Back to home

Data Processing Agreement

Last updated: July 2026

This Data Processing Agreement (“DPA”) forms part of the Clospad Terms of Service and applies to every workspace, wherever Clospad processes personal data on a customer’s behalf. A countersigned copy for your procurement records is available on request from hello@clospad.com.

1. Roles

For personal data your team stores in Clospad — contacts, companies, deals, communications, and related records — you are the data controller and Clospad is the data processor. We process this data only to provide the service and only on your documented instructions, which are given through your use of the product.

2. Details of processing

  • Subject matter & purpose: providing the Clospad CRM — storage, search, reporting, communication, and AI-assisted features over your workspace data.
  • Duration: the term of your subscription, plus the deletion window in Section 7.
  • Categories of data: contact and business information (names, email addresses, phone numbers, job titles, companies), communication content (notes, emails, messages, call recordings where enabled), and account data of your workspace members.
  • Data subjects: your workspace members and the contacts, leads, and business partners your team manages in the CRM.

3. Our obligations as processor

  • Process personal data only to deliver the service — never for advertising, and never sold.
  • Ensure personnel with production access are bound by confidentiality obligations.
  • Apply the technical and organisational measures described on our Trust & Security page, including encryption in transit and of stored credentials, workspace isolation, role-based access control, and audit logging.
  • Notify you without undue delay after becoming aware of a personal data breach affecting your workspace.
  • Assist you, taking into account the nature of processing, in responding to data-subject requests (access, correction, export, deletion) and in meeting your GDPR obligations.

4. Sub-processors

We use the following sub-processors to deliver the service. By using Clospad you authorise this list; we will update this page before adding or replacing a sub-processor, and you may object on reasonable data-protection grounds by contacting us.

  • Cloud hosting provider — infrastructure and hosting (EU/US). Named on request under a mutual NDA.
  • Stripe — payment processing (card details are handled entirely by Stripe).
  • Twilio — voice calling, SMS, and WhatsApp messaging, where your workspace enables calling features.
  • Anthropic — AI processing for assistant and automation features, where your workspace uses them.
  • OpenAI — call transcription, where your workspace enables call recording review.

Integrations you connect yourself — for example email providers, calendar, or data enrichment services — are governed by your agreement with that provider; Clospad shares with them only the data required for the integration to function.

5. International transfers

Where personal data is transferred outside the EEA or UK, we rely on the European Commission’s Standard Contractual Clauses or the sub-processor’s equivalent approved transfer mechanism.

6. Audits & information

On written request, and no more than once per year unless required by a supervisory authority, we will provide the information reasonably necessary to demonstrate compliance with this DPA.

7. Deletion & return

Workspace owners can export their data at any time and can delete their workspace from the settings page. On termination of your subscription, we delete personal data processed on your behalf within 30 days, except where retention is required by law.

8. Contact

Questions about this DPA, sub-processors, or data protection generally: hello@clospad.com.