Data Processing Agreement
Effective date: 1 September 2026
Last updated: 16 September 2026
This Data Processing Agreement ("DPA") forms part of the Terms of Service between Clynto AI INC, 8 The Green STE B, Dover, DE 19901 ("Clynto", "we", "us") and the customer agreeing to those terms ("Customer", "you"). It governs our processing of personal data that you load into, or connect to, the platform.
Where this DPA conflicts with the Terms of Service, this DPA governs for the processing of personal data.
1. Roles
You are the controller of the personal data you put into Clynto: your account records, your contacts, your support history, your email correspondence. You decide why and how it is processed.
We are the processor. We act only on your documented instructions, which are the Terms of Service, this DPA, and your configuration of the product.
Where we decide the purpose ourselves — website visitors, people who request a demo, the individuals who administer your account — we are a controller, and our Privacy Policy governs that instead.
2. Scope of processing
| Subject matter | Provision of the Clynto customer-success platform |
| Duration | For the term of your subscription, plus the return and deletion periods in section 8 |
| Nature and purpose | Hosting, storing, analysing and surfacing your customer records; running the agents, workflows and reports you configure; sending email you instruct us to send |
| Types of personal data | Names, business email addresses, job titles, phone numbers, employer, correspondence content, support ticket content, product-usage events, and any other personal data you choose to load |
| Categories of data subject | Your customers' employees and contacts; your own staff who use the platform |
| Special category data | Not required by the service, and not to be loaded. If you load it, you do so on your own assessment and lawful basis |
3. Our obligations
We will:
- Process personal data only on your documented instructions, including for transfers, unless required otherwise by law — in which case we will tell you first, unless the law forbids it
- Ensure that people authorised to process the data are bound by confidentiality
- Implement the technical and organisational measures in section 5
- Respect the sub-processor conditions in section 4
- Assist you, taking into account the nature of the processing, with data subject requests, data protection impact assessments and prior consultations
- Make available the information reasonably necessary to demonstrate compliance
- Delete or return the data as set out in section 8
If we consider an instruction to infringe applicable data protection law, we will tell you.
4. Sub-processors
You give general authorisation for us to engage the sub-processors listed below.
| Sub-processor | Purpose | Region |
|---|---|---|
| Microsoft Azure | Cloud hosting, database, and AI services | Azure East US 2 |
| Resend | Transactional and customer-initiated email delivery | Azure East US 2 |
Each is bound by a written agreement imposing data protection obligations at least as protective as those in this DPA. We remain liable to you for their performance.
We will give at least 30 days' notice before adding or replacing a sub-processor. If you reasonably object on data protection grounds within that period, we will work with you in good faith on an alternative; if none is available, you may terminate the affected part of the service without penalty.
Services you connect yourself are not our sub-processors. When you link your own help desk, CRM, billing, messaging, analytics or mailbox account, you are instructing us to exchange data with a provider you have chosen and contracted with. That provider acts for you, and your agreement with them governs.
5. Security
We maintain technical and organisational measures appropriate to the risk, including:
- Tenant isolation enforced at the database layer, not by query discipline
- Encryption in transit (TLS) and at rest, with additional field-level encryption on sensitive commercial fields
- Access control on a least-privilege basis, with role-based permissions and a granular permission model
- Secrets management through Azure Key Vault, with no long-lived cloud credentials in the deployment pipeline
- Audit logging of actions taken in the platform, including automated ones
- Model isolation — your data is processed by AI deployments within our own cloud tenancy and is never used to train models shared with other customers
Our security practices are described further in our Trust Center.
6. Personal data breaches
We will notify you without undue delay after becoming aware of a personal data breach affecting your data, and in any case within 72 hours. The notification will describe, to the extent known: the nature of the breach, the categories and approximate number of data subjects and records concerned, the likely consequences, and the measures taken or proposed.
We will cooperate with you and take reasonable steps to mitigate the effects.
7. Data subject requests and international transfers
Data subject requests. If we receive a request from one of your data subjects, we will not respond substantively; we will refer them to you and tell you promptly. We will assist you in responding, including through the export and deletion functions in the product.
International transfers. Our production systems run in Azure East US 2. Where personal data originating in the EEA, the UK or Switzerland is transferred to us, the transfer is made under the European Commission's Standard Contractual Clauses, which are incorporated into this DPA by reference, together with the UK Addendum where the UK GDPR applies. We will implement supplementary measures where a transfer risk assessment indicates they are needed.
8. Return and deletion
During the subscription term you may export your data through the product at any time.
On termination, you may export your data for 30 days. After that, we delete customer data within 30 days, and confirm deletion on request. Backups are purged on their ordinary rotation cycle.
We may retain data where law requires it, for as long as that requirement lasts, and it remains subject to this DPA.
9. Audit
We will make available the information reasonably necessary to demonstrate compliance with this DPA, including our security documentation and completed vendor security questionnaire.
Where that is not sufficient for your own compliance obligations, you may request an audit no more than once in any twelve-month period, on at least 30 days' written notice, during business hours, without unreasonable disruption, and subject to confidentiality. You bear your own costs.
10. Liability and term
Each party's liability under this DPA is subject to the limitations in the Terms of Service.
This DPA takes effect when you accept the Terms of Service and continues for as long as we process personal data on your behalf.
11. Contact
Privacy enquiries and data protection matters: privacy@clynto.ai Security issues: security@clynto.ai Postal: Clynto AI INC, 8 The Green STE B, Dover, DE 19901