steps to stop and remediate any unauthorized use of Customer Personal Data, and to ensure CleverQA uses it consistently with Customer's obligations under the CCPA.

11.5 CleverQA certifies that it understands and will comply with the restrictions in this Section 11.

13Liability, term and general

12.1 Liability. Each party's liability arising out of or relating to this DPA, however arising, is subject to the limitations and exclusions of liability in the Agreement, except that nothing in this DPA limits either party's liability to Data Subjects under the EU SCCs or UK Addendum, or any liability that cannot be limited under applicable law.

12.2 Term. This DPA remains in effect for as long as CleverQA Processes Customer Personal Data, and the obligations in Sections 8, 9 and 10 survive termination of the Agreement until that Processing ends.

12.3 Order of precedence. In the event of conflict: (a) the EU SCCs and UK Addendum, where they apply, prevail over this DPA and the Agreement; and (b) this DPA prevails over the Agreement with respect to the Processing of Customer Personal Data.

12.4 Changes in law. If Data Protection Laws change in a way that requires changes to this DPA, CleverQA may update it on 30 days' notice, provided the update does not reduce the protection of Customer Personal Data. Any change to the transfer mechanisms in Section 9 that a Supervisory Authority or court requires takes effect as required.

12.5 Governing law. This DPA is governed by Delaware law and the courts of Delaware, as specified in the Agreement, except that the EU SCCs and UK Addendum are governed by the law and courts specified in Annex IV.

12.6 Severability. If any provision of this DPA is held invalid or unenforceable, the rest remains in effect.

14Annex I: Details of Processing

  • Data exporter — Customer, as identified in the Agreement and its account. Role: Controller (or Processor, under Module 3).
  • Data importer — Clementina Enterprises, LLC, 131 Continental Dr, Suite 305, Newark, DE 19713, United States. Contact: privacy@cleverqa.com. Role: Processor.
  • Subject matter — Provision of the Service: uptime and endpoint monitoring, crash and error intelligence, AI-assisted incident and defect analysis, automated defect filing, release quality scoring and public status pages.
  • Nature and purpose — Collecting, receiving, storing, analyzing, displaying and transmitting data Customer submits or connects, in order to provide the Service and its notifications, as instructed by Customer.
  • Duration — The term of the Agreement plus the export and deletion periods in Section 8.
  • Frequency — Continuous.
  • Data Subjects — (1) Customer's authorized users of the Service. (2) Customer's end users whose data appears in crash reports, logs, monitoring payloads or Connected Services data. (3) Subscribers to Customer's public status pages. (4) Customer's personnel and contacts designated to receive alerts.
  • Personal Data — (1) Users: name, email address, phone number (for verification and alerts), role, workspace and activity metadata, IP address and access logs. Passwords are stored only as salted hashes. (2) End users: any Personal Data Customer's applications include in crash reports, stack traces, logs, request data or monitoring payloads, which may include user IDs, email addresses, IP addresses, device identifiers and URLs. (3) Status page subscribers: email address and/or phone number, and subscription preferences. (4) Alert contacts: name, email address and phone number.
  • Special categories — None intended. Customer will not submit them (Section 4.3).
  • Retention — Per Customer's retention settings in the Service, default 90 days for crash and monitoring event data, and Section 8 on termination.
  • Sub-processor Processing — As described in Annex III, for the same duration.

15Annex II: Technical and Organizational Measures

This Annex describes CleverQA's current security program.

  • Encryption in transit — TLS 1.2 or higher for all external connections; HSTS on the web application.
  • Encryption at rest — Azure platform encryption for compute, databases and storage. Third-party secrets (such as Connected Service credentials) are additionally envelope-encrypted with AES-256-GCM data keys wrapped by an Azure Key Vault key.
  • Access control — Role-based access control in the Service; per-tenant logical isolation enforced by database row-level security; least-privilege managed identities for service-to-service access; administrative actions audit-logged.
  • Personnel — Production access is limited to named personnel with a business need, bound by confidentiality commitments, with access removed promptly on role change or departure.
  • Application security — Content-Security-Policy and baseline security headers; webhook signature verification; SSRF protections on outbound fetches; rate limiting on authentication and sensitive endpoints; code review and automated CI checks (lint, type checking, tests) before deployment.
  • Logging and monitoring — Centralized application and infrastructure logs; health probes and alerting on availability and error rates.
  • Incident response — A process covering detection, triage, containment, Customer notification under Section 10, and post-incident review.
  • Resilience and backup — Point-in-time restore on primary databases (35 days); a cross-region backup copy; health probes and automated recovery.
  • Secrets management — Secrets stored in Azure Key Vault; no secrets in source code.
  • AI processing — AI features use Azure OpenAI Service under Microsoft's enterprise terms; prompts and outputs are not used to train models.
  • Data minimization — Configurable retention for event data.
  • Review — This Annex is reviewed at least annually.

16Annex III: Authorized Sub-processors

  • Microsoft Azure (Microsoft Corporation, USA; US West primary, East US 2 backup) — Cloud hosting: compute, databases, storage, secrets and messaging. Data processed: all Customer Personal Data. Transfer mechanism: Microsoft DPA with SCCs.
  • Azure OpenAI Service (Microsoft Corporation, USA) — AI-assisted analysis of incidents, crashes and defects. Data processed: crash, defect and monitoring content submitted for analysis. Transfer mechanism: Microsoft DPA with SCCs.
  • Azure Communication Services (Microsoft Corporation, USA) — Transactional and alert email. Data processed: recipient names and email addresses; alert content. Transfer mechanism: Microsoft DPA with SCCs.
  • Telnyx LLC (USA) — SMS for phone verification and alerts. Data processed: phone numbers; message content. Transfer mechanism: SCCs.
  • Stripe, Inc. (USA) — Payment processing, subscriptions and invoicing. Data processed: billing contact details. Transfer mechanism: Stripe DPA with SCCs.

CleverQA's marketing website analytics (Google Analytics 4) is not listed because it does not Process Customer Personal Data. It is described in CleverQA's Privacy Policy and runs only with visitor consent. Connected Services are not Sub-processors (Section 5.5). The current list is maintained at cleverqa.com/legal/subprocessors.

17Annex IV: Transfer mechanism details

EU SCCs. The following selections apply:

  • Modules — Module 2 where Customer is a Controller; Module 3 where Customer is a Processor.
  • Clause 7 (docking clause) — Included.
  • Clause 9(a) (sub-processors) — Option 2, general written authorization, with the notice period in Section 5.3 of this DPA.
  • Clause 11(a) (redress) — Optional language not included.
  • Clause 13 (supervision) — The supervisory authority of the EU member state in which Customer is established or, if Customer is not established in the EU, of the member state where its Article 27 representative is established.
  • Clause 17 (governing law) — Option 1: the law of Ireland.
  • Clause 18 (forum) — The courts of Ireland.
  • Annex I.A (parties) — As in Annex I of this DPA. Each party's acceptance of the Agreement constitutes its signature of the SCCs.
  • Annex I.B (description) — Annex I of this DPA.
  • Annex I.C (competent authority) — As in Clause 13.
  • Annex II (security) — Annex II of this DPA.
  • Annex III (sub-processors) — Annex III of this DPA.

UK Addendum. The following completions apply:

  • Table 1 (parties) — As in Annex I of this DPA.
  • Table 2 (selected SCCs) — The EU SCCs as completed above, including the modules and options selected.
  • Table 3 (appendix information) — Annexes I to III of this DPA.
  • Table 4 (ending the Addendum) — Either party may end the UK Addendum as set out in its Section 19.
  • Governing law — The EU SCCs as amended by the UK Addendum are governed by the laws of England and Wales, with disputes before the courts of England and Wales.

Switzerland. For transfers subject to the Swiss Federal Act on Data Protection (FADP), the EU SCCs apply with these adaptations: references to the GDPR are read as references to the FADP; the competent supervisory authority is the Swiss Federal Data Protection and Information Commissioner; Data Subjects in Switzerland may bring claims in Swiss courts; and "member state" is read to include Switzerland.

See also:Terms · Privacy · Refund · Cookies · EULA