Legal

Data Processing Addendum

Last updated

How we handle your clients’ personal data on your behalf when you use Clientwharf.

1. Scope and incorporation

This Data Processing Addendum (“DPA”) is between the customer that holds a Clientwharf workspace (“Customer”) and Goohoost Ltd, trading as Clientwharf, a private limited company registered in England and Wales under company number 17040971, with its registered office at First Floor Office, 3 Hornton Place, London, W8 4LZ, United Kingdom (“Processor”, “we”). It applies whenever we process Customer Personal Data on the Customer’s behalf in providing Clientwharf.

This DPA is incorporated into and forms part of our Terms of Service. By accepting the Terms, the Customer also accepts this DPA, so no separate signature is needed. If the Customer needs a countersigned copy for its records, email legal@clientwharf.com.

If this DPA conflicts with the Terms on the processing of Customer Personal Data, this DPA prevails. If the Standard Contractual Clauses apply and conflict with this DPA, the Standard Contractual Clauses prevail.

2. Definitions

  • Data Protection Laws: all laws on the processing of personal data that apply to the processing under this DPA, including the EU General Data Protection Regulation 2016/679 (“GDPR”), the UK GDPR and Data Protection Act 2018, the Swiss Federal Act on Data Protection, and US state privacy laws where applicable.
  • Customer Personal Data: personal data in Customer Content (as defined in the Terms) that we process on the Customer’s behalf.
  • Controller, processor, data subject, personal data, processing, personal data breach and supervisory authority have the meanings given in the GDPR.
  • Subprocessor: any third party we engage to process Customer Personal Data.
  • Standard Contractual Clauses or SCCs: the clauses adopted by European Commission Implementing Decision (EU) 2021/914, and, for UK transfers, the UK International Data Transfer Addendum to them.

3. Roles of the parties

The Customer is the controller (or a processor acting for its own controller) of Customer Personal Data, and we are its processor (or subprocessor). The Customer is responsible for the lawfulness of the processing it instructs, including having a lawful basis for sharing data with us and with the client contacts it invites, and for giving data subjects any required notices.

We act as an independent controller only for the limited data described in our Privacy Policy, such as account, billing and security data.

4. Details of the processing

Details of the processing
ItemDescription
Subject matterProviding the Clientwharf client portal service to the Customer under the Terms.
DurationFor the term of the Customer's use of the Service, plus the read-only and deletion periods described in "Deletion and return of data" below.
Nature and purposeHosting, storing, transmitting, displaying, organizing, backing up and deleting Customer Personal Data; sending notification emails; enabling the Customer's team members and invited client contacts to access portals; securing the Service and providing support the Customer requests.
Categories of personal dataNames, email addresses, roles and job titles of client contacts and team members; sign-in and activity records within the workspace (such as who approved what and when); content of comments, updates, requests and documents; and any personal data contained in files the Customer or its client contacts upload.
Data subjectsThe Customer's team members; the Customer's clients and their staff who are invited as client contacts; and any individuals whose personal data appears in content uploaded to the workspace.
Special categoriesNot intended. The Customer should not upload special category data (such as health data) or criminal-offence data unless it has a lawful basis and has assessed that the security measures below are appropriate.
FrequencyContinuous, while the Customer uses the Service.

5. Our obligations as processor

In line with Article 28 of the GDPR, we will:

  1. process Customer Personal Data only on the Customer’s documented instructions, which are the Terms, this DPA and the Customer’s use and configuration of the Service, unless the law requires otherwise (in which case we will tell the Customer first, unless the law prohibits it);
  2. tell the Customer if we believe an instruction infringes Data Protection Laws;
  3. ensure people authorized to process Customer Personal Data are bound by confidentiality;
  4. implement the technical and organizational security measures described below;
  5. engage subprocessors only as described in this DPA;
  6. assist the Customer in responding to data subject requests and in meeting its security, breach-notification and impact-assessment obligations;
  7. delete or return Customer Personal Data at the end of the Service as described below; and
  8. make available the information needed to demonstrate compliance with this DPA and allow for audits as described below.

We do not sell Customer Personal Data or use it for our own purposes, such as advertising.

6. Confidentiality

We treat Customer Personal Data as confidential. Access is limited to personnel and contractors who need it to provide, secure or support the Service, and who are bound by written confidentiality obligations or a statutory duty of confidentiality. We do not routinely access Customer Content; we access it only where needed to provide support the Customer requests, investigate abuse or a security incident, or comply with law.

7. Subprocessors

The Customer gives general authorization for us to engage subprocessors. Our current subprocessors are listed below and on our subprocessors page. We impose data protection obligations on each subprocessor that are no less protective than this DPA, and we remain responsible for their performance.

Subprocessors used by Clientwharf
SubprocessorPurposeLocationPrivacy policy
Paddle.com Market Ltd (and affiliates)Merchant of Record: checkout, payments, invoicing, sales tax, refundsUnited Kingdom / United StatesPrivacy policy of Paddle.com Market Ltd (and affiliates) (opens in a new tab)
Vercel Inc.Application hosting and content deliveryUnited States (functions in us-east-1)Privacy policy of Vercel Inc. (opens in a new tab)
Neon Inc. (Databricks)Managed PostgreSQL databaseUnited States (AWS us-east-1)Privacy policy of Neon Inc. (Databricks) (opens in a new tab)
Cloudflare, Inc.File storage (R2), DNS, email routing, network securityUnited States / global networkPrivacy policy of Cloudflare, Inc. (opens in a new tab)
Resend (Plus Five Five, Inc.)Transactional email deliveryUnited States (AWS us-east-1)Privacy policy of Resend (Plus Five Five, Inc.) (opens in a new tab)

We will give at least 30 days’ notice before a new subprocessor starts processing Customer Personal Data, by updating the subprocessors page and emailing workspace owners. The Customer may object on reasonable data protection grounds by emailing privacy@clientwharf.com within that period. We will then work in good faith to find a solution. If we cannot, the Customer may cancel the affected subscription and we will ask Paddle to refund prepaid fees for the unused remainder of the billing period.

In an emergency, for example to replace a provider that has suffered a security failure, we may make a change with shorter notice and will inform the Customer as soon as possible.

8. Security measures

We maintain the following technical and organizational measures, and we may improve them over time without lowering overall protection.

Technical and organizational measures
AreaMeasures
Encryption in transitTLS on every connection to the website, app, portals and file storage, with HTTP Strict Transport Security.
Encryption at restDatabase (Neon, PostgreSQL) and file storage (Cloudflare R2) are encrypted at rest by the providers.
Tenant isolationEvery query on customer data is scoped to the workspace in our data layer; client contacts can see only the portal of the client they were invited to. Automated tests try cross-tenant access.
File accessFiles are stored in a private bucket with no public URLs. Uploads and downloads use signed, short-lived links. Executable file types are blocked by default.
AuthenticationPasswords stored as secure hashes; optional TOTP two-factor authentication; email verification; single-use sign-in links that expire after 15 minutes; rate limiting on sign-in, sign-up and recovery.
Access controlWorkspace roles (owner, admin, member) control what team members can do. Access to production systems is limited to authorized personnel.
Application securityInput validation on every form and API route, CSRF protection, secure cookies and a strict Content Security Policy.
LoggingAudit events are recorded for sensitive actions such as role changes, deletions, exports and billing changes.
Availability and backupsHosted on Vercel; provider-level database backups with point-in-time restore (Neon), and a documented restore procedure.
SecretsCredentials are kept in environment variables, never in code or logs.
Vulnerability reportsSecurity issues can be reported to security@clientwharf.com; we publish a security.txt file.

9. Personal data breaches

If we become aware of a personal data breach affecting Customer Personal Data, we will notify the Customer without undue delay, with a target of no later than 72 hours after becoming aware of it, by email to the workspace owner.

The notice will describe, as far as we know at the time: the nature of the breach, the categories and approximate number of data subjects and records concerned, the likely consequences, the measures taken or proposed, and a contact point. Where we cannot give all the information at once, we will provide it in phases. We will take reasonable steps to contain the breach and reduce its effects. Our notification is not an acknowledgment of fault.

10. Assistance to the Customer

  • Data subject requests. The Service lets the Customer access, correct, export and delete Customer Personal Data itself. If we receive a request directly from a data subject about Customer Personal Data, we will pass it to the Customer and not respond ourselves, except to tell the requester to contact the Customer.
  • Impact assessments and consultations. We will provide reasonable information to help the Customer carry out data protection impact assessments and prior consultations with supervisory authorities, to the extent they relate to our processing.
  • Authority requests. If a public authority asks us for Customer Personal Data, we will redirect it to the Customer where possible, challenge requests we consider unlawful, and notify the Customer unless the law prohibits it.

11. Deletion and return of data

  • During the subscription, and while the workspace is read-only afterwards, the Customer can export all files and a machine-readable copy of workspace records at any time.
  • After a trial or subscription ends, we keep the workspace read-only for at least 30 days, and we email the owner at least 14 days before deleting it.
  • When the Customer deletes its workspace, or the workspace is deleted after that period, we delete Customer Personal Data from live systems within 30 days. Copies in rolling provider backups expire within a further 30 days and are not restored except to recover from a disaster.
  • We may keep Customer Personal Data longer only where the law requires it, and we continue to protect it under this DPA.

12. Audits

We will make available, on written request to legal@clientwharf.com, the information reasonably needed to demonstrate compliance with this DPA, including written answers to security questionnaires and information about our subprocessors’ security certifications.

If that information is not enough to meet a requirement of Data Protection Laws, or a supervisory authority requires it, the Customer may carry out an audit, by itself or through an independent auditor bound by confidentiality, no more than once a year, with at least 30 days’ written notice, during business hours and without disrupting the Service or accessing other customers’ data. Each party bears its own costs unless the audit reveals a material breach of this DPA by us.

13. International transfers

Customer Personal Data is hosted in the United States, and subprocessors may process it in the countries listed above. Where Customer Personal Data is transferred from the European Economic Area, the United Kingdom or Switzerland to a country without an adequacy decision, the parties agree that:

  • the Standard Contractual Clauses apply, Module Two (controller to processor) or Module Three (processor to processor) as relevant, incorporated by reference, with the details of processing in this DPA serving as Annex I and the security measures serving as Annex II;
  • the optional docking clause applies; Clause 9 option 2 (general authorization) applies with the notice period above; the optional wording in Clause 11 does not apply; Clauses 17 and 18 are governed by the law and courts of Ireland;
  • for UK transfers, the UK International Data Transfer Addendum applies; for Swiss transfers, the SCCs apply with the necessary adaptations; and
  • where a recipient is certified under the EU–US Data Privacy Framework (or its UK or Swiss extensions), that certification may be relied on instead.

We ensure that onward transfers to subprocessors are covered by equivalent safeguards.

14. Liability

Each party’s liability under or in connection with this DPA is subject to the limitations and exclusions of liability in the Terms of Service, except where Data Protection Laws or the Standard Contractual Clauses do not allow such limitation.

15. Term and changes

This DPA applies for as long as we process Customer Personal Data. We may update it to reflect changes in law or the Service; we will not reduce the overall protection it provides, and we will notify workspace owners of material changes at least 30 days in advance. Questions about this DPA can be sent to privacy@clientwharf.com or by post to Goohoost Ltd, First Floor Office, 3 Hornton Place, London, W8 4LZ, United Kingdom.