Skip to content
ClaireAI

Data Processing Addendum

This Data Processing Addendum is part of ClaireAI’s Terms of Service whenever ClaireAI processes Customer Personal Data for a customer. Acceptance of the Terms incorporates this DPA without a separate signature. It establishes processing instructions, confidentiality, security, subprocessor, assistance, deletion, and international-transfer obligations for the services described below.

Version 1 · Last updated: September 4, 2026 · Issued by Claire AI, LLC

1. Parties, scope, and precedence

This DPA is between Claire AI, LLC (“ClaireAI”) and the Customer identified in the accepted Terms or Order Form (“Agreement”). Customer Personal Data is personal information in Customer Data processed by ClaireAI on Customer’s behalf. “Data Protection Law” means privacy and data-protection laws applicable to that processing, including the GDPR, UK GDPR, Swiss Federal Act on Data Protection, and applicable U.S. state privacy laws, including the CCPA as amended. Other capitalized terms have the Agreement’s meanings.

Customer is the controller or business, and ClaireAI is the processor or service provider; where Customer is itself a processor, ClaireAI is a subprocessor and Customer warrants that its controller authorized these instructions. ClaireAI’s independent processing of account and business information is described in the Privacy Policy. This DPA controls processing conflicts with the Agreement. The transfer clauses in section 10 prevail over inconsistent terms, including audit, liability, dispute-resolution, and third-party-rights restrictions. A separately executed DPA controls only to the extent legally permitted.

This DPA does not authorize HIPAA-regulated processing or constitute a business associate agreement. Such processing requires ClaireAI’s express agreement to support it and a separately executed BAA.

2. Instructions and permitted purposes

Customer instructs ClaireAI to process Customer Personal Data only to perform the services described in Annex I, follow documented settings and authorized support requests, protect those services, and comply with applicable law. The Agreement, this DPA, and Customer’s authorized configuration and written instructions constitute documented instructions, including for transfers. Additional instructions must be lawful and within the purchased services; additional assistance may be scoped and charged at reasonable rates where permitted by law.

ClaireAI will not process Customer Personal Data for unrelated commercial purposes, sell it, share it for cross-context behavioral advertising, or use it to train a general-purpose or public foundational model. Customer Personal Data will not be combined with information obtained from another customer or from ClaireAI’s own interactions with individuals except as expressly permitted by Data Protection Law for the specified service purposes. Aggregated or de-identified information may be used only consistently with applicable law, confidentiality, and the Agreement’s safeguards against identification; identifiable information is not exempt merely because it is labeled Usage Data.

ClaireAI will inform Customer promptly if, in its opinion, an instruction infringes Data Protection Law and may suspend that instruction while the parties resolve the issue. If law requires processing outside Customer’s instructions, ClaireAI will notify Customer before that processing unless the law prohibits notice. Customer remains responsible for a lawful basis, required sensitive-data conditions, accurate instructions, privacy notices, communications consent, and the lawfulness of its underlying legal practice.

3. U.S. processor and service-provider terms

For applicable state law, the specified business purposes are intake and communications delivery, customer-directed scheduling and integrations, account support for those functions, troubleshooting, and service security as described in Annex I. ClaireAI will not retain, use, or disclose personal information outside those purposes or the direct business relationship with Customer, except as the applicable law expressly permits. ClaireAI certifies that it understands these restrictions and will comply with them.

ClaireAI will provide the level of privacy protection required by applicable law, notify Customer if it can no longer meet its obligations, and allow Customer to take reasonable and appropriate steps to verify consistent processing and to stop and remediate unauthorized use. Section 9 supplies the ordinary verification process and does not restrict a mandatory statutory right. ClaireAI will cooperate in reasonable assessments and provide information needed for Customer’s legally required privacy assessments.

4. Confidentiality and security

ClaireAI will ensure persons authorized to process Customer Personal Data are bound by confidentiality obligations or an appropriate statutory duty, and limit access to their authorized responsibilities. ClaireAI will maintain technical and organizational measures appropriate to the processing risks, including the measures in Annex II, and will not materially reduce their overall protection during the term.

Customer must secure its own accounts, endpoints, integrations, and authorized-user access and configure the services consistently with its data classification. No particular certification or service-level commitment is implied by this DPA; separately agreed security commitments remain enforceable.

5. Subprocessors

Customer generally authorizes the subprocessors on the Subprocessor List for the listed functions. ClaireAI will enter into written obligations with each subprocessor providing substantially the same protection as this DPA to the extent relevant to its work, including lawful processing, confidentiality, security, and use restrictions. ClaireAI remains responsible to Customer for its subprocessors’ performance of those obligations.

ClaireAI will provide at least 30 days’ advance notice of an intended addition or replacement by email to Customer’s account notice contact, including the provider, function, and processing-location information. Customer may object within that period on reasonable, documented data-protection grounds. The parties will work in good faith on an alternative or mitigation before the new provider processes the affected data. If no reasonable solution is available, Customer may terminate the affected service before the change takes effect and receive a refund of unused prepaid fees for that service. A general website update alone does not replace the promised notice.

A system that Customer independently contracts with and directs ClaireAI to connect is governed by Customer’s arrangement with that provider. ClaireAI must still protect and lawfully transmit data at the integration boundary. Classification depends on the actual relationship; calling a provider an integration does not exclude it from subprocessor obligations when ClaireAI engages it to process on Customer’s behalf.

6. Personal-data incidents

A “Personal Data Breach” is a breach of security leading to accidental or unlawful destruction, loss, alteration, unauthorized disclosure of, or access to Customer Personal Data. ClaireAI will notify Customer without undue delay after becoming aware of a Personal Data Breach. Notification will go to the designated security contact, or the account notice contact if no security contact is designated.

As information becomes available, ClaireAI will describe the nature of the breach, affected data and individuals and approximate numbers where known, likely consequences, mitigation or remedial measures, and a contact for follow-up. Initial notice need not await a completed investigation; information may be provided in phases without undue further delay. ClaireAI will take reasonable containment and remediation steps, preserve relevant evidence, and cooperate with Customer’s legally required response. Notice is not an admission of liability.

Customer determines notices to individuals and authorities unless applicable law requires ClaireAI to act directly. Unsuccessful attempts that do not compromise Customer Personal Data are not Personal Data Breaches, although ClaireAI may report them voluntarily.

7. Assistance and requests

Taking into account the nature of processing and information available to it, ClaireAI will reasonably assist Customer with data-subject requests, security obligations, breach notifications, data-protection impact assessments, and prior consultations required by Data Protection Law. ClaireAI will promptly forward requests it receives concerning Customer Personal Data and will not independently respond substantively except on instructions or as law requires.

ClaireAI will assess binding government requests, seek to limit unlawful or disproportionate demands where appropriate, disclose only legally required data, and notify Customer where permitted. Transfer-clause obligations concerning access requests, documentation, and challenges remain controlling. Reasonable charges for extraordinary assistance may be agreed in advance where lawful, but do not excuse mandatory assistance and do not apply to remediation of ClaireAI’s own breach of this DPA.

8. Return, deletion, and retained copies

At termination or Customer’s lawful instruction, Customer may elect return of Customer Personal Data in an available commonly used format and deletion of remaining copies, or deletion without return. Customer should communicate its choice before termination or within 30 days afterward; if no choice is received, ClaireAI will delete the data. ClaireAI will complete return or deletion without undue delay and within 60 days of the applicable instruction or end of that election period, unless a shorter period is legally required. Return may be provided through secure assistance after ordinary portal access ends.

Copies whose retention is required by law remain isolated and protected, are used only for that required purpose, and are deleted when the requirement ends. Backup copies may remain isolated until overwritten in the ordinary backup deletion cycle; ClaireAI will disclose the applicable cycle on request, prohibit ordinary use, and reapply deletion if a backup is restored. Security or audit labels do not permit indefinite retention or unrelated use. ClaireAI will procure corresponding deletion by subprocessors and confirm completion on written request, identifying any lawful retention exception.

Customer is responsible for its own required archives and for copies transferred to systems it controls. ClaireAI does not provide a legal-hold or evidentiary-preservation system. These obligations do not require destruction of records ClaireAI must lawfully retain in its independent controller role, provided that role is not used to evade this DPA.

9. Verification and audits

ClaireAI will make information reasonably necessary to demonstrate compliance available to Customer. Ordinarily, this begins with relevant current security documentation and independent reports, including SOC 2 reports if available, subject to confidentiality or an NDA. Providing such a report does not imply ClaireAI holds an attestation that has not been expressly identified.

When those materials are insufficient to satisfy a legally required audit right, ClaireAI will allow and contribute to a proportionate audit by Customer or an independent qualified auditor bound by confidentiality. The parties will first agree on scope, reasonable advance notice, business-hour access, and safeguards against disruption or exposure of other customers’ data, secrets, or privileged material. Routine audits are limited to once annually; that limit and advance-notice requirements do not restrict regulator demands, mandatory transfer-clause rights, or additional audits reasonably needed following a breach or credible evidence of noncompliance.

Customer normally bears its audit costs and ClaireAI’s reasonable agreed costs, except where law requires otherwise or an audit establishes ClaireAI’s material noncompliance. Security-sensitive testing requires an agreed safe method. Cost, NDA, and scheduling terms may not prevent an audit required by Data Protection Law or the transfer clauses.

10. International transfers

ClaireAI will transfer Customer Personal Data only in accordance with Data Protection Law and Customer’s documented instructions. The parties will complete any required transfer assessment and implement appropriate supplementary measures before relying on a transfer mechanism. Where the mechanism or applicable measures cannot lawfully support the transfer, the affected processing must be suspended until a lawful alternative is available.

EEA transfers

For a restricted transfer to ClaireAI that falls within their permitted scope, the standard contractual clauses annexed to Commission Implementing Decision (EU) 2021/914 (“EU SCCs”) are incorporated without modification. Module Two applies when Customer is controller; Module Three applies when Customer is processor. The optional docking clause 7 applies; clause 9 uses general written authorization with the 30-day notice in section 5; the optional language in clause 11 is omitted. Clause 17 uses Option 1 and the law of Ireland; clause 18 designates the courts of Ireland. The competent supervisory authority is determined under clause 13 by Customer’s establishment, representative, or affected data subjects. The parties accept the EU SCCs by accepting the Agreement; Annexes I–III below supply their Appendix information.

UK transfers

For restricted transfers under UK law, the ICO’s International Data Transfer Addendum, version B1.0 effective 21 March 2022, applies to the EU SCCs, as revised under its mandatory provisions. Table 1 uses the parties and contacts in Annex I and the Agreement’s acceptance date. Table 2 selects the EU SCCs and modules and options stated above. Table 3 uses Annexes I–III. For Table 4, either party may end the Addendum as allowed by section 19 of its mandatory clauses. Part 2’s mandatory clauses are incorporated and prevail where required.

Swiss transfers

For transfers governed by Swiss law, the EU SCCs also protect Swiss data subjects, references to GDPR include the applicable Swiss law, and the competent authority is the Swiss Federal Data Protection and Information Commissioner where the transfer is subject exclusively to Swiss law. References to a Member State do not exclude Swiss individuals from enforcing their rights in Switzerland. Where GDPR also applies, its protections and supervisory authority remain intact.

ClaireAI does not rely on a claim that Claire AI, LLC is Data Privacy Framework certified. The Agreement’s general arbitration clause and liability cap do not override mandatory transfer rights, liabilities, or remedies.

Annex I. Parties and processing description

Data exporter: Customer, with legal name, address, authorized representative, and privacy contact recorded in its Order Form or account details. Customer is controller or processor as described in section 1. Customer must keep those details current and provide any missing transfer information before a restricted transfer. Its relevant activity is using ClaireAI for authorized intake and firm operations.

Data importer: Claire AI, LLC, 4410 NW 5th Ave, Boca Raton, FL 33431, United States; contact: info@theclaireai.com, Privacy Officer. ClaireAI acts as processor or subprocessor and provides the contracted intake services. The acceptance date of the Agreement is the parties’ execution date for this DPA and incorporated transfer terms.

Individuals: callers, leads, prospective and existing clients, people mentioned in inquiries or conflict records, firm personnel, and other people whose information Customer lawfully supplies.

Categories: identity and contact details; call audio and transcripts; message content and consent evidence; legal-inquiry and conflict information; scheduling records; customer-specific summaries and classifications; configuration and integration data; and operational or delivery metadata necessary for these services.

Sensitive information: callers may disclose health, criminal allegations or convictions, family circumstances, financial information, or other information requiring additional protection. Processing is limited to lawful Customer instructions and necessary service purposes, with confidentiality, access restrictions, and minimization. Customer must establish required special-category and criminal-data conditions. HIPAA-regulated information is excluded without a separate supported arrangement and executed BAA.

Nature, purpose, and frequency: ongoing collection, transmission, hosting, retrieval, transcription, AI inference, organization, customer-directed routing and integration, troubleshooting, protection, return, and deletion for intake and related firm operations. Processing is continuous or event-driven as Customer uses the service; it does not authorize an independent legal decision-making purpose.

Duration: the service term plus the limited return, deletion, and lawful retention periods in section 8. The subject matter and subprocessor processing duration are the relevant services and the same applicable retention restrictions.

Annex II. Technical and organizational measures

The following measures form ClaireAI’s security obligations for Customer Personal Data. Their implementation is proportionate to each system’s function and risk; Customer may request supporting documentation under section 9.

  • Access and tenant separation: authenticate portal and API users; enforce server-side roles and tenant scope; restrict privileged administrative operations and retain relevant access or change records.
  • Transmission and credentials: use protected network connections for supported service endpoints, restrict credentials to approved operational stores, protect integration tokens, and validate authenticated integration boundaries.
  • Storage protection: apply access restrictions and risk-appropriate encryption to stores containing Customer Personal Data, with provider and configuration details available for the relevant service on request.
  • Service integrity: validate relevant provider callbacks, restrict untrusted outbound destinations, control privileged changes, and review code before release through the applicable deployment process.
  • Operations: maintain monitoring, incident-response procedures, controlled access to diagnostic information, data-minimization practices, and a process to address identified security weaknesses.
  • Resilience and lifecycle: maintain safeguards for restoration and availability appropriate to the service; limit backup access; implement Customer return and deletion instructions and applicable retention controls; periodically assess the effectiveness of these measures.
  • People and providers: require confidentiality for authorized personnel, communicate relevant data-handling duties, restrict subprocessor access to its function, and assess whether provider measures meet the applicable processing risk.

No fixed cryptographic algorithm, universal staff MFA coverage, certification, penetration-test schedule, restoration time, or uninterrupted availability is represented unless expressly stated in a separately agreed security exhibit supported by current evidence.

Annex III. Subprocessor information

The Subprocessor List identifies providers and functions. The approved list at acceptance and changes made under section 5 form this annex. Customer may obtain applicable location, contact, safeguard, and processing-scope information by contacting ClaireAI. Missing information needed for a lawful restricted transfer must be supplied and assessed before that transfer occurs.

11. Contact and duration

This DPA remains effective while ClaireAI holds Customer Personal Data. Amendments follow the Agreement’s notice and acceptance process and may not diminish mandatory protections or silently modify the incorporated transfer clauses.

Claire AI, LLC · Attn: Privacy Officer
4410 NW 5th Ave
Boca Raton, FL 33431, United States
info@theclaireai.com
+1 (954) 997-0065