ClonePartner Talk to us
Terms Privacy DPA GDPR CCPA Security Cookies Trust Center

GDPR

Last updated: 28 July 2026
View as Markdown ·
On this page
  • Background
  • Our Commitment
  • 1. Controller and Processor Roles
  • 2. Risk Assessment
  • 3. Data-Subject Consent
  • 4. Contracts with Sub-processors
  • 5. International Data Transfers
  • 6. Data Retention & Erasure
  • 7. Article 30 Record-Keeping
  • 8. Breach Response
  • 9. Ongoing Compliance
  • 10. EU & UK Representatives
  • 11. Questions

Background

On May 25 2018, the European Union (EU) began enforcing the General Data Protection Regulation (GDPR). After Brexit, the United Kingdom adopted the UK GDPR. Together, these regulations harmonize data-protection rules across the EU and UK and give individuals stronger, more consistent rights over their personal information.

Our Commitment

Yin Yang Inc. (“we”, “us”, “our”, ClonePartner) takes data-privacy and security obligations seriously. We continuously review our operations to keep every aspect of the clonepartner.com platform and our associated services—including bespoke data migrations, custom integrations, automated backup and recovery, continuous data sync, and implementation-partner engagements—aligned with GDPR requirements.

1. Controller and Processor Roles

  • Data Controller: For any personal information submitted directly on clonepartner.com (e.g., contact forms, demo requests, job applications), ClonePartner determines the purposes and means of processing.
  • Data Processor: When customers use our Services and supply personal information about their end-users, we process that data strictly on their documented instructions.

2. Risk Assessment

We conduct organization-wide information-discovery exercises to identify:

  • what personal data we hold,
  • where it originates,
  • how and why we process it, and
  • with whom it is shared.

Findings drive continual improvements to our technical and organizational safeguards. Where a processing activity is likely to result in a high risk to individuals, we carry out a Data Protection Impact Assessment, and we assist customers with their own DPIAs as described in our Data Processing Agreement.

3. Data-Subject Consent

  • Website visitors are informed of our Privacy Policy and Cookie Policy; personal data submitted through the Website is processed on the lawful bases described in our Privacy Policy (consent, performance of a contract, or legitimate interests).
  • Users can exercise GDPR rights—access, rectification, erasure, restriction, objection, and portability—by contacting legal@clonepartner.com.

4. Contracts with Sub-processors

When acting as a Controller, we execute GDPR-compliant data-processing agreements with every sub-processor, ensuring they handle personal data only under our instructions and with robust security controls.

As a Processor, we adopt the safeguards and follow the instructions defined in each customer’s data-processing addendum.

The current sub-processor list, including each vendor’s purpose and location, is published in our Trust Center.

5. International Data Transfers

We rely on:

  • the EU Standard Contractual Clauses (SCCs) and
  • the UK International Data Transfer Addendum (IDTA)

Together, these provide a lawful basis for any transfer of personal data outside the EU or UK. The precise configuration — module selection, options, and annex mapping — is set out in Section 9.6 of our Data Processing Agreement.

Customers can also reduce cross-border transfers of migrated personal data altogether. For cloud-delivered migrations, the temporary staging database can be provisioned in an EU region (on DigitalOcean or OVHcloud infrastructure) so migrated personal data remains in the EU for the duration of the project, and self-hosted deployments keep personal data entirely within the customer’s own environment. Available regions are listed on our Security page.

6. Data Retention & Erasure

ClonePartner’s internal Data-Protection Compliance Policy embeds the GDPR principles of data minimization and storage limitation. Personal data is retained only as long as necessary for its stated purpose, after which it is securely deleted or anonymised. For migration engagements, temporary staging databases are automatically purged no later than 30 days after project close, or earlier on request.

7. Article 30 Record-Keeping

We maintain detailed records of all personal-data processing activities—both as Controller and as Processor—in line with Article 30(1) and 30(2) requirements.

8. Breach Response

Robust preventive measures reduce the likelihood of a data breach. Should a breach occur, we will:

  1. Contain and investigate the incident immediately.
  2. Notify affected customers and the relevant supervisory authority without undue delay, following GDPR timelines.
  3. Provide timely updates and remediation actions to all stakeholders.

9. Ongoing Compliance

We review policies, contracts, and security controls regularly, train staff on data-protection best practices, and audit sub-processors to ensure continued adherence to GDPR standards.

10. EU & UK Representatives

EU Representative (GDPR Art. 27)
Rickert Rechtsanwaltsgesellschaft mbH – YIN YANG, INC.
Colmantstraße 15, 53115 Bonn, Germany
art-27-rep-yinyang@rickert.law
UK Representative (UK GDPR Art. 27)
Rickert Services Ltd UK – YIN YANG, INC.
PO Box 1487, Peterborough PE1 9XX, United Kingdom
art-27-rep-yinyang@rickert-services.uk

11. Questions

For any GDPR-related inquiry, reach our Data Protection Officer at dpo@clonepartner.com or write to legal@clonepartner.com. ClonePartner remains committed to safeguarding personal data and upholding every right granted under the GDPR.

On this page

  • Background
  • Our Commitment
  • 1. Controller and Processor Roles
  • 2. Risk Assessment
  • 3. Data-Subject Consent
  • 4. Contracts with Sub-processors
  • 5. International Data Transfers
  • 6. Data Retention & Erasure
  • 7. Article 30 Record-Keeping
  • 8. Breach Response
  • 9. Ongoing Compliance
  • 10. EU & UK Representatives
  • 11. Questions
ClonePartner

Best-in-class custom data migration and custom integration services for your best customers.

SOC 2, GDPR, ISO 27001, HIPAA Certified

9450, SW Gemini Drive, Beaverton, Oregon, US - 97008 Contact: support@clonepartner.com | (415)-592-5896

Case Studies

Decantalo Highsnobiety Shade Station Paazl 24 Hour Home Care Emergicon Watts & Co Flowtex Energy Integrative Nutrition RPM Shop Sales ATÖLYE Inuka Takomo Golf Loving Tan Parker Baby

Services

Help Desk Data Migration CRM Migration HRIS Migration Ecommerce Migration ATS Migration Accounting Migration Knowledge Base Migration ITSM Migration ERP Migration Financial Services CRM Migration

Resources

Pricing Customers Partners Refer a Deal Blog Philosophy Contact

Legal

Terms of Service Privacy Policy Data Processing Agreement GDPR CCPA Security Cookie Policy Manage Cookies Trust Center

Listed On

Zendesk Front Missive HubSpot Close Copper tawk.to Drupal Customer.io