Data Processing Addendum
Last Updated: September 13, 2026
This Data Processing Addendum (“DPA”) forms part of the Terms of Service or other written or electronic agreement (the “Agreement”) between Clousys (“Processor”, “we”, “us”, or “our”) and the customer identified in the applicable Sales Order or Agreement (“Customer”, “Controller”, or “you”).
This DPA governs the processing of Personal Data by Clousys on behalf of the Customer in connection with the provisioning of the Clousys AI-powered Professional Services Operations Platform and related services (the “Services”).
1. Definitions
“Data Protection Laws” means all applicable local, state, national, and international laws, rules, and regulations relating to data privacy and security, including but not limited to the General Data Protection Regulation (EU) 2016/679 (“GDPR”), the UK GDPR, and the California Consumer Privacy Act (“CCPA”), as amended.
“Personal Data” means any information relating to an identified or identifiable natural person that is processed by Clousys on behalf of the Customer in the course of providing the Services.
“Processing” means any operation or set of operations performed on Personal Data, whether or not by automated means, such as collection, storage, access, transmission, or deletion.
“Data Subject” means the identified or identifiable natural person to whom the Personal Data relates (e.g., Customer’s employees, contractors, or clients).
“Subprocessor” means any third-party data processor engaged by Clousys to assist in fulfilling its obligations with respect to providing the Services pursuant to the Agreement or this DPA.
“Standard Contractual Clauses” or “SCCs” means the standard contractual clauses for the transfer of personal data to third countries as approved by the European Commission, and the UK International Data Transfer Addendum, as applicable, each as may be updated or replaced from time to time.
2. Roles of the Parties
For the purposes of the Data Protection Laws, the Customer is the Data Controller (or a processor acting on behalf of a third-party controller), and Clousys is the Data Processor. Clousys will process Personal Data solely on behalf of and according to the Customer's documented instructions.
3. Details of Processing
The subject matter, duration, nature, and purpose of processing, the types of Personal Data, and the categories of Data Subjects are described in Annex 1 to this DPA.
4. Processing Instructions
Clousys will process Personal Data only to the extent necessary to provide the Services, in accordance with the Agreement and this DPA, and in compliance with the Customer's documented lawful instructions. Clousys will not “sell” or “share” Personal Data as those terms are defined under the CCPA. Clousys will immediately notify the Customer if, in its opinion, an instruction infringes applicable Data Protection Laws.
5. Confidentiality
Clousys shall ensure that all personnel (including employees and contractors) authorized to process Personal Data are subject to a strict duty of confidentiality and process the data only as strictly necessary for the provision of the Services.
6. Security Measures
Taking into account the state of the art, the costs of implementation, and the nature of the processing, Clousys shall implement and maintain appropriate technical and organizational security measures to protect Personal Data against unauthorized or accidental access, loss, destruction, alteration, or disclosure, as further described in Annex 2 to this DPA.
7. Subprocessors
The Customer provides a general authorization for Clousys to engage Subprocessors to support the delivery of the Services. A current list of Subprocessors is set out in Annex 3 to this DPA and on our Subprocessors page, and is updated from time to time.
New Subprocessors. Clousys will notify the Customer of any intended changes concerning the addition or replacement of Subprocessors at least 30 days in advance. The Customer may object to such changes on reasonable, data-protection-related grounds.
Liability. Clousys remains fully liable for the acts and omissions of its Subprocessors in relation to the processing of Personal Data under this DPA.
8. Data Subject Requests
Taking into account the nature of the processing, Clousys shall assist the Customer by implementing appropriate technical and organizational measures, insofar as this is possible, for the fulfillment of the Customer's obligation to respond to requests for exercising Data Subject rights (such as access, rectification, erasure, and data portability). If Clousys receives a request directly from a Data Subject, it will promptly forward the request to the Customer and will not respond independently unless legally required to do so.
9. Personal Data Breaches
Clousys shall notify the Customer without undue delay (and in any event within 48 hours) after becoming aware of a confirmed Personal Data breach affecting Customer Data. Clousys will provide sufficient information to allow the Customer to meet any obligations to report or inform Data Subjects or regulatory authorities of the breach. Clousys will take all reasonable steps to mitigate the effects of the breach and prevent recurrence.
10. International Data Transfers
If Clousys transfers Personal Data originating from the European Economic Area (EEA), the UK, or Switzerland to countries that do not ensure an adequate level of data protection, Clousys will ensure that appropriate safeguards are in place. This includes executing the Standard Contractual Clauses approved by the European Commission or utilizing another valid transfer mechanism recognized by applicable Data Protection Laws. Where the SCCs apply, they are incorporated into this DPA by reference and shall be completed using the details set out in Annex 1 (Details of Processing), Annex 2 (Technical and Organizational Measures), and Annex 3 (List of Subprocessors) to this DPA.
11. Audits and Compliance
Upon the Customer's reasonable written request (no more than once annually), Clousys shall make available all information necessary to demonstrate compliance with the obligations laid down in this DPA. Clousys will allow for and contribute to audits, including inspections, conducted by the Customer or another auditor mandated by the Customer, provided that such audits are subject to strict confidentiality and do not disrupt Clousys's business operations.
12. Return or Deletion of Data
Upon termination or expiration of the Agreement, or upon the Customer's request, Clousys shall, at the choice of the Customer, securely delete or return all Personal Data processed on behalf of the Customer, and delete existing copies unless applicable law requires continued storage of the Personal Data.
13. Relationship to the Agreement
This DPA supplements and forms part of the Agreement, including the Terms of Service, between the parties. In the event of a conflict between this DPA and the Agreement concerning data protection matters, this DPA will control to the extent of the conflict. This DPA does not apply to Clousys's collection and use of personal information in its own capacity as a controller (for example, about website visitors, prospective customers, and individual Platform users), which is instead described in the Clousys Privacy Policy and Cookie Policy.
14. Governing Law
This DPA shall be governed by and construed in accordance with the governing law and jurisdiction provisions specified in the Agreement, unless applicable Data Protection Laws require otherwise.
15. Contact Information
For any privacy or data protection inquiries related to this DPA, please contact our Data Protection Officer at:
Clousys
Data Protection Contact: Data Protection Officer
Email: connect@clousysbs.com
Website: https://www.clousysbs.com
Annex 1: Details of Processing
| Field | Description |
|---|---|
| Data Exporter | Customer, as identified in the applicable Sales Order or Agreement. |
| Data Importer | Clousys, provider of the Clousys AI-powered Professional Services Operations Platform. |
| Subject Matter | The processing of Personal Data to provide the Clousys Platform (including ATS, HRMS, Resource Management, and Project Financials modules) as described in the Agreement. |
| Duration | For the duration of the Subscription Term, plus the period until all Personal Data is securely deleted or returned in accordance with this DPA. |
| Nature and Purpose of Processing | Hosting, storage, transmission, and processing of Personal Data as necessary to provide, secure, support, and improve the Services in accordance with Customer's documented instructions. |
| Types of Personal Data | Name, contact information (email, phone, address), employment history, job titles, organizational roles, billing/invoicing details, performance metrics, timesheet data, and any other Personal Data uploaded to the Services by the Customer. |
| Categories of Data Subjects | Customer's employees, applicants, contractors, consultants, and clients. |
| Frequency of Transfer | Continuous, for the duration of the Subscription Term. |
| Special Categories of Data (if any) | Not intentionally collected by Clousys; Customer is responsible for ensuring an appropriate legal basis if such data is uploaded to the Services. |
Annex 2: Technical and Organizational Measures
Clousys maintains the following categories of technical and organizational measures to protect Personal Data. These measures are reviewed and updated periodically to reflect the evolving state of the art, applicable risk, and regulatory expectations.
| Measure | Description |
|---|---|
| Encryption | End-to-end encryption of Personal Data in transit and at rest. |
| Access Control | Role-based access controls and strict authentication mechanisms limiting access to Personal Data on a need-to-know basis. |
| Vulnerability Management | Regular vulnerability scanning and penetration testing of production systems. |
| Data Minimization / Masking | Data masking applied where appropriate within the platform to limit exposure of Personal Data. |
| Network Security | Firewalls, network segmentation, and monitoring designed to protect infrastructure hosting Personal Data. |
| Logging and Monitoring | Centralized logging and monitoring to detect and respond to potential security incidents. |
| Backup and Recovery | Regular backups and documented disaster recovery procedures. |
| Personnel Security | Confidentiality obligations, security training, and access provisioning/deprovisioning procedures for personnel. |
| Incident Response | Documented incident response procedures, including the breach notification process described in Section 9 of this DPA. |
| Vendor Management | Due diligence and contractual data protection requirements imposed on Subprocessors. |
Annex 3: List of Subprocessors
The table below summarizes the categories of Subprocessors currently engaged by Clousys to support delivery of the Services. A detailed, current list (including specific Subprocessor names) is available on our Subprocessors page or upon written request.
| Category | Purpose | Example Location |
|---|---|---|
| Cloud infrastructure & hosting | Hosting the Platform, application servers, and databases | India / EU / United States (region selected per deployment) |
| Database & storage providers | Secure storage and backup of Customer Data | India / EU / United States |
| Email & communications providers | Transactional emails, notifications, and support communications | United States / European Union |
| Analytics providers | Product usage analytics and performance monitoring | United States |
| Payment processors | Processing subscription fees and billing | India / United States |
| Customer support tools | Managing and responding to support tickets | United States |
| Security & monitoring providers | Threat detection, logging, and infrastructure protection | United States / European Union |



