Skip to content
C50 Clause50EU AI Act transparency — made auditable.EU AI Act evidence, made auditable
Legal

Data Processing Agreement

Version 2026-07-dpa-1 · Effective 2026-07-26

The instrument governing Clause50's processing of your customers' data as a processor.

Parties

Data controller: B N Atre, trading as Clause50

Address: Bangalore, Karnataka, India — PIN 560017

Country of establishment: India

Privacy contact: admin@clause50.com

A sole proprietorship has no legal personality separate from its owner — the controller named above is the natural person, not a company.

This Data Processing Agreement forms part of, and is accepted by reference from, Terms of Service. It applies whenever Clause50 processes personal data on your instructions as your processor, under Art. 28 GDPR.

Subject-matter and duration

Subject-matter: processing of the AI-system metadata, evidence, and related personal data you submit to Clause50, for the purpose of generating and maintaining EU AI Act evidence artifacts. Duration: for as long as your account is active, plus the operator-assisted deletion/return process on termination described below.

Instructions

Clause50 processes personal data only on your documented instructions — the actions you take in the product (connector configuration, manual imports, uploads, artifact generation) constitute those instructions. We will inform you if an instruction, in our reasonable view, infringes GDPR or another applicable data-protection law.

Confidentiality

Anyone processing your data on our behalf is bound to confidentiality. Connector credentials are sealed-box encrypted at the application layer and are never returned in plaintext by any part of the product, including our own internal support tooling.

Security measures (Art. 32)

Summary of the technical and organisational measures in place today:

  • Connector credentials sealed-box encrypted at rest; never logged or returned in plaintext.
  • Two independent layers of tenant isolation on every data path, backed by a standing automated cross-tenant test.
  • Tamper-evident, hash-chained evidence and activity records, cryptographically signed generated documents, and offline verification tooling.
  • Fail-closed authorization: an unconfigured or misconfigured access control denies access, never grants it.
  • Every cross-tenant support access by a Clause50 operator is itself audited into your own account's activity trail.

We are equally honest about current limits: data at rest is not encrypted at the application layer beyond connector credentials (it relies on our infrastructure providers' disk/storage encryption), and role-based permissions within an organisation are not yet enforced beyond account ownership. These are tracked internally and are available on request for a security questionnaire.

Subprocessing

We use a limited set of subprocessors, listed with their function and location at Subprocessors. We will notify you of any new subprocessor before it is used to process your data.

Assistance with data-subject requests

We will assist you, taking into account the nature of the processing, in responding to requests from data subjects to exercise their GDPR rights, and in meeting your own obligations around security, breach notification, and data-protection impact assessments where these concern data we process on your behalf.

Breach notification

If we become aware of a personal-data breach affecting your data, we will notify you without undue delay, describing what happened, the categories and approximate number of records affected, and the measures taken or proposed.

Deletion and return on termination

On termination, we will delete or return your data. Because evidence and activity records are held in tamper-evident append-only chains, deletion is performed at the whole-organisation or whole-system level rather than by editing individual records — the same operator-assisted, audited procedure described in our Privacy Policy. Cancellation alone does not trigger deletion: already-signed artifacts remain available to you throughout the read-only period described in our Refund and Cancellation Policy, because they are your evidence of what was true when they were generated. That read-only period is 6 monthsfrom cancellation, after which account data is deleted per the retention terms above.

Audit rights

On reasonable notice, we will provide information reasonably necessary to demonstrate compliance with this DPA, including our Art. 25/32 technical-measures summary above in fuller written form.

International transfers

Clause50 is established in India. If you are established in the EU/EEA, your transfer of personal data to us as processor is a restricted transfer under GDPR Chapter V. We intend to add a Standard Contractual Clauses (Module 2) annex to this DPA ahead of onboarding our first EU-established business customer — contact admin@clause50.com if you need this in place sooner.