Draft data processing agreement

Version 1.1 (draft for customer and counsel review), July 12, 2026

This page is a working template published for customer and counsel review. It is not an offer, is not signable or binding as published, and is not incorporated into self-serve agreements. A DPA applies only when an execution copy is signed by authorized representatives or expressly incorporated into a signed customer agreement. Contact [email protected] to begin that review.

1. Parties and definitions

This Data Processing Agreement (the "DPA") is entered into between Klarefi("Klarefi," "Processor") and the customer identified in the applicable customer agreement or Order Form ("Customer," "Controller"). It applies to the extent Klarefi processes personal data on behalf of Customer in connection with the Services.

In this DPA:

  • "GDPR" means Regulation (EU) 2016/679, and where applicable the equivalent provisions of the UK GDPR.
  • "personal data," "processing," "controller," "processor," "data subject," and "supervisory authority" have the meanings given in the GDPR.
  • "Customer Personal Data" means personal data contained in Customer Data that Klarefi processes on behalf of Customer under the customer agreement.
  • "Services" has the meaning given in the customer agreement or, absent one, in the Terms of Service.
  • "Subprocessor" means a third party engaged by Klarefi to process Customer Personal Data on behalf of Customer.

This DPA forms part of, and is governed by, the customer agreement between the parties. In the event of a conflict between this DPA and the customer agreement regarding the processing of Customer Personal Data, this DPA controls.

2. Subject matter, duration, nature and purpose of processing

The subject matter of the processing is the provision of the Services: hosted intake experiences, document upload and processing, AI-assisted extraction and verification, gap resolution, workflow routing, operator review, reporting, and integrations, as configured by Customer.

The duration of the processing is the term of the customer agreement, plus any limited retention period required for deletion or return under section 9.

The nature and purpose of the processing is the collection, storage, organization, structuring, extraction, analysis, retrieval, disclosure to Customer, and deletion of Customer Personal Data as necessary to deliver the Services to Customer and as further described in Annex 1.

3. Categories of data subjects and personal data

Categories of data subjects typically include:

  • applicants, claimants, and other end users who submit information through Customer-configured intake workflows;
  • Customer employees, administrators, and authorized users of the Services; and
  • other individuals whose personal data is contained in documents or submissions provided through Customer workflows.

Categories of personal data typically include:

  • identity and contact data, such as names, email addresses, phone numbers, and postal addresses;
  • case documents and their contents, including uploaded files, scanned documents, photographs, and attachments, together with any personal data those documents contain;
  • structured and free-text intake responses, identifiers, and reference numbers; and
  • workflow, review, and audit metadata generated in the normal operation of the Services.

Customer determines what information its workflows request. Where Customer workflows involve special categories of personal data, Customer is responsible for ensuring a valid legal basis and any required additional safeguards. Annex 1 summarizes the processing details.

4. Roles of the parties

For Customer Personal Data processed through the Services, Customer is the controller (or, where Customer acts on behalf of another controller, a processor with authority to engage Klarefi as a subprocessor) and Klarefi is the processor. Customer determines the purposes and means of the processing, including the intake questions, workflow rules, review requirements, and retention settings it configures.

This DPA does not apply to personal data Klarefi processes as a controller for its own purposes, such as account administration, billing, website operations, security, and privacy-minimized service telemetry used for service reliability and improvement where Klarefi independently determines those purposes. Such telemetry excludes raw applicant documents, case content, extracted values, and evidence text; Klarefi will not use it to reconstruct case content or identify an applicant. That processing is described in the Privacy Policy.

5. Processor obligations

Klarefi will:

  • process Customer Personal Data only on documented instructions from Customer, including with regard to international transfers, unless required to do otherwise by EU or member state law to which Klarefi is subject. In that case Klarefi will inform Customer of the legal requirement before processing, unless the law prohibits such notice. The customer agreement, this DPA, and Customer's use and configuration of the Services constitute Customer's documented instructions;
  • inform Customer if, in Klarefi's opinion, an instruction infringes the GDPR or other applicable data protection law;
  • ensure that persons authorized to process Customer Personal Data have committed themselves to confidentiality or are under an appropriate statutory obligation of confidentiality;
  • implement and maintain the technical and organizational measures described in Annex 2, taking into account the state of the art, costs of implementation, and the nature, scope, context, and purposes of the processing;
  • not use applicant documents, case content, extracted facts, evidence, or Customer Personal Data to train models shared across customers or for unrelated purposes;
  • use Customer Personal Data in a customer-specific evaluation only on Customer's documented instructions and solely to provide, validate, or improve the Services for that Customer, subject to the agreed access, residency, retention, and deletion controls; and
  • notify Customer without undue delay after becoming aware of a personal data breach affecting Customer Personal Data, and provide information reasonably available to Klarefi to support Customer's obligations under Articles 33 and 34 GDPR.

6. Subprocessors

Customer grants Klarefi general written authorization to engage Subprocessors for the processing of Customer Personal Data. The current list of Subprocessors is published at klarefi.com/subprocessors and is incorporated into this DPA by reference.

Klarefi will impose data protection obligations on each Subprocessor that are materially no less protective than those in this DPA, and remains liable to Customer for the performance of each Subprocessor's obligations.

Klarefi will give Customer notice of any intended addition or replacement of a Subprocessor by updating the subprocessor page and, for customers subscribed to change notifications, by email at least fourteen (14) days before the change takes effect. Customer may object to the change on reasonable data protection grounds within that notice period. If the parties cannot resolve the objection in good faith, Customer may terminate the affected Services and receive a pro rata refund of prepaid fees for the terminated portion.

7. International transfers

Klarefi stores and processes Customer Personal Data in the EU by default. Where a Subprocessor processes Customer Personal Data outside the EEA, or where a deployment-specific configuration involves such processing, Klarefi will ensure a valid transfer mechanism under Chapter V GDPR, which may include the European Commission's standard contractual clauses, an adequacy decision, or another recognized transfer tool.

Deployment-specific residency commitments, where agreed, are set out in the applicable Order Form or customer agreement.

8. Assistance to Customer

Taking into account the nature of the processing, Klarefi will assist Customer by appropriate technical and organizational measures, insofar as this is possible, in fulfilling Customer's obligation to respond to data subject requests under Chapter III GDPR (access, rectification, erasure, restriction, portability, and objection). The Services include data subject export and erasure tooling; where a request cannot be handled through the Services, Klarefi will provide reasonable assistance on request.

Klarefi will further assist Customer in ensuring compliance with Articles 32 to 36 GDPR (security of processing, breach notification, data protection impact assessments, and prior consultation), taking into account the nature of the processing and the information available to Klarefi.

If a data subject contacts Klarefi directly regarding personal data processed on behalf of Customer, Klarefi will direct the data subject to Customer where the relevant Customer can be identified, and will not respond substantively except as required by law.

9. Deletion or return on termination

Upon termination or expiry of the customer agreement, Klarefi will, at Customer's choice, delete or return Customer Personal Data and delete existing copies, unless EU or member state law requires continued storage. Customer may export Customer Personal Data through the Services before termination, and may request export assistance.

Where Customer has configured retention settings in the Services, those settings apply during the term. Residual copies in backups are deleted in the ordinary course of Klarefi's backup rotation and remain protected by this DPA until deleted.

10. Audit rights

Klarefi will make available to Customer information reasonably necessary to demonstrate compliance with Article 28 GDPR, including responses to reasonable written security questionnaires and available third-party attestations or reports for Klarefi's infrastructure providers.

Where that information is insufficient to demonstrate compliance, Klarefi will allow for and contribute to audits, including inspections, conducted by Customer or an independent auditor mandated by Customer, provided that: audits occur no more than once in any twelve (12) month period unless required by a supervisory authority or following a personal data breach; are conducted on reasonable prior written notice of at least thirty (30) days, during normal business hours, without disrupting operations; are subject to confidentiality obligations; and are at Customer's cost.

11. Liability

The liability of each party under this DPA is subject to the exclusions and limitations of liability set out in the customer agreement. Nothing in this DPA limits either party's liability to data subjects under the GDPR.

12. Final provisions

This DPA takes effect on the effective date of the customer agreement it forms part of, and remains in force for as long as Klarefi processes Customer Personal Data. If any provision of this DPA is held invalid, the remainder stays in effect, and the parties will replace the invalid provision with a valid one that most closely reflects its intent.

Klarefi may update this DPA for future contract terms; the version incorporated into a signed customer agreement continues to govern that agreement unless the parties agree otherwise.

Annex 1: processing details

Subject matterProvision of the Klarefi intake platform: hosted intake, document processing, AI-assisted extraction, review workflows, and integrations.
DurationTerm of the customer agreement, plus the deletion or return period in section 9.
Nature and purposeCollection, storage, structuring, extraction, analysis, disclosure to Customer, and deletion of intake data as necessary to deliver the Services.
Categories of data subjectsApplicants, claimants, and end users submitting information through Customer workflows; Customer employees and authorized users; individuals referenced in submitted documents.
Categories of personal dataIdentity and contact data; case documents and their contents; structured and free-text intake responses; identifiers and reference numbers; workflow, review, and audit metadata.
Special categoriesOnly where Customer configures workflows that request them. Customer is responsible for the legal basis and any additional safeguards.
FrequencyContinuous, for the duration of the customer agreement.
Processing locationCase content and primary application/AI processing are EU-hosted by default. Other disclosed provider locations are listed at klarefi.com/subprocessors.

Annex 2: technical and organizational measures

Klarefi maintains the following technical and organizational measures for Customer Personal Data. A longer-form description is available on the security page and in diligence materials on request.

  • Encryption in transit and at rest. Data in transit over public networks is protected with TLS, with HSTS enabled on the application. Customer documents and extracted data are encrypted at rest by the managed EU data platform. Connector and webhook secrets are additionally application-encrypted, and production deployments fail closed if encryption keys are not configured.
  • Tenant isolation. Application data is organization-scoped end to end. Organization membership is verified server-side on every request, and every data query is scoped to the verified organization, designed so one customer cannot read or query another customer's records.
  • Access control and authentication. Operator and administrative surfaces require authenticated access with organization-scoped roles and permission checks. Enterprise deployments can use single sign-on. API keys are generated with high entropy, stored only as hashes, scoped, and rate limited. Applicant intake sessions are protected by per-session secrets rather than shared credentials.
  • Audit logging. Append-only audit records cover intake submissions, workflow state changes, operator and administrative actions, consent capture, privacy requests, and reads of case data. Audit tables have no update or delete mutations by construction.
  • EU data residency by default. Customer case content, primary application storage, document parsing, and AI inference are EU-hosted by default. The UI tier handles case data while rendering but does not persist customer documents locally. Limited identity, billing, email, status, and encrypted-backup provider paths are disclosed on the subprocessor page. Deployment-specific commitments are set out in the customer agreement.
  • No shared-model training on case content. Applicant documents, case content, extracted facts, evidence, and Customer Personal Data are not used to train models shared across customers. AI processing is inference scoped to the requested workflow. Customer-specific evaluations using case material require documented instructions and remain subject to this DPA. Klarefi may use privacy-minimized operational telemetry that excludes raw documents, extracted values, and evidence text to operate, secure, evaluate, and improve the service in accordance with the applicable agreement and law.
  • Data subject rights tooling. The platform includes subject data export and scoped erasure that removes stored records and their file storage, supporting Customer's obligations under Chapter III GDPR.
  • Secure development and operations. Code changes go through review and automated testing. Input validation, outbound request safeguards, security headers, rate limits, and fail-closed production configuration checks are applied across the service. Personnel access to production systems is restricted and secrets are managed outside source control.