Legal · DPA
Data Processing Addendum
How Clientlly processes personal data for customers under data-protection law. Last updated June 6, 2026.
1. Scope and roles
This DPA supplements the Terms. The customer is the controller and Clientlly is the processor; where the customer is a processor, Clientlly acts as sub-processor.
2. Duration
Processing continues for the subscription term and as needed to provide the service.
3. Purpose
Clientlly processes personal data only to provide, secure and support the service, follow documented instructions and comply with law.
4. Data and people
Data may include identity, contact, financial, billing, employment and payroll records concerning staff, clients, suppliers and other contacts.
5. Customer duties
The customer is responsible for lawful data collection, an appropriate legal basis and lawful instructions.
6. Confidentiality
Authorised personnel are bound by confidentiality and process data only as instructed.
7. Security
Clientlly uses appropriate measures including encryption in transit, access controls, tenant isolation and logging.
8. Sub-processors
Clientlly may use contracted hosting, database, email and payment providers and remains responsible for their processing under this DPA.
9. International transfers
Cross-border transfers use safeguards recognised by applicable law, such as Standard Contractual Clauses.
10. Assistance
Clientlly provides reasonable assistance with data-subject requests, security duties, breach notices and impact assessments.
11. Data breaches
Clientlly notifies the customer without undue delay after becoming aware of a relevant personal-data breach.
12. Return and deletion
After termination, data is returned or deleted as chosen by the customer, except where law requires retention.
13. Audits
Clientlly provides reasonable compliance information and permits audits under appropriate confidentiality and security conditions.
14. Contact
Request a signed DPA or ask a data-protection question at privacy@clientlly.com.