Data Processing Agreement (GDPR Art. 28) – Community (SaaS)

Effective Date: February 1, 2026

This Data Processing Agreement (“DPA”) forms part of the agreement between ClearML, as it is defined in the Terms of Use (“Processor”) and the Customer (“Controller” or “Processor,” as applicable).

This Data Processing Agreement (“DPA”) forms part of the agreement between ClearML, as defined in the Terms of Use (“ClearML” or “Processor”), and the Customer (“Customer”), who acts either as controller or as processor on behalf of its own controller(s), as applicable. For the purposes of this DPA, (i) where Customer acts as controller of personal data, ClearML processes such personal data as Customer’s processor; and (ii) where Customer acts as processor, ClearML processes such personal data as Customer’s sub-processor.

This DPA applies only to ClearML’s processing of personal data on behalf of Customer under the main agreement; any processing by ClearML as an independent controller (including for account administration, billing, security, or service improvement) remains governed by ClearML’s Privacy Policy and the main agreement and is outside the scope of this DPA.

1. Subject Matter and Duration

Processing is limited to providing the Services as defined in the main agreement and continues for the term of the agreement.

Processing under this DPA is limited to ClearML’s processing of personal data on behalf of Customer as necessary to provide the Services as defined in the main agreement and continues for the term of the main agreement.

2. Nature and Purpose of Processing

Support diagnostics, incident response, and service maintenance (exception-based only); no routine processing.

3. Types of Personal Data and Categories of Data Subjects

Limited account identifiers and logs, as necessary for support; data subjects may include Customer personnel authorized to use the Services.

4. Controller Instructions

Processor shall process personal data only on documented instructions from Controller, including with respect to data transfers.

Processor shall process personal data only on documented instructions from Customer (acting as controller or as processor on behalf of its own controller(s)), including with respect to data transfers.

Where Customer acts as a processor, Customer represents and warrants that it is authorized by its controller(s) to appoint Processor as sub-processor and to issue such instructions on their behalf, and that Customer will pass through any relevant controller instructions or restrictions to Processor.

5. Confidentiality

Processor shall ensure persons authorized to process the personal data are under confidentiality obligations.

6. Security Measures

Processor implements appropriate technical and organizational measures. A summary of measures may be attached as Annex II.

7. Sub-processors

Processor may engage sub-processors subject to written authorization, with obligations equivalent to this DPA. A list of sub-processors is maintained and will be provided upon request.

8. Data Subject Rights

Processor shall assist Controller by appropriate technical and organizational measures, insofar as possible, in fulfilling Controller’s obligations to respond to data subject requests.

9. Personal Data Breach

Processor shall notify Controller without undue delay after becoming aware of a personal data breach and shall assist with remediation.

10. Data Transfers

International transfers will occur only under approved mechanisms (e.g., SCCs, EU-U.S. DPF/UK Extension) as instructed by Controller.

11. Audit and Compliance

Processor shall make available information necessary to demonstrate compliance and allow for audits, subject to confidentiality and reasonable limits.

12. Return or Deletion

Upon termination, Processor shall, at Controller’s choice, delete or return personal data and delete existing copies unless law requires storage.

13. Liability and Indemnity

Each party remains responsible for its own obligations under this DPA and applicable law. Liability is subject to the limitations in the main agreement.

14. Miscellaneous

In case of conflict, this DPA prevails over related privacy terms regarding processing obligations. NY law applies, without prejudice to mandatory EU data protection law.

Annex I – Processing Details

A. Subject matter and duration; B. Nature and purpose; C. Type of personal data; D. Categories of data subjects; E. Frequency of processing; F. Data retention; G. Locations.

Annex II – Technical and Organizational Measures

Describe security measures: access controls, encryption, logging/monitoring, vulnerability management, incident response, business continuity, and personnel security.

Annex III – Sub-processors

List authorized sub-processors (if any), with contact details and processing descriptions.

Scroll to Top