Legal · DPA
Data Processing Agreement
Last updated: 2026-05-06 · LEGAL_REVIEW_PENDING — outside-counsel pass before public launch.
Clarifi processes personal data on behalf of its Customers as a "Processor" under applicable data protection law (GDPR / UK GDPR / CCPA), with the Customer acting as the "Controller". This page is the public summary of the Data Processing Agreement (DPA); the signed long-form agreement is available below.
Scope
The DPA applies to Customer Data processed by the Clarifi platform — including financial transactions, account mappings, KPI computations, and audit logs. The Sub-processor list and the Standard Contractual Clauses (SCCs) for cross-border transfers are appended as Schedule 1 and Schedule 2 of the long-form agreement.
Controls and security
Clarifi maintains the security and operational controls listed on the security page, including AES-256 encryption at rest, TLS 1.3 in transit, role-based access, and audit logging of significant actions. SOC 2 Type II audit is underway. Until then, our security controls inherit from SOC 2 Type II–audited infrastructure (AWS).
Sub-processors
Clarifi uses a documented list of sub-processors for hosting, observability, customer success tooling, and payment processing. The current list is appended to the long-form DPA (Schedule 1).
Request the signed long-form DPA
Customers and prospective customers can request the signed long-form DPA via the contact page below. We countersign and return within one business day.
Sign + return
Request the signed long-form DPA
Email security@ to request the long-form agreement. We countersign and return within one business day.
