ClonePartner Talk to us
Terms Privacy DPA GDPR CCPA Security Cookies Trust Center

Data Processing Agreement

Last updated: 28 July 2026
View as Markdown ·
On this page
  • Introduction
  • 1. Definitions
  • 2. Roles and Scope
  • 3. Term and Termination
  • 4. Processing Instructions
  • 5. Personnel
  • 6. Data‑Subject & Regulatory Assistance
  • 7. Security Measures
  • 8. Sub‑Processors
  • 9. International Transfers, Data Residency & Regional Compliance
  • 10. AI‑Assisted Tooling
  • 11. Personal Data Breach
  • 12. Deletion or Return of Data
  • 13. Audit and Compliance
  • 14. Liability
  • 15. Miscellaneous
  • Schedule A – Parties & Governing Law for SCCs
  • Schedule B – Technical & Organisational Measures
  • Schedule C – Authorised Sub‑Processors
  • Schedule D – UK Addendum
  • Schedule E – Description of Processing

Introduction

This Data Processing Agreement (“DPA”) forms part of the Terms of Service between Yin Yang Inc. DBA ClonePartner (“Company”) and the entity that accepts the Terms (“Customer”). It applies whenever the Company processes Personal Data on Customer’s behalf.

Data Protection Officer
dpo@clonepartner.com
EU Representative (GDPR Art. 27)
Rickert Rechtsanwaltsgesellschaft mbH – YIN YANG, INC.
Colmantstraße 15, 53115 Bonn, Germany
art-27-rep-yinyang@rickert.law
UK Representative (UK GDPR Art. 27)
Rickert Services Ltd UK – YIN YANG, INC.
PO Box 1487, Peterborough PE1 9XX, United Kingdom
art-27-rep-yinyang@rickert-services.uk
Signed copy
Available on request to legal@clonepartner.com

Both parties agree to comply with applicable data‑protection laws, including GDPR, UK GDPR, Swiss FADP, CCPA/CPRA, and any superseding legislation (“Data Protection Laws”).

1. Definitions

Unless defined here, capitalised terms have the meanings in the Terms or relevant legislation.

Controller, Processor, Data Subject, Processing, Personal Data Breach – as in GDPR

Personal Data – any data relating to an identified or identifiable natural person contained in Customer Data

Restricted Transfer – a cross‑border transfer requiring safeguards under Data Protection Laws

Standard Contractual Clauses (SCCs) – the EU standard contractual clauses adopted by Commission Implementing Decision (EU) 2021/914, as configured in Section 9.6, together with the UK Addendum (Schedule D) and the Swiss adaptations in Section 9.8, as applicable

Sub‑Processor – any Processor engaged by the Company to assist in fulfilling obligations under this DPA

Service Term – the period during which the Company provides Services to the Customer: for SaaS, the subscription term; for migration or other professional‑services engagements, the project term stated in the applicable Order Form or Statement of Work

2. Roles and Scope

2.1.Customer acts as Controller (or Processor on behalf of a Controller). The Company acts as Processor (or Sub‑Processor).

2.2.The Company processes Personal Data only on documented instructions from Customer.

2.3.Each Party will comply with its obligations under Data Protection Laws.

2.4.Self‑Hosted Deployments. Where the Services are delivered as a self‑hosted (on‑premises) deployment operated by Customer, Customer Data records are processed entirely within Customer’s own environment and the Company does not access, receive, or store them. For such deployments, this DPA applies only to the limited Personal Data the Company actually processes in connection with the engagement — namely account, configuration, support, and diagnostic telemetry data.

2.5.Customer Warranties. Customer warrants that it has, and will maintain, all rights, consents, notices, and lawful bases required under Data Protection Laws for the Personal Data it makes available to the Company, and that its Processing instructions are lawful. Customer is responsible for the accuracy, quality, and legality of that Personal Data and the means by which it was acquired.

3. Term and Termination

This DPA remains in effect while the Company processes Personal Data for Customer. Termination follows the Terms or mutual written agreement. Clauses intended to survive (e.g., Confidentiality, Liability) will do so.

4. Processing Instructions

4.1.The Company will process Personal Data only as necessary to deliver the Services, as set out in the Terms, Order Forms, this DPA, or later written instructions.

4.2.If an instruction appears to violate Data Protection Laws, the Company will promptly inform Customer.

5. Personnel

The Company restricts Personal Data access to authorised personnel bound by confidentiality and security obligations.

6. Data‑Subject & Regulatory Assistance

6.1.The Company will, taking into account the nature of Processing, assist Customer by appropriate technical and organisational measures to fulfil obligations to respond to Data‑Subject requests, conduct Data‑Protection Impact Assessments, and engage in prior consultations with supervisory authorities.

6.2.Any such assistance beyond routine self‑service features may be chargeable on a time‑and‑materials basis, subject to advance written approval by Customer.

7. Security Measures

The Company maintains appropriate technical and organisational measures (“TOMs”) to safeguard Personal Data. A high‑level summary is provided in Schedule B. Detailed documentation (including our ISO 27001 certificate and SOC 2 Type II report) is available under NDA via our Trust Center or on request to legal@clonepartner.com

8. Sub‑Processors

8.1.General Authorisation – Customer authorises the Sub‑Processors listed in Schedule C.

8.2.The Company will notify Customer at least thirty days before adding or replacing a Sub‑Processor and allow reasonable objections based on data‑protection grounds.

8.3.All Sub‑Processors sign data‑processing agreements imposing obligations equivalent to this DPA, and the Company remains fully liable for their acts and omissions.

8.4.Upon written request, the Company will provide summary audit reports or certifications demonstrating the Sub‑Processor’s compliance.

8.5.Objections. If Customer objects to a new or replacement Sub‑Processor on reasonable data‑protection grounds and the Parties cannot resolve the objection within thirty days, either Party may terminate the affected Services or engagement on written notice, and the Company will refund any prepaid fees covering the unused portion.

9. International Transfers, Data Residency & Regional Compliance

9.1.Restricted Transfers – safeguarded by the SCCs as configured in Section 9.6, or by alternative lawful transfer mechanisms.

9.2.California – Service Provider – The Parties acknowledge that Personal Data is processed for limited and specified purposes; the Company does not sell or share Personal Data as defined by CPRA and will not retain, use, or disclose Personal Data outside the scope of Customer’s instructions. The Company certifies that it understands and will comply with its obligations as a “service provider” under the CCPA/CPRA and will notify Customer if it determines it can no longer meet them.

9.3.If existing transfer mechanisms become invalid, the Parties will implement lawful alternatives or suspend transfers.

9.4.Data Residency. For cloud‑delivered engagements, Customer may designate an available hosting region (the “Designated Region”) in the applicable Order Form or SOW. The Company will provision the temporary staging database for the engagement in the Designated Region and will not transfer Customer Data held in that staging database out of the Designated Region, except on Customer’s documented instructions or where required by law. Available regions run on the Company’s infrastructure Sub‑Processors (currently DigitalOcean and OVHcloud) and are listed on the Company’s Security page.

9.5.Remote Access. Authorised Company personnel may access the staging environment remotely from other jurisdictions strictly to deliver and support the Services. Where such access constitutes a Restricted Transfer, it is safeguarded by the SCCs and the measures in Schedule B.

9.6.Standard Contractual Clauses. The EU SCCs (Commission Implementing Decision (EU) 2021/914) are incorporated into this DPA by reference. Module Two (Controller to Processor) applies where Customer acts as Controller; Module Three (Processor to Processor) applies where Customer acts as Processor on behalf of another Controller. For each module: Clause 7 (docking clause) is included; under Clause 9(a), Option 2 (general written authorisation) applies with the thirty‑day notice period in Section 8.2; the optional language in Clause 11(a) is not included; under Clause 17 (Option 1), the SCCs are governed by Irish law; and under Clause 18(b), disputes will be resolved before the courts of Ireland. Annexes I.A and I.C are completed by Schedule A, Annex I.B by Schedule E, Annex II by Schedule B, and Annex III by Schedule C. In case of conflict between this DPA and the SCCs, the SCCs prevail.

9.7.Competent Supervisory Authority. For the purposes of Clause 13 of the SCCs and Annex I.C, the competent supervisory authority is (a) the supervisory authority of the EU Member State in which Customer is established; (b) where Customer is not established in the EU but has appointed an EU representative under Article 27 GDPR, the supervisory authority of the Member State in which that representative is based; or (c) otherwise, the Irish Data Protection Commission.

9.8.Swiss Transfers. For transfers subject to the Swiss FADP, the SCCs apply with the following adaptations: references to the GDPR are read as references to the FADP, references to EU Member States include Switzerland, and the competent supervisory authority is the Swiss Federal Data Protection and Information Commissioner (FDPIC).

9.9.Government Access Requests. If the Company receives a legally binding request from a public authority for access to or disclosure of Customer Data, it will notify Customer without undue delay unless legally prohibited from doing so, will review the legality of the request and challenge it where reasonable grounds to do so exist, and will disclose only the minimum data necessary to comply.

10. AI‑Assisted Tooling

10.1.The Company uses AI‑assisted engineering tools — currently Cursor, by Anysphere, Inc. — when building, testing, and validating migration scripts and field mappings. In the course of an engagement, these tools may process limited Customer Data (for example, schema structures, field values, or records encountered while developing and debugging transformations).

10.2.All such tools are used with privacy mode enforced: inputs are not used to train models and are subject to zero‑ or limited‑retention commitments from the providers. Requests may be routed to third‑party foundation‑model providers (such as OpenAI, Anthropic, or Google) under the same no‑training, limited‑retention terms. These providers are identified in the Sub‑Processor list referenced in Schedule C.

10.3.Customer may prohibit or restrict the use of AI‑assisted tooling on Customer Data for a given engagement by written notice (email to legal@clonepartner.com or an instruction in the applicable Order Form or SOW), and the Company will honour that instruction.

11. Personal Data Breach

The Company will notify Customer without undue delay and, where feasible, within 48 hours after becoming aware of a Personal Data Breach and will cooperate in investigation, mitigation, and regulatory notifications.

12. Deletion or Return of Data

Upon termination or completion of the Services, the Company will delete Customer Data — including account, configuration, support, and diagnostic telemetry data — within ninety (90) days; for migration engagements, staging databases are automatically purged no later than thirty (30) days after project close. Backup copies containing Customer Data are created daily and expire automatically on a rolling seven (7)‑day cycle; in no event are backups retained for more than fourteen (14) days. If Customer requires accelerated deletion or bespoke retention handling, we will review and, where feasible, accommodate such requests on a case‑by‑case basis. Where a legal obligation necessitates continued storage, the data will be isolated and safeguarded. Upon written request, the Company will certify deletion.

13. Audit and Compliance

13.1.The Company will provide information necessary to demonstrate compliance with this DPA.

13.2.Once per twelve‑month period and on thirty days’ notice, Customer may audit the Company’s Processing. Additional or unplanned audits may incur fees.

13.3.The Company will cooperate with supervisory‑authority inquiries.

14. Liability

Liability is governed by the limitation clauses in the Terms. Nothing limits either Party’s liability for intentional or wilful breach of this DPA.

15. Miscellaneous

15.1.In case of conflict, this DPA prevails over the Terms, and the SCCs prevail over this DPA (Section 9.6).

15.2.Amendments require written agreement.

15.3.Notices should be sent to legal@clonepartner.com and Customer’s designated contact.

15.4.If any provision is held invalid, the remainder stays effective.

15.5.Headings are for convenience only and do not affect interpretation.

Schedule A – Parties & Governing Law for SCCs

Data Exporter: Customer (as defined in the Terms) — role: Controller (Module Two) or Processor (Module Three); activities: receipt of the Services described in Schedule E

Data Importer: Yin Yang Inc. DBA ClonePartner, 9450 SW Gemini Dr PMB 69868, Beaverton OR 97008‑7105 US, contact: legal@clonepartner.com — role: Processor; activities: provision of the Services described in Schedule E

For EU SCCs Clause 17, the governing law shall be Irish law; for Clause 18(b), the forum is the courts of Ireland. The competent supervisory authority (Annex I.C) is determined in accordance with Section 9.7.

Schedule B – Technical & Organisational Measures

The measures below are organised by the categories described in Annex II of the SCCs. Detailed documentation (including our ISO 27001 certificate and SOC 2 Type II report) is available under NDA via our Trust Center.

Encryption & Key Management

  • Encryption of data in transit (TLS 1.2+) and at rest (AES‑256)
  • Encryption‑key management handled by the Company with quarterly rotation

Access Control & Personnel

  • Role‑based access control (RBAC) and multi‑factor authentication (MFA)
  • Network segmentation, firewalling, and zero‑trust access policies
  • Background screening at hire for personnel with access to Customer Data, where permitted by local law
  • Annual security‑awareness and privacy training for all personnel

Monitoring & Logging

  • Continuous monitoring, centralised logging, and intrusion detection

Vulnerability Management & Testing

  • Continuous vulnerability scanning, annual third‑party penetration testing, and prompt patch management

Continuity & Recovery

  • Business‑continuity and disaster‑recovery plans with encrypted off‑site backups

Governance & Assurance

  • ISO 27001 certification and SOC 2 Type II audit programme
  • Sub‑Processor due‑diligence and contract reviews
  • Cyber‑liability insurance commensurate with the scale and sensitivity of engagements

Schedule C – Authorised Sub‑Processors

Customer authorises the Sub‑Processors listed in the Subprocessors section of the Company’s Trust Center at trust.clonepartner.com, which is the live, authoritative list and identifies each Sub‑Processor’s purpose and location. The Company updates that list and notifies Customer in accordance with Section 8 before adding or replacing any Sub‑Processor.

As of the Last Updated date of this DPA, the authorised Sub‑Processors are:

Sub‑ProcessorPurposeLocation
DigitalOceanCloud infrastructure and temporary staging databases for cloud‑delivered migrationsCustomer’s Designated Region (US, Canada, UK, Netherlands, Germany, India, Singapore, Australia)
OVHcloudCloud infrastructure and temporary staging databases for cloud‑delivered migrationsCustomer’s Designated Region (France, Germany, UK, Poland, Canada, US, India, Singapore, Australia)
CloudflareContent delivery, DNS, and edge securityGlobal edge network (HQ: United States)
Cursor (Anysphere, Inc.)AI‑assisted engineering tooling (Section 10) — privacy mode enforced, no model training, zero‑ or limited‑retentionUnited States
OpenAI / Anthropic / GoogleFoundation‑model providers reached via Cursor, under the same no‑training, limited‑retention terms (Section 10)United States
Truto.oneUnified‑API framework powering integration orchestrationUnited States
Google WorkspaceBusiness email, documents, and internal collaborationUnited States / EU
SlackTeam and customer‑channel communicationsUnited States
ResendTransactional email deliveryUnited States
Cal.comScheduling for demos, support, and project callsUnited States
Tally.soForms for intake and feedbackEU (Belgium)

Sub‑Processors fall into three categories: cloud infrastructure and staging, provisioned in the Customer’s Designated Region (Section 9.4); AI‑assisted engineering tooling (Section 10); and business operations (scheduling, forms, communications, and email).

Schedule D – UK Addendum

For transfers subject to the UK GDPR, the UK International Data Transfer Addendum to the EU SCCs issued by the Information Commissioner’s Office (version B1.0, in force 21 March 2022) (“UK Addendum”) is incorporated by reference. Table 1 is completed by Schedule A; Table 2 refers to the EU SCCs as configured in Section 9.6; Table 3 is completed by Schedules A, B, C, and E; and for Table 4, either Party may end the UK Addendum as set out in its Section 19.

Schedule E – Description of Processing

Nature and purpose — Provision of the ClonePartner SaaS integration platform and professional migration, backup, recovery, and continuous data‑synchronisation services. Cloud‑delivered migrations use a temporary staging database provisioned in the Customer’s Designated Region (see Section 9.4). For self‑hosted deployments, Customer Data records are processed within Customer’s own environment and the scope of this DPA is limited as described in Section 2.4.

Categories of Data Subjects — Customer employees, contractors, end‑users, and any individuals whose data is present in the source or destination systems involved in migrations or integrations.

Categories of Personal Data — Basic identifiers (name, email, user ID), contact details, role or title, authentication tokens, log data, technical metadata required to operate migrations. Optional configuration or mapping files may include limited Personal Data supplied by Customer.

Sensitive Personal Information — Not intentionally collected. Customer must not transmit special‑category or sensitive Personal Data unless required for the engagement and explicitly authorised in writing.

Retention — For SaaS subscriptions, Personal Data is retained for the active Subscription Term. For one‑off migration or other professional‑services projects, Personal Data is retained for the project term set out in the relevant Order Form or Statement of Work. Staging databases used for cloud‑delivered migrations are provisioned in the Customer’s Designated Region, remain there for the duration of the project, and are automatically purged no later than thirty (30) days after project close. After the applicable term ends, data is deleted within ninety (90) days unless law requires longer storage. Backup copies expire automatically on a rolling seven (7)‑day cycle and are never retained for more than fourteen (14) days. Customer may request expedited deletion or alternative retention, which the Company will evaluate case by case.

Frequency of transfer — Continuous or ad‑hoc transfers occur as needed to perform the Services.

Duration of Processing — For SaaS subscriptions, Processing continues for the Subscription Term. For migration or other professional‑services engagements, Processing continues for the project term. Limited Processing may continue thereafter only as required by law or agreed retention arrangements.

The Customer is deemed to have executed this DPA, including incorporated SCCs, by accepting the Terms of Service or signing an Order Form

On this page

  • Introduction
  • 1. Definitions
  • 2. Roles and Scope
  • 3. Term and Termination
  • 4. Processing Instructions
  • 5. Personnel
  • 6. Data‑Subject & Regulatory Assistance
  • 7. Security Measures
  • 8. Sub‑Processors
  • 9. International Transfers, Data Residency & Regional Compliance
  • 10. AI‑Assisted Tooling
  • 11. Personal Data Breach
  • 12. Deletion or Return of Data
  • 13. Audit and Compliance
  • 14. Liability
  • 15. Miscellaneous
  • Schedule A – Parties & Governing Law for SCCs
  • Schedule B – Technical & Organisational Measures
  • Schedule C – Authorised Sub‑Processors
  • Schedule D – UK Addendum
  • Schedule E – Description of Processing
ClonePartner

Best-in-class custom data migration and custom integration services for your best customers.

SOC 2, GDPR, ISO 27001, HIPAA Certified

9450, SW Gemini Drive, Beaverton, Oregon, US - 97008 Contact: support@clonepartner.com | (415)-592-5896

Case Studies

Decantalo Highsnobiety Shade Station Paazl 24 Hour Home Care Emergicon Watts & Co Flowtex Energy Integrative Nutrition RPM Shop Sales ATÖLYE Inuka Takomo Golf Loving Tan Parker Baby

Services

Help Desk Data Migration CRM Migration HRIS Migration Ecommerce Migration ATS Migration Accounting Migration Knowledge Base Migration ITSM Migration ERP Migration Financial Services CRM Migration

Resources

Pricing Customers Partners Refer a Deal Blog Philosophy Contact

Legal

Terms of Service Privacy Policy Data Processing Agreement GDPR CCPA Security Cookie Policy Manage Cookies Trust Center

Listed On

Zendesk Front Missive HubSpot Close Copper tawk.to Drupal Customer.io