Sign in or contact us
Sign in to accept the DPA per company you administer, or email [email protected] for a counter-signed PDF or to request edits.
Roles and terminology
“Customer Personal Data” means personal data Clawviyo processes on the merchant’s behalf in connection with the platform — primarily inquiry content, the verified-human email associated with that inquiry, and merchant-side CRM metadata. The merchant is the “Controller” and Clawviyo is the “Processor.” Other terms (Personal Data, Processing, Data Subject, Supervisory Authority) carry the meaning given in EU GDPR Article 4.
What Clawviyo does and doesn’t do
Clawviyo processes Customer Personal Data only to (a) operate the platform for the merchant, (b) prevent abuse and fraud across the network, (c) meet legal obligations, and (d) follow the merchant’s documented instructions, which include the merchant’s configuration of MCP tools, qualification rules, and notification targets. Clawviyo does not sell Customer Personal Data, does not use it to train AI models, and does not share it with the merchant’s competitors.
Authorized sub-processors
Clawviyo uses the sub-processors listed at /sub-processors. The merchant grants general authorization to engage these sub-processors. Clawviyo will give at least 14 days’ email notice before engaging a new sub-processor; the merchant may object on reasonable data-protection grounds during that window.
EEA / UK transfers
Where Customer Personal Data is transferred from the EEA, UK, or Switzerland to a country without an adequacy decision, the transfer is governed by the EU Standard Contractual Clauses (Module 2: Controller to Processor, 2021/914) and, for UK transfers, the UK International Data Transfer Addendum, both incorporated by reference. Clawviyo’s production infrastructure today runs in AWS us-west-2.
Technical and organizational measures
- TLS 1.2+ for all data in transit; AES-256 encryption at rest in the database.
- Principle of least privilege: service-role database access is limited to API routes; admin-scoped reads use Postgres row-level security.
- OAuth 2.1 with PKCE for AI assistant integrations; bearer tokens are stored hashed.
- Slack bot tokens encrypted at rest with a separate key.
- Daily automated retention sweep enforces the windows in the privacy policy.
- Access to production by Clawviyo personnel is restricted to a small number of named operators authenticated via SSO + 2FA.
72 hours
Clawviyo will notify affected merchants without undue delay and in any event within 72 hours of becoming aware of a Personal Data Breach affecting Customer Personal Data, with the information needed for the merchant to meet its own Article 33 obligations.
Cooperation
Clawviyo will assist the merchant in fulfilling data subject access, rectification, erasure, portability, restriction, and objection requests. The dashboard exposes inquiry data the merchant can self-serve; for cross-cutting requests, contact [email protected].
Information rights
Clawviyo will make available the information necessary to demonstrate compliance with this DPA. For merchants with regulated audit obligations, Clawviyo will cooperate with reasonable audits subject to mutual NDA, on no more than once per 12 months absent a material incident.
End of processing
On termination, Clawviyo will delete Customer Personal Data within 30 days, except to the extent a backup copy is retained under standard rotation (deleted at next cycle, not later than 90 days), or where law requires longer retention. Aggregate cross-merchant fraud signals are retained in de-identified form indefinitely.
Order of precedence
This DPA is governed by the law specified in the Terms of Use. In case of conflict with the Terms of Use, this DPA controls for matters of data protection. Clawviyo may update this DPA to reflect changes in law or sub-processors; material changes require a new acceptance from the merchant. The version below is binding once the merchant clicks accept.