Preamble
This Data Processing Agreement ("DPA") forms part of the Master Subscription Agreement or Order Form ("Agreement") between Clearlinks, Inc. ("Processor") and the customer entity ("Controller") and applies to any processing of Personal Data carried out by Processor on Controller's behalf in connection with the Services.
The Standard Contractual Clauses (Module Two: controller to processor) adopted by the European Commission on 4 June 2021 are incorporated by reference and apply to transfers of Personal Data from the EEA, UK, or Switzerland to a country without an adequacy decision.
Definitions
- Personal Data means any information relating to an identified or identifiable natural person, processed by Processor on behalf of Controller in connection with the Services.
- Processing has the meaning given in Article 4(2) GDPR.
- Subprocessor means a third party engaged by Processor to process Personal Data on its behalf.
- Data Subject Request means a request from a data subject to exercise rights under applicable data protection law.
Subject matter and duration
The subject matter, duration, nature, and purpose of the processing, the types of Personal Data, and the categories of data subjects are set out in Annex I to this DPA.
Processor instructions
Processor will process Personal Data only on documented instructions from Controller, including with regard to international transfers, unless required to do so by law. Processor will inform Controller of any such legal requirement before processing, unless the law prohibits such notice.
The Agreement, this DPA, and Controller's use of the Services constitute Controller's documented instructions.
Confidentiality
Processor ensures that persons authorized to process the Personal Data have committed themselves to confidentiality or are under an appropriate statutory obligation of confidentiality.
Security of processing
Processor implements appropriate technical and organisational measures to ensure a level of security appropriate to the risk, including:
- Encryption of Personal Data in transit (TLS 1.2+) and at rest (AES-256);
- Role-based access controls with least-privilege defaults;
- Continuous logging and monitoring of access to Personal Data;
- Annual third-party penetration testing of the production environment;
- SOC 2 Type II audit covering Security, Availability, and Confidentiality.
Subprocessors
Controller provides general authorization for Processor to engage the Subprocessors listed at clearlinks.org/subprocessors. Processor will give Controller at least 30 days' notice of any addition or replacement, during which Controller may object on reasonable grounds related to data protection.
Processor enters into a written agreement with each Subprocessor imposing data protection obligations no less protective than this DPA and remains liable to Controller for the performance of each Subprocessor's obligations.
Assistance with data subject requests
Processor will, taking into account the nature of the processing, assist Controller by appropriate technical and organisational measures, insofar as possible, in fulfilling Controller's obligation to respond to Data Subject Requests. Where a request is received directly by Processor, Processor will forward it to Controller without undue delay.
Personal data breaches
Processor will notify Controller without undue delay and in any event within 72 hours after becoming aware of a Personal Data breach. The notification will include the information required by Article 33(3) GDPR to the extent then known to Processor, and updates as additional information becomes available.
Audits
Processor makes available to Controller the information necessary to demonstrate compliance with the obligations laid down in this DPA, including the most recent SOC 2 Type II report and pen test summary letter. Controller may conduct, at its own expense and subject to reasonable notice and confidentiality undertakings, one audit per year.
Deletion and return of personal data
Upon termination of the Services, Processor will, at Controller's choice, delete or return all Personal Data and delete existing copies within 30 days, unless retention is required by applicable law. Deletion is carried out via cryptographic zeroize and confirmed in writing on request.
International transfers
Where Personal Data is transferred from the EEA, UK, or Switzerland to a country without an adequacy decision, the SCCs (Module Two) apply. Annex II to this DPA sets out the technical and organisational measures for transfer security. UK transfers rely on the UK International Data Transfer Addendum to the SCCs.
Annex I — Description of processing
Categories of data subjects
- Controller's employees, contractors, and agents;
- Controller's students, faculty, staff, parents, and guardians;
- Visitors to Controller's websites and digital resources.
Categories of personal data
- Account data: name, work email, role, authentication metadata;
- Customer Content submitted for processing, which may contain personal data;
- Usage and audit logs.
Nature and purpose
Processing necessary to provide the Services, including ingestion, accessibility remediation, generation of derived assets (e.g., alt text, captions), and delivery back to Controller's systems.
Annex II — Technical and organisational measures
The full description of measures is set out on our security page and is incorporated by reference. Updates to those measures will not reduce the overall level of protection.