Data Processing Agreement (DPA)
Last updated: 2026-01-15
Purpose
This Data Processing Agreement (“DPA”) supplements the master agreement between Sales Led Oy (“Clevenio”, Processor) and the customer (Controller) when Clevenio processes personal data on the Controller’s behalf.
Subject matter
Clevenio processes personal data necessary to deliver the Service: company and contact information ingested by the Controller, communication metadata generated by Sequences, and CRM records synced via integrations.
Duration
The DPA is in force for as long as Clevenio processes personal data on the Controller’s behalf, plus the retention periods set out in the Privacy Policy.
Sub-processors
Clevenio uses a limited set of cloud and email sub-processors (current list available on request). Sub-processor changes are notified to the Controller in advance.
Security
Clevenio applies industry-standard technical and organisational measures: encryption in transit and at rest, role-based access, audit logging, regular vulnerability scans, and incident response procedures.
International transfers
Where data is transferred outside the EU/EEA, transfers are protected by Standard Contractual Clauses or another lawful mechanism.
Data subject requests
Clevenio assists the Controller in responding to access, rectification, deletion, and portability requests from data subjects.
Termination
On termination, Clevenio deletes or returns personal data within 30 days, except where retention is required by law.
For an executable copy of this DPA, contact legal@clevenio.com.