Skip to main content
clustra
Browse legal documents

Data Processing Agreement

Last Modified: May 30, 2026 · Version 2026-05-30

This Data Processing Agreement ("DPA") supplements the Terms of Service (the "Agreement") between Clustra Technologies Ltd. ("Clustra", "Processor") and the customer entity that has accepted the Agreement ("Customer", "Controller"), each a "Party" and together the "Parties". It governs the Processing of Personal Data by Clustra on behalf of the Customer in connection with the Service. By accepting the Agreement, or by using the Service to Process Personal Data on behalf of identifiable data subjects, the Customer accepts this DPA as a binding part of the Agreement.

This DPA reflects the requirements of Article 28 of Regulation (EU) 2016/679 ("GDPR"), the UK General Data Protection Regulation as supplemented by the Data Protection Act 2018 ("UK GDPR"), the Nigeria Data Protection Act 2023 ("NDPA"), and analogous obligations under other African and U.S. state privacy frameworks.

1. Definitions

Capitalised terms not defined here have the meaning given to them in the Agreement, the GDPR, the UK GDPR, or the NDPA, as the context requires. The following terms have the following meanings:

  • Applicable Data Protection Law — every law applicable to the Processing of Personal Data under this DPA, including the GDPR, the UK GDPR, the NDPA, the Swiss Federal Act on Data Protection, the South African POPIA, the Kenya Data Protection Act 2019, the Ghana Data Protection Act 2012, the California Consumer Privacy Act as amended by the CPRA, and any other U.S. state comprehensive privacy law.
  • Customer Personal Data — Personal Data that Clustra Processes on behalf of the Customer as described in Annex I.
  • Data Subject — an identified or identifiable natural person to whom Customer Personal Data relates.
  • EEA — the European Economic Area.
  • Personal Data Breach — a breach of security leading to the accidental or unlawful destruction, loss, alteration, unauthorised disclosure of, or access to, Customer Personal Data.
  • Processing (and its derivatives) — any operation performed on Personal Data, whether or not by automated means.
  • Standard Contractual Clauses or SCCs — the standard contractual clauses adopted by the European Commission Implementing Decision (EU) 2021/914, as amended.
  • Sub-processor — any third party engaged by Clustra to Process Customer Personal Data on behalf of the Customer in connection with the Service.
  • UK IDTA — the UK International Data Transfer Agreement and the UK Addendum to the SCCs issued by the Information Commissioner's Office.

2. Subject Matter, Duration, Nature & Purpose

The processing details required by Article 28(3) GDPR are set out in Annex I and summarised below:

  • Subject matter — Processing of Customer Personal Data necessary to provide the Service to the Customer.
  • Duration — for the term of the Agreement, plus any further period during which Clustra Processes Customer Personal Data under a legal obligation or pending its return or deletion under §13.
  • Nature and purpose — hosting, transmission, storage, search, indexing, retrieval, back-up, and other technical operations required to make the Service available, to keep it secure, and to support Customer use of it.
  • Categories of Data Subjects — set out in Annex I.
  • Categories of Personal Data — set out in Annex I.
  • Special category data — Clustra does not solicit and is not designed to Process special category Personal Data. If the Customer chooses to upload such data into a Workspace, the Customer is responsible for having a lawful basis to do so.

3. Roles & Customer Instructions

The Customer is the Controller of Customer Personal Data and Clustra is the Processor. Clustra will Process Customer Personal Data only on the Customer's documented instructions, which include this DPA, the Agreement, the configuration of the Service that the Customer chooses, and any further written instructions agreed by the Parties.

Clustra will inform the Customer if, in its opinion, an instruction infringes Applicable Data Protection Law, save where it is prohibited from doing so by law, in which case Clustra will rely on that exception only to the extent strictly necessary.

4. Processor Obligations

Clustra will:

  • Process Customer Personal Data only as instructed by the Customer and only for the duration of the Agreement.
  • Maintain a record of Processing activities to the extent required by Article 30(2) GDPR and equivalent provisions.
  • Implement the technical and organisational measures described in Annex II.
  • Ensure that personnel authorised to Process Customer Personal Data are bound by appropriate confidentiality obligations.
  • Make available to the Customer all information reasonably necessary to demonstrate compliance with Article 28 GDPR and equivalent provisions, on reasonable request.
  • Assist the Customer with the obligations described in §§7, 8, and 9 below.

5. Confidentiality of Personnel

Clustra will limit access to Customer Personal Data to personnel who need it to perform the Agreement. Every such person is bound by a confidentiality obligation that survives the end of their engagement. Clustra maintains role-based, just-in-time access controls and an audit trail of privileged access, as described in §9 of the Security Policy.

6. Sub-processors

The Customer grants Clustra a general authorisation to engage Sub-processors to Process Customer Personal Data, subject to the conditions below.

  • Current Sub-processors — Annex III lists the current Sub-processors. The list is also available on request from privacy@clustra.org.
  • Notice of changes — Clustra will give the Customer at least 30 days' advance notice of any new Sub-processor or replacement Sub-processor, by email to the Workspace Administrator and through the in-product notice channel.
  • Objection right — the Customer may object on reasonable grounds related to protection of Personal Data within the notice period. The Parties will work in good faith to resolve the objection. If the Parties cannot reach a resolution, the Customer may terminate the affected portion of the Service for cause and receive a prorated refund of pre-paid, unused fees attributable to the affected portion.
  • Flow-down terms — Clustra imposes on every Sub-processor data-protection obligations no less protective than those in this DPA, including in respect of confidentiality, security, breach notification, audit, and international transfers.
  • Liability for Sub-processors — Clustra remains responsible to the Customer for the performance of its Sub-processors' obligations under this DPA, subject to the liability cap in the Agreement.

7. Assistance with Data Subject Rights

The Service provides administrative tools and APIs by which the Customer can respond to Data Subject requests under Articles 12 to 23 GDPR and equivalent provisions, including the right of access, rectification, erasure, restriction of Processing, data portability, and objection. Clustra's data subject request engine supports two erasure modes (anonymise and hard-delete) and a portability export across all relevant data stores.

Where the Service's self-service tools are insufficient, Clustra will provide reasonable additional assistance to the Customer at the Customer's cost. If Clustra receives a Data Subject request directly, it will not respond to that request (except to confirm receipt and direct the individual to the relevant Customer) and will inform the Customer without undue delay.

8. Personal Data Breach Notification

Clustra will notify the Customer of a confirmed Personal Data Breach affecting Customer Personal Data without undue delay, and in any event within 48 hours of becoming aware. The notification will, to the extent then known and as further information becomes available:

  • Describe the nature of the Personal Data Breach, including, where possible, the categories and approximate number of Data Subjects and records concerned.
  • Provide the name and contact details of a Clustra contact point for further information.
  • Describe the likely consequences.
  • Describe the measures taken or proposed to address the Personal Data Breach and to mitigate its effects.

Clustra will provide reasonable assistance to the Customer with the Customer's notification obligations under Articles 33 and 34 GDPR, NDPA s. 40, and equivalent provisions. A notification under this DPA is not an admission of fault or liability by Clustra.

9. Data Protection Impact Assessments & Prior Consultation

Clustra will provide reasonable assistance to the Customer with data protection impact assessments and prior consultations with supervisory authorities under Articles 35 and 36 GDPR, NDPA s. 28, and equivalent provisions, taking into account the nature of the Processing and the information available to Clustra.

10. Security Measures

Clustra implements appropriate technical and organisational measures to ensure a level of security appropriate to the risk, as required by Article 32 GDPR and NDPA s. 39. The measures are described in Annex II and in the Security Policy, which is incorporated by reference. Clustra may update those measures from time to time provided the level of protection is not materially decreased.

11. Audits & Inspections

The Customer may verify Clustra's compliance with this DPA as follows:

  • Documentation — on reasonable written request and no more than once per 12-month period, Clustra will make available the security and privacy documentation reasonably necessary to demonstrate compliance, including the current sub-processor list, the description of TOMs (Annex II), summaries of internal security reviews, and copies of independent audit reports or certifications where available.
  • On-site audits — where the documentation above is insufficient to demonstrate compliance, the Customer (or a qualified independent auditor it appoints who is not a competitor of Clustra) may conduct an audit on at least 30 days' advance written notice, during normal business hours, with reasonable steps to avoid disruption, and at the Customer's expense. Each Party will bear its own costs of any such audit.
  • Regulator-mandated audits — the limits above do not restrict audits required by a competent supervisory authority.

12. International Data Transfers

Clustra Processes Customer Personal Data in the locations described in Annex III. Where this DPA results in a transfer of Customer Personal Data:

  • From the EEA, Switzerland, or the UK to a country without an adequacy decision — the SCCs (Module Two: Controller-to-Processor or Module Three: Processor-to-Processor, as applicable) are incorporated by reference and apply as set out in Annex IV. Where the transfer originates in the UK, the UK IDTA or the UK Addendum to the SCCs applies. Where the transfer originates in Switzerland, the SCCs apply with the Swiss-specific amendments published by the FDPIC.
  • From Nigeria to a country without an adequacy decision under NDPA s. 41 — Clustra relies on the contractual safeguards in this DPA, the SCCs (where the destination is also a non-EEA country), and any further approved mechanism required by the Nigeria Data Protection Commission.
  • From other jurisdictions — Clustra relies on the approved transfer mechanism applicable to that jurisdiction.
  • Supplementary measures — Clustra applies supplementary technical measures including encryption in transit and at rest, blind indexing of identity PII, segregation of cryptographic keys, and access controls described in Annex II and the Security Policy.

13. Return or Deletion of Customer Personal Data

At the Customer's choice, on termination or expiry of the Agreement Clustra will either return all Customer Personal Data to the Customer in a structured, commonly used, machine-readable format or delete it, subject to backup expiry windows and any legal obligation to retain. Where Clustra is required by law to retain Customer Personal Data after termination, it will protect the confidentiality of that data and will Process it only as required by the law that requires retention. The Service provides a self-service export and account-deletion path that the Customer may use at any time during the term.

14. Liability

Each Party's liability arising out of or in connection with this DPA is subject to the liability limits in the Agreement, including the cap in §16 of the Terms of Service. Where the SCCs apply, the liability provisions of the SCCs apply to the extent they cannot be contractually limited under Applicable Data Protection Law.

15. Term & Termination

This DPA takes effect on the date the Agreement takes effect and continues for the term of the Agreement. The obligations in §§5, 8, 13, and 14 survive termination of the Agreement for as long as Clustra Processes Customer Personal Data or holds it under a retention obligation.

16. Governing Law & Jurisdiction

This DPA is governed by the law and subject to the jurisdiction specified in the Agreement, except that, where the SCCs apply to a transfer governed by this DPA, the governing law and jurisdiction clauses of the SCCs apply to that transfer.

17. Order of Precedence

In case of conflict between this DPA and any other part of the Agreement with respect to Processing of Customer Personal Data, this DPA prevails. In case of conflict between this DPA and the SCCs in respect of a transfer to which the SCCs apply, the SCCs prevail.

Annex I — Description of Processing

I.1 List of Parties

Data Exporter / Controller: the Customer that has accepted the Agreement. Contact details are those provided by the Customer in the Workspace billing settings.

Data Importer / Processor: Clustra Technologies Ltd. Contact: dpo@clustra.org.

I.2 Categories of Data Subjects

  • The Customer's personnel, contractors, and other authorised members of the Customer's Workspace.
  • The Customer's end users, customers, prospects, suppliers, and other third parties whose Personal Data is uploaded to or processed in the Customer's Workspace.

I.3 Categories of Customer Personal Data

  • Identity and contact data: name, email address, profile photo URL, workspace role.
  • Authentication metadata: 2FA enabled flag, OAuth provider identifiers, age confirmation timestamp.
  • Workspace metadata: role, team membership, seat assignment, presence status, status text.
  • Customer Content created or uploaded by the Customer, including notes, tasks, calendar entries, mailbox content (where the Customer connects a mailbox), chat messages, helpdesk tickets and customer-contact records, collaborative documents, and content in custom databases.
  • Uploaded files, scoped to the user's storage path in object storage.
  • Operational telemetry: IP address, user agent, session and refresh-token metadata, security event records.
  • Billing metadata: billing email and contact name, plan, subscription state, currency, seat count, provider customer and invoice identifiers.

I.4 Special Categories of Personal Data

The Service is not designed to Process special categories of Personal Data within the meaning of Article 9 GDPR. To the extent the Customer chooses to upload such data, the Customer is responsible for the lawful basis and any required safeguards.

I.5 Frequency & Duration of Processing

Continuous, for the duration of the Agreement.

I.6 Nature of Processing

Hosting, transmission, storage, search, indexing, retrieval, back-up, monitoring, security, and support as required to provide the Service.

I.7 Purpose of Processing

To provide the Service to the Customer and meet related contractual and legal obligations.

I.8 Retention

For the term of the Agreement and the retention periods set out in §5 of the Privacy Policy, save where a longer period is required by law.

Annex II — Technical & Organisational Measures

The current technical and organisational measures are described in detail in the Security Policy, which is incorporated by reference into this DPA, and summarised below.

  • Encryption — TLS 1.2+ in transit; AES-256-GCM envelope encryption at rest for identity Personal Data with blind indexing for lookups; per-workspace data encryption keys for free-text content; KMS-held TOTP secrets; bcrypt-hashed passwords at cost 13.
  • Identity and access management — single sign-on with mandatory MFA for internal accounts; just-in-time elevation for production access; quarterly access reviews; least privilege at every layer.
  • System security — automated dependency scanning, container and runtime scanning, ESLint security rules and TypeScript strict mode in CI; OAuth state binding; brute-force lockout; single-use refresh tokens; HSTS and Content Security Policy.
  • Operations — production change management through reviewed pull requests and infrastructure-as-code; audit trail of administrative actions in the audit-event store; backup, recovery, and disaster recovery as described in the Security Policy.
  • Personnel security — background checks, confidentiality undertakings, security training at onboarding and annually thereafter, and offboarding controls.
  • Incident response — documented runbook covering detection, triage, containment, eradication, recovery, notification, and post-incident review.

Annex III — Sub-processors & Processing Locations

The categories of Sub-processors currently engaged are:

  • Hosting & infrastructure — Vercel (web hosting), DigitalOcean (server hosting), MongoDB Atlas (global user and workspace data), managed PostgreSQL (per-feature application databases), Redis (sessions, OAuth state, cache), Google Cloud Storage (uploaded files).
  • Identity & secrets — Google OAuth (sign-in only), Infisical (key management).
  • Email delivery — the configured transactional email provider.
  • Payments — Paystack (tokenisation, subscriptions, invoices; no raw card data is shared with Clustra).
  • Error monitoring & product analytics — Sentry (with redaction at source) and PostHog (consent-gated).
  • Internal security alerting — Slack (private channel for event triage; payloads limited to event type and scoping identifier).

A current list including each Sub-processor's legal entity, processing location, and the categories of Personal Data Processed is available on request from privacy@clustra.org.

Annex IV — Transfer Mechanisms

  • EEA exports — the SCCs (Module Two for Controller-to-Processor; Module Three for Processor-to-Processor where applicable) are incorporated by reference, with Clause 7 (docking clause) included, Clause 9(a) Option 2 (general written authorisation) with a 30-day notice period for new Sub-processors, Clause 11(a) optional independent dispute-resolution body not selected, Clause 17 Option 1 with the governing law of the EEA Member State that the supervisory authority indicates as the competent authority of the data exporter, and Clause 18(b) with the courts of that Member State as the chosen forum. Annex I.A – I.C of the SCCs corresponds to Annex I of this DPA; Annex II of the SCCs corresponds to Annex II of this DPA; Annex III of the SCCs corresponds to Annex III of this DPA.
  • UK exports — the UK Addendum to the SCCs (or the UK IDTA, at the Customer's election) applies, with Table 1 completed from Annex I of this DPA, Table 2 selecting the approved SCC version above, Table 3 referring to Annexes I–III of this DPA, and Table 4 with neither Party able to end the addendum when the approved addendum changes.
  • Swiss exports — the SCCs apply with the Swiss-specific amendments published by the FDPIC, including reference to the Swiss FADP and the FDPIC as competent authority.
  • NDPA exports from Nigeria — Clustra relies on the contractual safeguards in this DPA and on any further mechanism required by the Nigeria Data Protection Commission.

Contact

Data Protection Officer: dpo@clustra.org
Privacy: privacy@clustra.org
Legal: legal@clustra.org

This DPA is provided for informational purposes and does not constitute legal advice. A version signed by an authorised representative of Clustra is available on request to enterprise customers that require a counter-signed copy.

Data Processing Agreement · Clustra