Data Processing Addendum

Last updated: August 31, 2026

This Data Processing Addendum ("DPA") forms part of and supplements the Terms of Use between Clakta LTDA ("Clakta"), and the customer that subscribes to the Services (the "Customer"), together the "Parties".

This DPA applies whenever Clakta processes personal data on the Customer's behalf in providing the Services. By accepting the Terms of Use, the Customer also accepts this DPA. No separate signature is required; a Customer that needs a signed copy may request one at [email protected].


1. Definitions

"Data Protection Law" means Brazilian Law No. 13,709/2018 (LGPD) and, where applicable to the processing, Regulation (EU) 2016/679 (GDPR), the UK GDPR, and other data protection laws applicable to the Parties.

"Customer Personal Data" means the personal data contained in the Customer Data, as defined in the Terms of Use, processed by Clakta on the Customer's behalf in providing the Services.

"Data subject", "controller", "processor", "processing", and "personal data breach" have the meanings given to them in Data Protection Law. Under the LGPD, "controller" corresponds to controlador and "processor" to operador.

"Subprocessor" means a third party engaged by Clakta to process Customer Personal Data in providing the Services.

"Services", "Connected Platform", "Project", "Properties", "Authorized User", and "End User" have the meanings given to them in the Terms of Use.

Terms not defined in this DPA have the meaning given in the Terms of Use.


2. Roles of the Parties and subject matter

2.1. In relation to Customer Personal Data, the Customer acts as controller and Clakta acts as processor. Where the Customer is itself a processor for a third party — for example, an agency operating the Services on behalf of its clients — Clakta acts as subprocessor, and the obligations in this DPA apply to the same extent.

2.2. Clakta acts as controller in relation to account, billing, support, marketing, security, and its own website visitor data, as described in the Privacy Policy. That data is outside the scope of this DPA.

2.3. The subject matter, nature, purpose, and duration of the processing, the categories of personal data, and the categories of data subjects are set out in Annex I.


3. Processing instructions

3.1. Clakta will process Customer Personal Data only on the Customer's documented instructions, unless required to do otherwise by law, in which case Clakta will inform the Customer beforehand unless the law prohibits that notice on important grounds of public interest.

3.2. The Customer's documented instructions consist of: (a) this DPA and the Terms of Use; (b) the configuration of the Services made by the Customer and its Authorized Users, including tracking mode, consent management, retention, integrations, and the sending of conversion signals to Connected Platforms; and (c) additional instructions given in writing and accepted by Clakta. Instructions that require changes to the Services may be subject to a separate agreement and additional charges.

3.3. Clakta will inform the Customer if, in its view, an instruction infringes Data Protection Law, and may suspend execution of that instruction until the matter is resolved.

3.4. Clakta will not sell Customer Personal Data, will not use it for its own targeted advertising, will not combine it with other customers' data to build profiles or identity graphs, and will not use it to train publicly available foundation models. Clakta may generate aggregated and anonymized data that cannot reasonably be used to identify the Customer, its Authorized Users, or End Users, and use it as set out in the Terms of Use.

3.5. Instructions relating to artificial intelligence features, including Assistant, are limited to answering the Customer's requests and performing actions the Customer has expressly approved. The AI providers listed in Annex III are contractually prohibited from using data submitted through the Services to train their models.


4. Customer obligations

4.1. The Customer represents and warrants that: (a) it has a valid legal basis for processing Customer Personal Data and for transferring it to Clakta; (b) it obtains, records, and honors End User consent where required, including for cookies and similar technologies; (c) it maintains an accurate and accessible privacy notice describing collection through analytics and attribution technologies, the transmission of data to Clakta and to Connected Platforms, and data subject rights; and (d) its instructions to Clakta comply with Data Protection Law.

4.2. The Customer is responsible for configuring the Services consistently with its legal obligations and its published notices, including tracking mode, consent management, IP and identifier handling, and retention periods.

4.3. The Customer will not send special categories of personal data, payment card numbers or full financial account credentials, government identification numbers, precise geolocation data, or data relating to children and adolescents to the Services, unless expressly agreed in writing by Clakta. Clakta is not responsible for such data submitted in breach of this Section.

4.4. The Customer is responsible for assessing whether the Services, including the selected storage region and the subprocessors listed in Annex III, meet its own legal obligations.


5. Confidentiality

Clakta ensures that persons authorized to process Customer Personal Data are subject to a contractual or statutory duty of confidentiality and receive appropriate data protection and information security training. Access is granted on a least-privilege basis and is logged.


6. Information security

6.1. Clakta implements and maintains the technical and organizational measures set out in Annex II, appropriate to the risk, taking into account the state of the art, the cost of implementation, and the nature, scope, and purposes of the processing.

6.2. Clakta may update those measures over time, provided it does not reduce the contracted level of protection.


7. Subprocessors

7.1. The Customer gives general authorization for Clakta to engage subprocessors. The current list is published at https://www.clakta.com/legal/subprocessors and summarized in Annex III.

7.2. Clakta will enter into a written agreement with each subprocessor imposing data protection obligations substantially equivalent to those in this DPA, and remains fully liable to the Customer for the acts and omissions of its subprocessors.

7.3. Clakta will give at least 30 days' notice of the addition or replacement of a subprocessor, by email to the Customer's privacy or administrative contact or by in-product notice. Customers can subscribe to change notifications on the subprocessors page.

7.4. The Customer may object on reasonable grounds, in writing to [email protected], within 15 days of the notice. If the Customer objects, the Parties will negotiate a reasonable alternative in good faith. If none is available, the Customer may terminate the affected Services on written notice, with a pro-rata refund of prepaid, unused fees as its exclusive remedy. Failure to respond within the period constitutes acceptance.

7.5. Where there is an imminent risk to the security or continuity of the Services, Clakta may engage a new subprocessor with immediate notice, and the right to object applies after the fact.


8. Data subject rights

8.1. Taking into account the nature of the processing, Clakta will assist the Customer by appropriate technical and organizational measures, insofar as reasonably possible, in responding to data subject requests concerning confirmation, access, correction, anonymization, blocking, deletion, portability, information about sharing, withdrawal of consent, and objection.

8.2. The Services provide query, export, and deletion functionality that allows the Customer to handle most such requests on its own.

8.3. If Clakta receives a request directly from a data subject relating to Customer Personal Data, it will not respond on the merits and will forward the request to the Customer without undue delay, unless legally required to respond.

8.4. In most configurations Clakta cannot identify a data subject from analytics data alone. The Customer must provide a sufficient identifier — such as an order reference, email address, or user identifier — to locate the records.


9. Personal data breaches

9.1. Clakta will notify the Customer of any personal data breach affecting Customer Personal Data without undue delay and, where feasible, within 48 hours of becoming aware of it.

9.2. The notice will include, to the extent the information is available: the nature of the breach, the categories and approximate volume of data and data subjects affected, the likely consequences, the measures taken or proposed to mitigate its effects, and a contact point for further information. Further information will be provided as the investigation progresses.

9.3. Clakta will take reasonable steps to contain, investigate, and mitigate the breach and will cooperate with the Customer in meeting its notification duties to the ANPD, other authorities, and data subjects. Notifying authorities and data subjects in relation to Customer Personal Data is the Customer's responsibility as controller.

9.4. Notification of a breach is not an acknowledgment of fault or liability by Clakta.


10. Impact assessments and cooperation with authorities

On reasonable request, and taking into account the information available to it, Clakta will assist the Customer with data protection impact assessments and any prior consultation with a competent authority relating to processing carried out through the Services. Requests going beyond Clakta's standard documentation may be charged on a time-and-materials basis, against a prior estimate.


11. Audit and information rights

11.1. Clakta will make available to the Customer the information necessary to demonstrate compliance with this DPA, including its security documentation, the description of the measures in Annex II, and responses to a standard security questionnaire.

11.2. The Customer may request an audit once every 12 months, on 30 days' notice, during business hours, without disrupting Clakta's operations and subject to confidentiality. Audits will be conducted primarily through documentation, questionnaires, and a remote technical meeting.

11.3. An on-site audit, or one conducted by an independent third party, will take place only where required by a competent authority or where the documentation provided is demonstrably insufficient. In that case the auditor must not be a competitor of Clakta and must sign a confidentiality undertaking. Costs are borne by the Customer, unless the audit reveals a material breach of this DPA by Clakta.

11.4. No audit will give access to other customers' data, third-party information, or information whose disclosure would compromise Clakta's security.


12. Data residency and international transfers

12.1. When a team is created, the Customer selects the region in which its project data is stored: the European Union or the United States. That selection is permanent and cannot be changed, and there is no migration path. Every project inherits its team's region.

12.2. Certain records are stored in the United States regardless of the region selected, including user accounts, team and billing data, API keys, sales platform credentials, product feedback, and support conversations. The full breakdown is set out at Data storage location and in Section 9 of the Privacy Policy.

12.3. Clakta is operated from Brazil and its personnel access both regions to run, secure, support, and troubleshoot the Services, under least-privilege controls and logging. Certain subprocessors also operate outside the selected region.

12.4. For international transfers from Brazil, the Parties adopt the standard contractual clauses approved by the ANPD, which are incorporated into this DPA where applicable.

12.5. For transfers from the European Economic Area, the United Kingdom, or Switzerland to a country without an adequacy decision, the European Commission's Standard Contractual Clauses (Implementing Decision (EU) 2021/914) are incorporated into this DPA, using Module Two where the Customer is controller and Clakta is processor, and Module Three where the Customer is processor and Clakta is subprocessor, together with the UK Addendum or the Swiss variant where applicable. For the purposes of those clauses: the Customer is the data exporter and Clakta is the data importer; the general subprocessor authorization option with a 30-day notice period applies (Clause 9(a)); and the governing law and forum follow Section 16 of this DPA to the extent permitted by those clauses.

12.6. Where the Customer instructs Clakta to send data to a Connected Platform, that platform receives it as an independent controller under its own terms, and the residency setting does not constrain it.


13. Return and deletion

13.1. During the term of the Agreement, the Customer may export its data at any time through the Services and the APIs.

13.2. On termination of the Agreement, Customer Personal Data remains available for export for 30 days, after which it is deleted — except where the account was terminated for unlawful activity or for breach of Section 6 of the Terms of Use, in which case deletion may occur immediately.

13.3. Clakta may retain Customer Personal Data to the extent and for the period required by law, or necessary to establish, exercise, or defend legal claims, restricting processing to those purposes. Backup copies are deleted on the normal overwrite cycle.

13.4. On written request made within 30 days of termination, Clakta will confirm deletion in writing.


14. Liability

Liability arising under this DPA is subject to the limitations and exclusions in Section 13 of the Terms of Use, and those limits are not applied cumulatively across the Agreement and this DPA. Nothing in this DPA limits liability that cannot be limited under Data Protection Law, or affects data subjects' rights against the controller.


15. Term and precedence

15.1. This DPA remains in force for as long as Clakta processes Customer Personal Data, and continues for as long as necessary to fulfill obligations that by their nature survive it.

15.2. In the event of a conflict between this DPA and the Terms of Use in relation to the processing of personal data, this DPA prevails. In the event of a conflict between this DPA and applicable standard contractual clauses, those clauses prevail.

15.3. All other provisions of the Terms of Use remain unchanged.


16. Language and governing law

16.1. This DPA is drafted in Portuguese (Brazil), which is its official version. Any version in another language, including this one, is a convenience translation, and in the event of divergence the Portuguese (Brazil) version prevails in full.

16.2. This DPA is governed by the laws of the Federative Republic of Brazil, with the courts of the judicial district (comarca) of Florianópolis, State of Santa Catarina, as the elected forum under Section 16 of the Terms of Use, subject to the standard contractual clauses applicable to international transfers.


Annex I — Description of the processing

A. Parties

Exporter / controllerThe Customer, as identified in its account
Importer / processorClakta LTDA
Processor's privacy contact[email protected]

B. Description of the processing

ItemDescription
Subject matterProvision of the website analytics and marketing attribution Services
Nature and purposeCollection, receipt, organization, storage, retrieval, analysis, aggregation, transmission to Connected Platforms on the Customer's instructions, and deletion, for the purpose of measuring website behavior, conversions, and campaign performance
Categories of data subjectsVisitors to and customers of the Customer's Properties; the Customer's Authorized Users
Categories of personal dataOnline identifiers (first-party cookie identifier, locally stored identifier, or rotating server-derived identifier; the Customer's own internal identifiers); technical and device data (truncated or hashed IP address, user agent, browser, operating system, device type, language, approximate location at country, state, or city level); event and behavioral data (pages, sessions, clicks, scrolls, form submissions, custom events, conversions); campaign and attribution data (UTM parameters, referrer, landing page URLs, advertising click identifiers such as fbclid, gclid, and ttclid); commercial and order data (identifier, value, currency, products, quantities, discounts, refunds, status); contact data sent by the Customer with an order or through an identify call (name, email, phone, address); and, where the Customer enables conversion APIs, email and phone hashed with SHA-256 before transmission
Sensitive dataNone. Submission is prohibited by Section 4.3
FrequencyContinuous and in real time for the duration of the Agreement
DurationFor the retention period configured by the Customer for each Project and, after termination, as set out in Section 13
SubprocessorsAs listed at https://www.clakta.com/legal/subprocessors

Annex II — Technical and organizational measures

  • Encryption — TLS in transit and encryption at rest; OAuth credentials and webhook secrets stored encrypted; SHA-256 hashing of contact identifiers transmitted to Connected Platforms.
  • Access control — role-based access, multi-factor authentication for administrative access, least-privilege principle, periodic access reviews, and revocation on departure.
  • Segregation — logical separation of data by team and Project; physical separation of project data by storage region.
  • Network and infrastructure — network isolation, protected endpoints, allowed-domain controls per tracking source, and rate limiting.
  • Logging and monitoring — audit trails of changes to Projects, authentication and API key usage logs, error and availability monitoring.
  • Resilience — regular backups, recovery procedures, and a public status page at https://www.clakta.com/status.
  • Minimization — privacy-friendly tracking mode with no cookies or browser storage, consent management, IP truncation or hashing, and configurable retention per Project.
  • Vendor management — security review before engagement and contracts imposing obligations equivalent to those in this DPA.
  • People and process — confidentiality obligations, data protection training, and a documented incident response process.

Annex III — Subprocessors

The current list, identifying each subprocessor, its purpose, and its processing location, is published at https://www.clakta.com/legal/subprocessors and forms part of this DPA. The categories currently used are:

CategoryPurpose
Cloud infrastructure and databasesApplication hosting and storage of project data in the EU and US regions
Analytics storeStorage and querying of events
Ingestion queueTransient buffering of events before they are written to the team's region
Object storageTeam logos and user avatars
Error monitoring and observabilityDiagnostics and availability
Email providerInvitations, verification links, and alerts
Payment processingBilling and invoicing
Support toolingTickets and chat
AI model providersAssistant features, with training on submitted data prohibited