Last Updated: August 7, 2026
This DPA is incorporated into the agreement governing a Customer's use of the ClearMark Services.
When this DPA applies, ClearMark acts as a processor/service provider for Customer Personal Data and Customer acts as the controller/business, unless Customer itself is a processor.
This Data Processing Addendum ("DPA") is between ClearMark LLC ("ClearMark") and the customer entity ("Customer") that has entered into ClearMark's Terms of Use, an Order Form, or another written agreement for the Services (the "Agreement"). It applies to the extent ClearMark Processes Personal Data on Customer's behalf. If this DPA conflicts with the Agreement regarding Processing of Customer Personal Data, this DPA controls.
1. Roles and Processing Instructions
1.1 Roles. Customer is the Controller or Business of Customer Personal Data and ClearMark is the Processor or Service Provider, as applicable. If Customer is itself a Processor, ClearMark acts as Customer's Subprocessor.
1.2 Instructions. ClearMark will Process Customer Personal Data only to provide, maintain, secure, support, and improve the Services in accordance with the Agreement, this DPA, Customer's documented instructions, and applicable law. ClearMark will notify Customer if, in its reasonable opinion, an instruction violates applicable data protection law.
1.3 Customer responsibilities. Customer is responsible for the lawfulness, accuracy, and collection of Customer Personal Data and for providing any required notices, obtaining any required consents, and ensuring it has authority to instruct ClearMark to Process the data.
2. Data Protection and Confidentiality
2.1 Confidentiality. ClearMark will limit access to Customer Personal Data to authorized personnel and contractors who require access to perform the Services and who are bound by appropriate confidentiality and data-protection obligations.
2.2 Use restrictions. ClearMark will not sell or share Customer Personal Data, use it for cross-context behavioral advertising, or retain, use, disclose, or combine it outside the direct business relationship with Customer except as permitted by applicable law and the Agreement.
2.3 Data subject requests. Taking into account the nature of the Processing, ClearMark will provide reasonable assistance to Customer with requests from individuals to exercise rights of access, correction, deletion, portability, restriction, objection, or similar rights under applicable law. ClearMark will not independently respond to a request relating to Customer Personal Data unless legally required.
3. Security
3.1 Safeguards. ClearMark will maintain reasonable administrative, technical, and physical safeguards appropriate to the nature of Customer Personal Data and the risks of Processing. These include, as applicable, encryption in transit and at rest, least-privilege access controls, multi-factor authentication for administrative access, security logging and monitoring, controlled software changes and deployments, vulnerability management, backups and recovery measures, and vendor risk management.
3.2 Security program. ClearMark's security program is designed to align with recognized security and governance frameworks. ClearMark may update its safeguards as technology and risks evolve, provided it does not materially reduce the overall protection of Customer Personal Data during an active subscription term.
4. Personal Data Breaches
4.1 Notification. ClearMark will notify Customer without undue delay and, where reasonably practicable, within twenty-four (24) hours after confirming a Personal Data Breach involving Customer Personal Data. An initial notice may be supplemented as additional information becomes available.
4.2 Cooperation. ClearMark will provide information and reasonable assistance necessary for Customer to investigate the incident and satisfy applicable notification obligations. ClearMark's notification of an incident is not an admission of fault or liability.
5. Subprocessors
5.1 Authorization. Customer generally authorizes ClearMark to engage Subprocessors to provide the Services. ClearMark will maintain a current Subprocessor List and will impose written data-protection obligations on Subprocessors appropriate to the Processing and materially consistent with this DPA. ClearMark remains responsible for its Subprocessors to the extent required by applicable law and this DPA.
5.2 Changes and objections. ClearMark will provide reasonable advance notice of a new Subprocessor that will Process Customer Personal Data. Customer may object on reasonable data-protection grounds within fifteen (15) days of notice. The parties will work in good faith to resolve the objection; if they cannot, Customer may terminate the affected Service as its sole remedy for the objection, subject to payment of amounts accrued before termination.
6. International Transfers
6.1 Transfer mechanisms. Where Customer Personal Data subject to the GDPR, UK GDPR, or Swiss data-protection law is transferred to a country not recognized as providing adequate protection, the parties will rely on a valid transfer mechanism. The European Commission Standard Contractual Clauses ("SCCs") are incorporated by reference where required, using Module 2 (Controller-to-Processor) or Module 3 (Processor-to-Processor), as applicable. For UK transfers, the UK International Data Transfer Addendum applies; for Swiss transfers, the SCCs apply with legally required Swiss adaptations.
6.2 Transfer information. For purposes of the SCCs, Customer is the data exporter and ClearMark is the data importer. The parties, Processing details, categories of data, categories of data subjects, purposes of Processing, retention, Subprocessors, and security measures are described in this DPA, the Agreement, ClearMark's Privacy Policy, Security Statement, and current Subprocessor List. Those documents complete the corresponding SCC annexes to the extent permitted by law.
7. Artificial Intelligence and Machine Learning
7.1 Assistive use. ClearMark may use machine-learning, statistical, and artificial-intelligence components within the Services to identify patterns, summarize information, prioritize opportunities, and produce insights. Such outputs are assistive and are not intended to replace professional judgment.
7.2 No third-party model training. ClearMark will not use Customer Personal Data to train, fine-tune, evaluate, or improve any third-party artificial-intelligence model, machine-learning model, large language model, foundation model, or generative-AI system operating outside the Services.
7.3 Third-party AI providers. If a third-party AI provider Processes Customer Personal Data to provide functionality within the Services, ClearMark will contractually require the provider not to use Customer Personal Data to train or improve its own or another party's models and not to retain Customer Personal Data beyond what is necessary to provide the relevant service, except as legally required.
7.4 De-identified data. ClearMark may use aggregated, anonymized, or de-identified data for analytics, benchmarking, product improvement, and improving ClearMark's own models operating within the Services, provided such data does not identify Customer or any individual and ClearMark does not attempt to re-identify it.
8. Assistance, Audits, and Compliance
8.1 Assistance. ClearMark will provide reasonable assistance, taking into account the nature of the Processing and information available to ClearMark, with Customer's legally required data-protection impact assessments, consultations with regulators, and privacy compliance obligations relating to the Services.
8.2 Compliance evidence. Upon reasonable request and subject to confidentiality and security restrictions, ClearMark will make available information reasonably necessary to demonstrate compliance with this DPA. Where available, ClearMark may satisfy routine audit requests through third-party audit reports, certifications, penetration-test summaries, security documentation, or equivalent evidence.
8.3 Audits. If such evidence is insufficient to satisfy a legally required audit, Customer may conduct one reasonable audit in a twelve-month period with at least thirty (30) days' notice, during normal business hours and in a manner that minimizes disruption and protects other customers' information. Additional audits may be permitted following a confirmed Personal Data Breach materially affecting Customer Personal Data or when required by a competent regulator.
9. Return, Deletion, and Retention
9.1 During the term. ClearMark will retain Customer Personal Data only for as long as reasonably necessary to provide the Services, follow Customer's documented instructions, or comply with law.
9.2 Termination. For thirty (30) days after termination of the applicable Services, ClearMark will, upon written request, make Customer Data available for export in a commercially reasonable format. Thereafter, ClearMark will delete or render inaccessible Customer Personal Data from active systems in accordance with its standard deletion processes, unless retention is legally required.
9.3 Backups. Customer Personal Data may remain in routine backups until the applicable backup cycle expires. During that period, it will remain protected and will not be restored for ordinary business purposes except as necessary for disaster recovery, security, or legal compliance.
10. U.S. State Privacy Laws
10.1 Service Provider/Processor terms. Where U.S. state privacy law applies, ClearMark will act as a Service Provider, Contractor, or Processor, as applicable; will Process Customer Personal Data only for the business purposes specified in the Agreement and this DPA; and will provide the level of privacy protection required by applicable law.
10.2 Oversight. Customer may take reasonable and appropriate steps permitted by applicable law to confirm that ClearMark Processes Customer Personal Data consistently with Customer's obligations and may require ClearMark to stop and remediate unauthorized use.
11. Liability, Duration, and General Terms
11.1 Liability. Except where applicable law or an incorporated transfer mechanism requires otherwise, the limitations of liability, exclusions of damages, indemnities, and other risk-allocation terms in the Agreement apply to this DPA.
11.2 Term. This DPA becomes effective when it is incorporated into or accepted under the Agreement and remains in effect for as long as ClearMark Processes Customer Personal Data on Customer's behalf. Obligations that by their nature should survive termination will survive for so long as ClearMark retains Customer Personal Data.
11.3 Updates. ClearMark may update this DPA to reflect changes in law, regulation, or the Services. ClearMark will provide reasonable notice of material changes and will not materially reduce Customer's data-protection rights during an active subscription term except where required by law or agreed in writing.
11.4 Contact. Privacy questions and notices may be sent to privacy@clearmark.ai. Security concerns may be sent to security@clearmark.ai. Legal notices may be sent to legal@clearmark.ai.
Processing Details
Subject matter and duration. ClearMark Processes Customer Personal Data to provide, operate, support, secure, and improve the Services for the term of the Agreement and any limited post-termination retention period described above.
Data subjects and categories. Data subjects may include Customer personnel, authorized users, producers or agents, and individuals whose information is contained in Customer-provided or Customer-authorized data sources. Personal Data may include business contact and account information, employment or professional information, identifiers, system or device information, and other Personal Data contained in Customer Data as determined by Customer.
Nature and purpose. Processing may include collection, organization, storage, retrieval, analysis, use, transmission, restriction, deletion, and other operations necessary to provide the Services. Customer should not provide sensitive personal information unless expressly authorized in writing by ClearMark and supported by the applicable Agreement and safeguards.
Subprocessors. ClearMark's then-current Subprocessor List is available through the Trust Center or upon request.