Legal
Data Processing Agreement
Last updated: September 9, 2026
“This Data Processing Agreement governs how Clevername processes personal data on behalf of its customers in compliance with GDPR and applicable data protection laws. It supplements our Terms of Service and Privacy Policy.”
— Floyd Media LLC
1. Definitions
For the purposes of this Agreement:
"Controller" means the entity that determines the purposes and means of the processing of Personal Data — the Customer.
"Processor" means the entity that processes Personal Data on behalf of the Controller — Clevername, operated by Floyd Media LLC.
"Data Protection Laws" means all applicable data protection and privacy legislation, including the General Data Protection Regulation (EU) 2016/679 ("GDPR"), the UK GDPR, and any national implementing legislation.
"Personal Data" means any information relating to an identified or identifiable natural person that is processed by Clevername in the course of providing the Service.
"Processing" means any operation performed on Personal Data, including collection, recording, organization, structuring, storage, adaptation, retrieval, consultation, use, disclosure, alignment, restriction, erasure, or destruction.
"Sub-processor" means any third party engaged by Clevername to process Personal Data on behalf of the Controller.
"Data Subject" means the identified or identifiable natural person to whom Personal Data relates.
"Service" means the Clevername AI agent governance platform, including all features described at clevername.net.
2. Scope and purpose of processing
This Data Processing Agreement ("DPA") forms part of the Terms of Service between the Customer ("Controller") and Floyd Media LLC, operating as Clevername ("Processor"), and governs the processing of Personal Data by the Processor on behalf of the Controller.
Clevername processes Personal Data solely to provide the AI agent governance service, which includes:
- Scanning AI agent content (prompts and responses) for prompt injection, PII, secrets, and toxicity
- Enforcing guardrail policies and agent drift detection
- Maintaining audit trails of agent activity
- Storing and managing API tokens and provider keys on behalf of users
- Authenticating users and managing organizational membership
- Delivering transactional notifications
Content scanning is performed in memory, on plaintext, before anything is stored. The platform-wide default for the agent I/O log and the tool-call log is metadata only — timestamp, model, token count, latency, verdicts, and a content hash keyed with a Processor-held key scoped to the Controller's organisation (at-rest hardening against a database copy; not zero-knowledge, as the Processor holds that key) — not prompt, response, or tool text; storing that text is a platform-wide setting that is off, and there is no per-organization switch. Independently of that default, each user may enable zero-knowledge I/O encryption: a key is derived from the user's passphrase in the browser, an RSA-OAEP-2048 keypair is generated there, and every stored copy of that user's agent content (I/O log prompts and responses; tool-call arguments, results, and errors; PII and secret-finding excerpts; tool-call renders in observed actions; system-prompt previews and baselines; false-positive report text; ClaimGuard evidence) is encrypted with a per-record AES-256-GCM key wrapped once to the user's public key. The Processor holds no escrow copy and has no decrypt path. Four categories remain readable by the Processor by necessity: tool arguments parked for a human approval (envelope-encrypted under the Processor's KMS key and deleted after execution or expiry), the results of asynchronous tool executions (same Processor KMS envelope, bound to the user and the execution, so the requesting agent can poll for them; purged with the 90-day content window), the contents of files the user's agent reads (same Processor KMS envelope, bound to the user and the file, so the server-side agent can receive the body it requested; the user's browser-held private key is not available to it), and content the user explicitly donates for training. For all four, personnel holding the Processor's KMS key together with database access can read the content; the envelope ensures a database dump alone is insufficient.
This encryption is an opt-in setting a user turns on for their own account, not a platform-wide control the Processor operates on the Controller's behalf. Where no user in the Controller's organization has enabled it, stored content is readable by the Processor subject to the platform-wide metadata-only default described above.
3. Duration of processing
Processing begins on the date the Controller creates a Clevername account or enters into a subscription agreement, and continues for the duration of the service relationship.
Upon termination of the service agreement, the Processor will delete or return all Personal Data in accordance with Article 14 of this DPA, subject to any legal retention obligations.
4. Types of personal data processed
The following categories of Personal Data may be processed:
Account data: Email address, display name, organizational role, and team membership.
Authentication data: OAuth tokens, session identifiers, and multi-factor authentication metadata.
AI content metadata: Timestamps, token counts, model identifiers, scan verdicts, and guardrail enforcement decisions associated with AI agent interactions.
Stored AI content: By platform default only metadata is stored, not prompt, response, or tool text. Where content is stored — PII and secret-finding excerpts, tool-call renders in observed actions, system-prompt previews and baselines, parked-approval tool arguments, asynchronous tool-execution arguments and results, false-positive report text (only when the reporter chooses to share scan content), ClaimGuard evidence, and any prompt/response text if platform-wide content logging is ever enabled — it is encrypted under the user's own key (zero-knowledge, Processor cannot read it) when that user has enabled I/O encryption, and is otherwise readable by the Processor. Content-bearing records are purged after 90 days by default; PII and secret-detection findings after 365 days by default (Controller-configurable).
Audit records: Structured logs of API calls, agent actions, security events, and governance decisions, retained according to plan — 7 days (Free), 30 days (Pro), and 365 days (Team); Enterprise retention is set by contract with no fixed platform expiry.
API credentials: Third-party provider API keys stored in encrypted form in GCP Secret Manager. The database stores only masked hints.
Organizational data: Team names, department structures, role assignments, and SCIM-provisioned identity attributes.
5. Categories of data subjects
The Personal Data processed concerns the following categories of Data Subjects:
- Users of the Controller's Clevername organization (employees, contractors, and authorized agents)
- Individuals whose personal data may appear in AI agent content processed through the platform (end users, customers, or other third parties referenced in prompts or responses)
6. Obligations of the Processor
Clevername, as Processor, shall:
(a) Process Personal Data only on documented instructions from the Controller, including with regard to transfers of Personal Data to a third country, unless required to do so by applicable law — in which case the Processor shall inform the Controller of that legal requirement before processing, unless prohibited by law.
(b) Ensure that persons authorized to process Personal Data have committed themselves to confidentiality or are under an appropriate statutory obligation of confidentiality.
(c) Implement appropriate technical and organizational measures to ensure a level of security appropriate to the risk, as described in Article 10 of this DPA.
(d) Assist the Controller, taking into account the nature of processing, by appropriate technical and organizational measures, insofar as possible, for the fulfillment of the Controller's obligation to respond to requests for exercising Data Subject rights.
(e) Assist the Controller in ensuring compliance with obligations related to security, breach notification, data protection impact assessments, and prior consultation, taking into account the nature of processing and the information available to the Processor.
(f) At the choice of the Controller, delete or return all Personal Data after the end of the provision of services, and delete existing copies unless applicable law requires storage of the Personal Data.
(g) Make available to the Controller all information necessary to demonstrate compliance with the obligations laid down in this DPA and allow for and contribute to audits, including inspections, as described in Article 13.
(h) Immediately inform the Controller if, in the Processor's opinion, an instruction infringes Data Protection Laws.
7. Obligations of the Controller
The Controller shall:
(a) Ensure that the processing of Personal Data is carried out in accordance with applicable Data Protection Laws, including having a lawful basis for processing.
(b) Provide documented instructions to the Processor regarding the processing of Personal Data. The Controller's use of the Service constitutes its instructions for the processing described in this DPA.
(c) Ensure that Data Subjects have been informed of the processing in accordance with applicable transparency requirements.
(d) Be responsible for the accuracy, quality, and legality of Personal Data provided to the Processor.
(e) Respond to Data Subject requests, with the Processor's reasonable assistance as described in Article 12.
(f) Ensure that any content processed through the platform complies with applicable laws and does not infringe the rights of third parties.
8. Sub-processors
The Controller provides general authorization for the Processor to engage Sub-processors. The Processor shall inform the Controller of any intended changes concerning the addition or replacement of Sub-processors, giving the Controller the opportunity to object to such changes within 30 days of notification.
Each entry below states the routing that is configured in the Processor's deployment configuration. Where the configuration running in production differs from that — because a change has been released to the staging environment but not yet promoted — the entry says so and gives the date. Sub-processor list last verified against the running configuration on 2026-09-09.
The Processor currently engages the following Sub-processors:
Cloudflare, Inc. — Authoritative DNS, CDN, WAF and TLS termination for clevername.net and its subdomains. Cloudflare terminates the TLS connection at its edge and re-originates the request to Vercel, so every request to the Service passes through Cloudflare in cleartext for the duration of that hop — including calls to /api/hub/ that carry agent prompts, responses and tool arguments. Cloudflare does not persist request bodies; it retains connection metadata and WAF event records under its own retention policy. Cloudflare also operates the Tunnel and Access controls in front of the Processor's AWS GPU host. Location: global anycast edge; the Processor's origins are in the United States.
Google Cloud Platform (Google LLC) — Cloud Run compute (us-east1) for the API, Secret Manager for encrypted key storage, Cloud Storage for file storage. Also GPU Cloud Run compute in us-east4 (primary) and us-central1 (fallback) running CleverGuard's Tier-2 machine-learning content-safety classifier, CleverGuard's Tier-3 deep content-safety judge, and the Processor's internal-LLM lane (ScopeGuard mandate extraction, questionnaire extraction, agent-questionnaire prefill, scanner-miss review) — all self-hosted, Clevername-trained models, not third-party or Controller-provided models. Scanned prompt and response content reaches these models in memory for threat, policy and mandate detection and is not persisted by the Sub-processor. Location: United States.
Supabase Inc. — PostgreSQL database hosting, user authentication, and real-time services. Infrastructure hosted on AWS us-east-1. Location: United States.
Vercel Inc. — Web application hosting and edge functions for the Clevername frontend. Location: United States (global edge network).
SendGrid (Twilio Inc.) — Transactional email delivery for account notifications and security alerts. Location: United States.
Anthropic, PBC — answers for Scout, the Processor's in-app support assistant: visitor support-widget questions and the public help articles Scout retrieves are sent to Anthropic on the Processor's own key. Scout has no access to Controller agent prompts, responses, or logs. The Processor's governance lanes — ClaimGuard claim extraction, ScopeGuard mandate extraction, questionnaire extraction and scanner-miss review — are configured to run on Processor-operated GPU infrastructure (Google Cloud Run for the ScopeGuard, questionnaire-extraction and scanner-miss lanes; AWS for ClaimGuard — see below) and to fail closed: if that infrastructure is unreachable the step is skipped, not routed to Anthropic. The mandate-extraction and scanner-miss-review lanes moved onto that infrastructure on 2026-09-07. Location: United States.
OpenAI, L.L.C. — Embedding generation for the in-app support assistant (Scout) knowledge base. Support documentation and support-chat queries are sent to the OpenAI Embeddings API to compute semantic-search vectors; OpenAI does not train on API data. ScopeGuard mandate-enforcement embeddings are NOT sent to OpenAI — agent request text and configured forbidden-action descriptions are embedded by a self-hosted BGE model on the Processor's own infrastructure. The scanner-miss review lane does not send miss-report content to OpenAI; it runs on the Processor's own GPU infrastructure and fails closed. Location: United States.
Amazon Web Services, Inc. — (a) the underlying infrastructure for the Supabase database described above (us-east-1); (b) the GPU host guard-ml-aws.clevername.net, reached over a Cloudflare Tunnel, which runs ClaimGuard's claim extractor. Content sent to the extractor is processed in memory and is not persisted by the Sub-processor. Deployment status: that host has been unreachable since 2026-08-10; while it is down ClaimGuard extracts no claims rather than falling back to a third-party model. CleverGuard's Tier-2 classifier and Tier-3 judge do NOT run on AWS — they run on Google Cloud Run in us-east4 and us-central1 (Tier-2 repointed 2026-09-03, Tier-3 on 2026-09-05), as described in the Google Cloud Platform entry above. Location: United States.
Stripe, Inc. — Payment processing and subscription billing. Processes billing contact details and payment metadata; cardholder data is handled directly by Stripe as an independent controller under PCI-DSS. Location: United States.
Upstash, Inc. — Serverless Redis used for distributed rate limiting and short-lived caching of the Processor's web and API layer. Stores rate-limit counters keyed by client IP address or account identifier, small cached values with short expirations, and — for users who have not enabled I/O encryption — tool-call results cached for up to five minutes. Caches no content for users with I/O encryption enabled; never stores provider keys or customer files. Location: United States.
Functional Software, Inc. (Sentry) — Application error monitoring and performance tracing for the Processor's services. Receives error metadata only — stack traces, request route, status, timing, and user/organization identifiers — when an error occurs; request bodies (including prompts, responses, and tool arguments) are never sent from either the web or the API tier. Sampled at a low rate and used only to diagnose and fix faults. Location: United States.
The Processor shall impose the same data protection obligations as set out in this DPA on each Sub-processor by way of a contract. Where a Sub-processor fails to fulfill its data protection obligations, the Processor shall remain fully liable to the Controller for the performance of that Sub-processor's obligations.
The Controller may object to a new Sub-processor by notifying the Processor in writing within 30 days of receiving notice. If the objection is reasonable and the parties cannot reach a resolution, the Controller may terminate the affected services without penalty.
9. Data transfers
Personal Data is processed and stored in the United States. The Processor's infrastructure is located in the following regions:
- Cloudflare (DNS, CDN, WAF, TLS termination for clevername.net): global anycast edge — every request to the Service, including agent content, transits a Cloudflare edge node before reaching the Processor's origin
- GCP Cloud Run and Secret Manager: us-east1 (South Carolina, USA)
- Supabase PostgreSQL and Auth: us-east-1 (AWS, Virginia, USA)
- Vercel: United States (primary), with global edge caching for static assets
- CleverGuard Tier-2 ML classifier and Tier-3 judge: Processor-operated GPU compute on Google Cloud Run, us-east4 (primary) and us-central1 (fallback), United States
- ClaimGuard claim extractor: Processor-operated GPU host on AWS EC2, us-east-1, United States (unreachable since 2026-08-10 — see Article 8)
- Anthropic (Scout support-assistant answers), OpenAI (support-assistant knowledge-base embeddings), Stripe (billing) and Upstash (rate-limit counters and short-lived cache): United States
- Internal governance models (mandate extraction, questionnaire extraction, agent-questionnaire prefill, scanner-miss review): Processor-operated GPU compute on Google Cloud Run, us-east4 (primary) and us-central1 (fallback), United States
- ScopeGuard scope embeddings: self-hosted BGE model on Processor-operated infrastructure (United States)
Where Personal Data is transferred from the European Economic Area, the United Kingdom, or Switzerland to the United States, such transfers are conducted in reliance on:
(a) The EU-U.S. Data Privacy Framework, where applicable and to the extent the Processor or relevant Sub-processor is certified; or
(b) Standard Contractual Clauses (SCCs) as adopted by the European Commission (Commission Implementing Decision (EU) 2021/914), which are hereby incorporated by reference into this DPA. For the purposes of the SCCs, the Controller is the "data exporter" and the Processor is the "data importer"; or
(c) Any other lawful transfer mechanism recognized under applicable Data Protection Laws.
The Processor shall promptly inform the Controller if it becomes aware that it can no longer comply with the obligations under the applicable transfer mechanism.
10. Security measures
The Processor implements the following technical and organizational measures to protect Personal Data:
Encryption at rest: All data stored in GCP services and Supabase is encrypted using AES-256. API keys are encrypted in GCP Secret Manager (decrypted by the Processor only at request time to call the Controller's provider); the database stores only masked display hints. Stored agent content belonging to a user who has enabled I/O encryption is additionally encrypted per record under that user's RSA-OAEP-2048 public key with no Processor-held decryption key. Parked-approval tool arguments are envelope-encrypted under the Processor's Cloud KMS key.
Encryption in transit: All data transmitted between services uses TLS 1.2 or higher. HSTS is enforced with preload directives. The Controller's TLS session terminates at Cloudflare's edge rather than at the Processor's origin (Article 8); the hop from Cloudflare to the origin is a separate TLS connection. Transport encryption is therefore not end-to-end between the Controller and the Processor's compute.
Access control: Role-based access control (RBAC) with organizational isolation. No cross-tenant data access. Hub Core is not publicly accessible — all traffic is routed through an authenticated proxy.
Authentication: Multi-factor authentication (MFA) enforcement on sensitive operations. Session management via Supabase Auth with secure cookie handling.
Audit logging: Comprehensive audit trail with plan-based retention — 7 days (Free), 30 days (Pro), 365 days (Team), and contract-defined retention for Enterprise with no fixed platform expiry. Audit records use hash-chain integrity to detect tampering.
Rate limiting: 300 requests per minute per IP address to prevent abuse and denial-of-service attacks.
Content processing and I/O logging: AI content (prompts, responses, tool calls) is scanned in memory for security threats. The platform-wide default stores metadata only (timestamp, model, token count, latency, verdicts, and an organisation-scoped keyed content hash the Processor can compute), not prompt or response text; there is no per-organization content-logging switch. Each user may enable zero-knowledge I/O encryption, after which all stored agent content for that user (see Article 4) is encrypted under a user-held key that the Processor cannot read, with the four stated exceptions (parked-approval arguments, asynchronous tool-execution results, and the contents of files the user's agent reads, all under the Processor's KMS key; explicit training donations). This is a per-user opt-in setting, not a control the Processor applies to an organization by default. Error monitoring never receives request bodies. Governance models operated by the Processor (CleverGuard classifiers and judge, ScopeGuard extraction and embeddings, ClaimGuard extraction, questionnaire extraction, agent-questionnaire prefill, false-positive review) are configured to run on Processor-operated self-hosted infrastructure, with no fallback to a third-party model: where that infrastructure is unreachable the step is skipped or the request fails, it is not re-routed. The agent-questionnaire prefill was the last of these lanes to move, on 2026-09-14; it previously called Google's Gemini API on the Processor's key.
Infrastructure security: GCP Cloud Run operates with strict IAM policies. No public endpoints are exposed directly. Service-to-service authentication uses GCP identity tokens.
Incident response: The Processor maintains incident response procedures and will notify the Controller of any Personal Data breach in accordance with Article 11.
The Processor regularly reviews and updates these measures to address evolving security threats. The Controller acknowledges that security measures are subject to technical progress and development, and the Processor may update measures provided the overall level of security is not materially decreased.
11. Data breach notification
The Processor shall notify the Controller without undue delay, and in any event within 72 hours, after becoming aware of a Personal Data breach affecting the Controller's data.
The notification shall include, to the extent available:
(a) A description of the nature of the breach, including the categories and approximate number of Data Subjects and records concerned.
(b) The name and contact details of the Processor's point of contact for further information.
(c) A description of the likely consequences of the breach.
(d) A description of the measures taken or proposed to address the breach, including measures to mitigate its possible adverse effects.
Where it is not possible to provide all information at the same time, the Processor shall provide the information in phases without undue further delay.
The Processor shall cooperate with the Controller and take reasonable commercial steps to assist in the investigation, mitigation, and remediation of each such breach.
Breach notifications shall be sent to the Controller's designated contact or, if none is designated, to the organizational administrator's email address on file.
12. Data subject rights assistance
The Processor shall assist the Controller in responding to requests from Data Subjects exercising their rights under applicable Data Protection Laws, including:
- Right of access (Article 15 GDPR)
- Right to rectification (Article 16 GDPR)
- Right to erasure (Article 17 GDPR)
- Right to restriction of processing (Article 18 GDPR)
- Right to data portability (Article 20 GDPR)
- Right to object (Article 21 GDPR)
The Controller may fulfill Data Subject requests by contacting privacy@clevername.net (portability requests) or through the Clevername dashboard (account deletion for erasure).
Where a Data Subject contacts the Processor directly, the Processor shall promptly redirect the request to the Controller, unless the request relates to the Data Subject's own Clevername account.
The Processor shall provide reasonable assistance to the Controller in responding to Data Subject requests, taking into account the nature of the processing. Where the Processor incurs material costs in providing such assistance beyond standard account management tools, the parties shall agree on reasonable compensation.
13. Audit rights
The Controller has the right to audit the Processor's compliance with this DPA. Audits may be conducted:
(a) By the Controller or an independent third-party auditor appointed by the Controller (subject to reasonable confidentiality obligations).
(b) No more than once per calendar year, unless a data breach or material compliance concern necessitates an additional audit.
(c) Upon at least 30 days' prior written notice.
(d) During normal business hours, with reasonable scope and duration.
The Processor shall cooperate with reasonable audit requests and provide access to relevant documentation, systems, and personnel. The Processor may require the auditor to execute a confidentiality agreement before granting access to proprietary systems or security infrastructure.
The Controller shall bear its own costs of conducting the audit. If the audit reveals a material compliance deficiency, the Processor shall remediate the deficiency at its own expense within a reasonable timeframe.
The Processor may satisfy audit requests by providing:
- Relevant certifications, audit reports, or compliance documentation from Sub-processors (e.g., GCP SOC 2 reports, Supabase compliance documentation)
- Written responses to reasonable compliance questionnaires
- Evidence of the technical and organizational measures described in Article 10
14. Data deletion and return
Upon termination of the service agreement, or upon the Controller's written request, the Processor shall:
(a) Return all Personal Data to the Controller in a structured, commonly used, and machine-readable format (available via the dashboard export feature or upon request); and/or
(b) Delete all Personal Data, including all copies, from the Processor's systems and those of its Sub-processors within 30 days of the request.
The Processor shall provide written confirmation of deletion upon the Controller's request.
Exceptions to deletion:
- Audit logs associated with organizational accounts may be anonymized rather than deleted to preserve the integrity of security records. Anonymized data is no longer considered Personal Data.
- The Processor may retain Personal Data to the extent required by applicable law, provided that the Processor ensures confidentiality and processes such data only for the purpose required by law.
API keys stored in GCP Secret Manager are permanently deleted immediately upon account termination or key removal — no recovery is possible after deletion.
15. Governing law
This DPA shall be governed by and construed in accordance with the laws that govern the underlying Terms of Service between the parties.
To the extent that this DPA relates to the processing of Personal Data of Data Subjects in the European Economic Area, the relevant provisions of the GDPR shall apply regardless of the governing law of the Terms of Service.
For Data Subjects in the United Kingdom, the UK GDPR and the Data Protection Act 2018 shall apply to the extent required by law.
In the event of any conflict between this DPA and the Terms of Service, this DPA shall prevail with respect to the processing of Personal Data.
This DPA is effective as of the date the Controller accepts the Terms of Service or begins using the Service, whichever is earlier.
Contact
For questions about this Data Processing Agreement or data protection matters:
Data protection inquiries: privacy@clevername.net
Security concerns: security@clevername.net
General legal: legal@clevername.net
Floyd Media LLC
Georgia, United States