Data Processing Addendum
Last updated: July 30, 2026
This Data Processing Addendum (“DPA”) forms part of the Terms of Servicebetween Caring Consulting Co. LLC (“Clariva”, “we”) and the organization using Clariva (“Customer”, “you”). It applies automatically when you use the service; no signature is required. If your organization needs a countersigned copy, email support@caringconsulting.co.
Where this DPA conflicts with the Terms of Service on the handling of Customer Personal Data, this DPA governs.
1. Definitions
- Customer Personal Data — personal information contained in the business records your organization enters into or generates within Clariva, including data about your customers, their contacts and their transactions.
- Processing — any operation performed on personal data, including collection, storage, use, disclosure and deletion.
- Sub-processor — a third party engaged by us that processes Customer Personal Data to help deliver the service.
- Applicable Privacy Law — US state privacy laws that apply to the parties, including the California Consumer Privacy Act as amended (CCPA/CPRA) and the Texas Data Privacy and Security Act (TDPSA).
- Security Incident — a breach of security leading to accidental or unlawful destruction, loss, alteration, or unauthorized disclosure of or access to Customer Personal Data.
2. Roles of the parties
For Customer Personal Data, you are the business / controller and we are the service provider / processor. You determine what data to collect, why, and how long to keep it. We process it only to provide and support the service.
We act as a controller only for our own account, billing and support records — who your administrators are, what you were invoiced, and our correspondence with you. That processing is described in our Privacy Policy and is outside this DPA.
You are responsible for the lawfulness of the data you put into Clariva, including having a lawful basis to collect it and providing any notices your own customers are owed.
3. Scope and instructions
We process Customer Personal Data only on your documented instructions. Your use of the service — and the configuration choices your administrators make within it — constitute your instructions. Additional instructions may be given in writing and, where they require work beyond the service's normal operation, may be subject to agreement on scope and cost.
We will tell you if, in our opinion, an instruction infringes Applicable Privacy Law, and may pause that processing until it is resolved.
4. Our commitments as a service provider
Under CCPA/CPRA and comparable state laws, we will not:
- sell or share Customer Personal Data, as those terms are defined in Applicable Privacy Law;
- retain, use or disclose it for any purpose other than providing the service, or as otherwise permitted by Applicable Privacy Law;
- retain, use or disclose it outside the direct business relationship between you and us;
- combine it with personal information received from another source, except as permitted to provide the service; or
- use it to train third-party or general-purpose AI models.
We certify that we understand these restrictions and will comply with them. If we can no longer meet them, we will notify you.
5. Confidentiality
We limit access to Customer Personal Data to personnel who need it to deliver or support the service. Those personnel are bound by confidentiality obligations and receive appropriate training. Our operational access is limited to what running and supporting the service requires, and administrative actions are recorded in an audit log.
6. Security measures
We maintain technical and organizational measures appropriate to the risk, including those described on our Security page. As at the date above, these include:
- encryption of data in transit (HTTPS) and at rest;
- tenant isolation, with the tenant derived from a verified identity token rather than from anything the client can set;
- role-based access control with per-capability permissions, administered by your own administrators;
- multi-factor authentication and passkey support, and re-authentication for sensitive actions;
- session lifetime limits, inactivity locking, and immediate session revocation on user offboarding;
- an append-only audit log of security-relevant and administrative actions;
- hosting on Google Cloud in the United States, using managed services with built-in redundancy and point-in-time recovery.
We may update these measures as the service evolves, provided we do not materially reduce the overall level of security.
7. Sub-processors
You authorize us to engage the sub-processors listed on our sub-processor page, which is incorporated into this DPA. Each is bound by written terms imposing data-protection obligations no less protective than those in this DPA, and we remain responsible for their performance.
We will update that page at least 30 days before a new sub-processor begins processing Customer Personal Data. To be notified of changes, email us and we will add you to the notification list. If you reasonably object to a new sub-processor on data-protection grounds within those 30 days, tell us and we will work with you in good faith to find an alternative; if we cannot, you may terminate the affected part of the service and receive a pro-rated refund of prepaid fees for the unused remainder of your term.
8. Data-subject requests
The service gives your administrators the ability to access, correct, export and delete the records your organization holds, which is normally sufficient to respond to a request yourself.
If a data subject contacts us directly about data we process on your behalf, we will not respond substantively — we will route the request to you, since it is your data and you decide the outcome. Where you need help we cannot provide through the product, we will give reasonable assistance, taking into account the nature of the processing.
9. Security incidents
We will notify you of a Security Incident affecting Customer Personal Data without undue delay, and in any event within 72 hours of becoming aware of it. The notice will describe, to the extent known: the nature of the incident and the categories and approximate volume of data involved; the likely consequences; the measures taken or proposed to address it; and a contact point for further information. Where the full picture is not yet available we will provide information in phases rather than delay the initial notice.
We will take reasonable steps to contain and remediate the incident, and will cooperate with you in meeting any notification obligations you owe to regulators or individuals. Our notification is not an acknowledgement of fault or liability.
10. Return and deletion
You can export your organization's data from within the service at any time during your subscription. After termination we retain your data for 30 days so that an accidental cancellation can be reversed, then delete it. You may request earlier deletion in writing.
We may retain Customer Personal Data where required by law, and in routine backups until those backups expire on their normal cycle. Data retained in backups remains subject to this DPA and is not restored to active use.
11. Audits and information
On reasonable written request, and no more than once in any twelve-month period unless required by a regulator or following a Security Incident, we will provide the information reasonably necessary to demonstrate our compliance with this DPA — including responses to a standard security questionnaire and any third-party attestations we hold.
Because Clariva is multi-tenant, on-site inspection of production systems is not available: it would expose other customers' data. Where a documentary response is genuinely insufficient for your regulatory obligations, we will discuss a proportionate alternative, such as an assessment by a mutually agreed independent auditor under confidentiality, at your cost.
12. International transfers
Clariva is operated from the United States and hosts Customer Personal Data in US regions. Our sub-processors process it in the United States. We do not currently offer data residency outside the US, and this DPA does not include the EU Standard Contractual Clauses or a UK Addendum. If your organization requires processing subject to the GDPR or UK GDPR, contact us before entering data governed by those laws.
13. Liability
Each party's liability arising out of this DPA is subject to the exclusions and limitation of liability in the Terms of Service. Nothing in this DPA limits liability that cannot be limited under Applicable Privacy Law.
14. Term and changes
This DPA takes effect when you begin using the service and continues for as long as we process Customer Personal Data. Sections that by their nature should survive — including confidentiality, deletion, and liability — survive termination.
We may update this DPA to reflect changes in law or in the service. Where a change materially reduces your rights or our obligations, we will give at least 30 days' notice before it takes effect.
Annex A — Details of processing
- Subject matter. Provision of the Clariva CRM and ERP service.
- Duration. The term of the subscription, plus the retention period in section 10.
- Nature and purpose. Hosting, storage, retrieval, indexing for search, transmission of transactional email, accounting synchronization where enabled, payment processing where enabled, error monitoring, and responding to in-product questions via the AI assistant.
- Categories of data subject. Your personnel who use the service; your customers and prospects; your customers' contacts; your vendors' contacts.
- Categories of personal data. Names, business contact details (email, phone, postal address), job titles, account and order history, invoice and payment records, correspondence, and user authentication and activity records.
- Special category data. None. The service is not designed for, and must not be used for, health data, government identifiers, full payment card numbers, or the data of children — see our Acceptable Use Policy.
Annex B — Sub-processors
The current list, with the purpose and data accessed for each, is maintained at clarivacrm.com/legal/subprocessors and forms part of this DPA.
Contact
Questions about this DPA, requests for a countersigned copy, and sub-processor notification requests: support@caringconsulting.co
Caring Consulting Co. LLC2221 Peachtree Road, Suite 6, PMB 1178
Atlanta, Georgia 30309
United States