Skip to main content
Legal

Data Processing Agreement

Last updated: March 30, 2026

“This Data Processing Agreement governs how Clevername processes personal data on behalf of its customers in compliance with GDPR and applicable data protection laws. It supplements our Terms of Service and Privacy Policy.”

— Floyd Media LLC

1. Definitions

For the purposes of this Agreement: "Controller" means the entity that determines the purposes and means of the processing of Personal Data — the Customer. "Processor" means the entity that processes Personal Data on behalf of the Controller — Clevername, operated by Floyd Media LLC. "Data Protection Laws" means all applicable data protection and privacy legislation, including the General Data Protection Regulation (EU) 2016/679 ("GDPR"), the UK GDPR, and any national implementing legislation. "Personal Data" means any information relating to an identified or identifiable natural person that is processed by Clevername in the course of providing the Service. "Processing" means any operation performed on Personal Data, including collection, recording, organization, structuring, storage, adaptation, retrieval, consultation, use, disclosure, alignment, restriction, erasure, or destruction. "Sub-processor" means any third party engaged by Clevername to process Personal Data on behalf of the Controller. "Data Subject" means the identified or identifiable natural person to whom Personal Data relates. "Service" means the Clevername AI agent governance platform, including all features described at clevername.net.

2. Scope and purpose of processing

This Data Processing Agreement ("DPA") forms part of the Terms of Service between the Customer ("Controller") and Floyd Media LLC, operating as Clevername ("Processor"), and governs the processing of Personal Data by the Processor on behalf of the Controller. Clevername processes Personal Data solely to provide the AI agent governance service, which includes: - Scanning AI agent content (prompts and responses) for prompt injection, PII, secrets, and toxicity - Enforcing guardrail policies and agent drift detection - Maintaining audit trails of agent activity - Storing and managing API tokens and provider keys on behalf of users - Authenticating users and managing organizational membership - Delivering transactional notifications Content scanning is performed in memory. By default, Clevername logs metadata only — timestamp, model, token count, and latency — not prompt or response content. Full I/O logging — storing a preview and truncated copy of prompt and response content in your agent I/O log for audit and replay — is opt-in and configurable per org. When enabled, stored I/O-log content is encrypted at rest; with encrypted (zero-knowledge) I/O logging enabled, that content is encrypted under a key derived from your passphrase that Clevername cannot read. You can return to metadata-only logging at any time, leaving only scan results and audit metadata.

3. Duration of processing

Processing begins on the date the Controller creates a Clevername account or enters into a subscription agreement, and continues for the duration of the service relationship. Upon termination of the service agreement, the Processor will delete or return all Personal Data in accordance with Article 14 of this DPA, subject to any legal retention obligations.

4. Types of personal data processed

The following categories of Personal Data may be processed: Account data: Email address, display name, organizational role, and team membership. Authentication data: OAuth tokens, session identifiers, and multi-factor authentication metadata. AI content metadata: Timestamps, token counts, model identifiers, scan verdicts, and guardrail enforcement decisions associated with AI agent interactions. Stored AI content (I/O logs): A preview and a truncated copy of prompt and response content, retained according to plan and encrypted at rest. I/O logging is opt-in and configurable per org — by default only metadata is logged, not prompt or response content. When full I/O logging is enabled, with encrypted (zero-knowledge) I/O logging content is stored under a key derived from your passphrase that Clevername cannot read. Audit records: Structured logs of API calls, agent actions, security events, and governance decisions, retained according to plan — 7 days (Free), 30 days (Pro), and 365 days (Team); Enterprise retention is set by contract with no fixed platform expiry. API credentials: Third-party provider API keys stored in encrypted form in GCP Secret Manager. The database stores only masked hints. Organizational data: Team names, department structures, role assignments, and SCIM-provisioned identity attributes.

5. Categories of data subjects

The Personal Data processed concerns the following categories of Data Subjects: - Users of the Controller's Clevername organization (employees, contractors, and authorized agents) - Individuals whose personal data may appear in AI agent content processed through the platform (end users, customers, or other third parties referenced in prompts or responses)

6. Obligations of the Processor

Clevername, as Processor, shall: (a) Process Personal Data only on documented instructions from the Controller, including with regard to transfers of Personal Data to a third country, unless required to do so by applicable law — in which case the Processor shall inform the Controller of that legal requirement before processing, unless prohibited by law. (b) Ensure that persons authorized to process Personal Data have committed themselves to confidentiality or are under an appropriate statutory obligation of confidentiality. (c) Implement appropriate technical and organizational measures to ensure a level of security appropriate to the risk, as described in Article 10 of this DPA. (d) Assist the Controller, taking into account the nature of processing, by appropriate technical and organizational measures, insofar as possible, for the fulfillment of the Controller's obligation to respond to requests for exercising Data Subject rights. (e) Assist the Controller in ensuring compliance with obligations related to security, breach notification, data protection impact assessments, and prior consultation, taking into account the nature of processing and the information available to the Processor. (f) At the choice of the Controller, delete or return all Personal Data after the end of the provision of services, and delete existing copies unless applicable law requires storage of the Personal Data. (g) Make available to the Controller all information necessary to demonstrate compliance with the obligations laid down in this DPA and allow for and contribute to audits, including inspections, as described in Article 13. (h) Immediately inform the Controller if, in the Processor's opinion, an instruction infringes Data Protection Laws.

7. Obligations of the Controller

The Controller shall: (a) Ensure that the processing of Personal Data is carried out in accordance with applicable Data Protection Laws, including having a lawful basis for processing. (b) Provide documented instructions to the Processor regarding the processing of Personal Data. The Controller's use of the Service constitutes its instructions for the processing described in this DPA. (c) Ensure that Data Subjects have been informed of the processing in accordance with applicable transparency requirements. (d) Be responsible for the accuracy, quality, and legality of Personal Data provided to the Processor. (e) Respond to Data Subject requests, with the Processor's reasonable assistance as described in Article 12. (f) Ensure that any content processed through the platform complies with applicable laws and does not infringe the rights of third parties.

8. Sub-processors

The Controller provides general authorization for the Processor to engage Sub-processors. The Processor shall inform the Controller of any intended changes concerning the addition or replacement of Sub-processors, giving the Controller the opportunity to object to such changes within 30 days of notification. The Processor currently engages the following Sub-processors: Google Cloud Platform (Google LLC) — Cloud Run compute (us-east1), Secret Manager for encrypted key storage, Cloud Storage for file storage. Location: United States. Supabase Inc. — PostgreSQL database hosting, user authentication, and real-time services. Infrastructure hosted on AWS us-east-1. Location: United States. Vercel Inc. — Web application hosting and edge functions for the Clevername frontend. Location: United States (global edge network). SendGrid (Twilio Inc.) — Transactional email delivery for account notifications and security alerts. Location: United States. Anthropic, PBC — historically used for AI content-safety processing (ClaimGuard claim extraction). As of the Processor's self-hosted cutover, ClaimGuard's claim-extraction model runs exclusively on the Processor's own infrastructure (see AWS, below) with no live fallback to Anthropic's API — if that self-hosted service is unreachable, extraction is skipped (zero claims returned) rather than routed to a managed model. Anthropic does not currently process scanned prompt or response content in production. Location: United States. OpenAI, L.L.C. — Embedding generation for ScopeGuard mandate enforcement. Agent request text and the organization's configured forbidden-action descriptions are sent to the OpenAI Embeddings API to compute semantic-similarity vectors; OpenAI does not train on API data. Location: United States. Amazon Web Services, Inc. — GPU-hosted CleverGuard Tier-2 machine-learning content-safety classifier and CleverGuard Tier-3 deep content-safety judge (a self-hosted, Clevername-trained model — not a third-party or customer-provided model), both operated by the Processor on AWS infrastructure. Scanned prompt and response content is transmitted to these models for in-memory threat/policy detection and is not persisted by the Sub-processor. Location: United States. Stripe, Inc. — Payment processing and subscription billing. Processes billing contact details and payment metadata; cardholder data is handled directly by Stripe as an independent controller under PCI-DSS. Location: United States. Functional Software, Inc. (Sentry) — Application error monitoring and performance tracing for the Processor's services. Receives diagnostic event data (stack traces, request metadata, and user/organization identifiers) when an error occurs; sampled at a low rate and used only to diagnose and fix faults. Location: United States. The Processor shall impose the same data protection obligations as set out in this DPA on each Sub-processor by way of a contract. Where a Sub-processor fails to fulfill its data protection obligations, the Processor shall remain fully liable to the Controller for the performance of that Sub-processor's obligations. The Controller may object to a new Sub-processor by notifying the Processor in writing within 30 days of receiving notice. If the objection is reasonable and the parties cannot reach a resolution, the Controller may terminate the affected services without penalty.

9. Data transfers

Personal Data is processed and stored in the United States. The Processor's infrastructure is located in the following regions: - GCP Cloud Run and Secret Manager: us-east1 (South Carolina, USA) - Supabase PostgreSQL and Auth: us-east-1 (AWS, Virginia, USA) - Vercel: United States (primary), with global edge caching for static assets - CleverGuard Tier-2 ML classifier (AWS GPU): United States - Anthropic, OpenAI (content-safety scanning and embeddings) and Stripe (billing): United States Where Personal Data is transferred from the European Economic Area, the United Kingdom, or Switzerland to the United States, such transfers are conducted in reliance on: (a) The EU-U.S. Data Privacy Framework, where applicable and to the extent the Processor or relevant Sub-processor is certified; or (b) Standard Contractual Clauses (SCCs) as adopted by the European Commission (Commission Implementing Decision (EU) 2021/914), which are hereby incorporated by reference into this DPA. For the purposes of the SCCs, the Controller is the "data exporter" and the Processor is the "data importer"; or (c) Any other lawful transfer mechanism recognized under applicable Data Protection Laws. The Processor shall promptly inform the Controller if it becomes aware that it can no longer comply with the obligations under the applicable transfer mechanism.

10. Security measures

The Processor implements the following technical and organizational measures to protect Personal Data: Encryption at rest: All data stored in GCP services and Supabase is encrypted using AES-256. API keys are encrypted in GCP Secret Manager; the database stores only masked display hints. Encryption in transit: All data transmitted between services uses TLS 1.2 or higher. HSTS is enforced with preload directives. Access control: Role-based access control (RBAC) with organizational isolation. No cross-tenant data access. Hub Core is not publicly accessible — all traffic is routed through an authenticated proxy. Authentication: Multi-factor authentication (MFA) enforcement on sensitive operations. Session management via Supabase Auth with secure cookie handling. Audit logging: Comprehensive audit trail with plan-based retention — 7 days (Free), 30 days (Pro), 365 days (Team), and contract-defined retention for Enterprise with no fixed platform expiry. Audit records use hash-chain integrity to detect tampering. Rate limiting: 300 requests per minute per IP address to prevent abuse and denial-of-service attacks. Content processing and I/O logging: AI content (prompts and responses) is scanned in memory for security threats. By default only metadata is logged (timestamp, model, token count, latency), not prompt or response content. I/O logging (storing a preview and truncated copy for audit and replay) is opt-in and configurable per org; when enabled it is encrypted at rest, and with encrypted (zero-knowledge) I/O logging it is encrypted under a Controller-held key that the Processor cannot read. Infrastructure security: GCP Cloud Run operates with strict IAM policies. No public endpoints are exposed directly. Service-to-service authentication uses GCP identity tokens. Incident response: The Processor maintains incident response procedures and will notify the Controller of any Personal Data breach in accordance with Article 11. The Processor regularly reviews and updates these measures to address evolving security threats. The Controller acknowledges that security measures are subject to technical progress and development, and the Processor may update measures provided the overall level of security is not materially decreased.

11. Data breach notification

The Processor shall notify the Controller without undue delay, and in any event within 72 hours, after becoming aware of a Personal Data breach affecting the Controller's data. The notification shall include, to the extent available: (a) A description of the nature of the breach, including the categories and approximate number of Data Subjects and records concerned. (b) The name and contact details of the Processor's point of contact for further information. (c) A description of the likely consequences of the breach. (d) A description of the measures taken or proposed to address the breach, including measures to mitigate its possible adverse effects. Where it is not possible to provide all information at the same time, the Processor shall provide the information in phases without undue further delay. The Processor shall cooperate with the Controller and take reasonable commercial steps to assist in the investigation, mitigation, and remediation of each such breach. Breach notifications shall be sent to the Controller's designated contact or, if none is designated, to the organizational administrator's email address on file.

12. Data subject rights assistance

The Processor shall assist the Controller in responding to requests from Data Subjects exercising their rights under applicable Data Protection Laws, including: - Right of access (Article 15 GDPR) - Right to rectification (Article 16 GDPR) - Right to erasure (Article 17 GDPR) - Right to restriction of processing (Article 18 GDPR) - Right to data portability (Article 20 GDPR) - Right to object (Article 21 GDPR) The Controller may fulfill Data Subject requests by contacting privacy@clevername.net (portability requests) or through the Clevername dashboard (account deletion for erasure). Where a Data Subject contacts the Processor directly, the Processor shall promptly redirect the request to the Controller, unless the request relates to the Data Subject's own Clevername account. The Processor shall provide reasonable assistance to the Controller in responding to Data Subject requests, taking into account the nature of the processing. Where the Processor incurs material costs in providing such assistance beyond standard account management tools, the parties shall agree on reasonable compensation.

13. Audit rights

The Controller has the right to audit the Processor's compliance with this DPA. Audits may be conducted: (a) By the Controller or an independent third-party auditor appointed by the Controller (subject to reasonable confidentiality obligations). (b) No more than once per calendar year, unless a data breach or material compliance concern necessitates an additional audit. (c) Upon at least 30 days' prior written notice. (d) During normal business hours, with reasonable scope and duration. The Processor shall cooperate with reasonable audit requests and provide access to relevant documentation, systems, and personnel. The Processor may require the auditor to execute a confidentiality agreement before granting access to proprietary systems or security infrastructure. The Controller shall bear its own costs of conducting the audit. If the audit reveals a material compliance deficiency, the Processor shall remediate the deficiency at its own expense within a reasonable timeframe. The Processor may satisfy audit requests by providing: - Relevant certifications, audit reports, or compliance documentation from Sub-processors (e.g., GCP SOC 2 reports, Supabase compliance documentation) - Written responses to reasonable compliance questionnaires - Evidence of the technical and organizational measures described in Article 10

14. Data deletion and return

Upon termination of the service agreement, or upon the Controller's written request, the Processor shall: (a) Return all Personal Data to the Controller in a structured, commonly used, and machine-readable format (available via the dashboard export feature or upon request); and/or (b) Delete all Personal Data, including all copies, from the Processor's systems and those of its Sub-processors within 30 days of the request. The Processor shall provide written confirmation of deletion upon the Controller's request. Exceptions to deletion: - Audit logs associated with organizational accounts may be anonymized rather than deleted to preserve the integrity of security records. Anonymized data is no longer considered Personal Data. - The Processor may retain Personal Data to the extent required by applicable law, provided that the Processor ensures confidentiality and processes such data only for the purpose required by law. API keys stored in GCP Secret Manager are permanently deleted immediately upon account termination or key removal — no recovery is possible after deletion.

15. Governing law

This DPA shall be governed by and construed in accordance with the laws that govern the underlying Terms of Service between the parties. To the extent that this DPA relates to the processing of Personal Data of Data Subjects in the European Economic Area, the relevant provisions of the GDPR shall apply regardless of the governing law of the Terms of Service. For Data Subjects in the United Kingdom, the UK GDPR and the Data Protection Act 2018 shall apply to the extent required by law. In the event of any conflict between this DPA and the Terms of Service, this DPA shall prevail with respect to the processing of Personal Data. This DPA is effective as of the date the Controller accepts the Terms of Service or begins using the Service, whichever is earlier.

Contact

For questions about this Data Processing Agreement or data protection matters: Data protection inquiries: privacy@clevername.net Security concerns: support@clevername.net General legal: legal@clevername.net Floyd Media LLC Georgia, United States