← Legal hub

Legal · Data Processing

Data Processing Addendum

Forms part of the Terms of Service between Skdaddle, Inc. and the customer organization. Sets out how we process Customer Personal Information on your behalf.

Effective June 9, 2026. This is a first-draft document and will be superseded by a lawyer-reviewed version before general availability. Questions: contact@skdaddle.com.

1. Definitions

  • “Applicable Data Protection Law”means the California Consumer Privacy Act (CCPA) as amended by the California Privacy Rights Act (CPRA), and any other privacy or data-protection law applicable to a party's processing of Customer Personal Information.
  • “Customer Personal Information”means personal information (as defined under Applicable Data Protection Law) that we Process on the Customer's behalf in providing the ClearReport service.
  • “Process,” “Processing,” and “Service Provider” have the meanings given in the CCPA / CPRA.
  • “Subprocessor” means any third party we engage to Process Customer Personal Information on our behalf. The current list is published at /legal/subprocessors.
  • “Security Incident” means a confirmed event resulting in unauthorized access, disclosure, alteration, or destruction of Customer Personal Information.

2. Role of the parties

ClearReport operates as a Service Provider under the CCPA when Processing Customer Personal Information on behalf of the Customer. The Customer is the Business. The Customer determines the purposes and means of Processing; ClearReport Processes only as instructed by the Customer through normal use of the service or as required by law.

To the extent the Customer is also subject to other Applicable Data Protection Law, the parties agree that the equivalent controller/processor roles apply, and this DPA is intended to satisfy the corresponding processor-obligation terms.

3. Permitted processing

We Process Customer Personal Information only for the following business purposes:

  • Operating and maintaining the ClearReport service for the Customer
  • Providing AI-assisted report review and the Ace advisor as documented
  • Generating regulatory PDFs and delivering them to recipients designated by the Customer
  • Generating audit logs and compliance-deadline tracking
  • Responding to Customer support requests with the Customer's explicit per-incident authorization
  • Detecting, preventing, and addressing fraud, abuse, or technical issues
  • Complying with our legal obligations, subject to Section 8

We will not Process Customer Personal Information for any other purpose. We will not sell or share Customer Personal Information as those terms are defined under the CCPA. We will not combine Customer Personal Information with personal information we receive from other sources except as permitted under CCPA § 1798.140(ag)(2)(C).

4. Subprocessors

The Customer authorizes us to engage Subprocessors to assist in providing the service. The current list is published at /legal/subprocessors.

  • We have a written agreement with each Subprocessor containing data-protection terms substantially as protective as those in this DPA.
  • We remain responsible to the Customer for the acts and omissions of our Subprocessors under this DPA.
  • We will notify the Customer in writing at least 30 days before engaging a new Subprocessor that will have access to Customer Personal Information. The Customer may reasonably object on data-protection grounds; if we cannot accommodate the objection, the Customer may terminate the affected service for cause.

5. Security measures

We maintain technical and organizational security measures appropriate to the risk, including:

  • TLS 1.2 or higher for data in transit
  • AES-256 disk encryption for data at rest
  • Role-based access control with logical separation of Customer data by organization ID, enforced in the application's server-side authorization layer on every request
  • Multi-factor authentication available to every user
  • Staff access to Customer data restricted to identified employees holding a corporate-domain identity verified by our identity provider, plus an explicit membership record revocable independently of the account, and recorded in a separate staff audit trail
  • Audit logging of every meaningful mutation, retained for seven years
  • Background-check requirements for employees with production access
  • Documented incident-response process — see Section 7

A more detailed posture is published at /security. We may update specific controls from time to time provided we do not materially diminish the overall security level described in this DPA.

6. Assistance with consumer rights

On Customer request, we will provide reasonable assistance in responding to Verifiable Consumer Requests under the CCPA / CPRA, including requests to access, delete, correct, opt out of sale or sharing, or limit use of sensitive personal information. Customer is responsible for verifying the identity of the requesting consumer before we act on the request.

Where a consumer contacts us directly with a request relating to Customer Personal Information, we will, without undue delay, forward the request to the Customer at the email address on file and decline to act except as instructed by the Customer.

7. Security Incident notification

On confirming a Security Incident affecting Customer Personal Information, we will:

  • Notify the Customer in writing within 72 hours of confirmation;
  • Provide the information reasonably required for the Customer to comply with its own notification obligations (the nature of the incident, the data and individuals affected to the extent known, the steps we are taking, and our point of contact);
  • Cooperate in good faith with the Customer's investigation;
  • Publish a post-incident summary to affected customers within 30 days of the incident's closure.

If ClearReport has separately executed a Business Associate Agreement with the Customer (see our Business Associate Agreement— not offered at this time) and an incident also constitutes a Breach of Unsecured PHI, both this Section and that agreement's notification requirements apply, and the shorterperiod governs.

8. Compelled disclosures

If we receive a subpoena, court order, or government request requiring disclosure of Customer Personal Information, we will, where legally permitted, notify the Customer in writing before responding and use reasonable efforts to allow the Customer to challenge the demand. Where prohibited from notifying, we will produce only the data strictly required and notify the Customer as soon as the prohibition ends.

9. Retention and deletion

Retention windows for Customer Personal Information are described in our Privacy Policy. Within 90 days of termination of the Terms of Service, we will delete or, at Customer's written request, return Customer Personal Information in a machine-readable format. We may retain Customer Personal Information after that window as required by law (e.g. seven-year audit-log retention) or in archived backups that expire on the schedule disclosed in our Privacy Policy.

10. Audits and reports

We will, upon reasonable written notice and no more than once per calendar year, make available to the Customer information reasonably necessary to demonstrate our compliance with this DPA. This includes our SOC 2 attestation if available, our then-current security documentation, and reasonable responses to Customer security questionnaires.

A more invasive audit (on-site or full system access) is available to enterprise customers under a separate written agreement with mutually agreed scope and cost-sharing terms.

11. International transfers

Our infrastructure is located in the United States and Customer Personal Information is Processed in the U.S. We do not currently offer European data residency. If your organization is subject to GDPR or UK GDPR, additional terms (including Standard Contractual Clauses) may be required before we sign — contact contact@skdaddle.com.

12. Order of precedence

In the event of a conflict between this DPA and the Terms of Service, this DPA controls solely with respect to the Processing of Customer Personal Information.

13. Term and termination

This DPA is effective concurrent with the Terms of Service and continues until all Customer Personal Information has been deleted or returned in accordance with Section 9. Sections that by their nature should survive termination (Sections 7, 8, 9, and 10) survive.