Skip to main content

Legal · DPA

Data Processing Agreement

Last updated: 2026-05-06 · LEGAL_REVIEW_PENDING — outside-counsel pass before public launch.

Clarifi processes personal data on behalf of its Customers as a "Processor" under applicable data protection law (GDPR / UK GDPR / CCPA), with the Customer acting as the "Controller". This page is the public summary of the Data Processing Agreement (DPA); the signed long-form agreement is available below.

Scope

The DPA applies to Customer Data processed by the Clarifi platform — including financial transactions, account mappings, KPI computations, and audit logs. The Sub-processor list and the Standard Contractual Clauses (SCCs) for cross-border transfers are appended as Schedule 1 and Schedule 2 of the long-form agreement.

Controls and security

Clarifi maintains the security and operational controls listed on the security page, including AES-256 encryption at rest, TLS 1.3 in transit, role-based access, and audit logging of significant actions. SOC 2 Type II audit is underway. Until then, our security controls inherit from SOC 2 Type II–audited infrastructure (AWS).

Sub-processors

Clarifi uses a documented list of sub-processors for hosting, observability, customer success tooling, and payment processing. The current list is appended to the long-form DPA (Schedule 1).

Request the signed long-form DPA

Customers and prospective customers can request the signed long-form DPA via the contact page below. We countersign and return within one business day.

Sign + return

Request the signed long-form DPA

Email security@ to request the long-form agreement. We countersign and return within one business day.

Clarifi