This one is unavoidably formal — it has to track the law word-for-word to actually protect you, so we haven't dressed it up. In plain terms: if you're an EU/UK business and your data falls under GDPR, this spells out our obligations when we handle personal data for you. It supplements the Terms of Service, applies where ClearCast processes personal data on behalf of a customer ("Controller") subject to the EU/UK GDPR or comparable laws, and reflects the requirements of GDPR Article 28.
For content and end-user data you bring into ClearCast, you are the Controller and ClearCast is the Processor. ClearCast processes that data only to provide the service and on your documented instructions.
You authorize ClearCast to engage the sub-processors listed at clear-cast.net/subprocessors. We impose data-protection obligations on each sub-processor and provide advance notice of changes so you may object.
Where personal data is transferred outside the EEA, UK, or Switzerland, such transfers are governed by the European Commission's Standard Contractual Clauses (Decision 2021/914), the UK International Data Transfer Addendum, and applicable Swiss provisions, as incorporated into this DPA.
To execute a countersigned copy of this DPA for your records, email support@clear-cast.net with your legal entity details.