C
CLAB
Data Processing Addendum

Data Processing Addendum

Version: 2026-06-06  ·  Effective: 2026-06-06  ·  Document code: dpa

This Data Processing Addendum ("DPA") forms part of the agreement between CLAB ("Processor") and the customer organisation ("Controller") that subscribes to the Service. Where capitalised terms used here are not defined, they take the meaning given in the GDPR, the UAE Personal Data Protection Law ("NDPL"), or the India Digital Personal Data Protection Act ("DPDP"), as applicable.

1. Roles

The Controller determines the purposes and means of processing personal data of its end-users via the Service. The Processor processes that personal data on the Controller's documented instructions, which the Controller provides through (a) the Service's configuration (RBAC, PII rules, retention windows), and (b) any written direction sent by the Controller's tenant admin.

2. Nature and purpose of processing

The Processor receives prompts and responses, applies PII redaction, routes sanitised prompts to the third-party LLM the Controller has selected, returns the response with PII re-injection (for the session owner only), and records audit metadata.

3. Categories of data and data subjects

4. Sub-processors

The Processor uses the following sub-processors. The Controller authorises their use by accepting this DPA. The Processor will give the Controller at least 30 days' notice before adding or replacing a sub-processor; the Controller may object in writing and, if a reasonable accommodation cannot be reached, terminate the relevant Service for the affected tenant.

5. Security measures

6. Data subject rights

The Processor will assist the Controller in responding to data-subject requests by providing:

7. Breach notification

If the Processor becomes aware of a personal-data breach affecting the Controller's data, it will notify the Controller's tenant admin without undue delay, and in any event within 72 hours of becoming aware. The notification will include, where known, the nature of the breach, the categories and approximate number of affected data subjects, the likely consequences, and the measures taken or proposed.

8. Audit rights

Once per 12-month period, the Controller may request — with at least 30 days' notice — a copy of the Processor's most recent third-party security report (SOC 2 Type II once available, ISO 27001 once available). Pending those certifications, the Processor will provide a written summary of its security controls signed by an officer.

9. International transfers

Where the Service involves transferring personal data outside the Controller's data-residency region, such transfer will take place only on the basis of a recognised transfer mechanism (standard contractual clauses, adequacy decision, or explicit consent of the data subject), and only as required to fulfil the Controller's documented instructions.

10. Return or deletion on termination

On termination of the agreement, the Processor will, at the Controller's choice, return or delete all personal data within 30 days, except where retention is required by law. Backups are overwritten in the ordinary course of operations within 90 days.

11. Liability and conflicts

This DPA is subject to the liability provisions of the main Terms of Service. In the event of a conflict between this DPA and the Terms, this DPA prevails for matters of personal-data processing.


Signed electronically on acceptance via the CLAB admin console. A countersigned copy is available at GET /v1/me/dsar/export for the Controller's tenant admin.

© 2026 CLAB. All rights reserved.  ·  Back to console