Data Processing Agreement (DPA)
Effective from 1 June 2026 · Version 1.1
Contents
Version 1.1 — aligned with the Terms and Conditions of Cliqsales for the English-language market.
This Data Processing Agreement (“Agreement” or “DPA“) forms part of the agreement for the supply of services (in particular Appendix B — AI Team Done-For-You, Appendix C — AI Platform and Appendix F — Cliqsales AI Team standalone subscription) between:
Controller (Customer):
Business name / Name: _______________________________
Registered office: _______________________________
Company number / Registration: _______________________________
VAT number: _______________________________
Represented by: _______________________________
(hereinafter the “Customer” or “Controller“)
and
Processor:
Cliqsales International Limited
Office 2, 12a Lower Main Street, Lucan, Dublin K78 X5P8, Ireland
CRO number: 793862
A private company limited by shares incorporated in Ireland
Represented by: Pavel Hrdlička, Director (and any other Directors registered at the Companies Registration Office as required under section 151 of the Companies Act 2014)
(hereinafter “Cliqsales” or the “Processor“)
(together the “Parties“)
RECITALS
(A) The Customer acts as Controller of personal data of its own customers, contacts and other data subjects.
(B) The Customer wishes to use Cliqsales services in which Cliqsales processes personal data on the Customer’s behalf as a processor. This DPA applies specifically to:
- the AI Team Done-For-You (Appendix B) — the done-for-you implementation service in which Cliqsales’ AI Solutions Engineer accesses and processes the Customer’s data while building the AI team on the Customer’s behalf;
- the Cliqsales AI Platform (Appendix C) — the B2B SaaS in which Cliqsales hosts and processes the Customer’s data on the underlying GoHighLevel infrastructure; and
- the Cliqsales AI Team standalone subscription (Appendix F) — the proprietary AI Team software which Cliqsales licenses to the Customer as a SaaS service hosted on Cliqsales’ own server infrastructure (Hetzner data centres in the European Union). Cliqsales develops, maintains and operates the software and the underlying servers; Cliqsales is therefore a processor of Customer data under Article 28 GDPR for this service. This applies whether the Customer accesses the Cliqsales AI Team standalone (Appendix F) or as part of a bundle that includes it (typically together with Appendix A or Appendix B).
This DPA does not apply to: the AI Transformation Accelerator (Appendix A — guided self-implementation, no Cliqsales access to Customer data); the AI Transformation Mastermind (Appendix D — Zoom mentoring calls and community only, no data processing on the Customer’s behalf); or the AI Transformation Summit (Appendix E). In those services Cliqsales does not act as the Customer’s processor.
(C) Cliqsales provides services on two types of infrastructure:
- For the AI Platform (Appendix C) — on the HighLevel Inc. (GoHighLevel) technology platform under Cliqsales’ own brand; Customer Data is stored in HighLevel infrastructure (USA).
- For the Cliqsales AI Team (Appendix F, and any bundles that include it) — on Cliqsales’ own infrastructure hosted at Hetzner Online GmbH (Germany, EU); each Customer has a dedicated SaaS instance on Cliqsales servers. Customer Data is stored in data centres located in the EU/EEA.
The list of Sub-processors used by Cliqsales for each type of service is set out in Schedule A.
(D) The Parties undertake to comply with Regulation (EU) 2016/679 (GDPR), the Data Protection Act 2018 (Ireland), and other applicable laws.
(E) The Parties expressly agree that this DPA may also be concluded by electronic acceptance of the Terms and Conditions available at cliqsales.com/terms-and-conditions/ (see Terms clause 11.2) — physical signature of this document is not a condition of its validity. For Customers who, due to internal compliance, audit or certification requirements (ISO 27001, SOC 2, etc.), require a separately signed DPA, Cliqsales will issue it on request as a signed document. Requests at info@cliqsales.com.
IT IS AGREED AS FOLLOWS:
1. Definitions and interpretation
1.1 Unless otherwise provided in this Agreement, capitalised terms have the following meanings:
1.1.1 “Agreement” means this Data Processing Agreement and all Schedules.
1.1.2 “Main Agreement” — the contractual relationship between the Customer and Cliqsales governed by the Terms and Conditions and any of Appendix B (AI Team Done-For-You), Appendix C (AI Platform) or Appendix F (Cliqsales AI Team — standalone subscription), or other as applicable.
1.1.3 “Customer Personal Data” — any Personal Data processed by Cliqsales or Sub-processors on the Customer’s behalf in connection with the provision of the Services.
1.1.4 “Sub-processor” — any third party appointed by Cliqsales to process Personal Data on the Customer’s behalf (see Schedule A).
1.1.5 “Data Protection Laws” — GDPR, the Data Protection Act 2018 (Ireland), and other applicable EU and Irish data protection laws.
1.1.6 “EEA” — European Economic Area.
1.1.7 “GDPR” — Regulation (EU) 2016/679.
1.1.8 “Data Transfer” — transfer of Customer Personal Data to countries outside the EU/EEA, in particular:
- to the USA (HighLevel, Cloudflare, Stripe, Twilio, OpenAI, Anthropic, Google);
- to other countries pursuant to Schedule A.
1.1.9 “Services” include in particular:
For the AI Platform (Appendix C):
- CRM system and contact management;
- marketing automation (email, SMS, WhatsApp);
- creation and management of websites and landing pages;
- A.I.Q. ultra personalisation (AI-powered personalisation system);
- calendar and meeting management;
- reporting and analytics;
- related services provided through the Cliqsales Platform.
For the Cliqsales AI Team (Appendix B and Appendix F):
- operation of AI agents (AI CEO, AI Marketer, AI Sales, AI Operations Manager, AI Developer) and their skills;
- the AI Data Center (LLM wiki) — central memory of the Customer’s business;
- content generation (text, images, video, presentations) through third-party AI models;
- management of the Customer’s Brand DNA and Product DNA;
- API integrations with the Customer’s tools;
- related services provided through the Command Center and Cliqsales infrastructure.
1.2 The terms “Controller”, “Processor”, “Data Subject”, “Personal Data”, “Personal Data Breach”, “Processing” and “Supervisory Authority” (the Irish Data Protection Commission) have the same meaning as in GDPR.
2. Processing of Customer Personal Data
2.1 Cliqsales’ obligations
Cliqsales undertakes:
2.1.1 To process Customer Personal Data solely on the basis of documented instructions of the Customer, including the Main Agreement, this DPA and instructions submitted through the Cliqsales Platform.
2.1.2 To comply with all applicable Data Protection Laws.
2.1.3 Not to process Personal Data for its own purposes and not to disclose it to third parties save for Sub-processors listed in Schedule A.
2.1.4 To inform the Customer if a Customer instruction would, in Cliqsales’ opinion, infringe GDPR or other data protection laws.
2.2 Scope of processing
| Parameter | Value |
|---|---|
| Purpose | Provision of CRM, marketing and AI personalisation services |
| Types of data | Names, email addresses, telephone numbers, IP addresses, behavioural data on the website, business communications, responses to quizzes / questionnaires, other data entered by the Customer |
| Special category data (Article 9 GDPR) | NO — the Customer must not process special category data (health, race, political opinion, etc.) in the platform without express separate legal basis and prior consultation with Cliqsales |
| Categories of data subjects | Customers, prospective customers, Customer’s contacts, employees, partners |
| Duration of processing | For the duration of the Main Agreement and thereafter under clause 9 |
3. Personnel and access to data
3.1 Cliqsales shall ensure that:
3.1.1 Access to Customer Personal Data is granted only to authorised employees and contractors who need it to provide the Services (need-to-know principle).
3.1.2 All employees and contractors with access to data are bound by statutory or contractual confidentiality obligations.
3.1.3 Employees are trained in data protection.
4. Technical and organisational measures
4.1 Cliqsales implements appropriate technical and organisational measures under Article 32 GDPR corresponding to the nature, scope, context and purposes of processing:
Technical measures:
- encryption in transit (TLS 1.3);
- data protection at rest at the operating-system level — dedicated VPS per Customer (full database and filesystem isolation); application-level encryption of specific sensitive fields is subject to ongoing development under clause 4.3;
- dedicated SaaS instance per Customer — full isolation at operating-system and database level; no shared database between Customers;
- backup systems — application-level backups inside the instance plus regular VPS snapshots;
- firewall and DDoS protection (Cloudflare);
- controlled infrastructure access — SSH keys without shared passwords, separated accounts per person;
- audit logging of application and infrastructure access;
- infrastructure hosted with an ISO 27001 certified provider (Hetzner Online GmbH).
Organisational measures:
- information security policies with regular review;
- access management on a need-to-know basis;
- explicit non-disclosure agreements with all employees and contractors with technical access to Customer Data;
- employee training in data protection;
- incident response procedures under clause 7 of this DPA and Articles 33 and 34 GDPR;
- regular review of the security posture.
4.2 Cliqsales relies on the security infrastructure of its Sub-processors:
- Hetzner Online GmbH — ISO 27001 certification; datacentres in the EU;
- HighLevel (GoHighLevel) — SOC 2 Type II certification;
- Cloudflare — ISO 27001 certification, enterprise security;
- AI providers (Anthropic, OpenAI) — SOC 2 Type II, ISO 27001, enterprise/commercial tier.
4.3 Ongoing development. Cliqsales continues to develop its security architecture over time in line with Customer needs, the technology environment and the state of the art (in particular application-level encryption of specific sensitive fields, expanded monitoring and the Enterprise tier described in Appendix F clause F6.3). Specific measures may change; the Customer shall be informed of material changes to this list.
5. Sub-processors
5.1 Pre-approved Sub-processors
The Customer expressly consents to use of the Sub-processors listed in Schedule A, in particular:
- HighLevel Inc. (GoHighLevel) — USA — primary platform provider;
- Cloudflare Inc. — USA — CDN, security and infrastructure;
- OpenAI, L.L.C. — USA — AI models (Enterprise/Business tier, zero training data);
- Anthropic PBC — USA — AI models (Commercial Agreement with SCCs Module 2/3 under Implementing Decision (EU) 2021/914);
- Stripe Payments Europe Limited / Stripe Inc. — Ireland/USA — payments;
- Twilio Inc., Mailgun, SendGrid — USA — SMS and email infrastructure;
- other Sub-processors per Schedule A.
5.2 Changes to Sub-processors
Cliqsales may add or replace Sub-processors on the following terms:
5.2.1 Cliqsales shall notify the Customer at least 30 days in advance by email of the planned change.
5.2.2 The Customer has the right to submit reasoned objections within 14 days of the notice.
5.2.3 If Cliqsales cannot resolve the objections, the Customer has the right to terminate the Agreement without penalty.
5.2.4 The current list of Sub-processors is always available at cliqsales.com/sub-processors/ or on request at info@cliqsales.com.
5.3 Liability for Sub-processors
Cliqsales remains fully responsible to the Customer for processing carried out by Sub-processors and shall ensure they are bound by contractual obligations at a level corresponding to this DPA.
6. Data subject rights
6.1 Assistance
Cliqsales shall provide the Customer with reasonable assistance in meeting its obligations to Data Subjects, in particular requests:
- for access to data (Article 15 GDPR);
- for rectification (Article 16 GDPR);
- for erasure — “right to be forgotten” (Article 17 GDPR);
- for restriction of processing (Article 18 GDPR);
- for portability (Article 20 GDPR);
- for objection to processing (Article 21 GDPR).
6.2 Process for handling requests
6.2.1 If Cliqsales receives a request directly from a Data Subject, it shall inform the Customer without undue delay (within 2 business days).
6.2.2 Cliqsales shall not respond to the request without the Customer’s express consent, save where required by law.
6.2.3 Cliqsales provides tools in the Platform for export, rectification and erasure of data.
6.2.4 Responsibility to respond to the Data Subject lies with the Customer as Controller.
7. Notification of personal data breaches
7.1 Obligation to notify
Cliqsales shall notify the Customer of a Personal Data Breach without undue delay and, as a contractual commitment beyond the GDPR baseline, shall use reasonable efforts to do so within 24 hours of becoming aware of it.
7.2 Content of notification
The notification shall contain at least:
- description of the nature of the breach (what data, how many subjects);
- name and contact for the contact person for further information;
- likely consequences of the breach;
- proposed or taken measures to remedy.
7.3 Cooperation in resolution
Cliqsales shall actively cooperate with the Customer in:
- investigating the incident;
- mitigating the negative impact;
- preventing future incidents;
- communicating with the Irish Data Protection Commission where required.
8. Data Protection Impact Assessment (DPIA)
8.1 On request Cliqsales shall provide the Customer with information necessary for a Data Protection Impact Assessment under Article 35 GDPR, in particular:
- description of processing operations;
- security measures;
- information on Sub-processors;
- information on data transfers outside the EU/EEA.
9. Duration of processing and data deletion
9.1 At end of agreement
Within 30 days of termination of the Main Agreement, Cliqsales shall:
9.1.1 At the Customer’s choice either:
- return all Personal Data in a structured, commonly used format (CSV / JSON export), or
- delete all Personal Data and provide written confirmation of deletion.
9.1.2 Exception: Cliqsales may retain data if required by law (e.g. accounting records — 6 years under Irish tax law), but only for the necessary period.
9.2 Backup copies
Data in automatic backups will be erased as part of the standard backup rotation cycle (up to 90 days).
10. Audit and control
10.1 Right to audit
The Customer has the right to carry out an audit of processing or to appoint an independent auditor:
10.1.1 A request for audit must be made at least 30 days in advance.
10.1.2 An audit may be carried out at most once per year (save in cases of suspicion of breach).
10.1.3 The audit shall be performed during business hours and shall not disrupt Cliqsales’ operations.
10.1.4 The auditor is subject to a duty of confidentiality.
10.1.5 The costs of the audit are borne by the Customer, unless the audit reveals a serious breach of this Agreement.
10.2 Documentation for audit
On request Cliqsales shall provide:
- documentation of security measures;
- records of employee training;
- certifications of Sub-processors;
- records of security breaches (where applicable).
10.3 Alternative to audit
Instead of its own audit the Customer may accept:
- SOC 2 reports of HighLevel;
- ISO certifications of Cloudflare and others;
- Internal security documentation of Cliqsales.
11. International data transfers
11.1 Transfers outside the EU/EEA
For the Cliqsales AI Team (Appendix B and Appendix F), Personal Data is primarily stored on Cliqsales’ infrastructure hosted at Hetzner Online GmbH in Germany (EU/EEA) — no international transfer occurs by virtue of the hosting itself. Transfers outside the EU/EEA occur only when specific AI Team functions invoke AI model providers located outside the EU/EEA (OpenAI, Anthropic, Google) — in which case the safeguards listed below apply.
For the AI Platform (Appendix C), Personal Data is stored in HighLevel Inc.’s infrastructure (USA); international transfers occur on an ongoing basis.
The Customer expressly consents to transfers of Personal Data outside the EU/EEA to the following Sub-processors:
To the USA:
| Sub-processor | Purpose | Legal safeguard |
|---|---|---|
| HighLevel Inc. (GoHighLevel) | Primary platform and database | EU-US Data Privacy Framework + SCCs |
| Cloudflare Inc. | CDN and security services | EU-US DPF + SCCs |
| OpenAI, L.L.C. | AI models (Business/Enterprise tier) | SCCs Module 2/3 under Implementing Decision (EU) 2021/914 |
| Anthropic PBC | AI models (Commercial Agreement) | SCCs Module 2/3 under Implementing Decision (EU) 2021/914 |
| Google LLC | AI models, Workspace, analytics | EU-US DPF + SCCs |
| Twilio Inc. | SMS, email (Mailgun, SendGrid) | EU-US DPF + SCCs |
| Stripe Inc. | Payments (back-up; primarily via Stripe Payments Europe Ltd in Ireland) | EU-US DPF + SCCs |
To other countries: Per the current list in Schedule A.
11.2 Safeguards for transfers
Cliqsales ensures that transfers comply with Articles 44–50 GDPR by way of:
- Standard Contractual Clauses (SCCs) approved by the European Commission (Implementing Decision (EU) 2021/914);
- Certification under the EU-US Data Privacy Framework (where applicable);
- Additional technical measures (end-to-end encryption, pseudonymisation where feasible).
11.3 “No training” assurance
Cliqsales contractually ensures that the Customer’s Personal Data shall not be used to train language models of any of the AI Sub-processors (Anthropic, OpenAI, Google). The assurance is derived from:
- Anthropic Commercial Terms (zero training by default);
- OpenAI Business Terms (zero training on API tier by default);
- enterprise/commercial agreements with Google.
11.4 Right to information
The Customer may at any time request copies of the relevant safeguards (SCCs, certifications) at info@cliqsales.com.
12. Liability and indemnity
12.1 Cliqsales’ liability
Cliqsales is liable for damages caused by breach of this Agreement to the extent set out in the Main Agreement and applicable laws.
12.2 Limits of liability
Liability for damages caused by Sub-processors is limited by the limits in their terms and insurance cover (in particular HighLevel Inc.). This limitation does not apply where the law does not permit such limitation — in particular for death or personal injury caused by negligence, fraud or any other liability which cannot be limited or excluded under Irish law.
12.3 Insurance
Cliqsales recommends that the Customer maintain its own cyber risk insurance for comprehensive protection.
13. General provisions
13.1 Confidentiality
Each Party shall maintain confidentiality of all confidential information received in connection with this Agreement, save where disclosure is required by law.
13.2 Notices
All notices must be:
- in written form (email is acceptable);
- sent to the contact addresses specified in the header of the Agreement;
- for critical notices (security breach) a combination of email + telephone.
Contact emails:
- Cliqsales for DPA: info@cliqsales.com
- Cliqsales for support: support@cliqsales.com
- Cliqsales for security incidents: info@cliqsales.com (please mark “SECURITY”)
- Customer: _______________________________
13.3 Amendments
Amendments to this Agreement must be in writing and signed by both Parties, save for updates to the list of Sub-processors under clause 5.2.
13.4 Severability
If any provision of this Agreement is invalid, the remaining provisions remain in force.
13.5 Priority
In the event of conflict between:
- this DPA,
- the Terms and Conditions and Appendix B, C or F,
- an individual agreement,
this DPA prevails on matters of personal data protection.
14. Governing law and jurisdiction
14.1 This Agreement is governed by Irish law.
14.2 All disputes shall be resolved by the courts of Ireland.
14.3 Before commencing legal proceedings, the Parties undertake to attempt amicable resolution of the dispute.
SIGNATURES
IN WITNESS whereof the Parties have entered into this Agreement on the date stated below.
For the Customer (Controller):
Name: _______________________________
Position: _______________________________
Date: _______________________________
Signature: _______________________________
For Cliqsales (Processor):
Name: _______________________________
Position: Director
Date: _______________________________
Signature: _______________________________
# SCHEDULE A — List of Sub-processors
Effective as of: date of execution of this DPA in the signature block
1. Primary platform and hosting infrastructure
| Sub-processor | Country | Purpose | Security |
|---|---|---|---|
| Hetzner Online GmbH | Germany (EU) | Server hosting infrastructure for the Cliqsales AI Team software (Appendix B and Appendix F) — dedicated EU data centres (Falkenstein / Nuremberg / Helsinki) | ISO 27001 (Hetzner), GDPR-compliant (EU established, no international transfer) |
| HighLevel Inc. (GoHighLevel) | USA | Provision of CRM platform, database, email/SMS infrastructure for the AI Platform (Appendix C) | SOC 2 Type II, EU-US DPF, SCCs |
| Cloudflare Inc. | USA | CDN, DDoS protection, security, infrastructure | ISO 27001, EU-US DPF, SCCs |
2. Communication services
| Sub-processor | Country | Purpose | Security |
|---|---|---|---|
| Twilio Inc. | USA | SMS delivery | SOC 2, ISO 27001, SCCs |
| Mailgun (Sinch Email) | USA | Email infrastructure | SOC 2, SCCs |
| SendGrid (Twilio) | USA | Email infrastructure | SOC 2, SCCs |
3. AI and analytics services
| Sub-processor | Country | Purpose | Security |
|---|---|---|---|
| OpenAI, L.L.C. | USA | AI models (GPT) — Business/Enterprise tier | SOC 2 Type II, SCCs Module 2/3, zero training default |
| Anthropic PBC | USA | AI models (Claude) — Commercial Agreement | SOC 2 Type II, SCCs Module 2/3 under Implementing Decision (EU) 2021/914, zero training default |
| Google LLC | USA | Google AI / Gemini, Google Workspace | SOC 2, ISO 27001, EU-US DPF, SCCs |
| Mistral AI | EU (France) | AI models | GDPR-compliant (EU established) |
4. Payment services
| Sub-processor | Country | Purpose | Security |
|---|---|---|---|
| Stripe Payments Europe Limited | Ireland (EU) | Payment processing in EU | PCI-DSS Level 1, GDPR-compliant |
| Stripe, Inc. | USA | Payment processing outside EU | PCI-DSS Level 1, EU-US DPF, SCCs |
5. Conferencing and collaboration tools
| Sub-processor | Country | Purpose | Security |
|---|---|---|---|
| Zoom Video Communications, Inc. | USA | Online workshops and calls | SOC 2, ISO 27001, EU-US DPF, SCCs |
| Fireflies.ai | USA | Call transcripts and summaries (with Customer consent) | SOC 2, SCCs |
Notes
- This list is regularly updated — current version at
cliqsales.com/sub-processors/. - Cliqsales notifies of changes under clause 5.2 of the main Agreement.
- All Sub-processors are bound by an equivalent DPA providing the same level of protection.
Abbreviations
- SCCs = Standard Contractual Clauses under Implementing Decision (EU) 2021/914
- EU-US DPF = EU-US Data Privacy Framework
- SOC 2 = Service Organization Control 2
- ISO 27001 = International Standard for Information Security Management
- PCI-DSS = Payment Card Industry Data Security Standard
- GDPR = Regulation (EU) 2016/679