Draft template — pending legal review
This page is an engineering draft for procurement and counsel review. It is not final legal advice. Questions: security@clarika.co.ke.
Data Processing Agreement
v2026-06-01 · Effective 2026-06-01 · Updated 2026-06-24Data Processing Agreement (Template)
This Data Processing Agreement ("DPA") forms part of the agreement between the customer ("Controller", "you") and Clarika ("Processor", "we", "us") for processing of personal data in connection with the Clarika Service.
Draft template: This document is pending review by Kenyan counsel. Execute only after legal sign-off. This template is published for procurement review and must be customized per customer order form.
1. Definitions
- Personal data, processing, data subject, and controller/processor have the meanings in the Kenya Data Protection Act, 2019 ("Kenya DPA") and, where applicable, the EU GDPR.
- Customer Content means documents, extracted data, and related metadata you submit to the Service.
- Sub-processor means a third party engaged by Clarika to process personal data on your behalf.
2. Roles
You are the Controller for personal data in Customer Content and account data you provide. Clarika processes that data as Processor solely on your documented instructions, except where we act as an independent Controller (e.g. billing, security logs, compliance).
3. Subject matter and duration
Subject matter: provision of document intelligence, extraction, review, pipeline, and connector services.
Duration: for the term of your subscription or workspace agreement and until deletion in accordance with Section 10.
4. Nature and purpose of processing
Processing includes storage, OCR, LLM-assisted schema operations, human review workflows, notifications, backups, and support. Purposes are limited to delivering the Service per your configuration and instructions.
5. Categories of data and data subjects
| Category | Examples |
|---|---|
| Data subjects | Your employees, contractors, customers, or other individuals whose data appears in uploaded documents |
| Personal data types | Names, contact details, identifiers, financial or health information only if present in Customer Content |
| Special categories | Only if included in documents you upload; you warrant lawful basis |
6. Processor obligations
Clarika will:
- Process personal data only on documented instructions, including regarding transfers
- Ensure personnel are bound by confidentiality
- Implement appropriate technical and organizational measures (see Security Annex summary below)
- Assist with data subject requests where feasible, via your workspace administrators
- Assist with DPIAs and ODPC consultations where required
- Notify you without undue delay after becoming aware of a personal data breach (target: within 48 hours of confirmation; ODPC notification within 72 hours where we act as controller for our own processing)
- Delete or return personal data at end of service, subject to legal retention
7. Sub-processors
You authorize Clarika to engage Sub-processors listed at /legal/sub-processors. We will notify you of material changes (typically 30 days before new Sub-processors process Customer Content). You may object on reasonable grounds relating to data protection.
We impose data protection terms on Sub-processors substantially similar to this DPA.
8. International transfers
Where personal data is transferred outside Kenya, Clarika will implement safeguards required under the Kenya DPA and ODPC guidance, which may include standard contractual clauses, adequacy decisions, or equivalent mechanisms. Sub-processor regions are disclosed in the Sub-processor list.
9. Audits
Upon reasonable notice, you may request information necessary to demonstrate compliance. Clarika may provide third-party audit reports (e.g. SOC 2, when available) in lieu of on-site audits where permitted.
10. Deletion and return
Upon termination, Clarika will delete Customer Content from production systems within [90] days unless you export data sooner or law requires retention. Backups may persist for a limited period before automatic purge.
11. Security measures (summary)
- Encryption in transit (TLS)
- Workspace-scoped access controls and RBAC
- Encrypted connector credentials at rest (Fernet)
- Object storage access controls for document blobs
- Error monitoring with PII scrubbing
- See SECURITY.md for vulnerability disclosure
12. Liability
Liability under this DPA is subject to the limitation of liability in the main Terms of Service, except where prohibited by the Kenya DPA.
13. Order of precedence
If this DPA conflicts with the Terms of Service regarding processing of personal data, this DPA prevails. Customer-specific order forms may supersede both where signed.
14. Contact
Data protection inquiries: security@clarika.co.ke
Related: Sub-processors · Privacy Policy · Terms of Service