Legal
Data Processing Agreement
Template effective: June 8, 2026 · GDPR Article 28 compliant
How to execute this DPA
This page contains the standard terms of our Data Processing Agreement. To execute a signed DPA for your organisation, email privacy@cloutbox.ai with subject "DPA Request" and your organisation name. We will send you a countersigned PDF within 5 business days. Enterprise customers may negotiate custom terms.
This Data Processing Agreement ("DPA") is entered into between Cloutbox Inc.("Processor") and the customer organisation identified in the applicable Order Form or subscription agreement ("Controller").
Annex 1 — Details of Processing
1. Processor Obligations
The Processor shall, in relation to any personal data processed in connection with the performance of its obligations under this DPA:
- Instructions: process personal data only on documented instructions from the Controller (including as set out in the subscription agreement and the Service itself). If required by applicable law, the Processor will inform the Controller before carrying out processing contrary to instructions, unless prohibited from doing so.
- Confidentiality: ensure that persons authorised to process personal data are subject to a binding duty of confidentiality.
- Security: implement and maintain the technical and organisational security measures described in Annex 2 of this DPA and in the Security Policy.
- Sub-processors: not engage any sub-processor without the Controller's general or specific written authorisation. The Controller provides general authorisation for the sub-processors listed in Annex 3. The Processor will notify the Controller of any intended changes (addition or replacement) to sub-processors at least 30 days in advance, giving the Controller the opportunity to object.
- Data subject rights: assist the Controller in fulfilling its obligations to respond to requests for exercising data subjects' rights (access, rectification, erasure, portability, restriction, objection). The Processor will forward any requests received directly from data subjects to the Controller within 5 business days.
- Data protection impact assessments: assist the Controller, at its cost, with conducting DPIAs and prior consultations with supervisory authorities where required by Article 35-36 GDPR.
- Deletion / return: at the Controller's choice, delete or return all personal data to the Controller at the end of the service term, and delete existing copies, unless applicable law requires retention. The Controller's deletion request must be submitted within 30 days of termination.
- Audit rights: make available to the Controller all information necessary to demonstrate compliance with this DPA, and allow for and contribute to audits conducted by the Controller or an independent auditor appointed by the Controller, subject to reasonable notice (at least 30 days), confidentiality obligations, and the Controller bearing audit costs.
2. Controller Obligations
- Ensure that the transfer of personal data to the Processor is lawful, including obtaining any necessary consents from data subjects.
- Maintain accurate records of processing activities under Article 30 GDPR.
- Promptly notify the Processor of changes in applicable laws that may affect processing.
- Be responsible for the accuracy and legality of personal data provided to the Processor.
3. Breach Notification
The Processor will notify the Controller without undue delay, and in any event within 24 hours of becoming aware of a personal data breach involving the Controller's data. Notification will include, to the extent available: the nature of the breach, categories and approximate number of data subjects affected, categories and approximate number of records affected, likely consequences, and measures taken or proposed to address the breach.
The Controller is responsible for notifying the competent supervisory authority and affected data subjects as required by GDPR Articles 33-34, using the information provided by the Processor.
4. International Transfers
Where the processing involves a transfer of personal data outside the EEA, UK, or Switzerland, the parties agree that such transfers are governed by:
- EEA to US: EU Standard Contractual Clauses (Module 2: Controller to Processor, 2021) supplemented by a Transfer Impact Assessment.
- UK to US: UK IDTA (International Data Transfer Addendum to the EU SCCs) plus UK Transfer Risk Assessment.
- Switzerland to US: Swiss nFADP SCCs.
The applicable SCCs and addenda are incorporated into this DPA by reference. Executed copies are available upon request at privacy@cloutbox.ai.
5. Liability
Each party's liability under this DPA shall be subject to the exclusions and caps in the Terms of Service, except where liability cannot be limited under applicable law (including GDPR). In the event of a conflict between this DPA and the Terms of Service, this DPA shall prevail with respect to data protection matters.
Annex 2 — Technical and Organisational Security Measures
See our Security Policy for the full list. Key measures include:
- Encryption in transit (TLS 1.2+) and at rest (AES-256).
- Role-based access controls with principle of least privilege; privileged access logged and reviewed.
- Encrypted storage of OAuth tokens.
- Daily automated backups with 30-day retention and point-in-time recovery.
- Annual third-party penetration testing.
- Real-time security monitoring and incident response procedures.
- Employee confidentiality agreements and data protection training.
- Vulnerability management and dependency update programme.
Annex 3 — Authorised Sub-Processors
The Controller provides general authorisation for the following sub-processors:
Request a Signed DPA
To receive a co-signed PDF of this DPA for your records:
privacy@cloutbox.aiInclude your organisation name and the email on your Cloutbox account. We respond within 5 business days.