Data Processing Agreement
This Data Processing Agreement (the "DPA") sets out the terms under which Clivio processes personal data on behalf of its customers, in accordance with Article 28 of the General Data Protection Regulation (GDPR).
1. Purpose and Scope
This DPA is entered into between Clivio, publisher of the Clivio service (the "Processor"), and the customer using the Service (the "Controller"). It applies to all processing of personal data carried out by Clivio on behalf of the customer in the course of providing the Service.
This DPA forms an annex to the Terms of Service. In the event of any conflict between the Terms of Service and this DPA on a matter relating to the processing of personal data, this DPA shall prevail.
2. Nature and Purpose of Processing
Clivio processes personal data on behalf of the customer solely for the following purposes:
- hosting, storing, and organizing the documents uploaded by the customer;
- extracting data from documents using artificial intelligence, exclusively at the customer's request;
- managing the user account and subscription;
- providing the technical support requested by the customer.
3. Types of Data and Data Subjects
The processing covers the following categories of data: the documents and files uploaded by the customer, the metadata and data extracted from those documents, and account data (name, email address, billing information).
The data subjects are those determined by the customer: the customer freely chooses which documents to upload to the Service and remains solely responsible for the lawfulness of their collection and transmission to Clivio.
4. Obligations of the Processor
Clivio undertakes to:
- process personal data only on documented instructions from the customer, including with regard to any transfers of data;
- ensure that persons authorized to process the data are subject to a duty of confidentiality;
- implement appropriate technical and organizational measures to ensure the security of the data.
These security measures include in particular:
- encryption of data in transit (TLS 1.3) for all network communications;
- encryption of data at rest via the cloud infrastructure;
- hosting of data within the European Union;
- short-lived signed URLs for document shares;
- an audit log of access to shared documents;
- the option to enable multi-factor authentication (MFA) on accounts.
5. Sub-processors
The customer authorizes Clivio to engage the following sub-processors (general authorization):
- Google Cloud Platform / Firebase — data hosting, within the European Union;
- Anthropic — AI processing via API, at the customer's request; documents are not used to train models;
- Stripe — payment processing (billing data only);
- PDF.co — fallback optical character recognition (OCR).
Some of these sub-processors are established outside the European Union; any transfers of data to such sub-processors are governed by standard contractual clauses.
Clivio will inform the customer of any intended change concerning the addition or replacement of a sub-processor, giving the customer the opportunity to raise reasoned objections.
6. Data Subject Rights
Taking into account the nature of the processing, Clivio will provide the customer with reasonable assistance in responding to requests from data subjects exercising their rights (right of access, rectification, erasure, restriction, portability, and objection).
7. Data Breach Notification
Clivio will inform the customer without undue delay upon confirmation of a personal data breach affecting data processed on the customer's behalf, describing, to the extent possible, the nature of the breach, its likely consequences, and the measures taken or proposed to address it.
8. Reversibility and Data Deletion
The customer may export all of their documents and associated metadata from the Service at any time.
Upon termination of the contract, and at the customer's choice, Clivio will return or delete all personal data processed on the customer's behalf within 30 days, unless a legal retention obligation requires otherwise.
9. Audits
Clivio will respond to reasonable security questionnaires submitted by the customer to enable the customer to verify compliance with the obligations of this DPA.
10. Legal Retention Responsibility
The customer remains solely responsible for complying with its own legal document retention obligations, including the obligation to retain commercial documents for ten years (Article L. 123-22 of the French Commercial Code). Clivio provides the export and return means enabling the customer to fulfil these obligations.
Contact
For any question relating to this DPA or to the processing of your data: contact@clivio.app.