
Loading CompliClear

Loading CompliClear
Version 2026-07-12. This standard addendum applies when incorporated into a CompliClear order or signed agreement and the customer submits personal data for processor services.
“Customer” is the organization identified in the applicable order; “CompliClear” is the service operator identified in that order. Customer acts as controller or processor, and CompliClear acts as processor or subprocessor, for Customer Personal Data. This DPA supplements the Terms and prevails for conflicting personal-data processing terms.
Because CompliClear's final legal entity and signing details must match the order, customers needing a signed DPA must obtain a countersigned copy from founder@compliclear.com before regulated production use. A webpage cannot substitute for missing party identity or signatures where required.
CompliClear processes Customer Personal Data only on documented instructions needed to provide and secure the service, support authorized users, comply with law, or as otherwise agreed in writing. Personnel with access are bound by confidentiality. If an instruction appears to violate applicable data-protection law, CompliClear will inform Customer unless law prohibits notice.
CompliClear is not presently SOC 2 or ISO 27001 certified. Customer remains responsible for its users, instructions, inputs, endpoint security, legal basis, data minimization, and professional review.
Customer gives general authorization for providers in the Subprocessor Register. CompliClear will require materially equivalent data-protection obligations where the provider acts as subprocessor and remains responsible for its processor obligations. Customers may request change notice and raise a reasoned data-protection objection; the parties will seek a reasonable alternative, configuration, or termination path.
Taking account of the processing and available information, CompliClear will reasonably assist with data-subject requests, security, breach assessment, DPIAs, regulator consultation, and evidence needed to demonstrate compliance. As processor, CompliClear will notify Customer without undue delay after becoming aware of a confirmed personal-data breach affecting Customer Personal Data and provide available facts in phases.
During the service, authorized admins can export workspace JSON and individual documents. On verified termination or instruction, CompliClear will delete or return Customer Personal Data, including linked active storage objects, unless law requires limited retention. Backup deletion follows documented cycles. Reasonable compliance information is available on request; audits must protect other customers, security, confidentiality, and provider restrictions and should begin with existing independent/vendor evidence.
The parties will identify restricted transfers and apply an adequate mechanism. Where the 2021 EU Standard Contractual Clauses are appropriate, the controller-to-processor or processor-to-processor module specified in a signed order/SCC annex applies, together with completed parties, transfer description, competent authority, technical measures, and transfer-impact assessment. This general DPA does not select a module or execute incomplete SCC annexes by itself.
Subject matter: hosted compliance assessment, generation, evidence, collaboration, storage, export, support, and security. Duration: the service term plus verified deletion, backup, dispute, and legal-retention periods. Nature/purpose: collection, organization, hosting, retrieval, transmission to configured providers, generation, review, export, support, security, and deletion.
Data subjects: customer users, personnel, contractors, suppliers, reviewers, and individuals described in authorized customer evidence. Data: business contact, account, company, assessment, document, system/vendor, audit, support, and customer-selected evidence data. Restricted sensitive categories are prohibited unless separately agreed.
Customer privacy contact: the administrator or contact in the order. CompliClear privacy and grievance contact: founder@compliclear.com; support@compliclear.com; Varanasi, Uttar Pradesh, India 221005. Incident reports: security@compliclear.com if configured, otherwise support@compliclear.com.