Clove Analytics
The Audit Case Study About
Book a Fit Call
The Audit Case Study About

Data Processing Agreement

Last updated September 29, 2026

Summary

This summary is for convenience. The agreement is the text that follows it.

  • During an engagement, Clove processes personal data about your customers on your behalf. You are the controller. Clove is the processor.
  • This agreement sets out how that data is protected: where it is stored, who can see it, which providers are involved, and when it is deleted.
  • It is accepted together with the Terms of Service. Nothing separate needs signing.

1. About this DPA

This Data Processing Agreement (“DPA”) has two parts: (1) the Key Terms and Annexes on this page, which are the Cover Page; and (2) the Common Paper DPA Standard Terms Version 1.1 posted at commonpaper.com/standards/data-processing-agreement/1.1 (the “DPA Standard Terms”), which are incorporated by reference. If there is any inconsistency between the parts, this Cover Page controls over the DPA Standard Terms.

Capitalized words have the meanings given on this page, in the DPA Standard Terms, or in the Agreement. If this page omits or does not define a variable used in the DPA Standard Terms, its meaning is “none” or “not applicable” and the related clause does not apply. This DPA is accepted when Customer accepts the Agreement and applies whenever Provider Processes Customer Personal Data.

2. Key Terms

AgreementThe Clove Analytics Terms of Service, together with each Engagement Summary accepted under them.
ProviderClove Analytics LLC.
CustomerThe Customer under the Agreement.
Approved SubprocessorsThe Subprocessors listed in Annex III on this page.
Provider Security Contactsecurity@cloveanalytics.com
Security PolicyProvider will use commercially reasonable efforts to secure the Service from unauthorized access, alteration, or use and other unlawful tampering, and will maintain the measures described in Annex II.
DPA Covered ClaimNone.
DPA Liability CapNone. The limitations of liability in the Agreement apply.
Governing Law and Chosen CourtsAs set out in the Agreement.
Governing Member StateEEA transfers: Ireland. UK transfers: England and Wales.

3. Service Provider Relationship

To the extent the California Consumer Privacy Act, Cal. Civ. Code § 1798.100 et seq. (“CCPA”) applies, the parties acknowledge and agree that Provider is a service provider and is receiving Personal Data from Customer to provide the Service as agreed in the Agreement and detailed in Annex I(B), which constitutes a limited and specified business purpose. Provider will not sell or share any Personal Data provided by Customer under the Agreement. In addition, Provider will not retain, use, or disclose any Personal Data provided by Customer under the Agreement except as necessary for providing the Service for Customer, as stated in the Agreement, or as permitted by Applicable Data Protection Laws. Provider certifies that it understands the restrictions of this paragraph and will comply with all Applicable Data Protection Laws. Provider will notify Customer if it can no longer meet its obligations under the CCPA.

Annex I(A). List of Parties

Data exporterCustomer. Address and contact person: as given in the Engagement Summary or at checkout. Activities relevant to the transfer: see Annex I(B). Role: Controller, or Processor where Customer Processes the Personal Data on behalf of another Controller.
Data importerClove Analytics LLC, 30 N Gould Street STE R, Sheridan, WY 82801, United States. Contact: the Provider Security Contact. Activities relevant to the transfer: see Annex I(B). Role: Processor.

Annex I(B). Description of Transfer and Processing Activities

ServiceThe Services described in an Engagement Summary, including any Hosted Software.
Categories of Data SubjectsCustomer’s end customers. Customer’s employees and contractors who use the Hosted Software or communicate with Provider.
Categories of Personal DataName. Contact information such as email address, phone number, or postal address. Transactional information such as orders, refunds, and purchase history. For Hosted Software users, user activity and analysis such as device information and IP address.
Special Category DataNone. Customer will not provide Special Category Data to Provider.
Frequency of TransferContinuous during the SOW Term.
Nature and Purpose of ProcessingCollection, storage, analysis, and reporting of Customer Personal Data to build and maintain Customer’s unit economics and profit model, and to provide and support the Hosted Software.
Duration of ProcessingThe SOW Term, plus the deletion period below.
RetentionProvider deletes Customer Personal Data within 90 days after the end of the SOW Term, or sooner on Customer’s instruction, except where retention is required by Applicable Laws or where data remains in routine backups until those are overwritten, in which case it stays protected under this DPA.
Transfers to SubprocessorsAs described in Annex III. Customer Personal Data in Provider’s data warehouse is stored in the European Union.

Annex II. Technical and Organizational Security Measures

  • Logical segregation of each Customer’s data from that of other Customers.
  • Encryption of Customer Personal Data in transit and at rest.
  • Multi-factor authentication on all accounts with access to Customer Personal Data or to the systems that hold it.
  • Access limited to personnel who need it to provide the Service, each bound by confidentiality obligations.
  • Credentials and API keys held in encrypted secret stores, not in code or shared documents.
  • Read-only access to Customer platforms wherever the platform supports it, granted and revocable by Customer.
  • Pseudonymization of direct identifiers where feasible for the analysis. Raw records are not shared with AI tools; AI tools are used only under commercial terms that prohibit training on the data.
  • Deletion of Customer Personal Data within 90 days after the end of the SOW Term.
  • Notification of a Security Incident without undue delay and in any case within 72 hours of becoming aware of it.

Annex III. Approved Subprocessors

Provider will give notice of changes to this list as set out in Section 2.7 of the DPA Standard Terms.

SubprocessorCountry of locationProcessing task
Google Cloud (Google LLC)United States; data hosted in the EUStorage and processing of Customer Personal Data
Airbyte, Inc.United States; EU-hosted instanceExtraction of storefront data
Windsor Group AGSwitzerlandExtraction of advertising and storefront data
Leadsie LtdUnited KingdomManagement of access grants to Customer platforms
Cloudflare, Inc.United StatesHosting and access control for the Hosted Software
Kinde Australia Pty LtdAustralia; EU-hosted instanceAuthentication for Hosted Software users
PostHog, Inc.United States; EU-hosted instanceProduct analytics for the Hosted Software
GitHub, Inc.United StatesExecution of data pipelines
Google Workspace (Google LLC)United StatesEmail, documents, and file storage
Resend, Inc.United StatesTransactional email to Hosted Software users
Anthropic, PBCUnited StatesAI-assisted analysis of pseudonymized data

Contact

Clove Analytics LLC
30 N Gould Street STE R, Sheridan, WY 82801, United States
security@cloveanalytics.com

This DPA incorporates the Common Paper Data Processing Agreement Standard Terms (Version 1.1), which are licensed under CC BY 4.0.

© 2026 Clove Analytics
Privacy Terms DPA hello@cloveanalytics.com