Clenzus - Data Processing Addendum
Version 1.1 · Last updated 2026-08-28 · Effective upon your acceptance of the Terms of Service.
This Data Processing Addendum ("DPA") forms part of, and is incorporated by reference into, the Terms of Service (the "Agreement") between Clenzus Inc., a corporation governed by the laws of the Province of Manitoba, Canada ("Clenzus," "we," "us"), and the customer that accepts the Agreement (the "Customer," "you"). It applies where, and only to the extent that, Clenzus processes Personal Data on the Customer's behalf in providing the Service and such processing is subject to Data Protection Law. If there is a conflict between this DPA and the rest of the Agreement on the subject of the processing of Personal Data, this DPA controls - except that the limitation of liability in the Terms of Service continues to apply to this DPA (Section 11).
By accepting the Terms of Service, the Customer enters into this DPA on behalf of itself and, to the extent required, its Affiliates. No separate signature is required; a Customer that requires a signed copy may request one at legal@clenzus.com.
1. Definitions
- "Data Protection Law" means all laws applicable to the processing of Personal Data under the
Agreement, including, as applicable, the EU General Data Protection Regulation 2016/679 ("GDPR"), the UK GDPR and Data Protection Act 2018 ("UK GDPR"), the Swiss FADP, Canada's PIPEDA and the private-sector privacy statutes of Alberta, British Columbia, and Québec (including Québec's Law 25), the California Consumer Privacy Act as amended by the CPRA ("CCPA/CPRA") and the other U.S. state comprehensive privacy laws as they take effect (including the Virginia CDPA, Colorado CPA, Connecticut CTDPA, Utah UCPA, Texas TDPSA, Oregon OCPA, Montana MCDPA, Delaware PDPA, and the Iowa, Nebraska, New Hampshire, New Jersey, Minnesota, Maryland MODPA, Tennessee, Indiana, Kentucky, and Rhode Island comprehensive privacy statutes), Brazil's LGPD, Singapore's PDPA, Japan's APPI, South Africa's POPIA, India's Digital Personal Data Protection Act, the Australian Privacy Act 1988, New Zealand's Privacy Act 2020, and any other data protection, privacy, or data-security law applicable to a party's processing under the Agreement.
- "Controller," "Processor," "Data Subject," "Personal Data," "Processing," "Special Categories," and
"Personal Data Breach" have the meanings given in the GDPR (and the equivalent terms in other Data Protection Law, e.g. "business," "service provider," and "consumer" under the CCPA/CPRA).
- "Customer Personal Data" means Personal Data that Clenzus processes on the Customer's behalf under
the Agreement.
- "Sub-processor" means any third party engaged by Clenzus to process Customer Personal Data.
- "SCCs" means the Standard Contractual Clauses approved by the European Commission (Implementing
Decision (EU) 2021/914), together with the UK International Data Transfer Addendum and any Swiss addendum, as applicable.
Capitalized terms not defined here have the meaning given in the Agreement.
2. Roles of the parties
For Customer Personal Data, the Customer is the Controller (or a processor acting for another controller) and Clenzus is the Processor. For the account, billing, and platform-security data that Clenzus collects for its own purposes (described in the Privacy Policy), Clenzus is an independent Controller and that processing is not governed by this DPA.
Where the Customer is itself a processor for a third-party controller, the Customer warrants that it is authorized to engage Clenzus as a sub-processor and to give the instructions in this DPA.
3. Customer responsibilities and warranties
The Customer is responsible for its own compliance with Data Protection Law as Controller. The Customer represents and warrants that, for all Customer Personal Data it (or its Authorized Users) submits to the Service, it has and will maintain:
- a valid legal basis and all necessary consents, notices, and authorizations to collect the data and
to have Clenzus process it as described in the Agreement;
- the right to transfer that data to Clenzus and to instruct the processing set out in this DPA; and
- accurate, lawful, and non-infringing data, provided in compliance with Data Protection Law.
The Customer is solely responsible for the accuracy, quality, and legality of Customer Personal Data and of its instructions. Clenzus is not responsible for determining whether the Customer's instructions or data comply with Data Protection Law, and the Customer's documented instructions are deemed lawful as between the parties.
4. Scope and instructions
Clenzus will process Customer Personal Data only on the Customer's documented instructions, including with regard to international transfers, unless required to act by a law to which Clenzus is subject (in which case Clenzus will, where legally permitted, inform the Customer of that requirement first). The following are the Customer's complete and final documented instructions for the processing:
- processing to provide, secure, maintain, and support the Service in accordance with the Agreement,
this DPA, and the Customer's configuration and use of the Service; and
- processing to comply with the Customer's other reasonable, documented instructions where consistent
with the Service's functionality.
Any additional or different processing requires a separate written agreement and may be subject to additional fees. If Clenzus believes an instruction infringes Data Protection Law, it will inform the Customer; Clenzus may suspend the affected processing until the instruction is confirmed, withdrawn, or amended, without liability.
The subject matter, duration, nature and purpose of the processing, the types of Personal Data, and the categories of Data Subjects are set out in Annex A.
5. Confidentiality
Clenzus ensures that personnel authorized to process Customer Personal Data are bound by appropriate obligations of confidentiality and are granted access on a need-to-know basis.
6. Security
Taking into account the state of the art, the costs of implementation, and the nature, scope, context and purposes of processing, Clenzus implements appropriate technical and organizational measures designed to ensure a level of security appropriate to the risk, as summarized in Annex B. The Customer has reviewed those measures and agrees they are appropriate for Customer Personal Data given the Customer's own assessment of the risk. Clenzus may update the measures from time to time provided the overall level of protection is not materially reduced. The Customer is responsible for its own secure use of the Service, including safeguarding credentials, configuring access and roles, and promptly removing access when a user leaves.
7. Sub-processors
The Customer provides a general authorization for Clenzus to engage Sub-processors to process Customer Personal Data. Clenzus will:
- impose data-protection obligations on each Sub-processor that are, in substance, no less protective than
those in this DPA; and
- remain responsible for each Sub-processor's performance of those obligations.
A current list of Sub-processors (by category, and named on request) is available at privacy@clenzus.com (see Annex C). Clenzus will give the Customer notice (which may be by email or through the Service) before adding or replacing a Sub-processor. The Customer may object on reasonable, data-protection grounds within fifteen (15) days of the notice. If the parties cannot resolve the objection, the Customer's sole and exclusive remedy is to terminate the affected part of the Service; the Customer's continued use after the notice period constitutes acceptance.
8. Data-subject requests
Taking into account the nature of the processing, Clenzus will provide the tools available in the Service and reasonable assistance to help the Customer respond to requests from Data Subjects to exercise their rights (access, rectification, erasure, restriction, portability, objection). If Clenzus receives such a request directly, it will, where permitted, redirect the Data Subject to the Customer and not respond substantively except on the Customer's instruction. Assistance beyond the Service's standard features may be subject to reasonable fees. The Customer is responsible for the substantive response to Data Subjects.
9. Personal Data Breach
Clenzus will notify the Customer without undue delay after becoming aware of a Personal Data Breach affecting Customer Personal Data, and will provide information reasonably available to it to help the Customer meet its own notification obligations. As Controller, the Customer is responsible for notifying supervisory authorities and affected Data Subjects where required. A notification or assistance by Clenzus is not an acknowledgement of fault or liability by Clenzus. Clenzus will take reasonable steps to mitigate and remediate the breach.
10. Data-protection impact assessments
Taking into account the nature of the processing and the information available to it, Clenzus will provide reasonable assistance to the Customer with data-protection impact assessments and prior consultations with supervisory authorities that the Customer is required to carry out under Data Protection Law. Assistance beyond providing reasonably available documentation may be subject to reasonable fees.
11. Liability
Each party's liability arising out of or related to this DPA, whether in contract, tort, or otherwise, is subject to, and counts toward, the exclusions and the aggregate limitation of liability set out in the Terms of Service (Terms §14). This DPA does not increase or expand Clenzus's liability beyond that cap, and any claims under this DPA and the rest of the Agreement are subject to a single, combined liability cap. Where the SCCs apply and a mandatory provision of the SCCs conflicts with this Section, the SCCs prevail only to the minimum extent required by law and only with respect to the SCC-governed transfer.
12. Customer indemnity
The Customer will defend, indemnify, and hold Clenzus harmless from and against any third-party claims, fines, penalties, losses, and costs (including reasonable legal fees) arising out of or related to (a) the Customer's breach of Sections 2-4 of this DPA, (b) Customer Personal Data or instructions that lack a valid legal basis or that infringe Data Protection Law or third-party rights, or (c) the Customer's use of the Service in violation of Data Protection Law. This is in addition to any indemnity in the Agreement.
13. International transfers
Where Clenzus processes Customer Personal Data originating in the EEA, the UK, or Switzerland in a country that has not received an adequacy decision, the SCCs are incorporated into this DPA by reference and apply as follows: Module Two (Controller-to-Processor) applies, with the Customer as data exporter and Clenzus as data importer; where the Customer is itself a processor, Module Three applies. The optional docking clause applies; the supervisory authority and governing law are as selected in the SCCs consistent with the transfer; and the technical and organizational measures in Annex B and the Sub-processor terms in Section 7 satisfy the corresponding SCC annexes. The UK Addendum and, for Swiss data, the Swiss adjustments apply where relevant. If the SCCs are amended or replaced, the updated version applies.
14. Return and deletion
On termination or expiry of the Agreement, Clenzus will, at the Customer's choice, delete or return Customer Personal Data, and delete existing copies, except to the extent applicable law requires Clenzus to retain some or all of it, in which case Clenzus will retain it only for the period and purpose required and keep it protected. Customer Personal Data in routine backups is deleted in the ordinary course of Clenzus's backup rotation. Where the Service offers self-service export or deletion, the Customer is responsible for exercising it before termination.
15. Audit
Clenzus will make available to the Customer information reasonably necessary to demonstrate compliance with Article 28 of the GDPR and this DPA, primarily through documentation, security summaries, and, where available, third-party reports or certifications. Where Data Protection Law grants the Customer a right to audit that cannot be satisfied by such materials, an on-site audit is subject to the following: it occurs no more than once in any twelve (12) month period (unless required by a supervisory authority following a breach), on at least thirty (30) days' written notice, during business hours, for no longer than one business day, under a confidentiality agreement, conducted so as not to disrupt Clenzus's operations, at the Customer's expense, and in a manner that does not grant access to any other customer's data, to Clenzus's confidential or proprietary information, or to systems beyond those processing the Customer's data. The Customer's auditor may not be a competitor of Clenzus.
16. CCPA / CPRA and other U.S. state privacy laws
To the extent the CCPA/CPRA applies, Clenzus acts as a service provider to the Customer (the business) and processes Customer Personal Data only to perform the Service under the Agreement. Clenzus will not sell or share Customer Personal Data, will not retain, use, or disclose it for any purpose other than the business purposes specified in the Agreement or as permitted by the CCPA/CPRA, and will not combine it with data from other sources except as permitted. Clenzus certifies that it understands and will comply with these restrictions. Clenzus will notify the Customer if it determines it can no longer meet its obligations under the CCPA/CPRA, and the Customer may, upon notice, take reasonable and appropriate steps to stop and remediate any unauthorized use of Customer Personal Data.
Other U.S. state privacy laws. Where Clenzus processes Customer Personal Data as a processor or service provider subject to another U.S. state comprehensive privacy law (for example the Virginia CDPA, Colorado CPA, Connecticut CTDPA, Utah UCPA, Texas TDPSA, Oregon OCPA, Montana MCDPA, Delaware PDPA, Maryland MODPA, and comparable laws as they take effect), Clenzus will: (a) process it only for the limited and specified purposes of providing the Service under the Customer's documented instructions; (b) provide the level of privacy protection the applicable law requires; (c) not sell or share it, and not process it for targeted advertising or any purpose other than those permitted; (d) not retain, use, or disclose it outside the direct business relationship, or combine it with data from other sources, except as permitted; (e) notify the Customer if it can no longer meet its obligations and cooperate with reasonable steps to stop and remediate unauthorized processing; (f) make available the information reasonably necessary to demonstrate compliance and cooperate with assessments as provided in Section 15; and (g) engage Sub-processors only under contracts imposing materially equivalent obligations (Section 7). The parties intend this DPA to satisfy the controller-to-processor and business-to-service-provider contract requirements of those laws.
17. Term, precedence, and general
This DPA takes effect when the Customer accepts the Agreement and continues for as long as Clenzus processes Customer Personal Data under the Agreement. This DPA is governed by the laws of the Province of Manitoba and the federal laws of Canada applicable therein, and disputes are resolved as set out in the Terms of Service, except where Data Protection Law or the SCCs require otherwise for a specific transfer. If any provision is held unenforceable, the rest remains in effect. Except as amended by this DPA, the Agreement remains in full force.
Annex A - Details of processing
- Subject matter: Clenzus's provision of the Service to the Customer under the Agreement.
- Duration: the term of the Agreement, plus any period during which Clenzus retains data as permitted
by Section 14.
- Nature and purpose: hosting, storing, organizing, and otherwise processing Customer Personal Data to
operate, secure, maintain, support, and improve the Service, and to provide the workforce-management, scheduling, time and attendance, task, payroll-support, and reporting functionality the Customer configures.
- Types of Personal Data: identity and contact details; role, employment, and payroll-support
identifiers (which may include a partial tax identifier and payroll file number); scheduling, time and attendance, and location/geofence data where the Customer enables it; operational records, photos, and documents the Customer uploads; and usage, device, and security-log data. The Customer controls what it submits and should not submit Special Categories of data except as the Service is intended to support.
- Categories of Data Subjects: the Customer's Authorized Users and workforce (e.g. administrators,
managers, supervisors, and field personnel) and the Customer's own clients/contacts to the extent the Customer records them.
Annex B - Technical and organizational measures
Clenzus maintains measures designed to protect Customer Personal Data, including, as applicable:
- Encryption in transit (TLS) and field-level encryption at rest (AES-256) of the most sensitive
identifiers (access PIN, partial tax identifiers, payroll file numbers);
- Strict multi-tenant isolation and row-level security, so one Customer's data is walled off from
another's;
- Role-based, least-privilege access controls, with additional identity verification required for the
most sensitive functions;
- Tamper-resistant, append-only audit logging of sensitive administrative access;
- Secure, reputable cloud infrastructure, access controls on production systems, and routine backups;
and
- Organizational measures including confidentiality obligations and least-privilege internal access.
These measures may evolve; Clenzus will not materially reduce the overall level of protection during the term.
Annex C - Sub-processors
Clenzus engages Sub-processors in the following categories to deliver the Service:
- Cloud database, authentication, and hosting - stores and serves Customer Data;
- Object/file storage - stores uploaded photos and documents;
- Transactional email delivery - sends account, security, and notification emails;
- Address geocoding - converts site addresses into map coordinates; and
- IP geolocation - derives the approximate city, region, and country from a request's IP address for security checks (for example, unusual-sign-in detection).
A current, named list of Sub-processors - including entity and processing location - is available on request at privacy@clenzus.com. New or replacement Sub-processors are handled under Section 7.
Annex D - Standard Contractual Clauses
For restricted international transfers (Section 13), the parties incorporate the SCCs as follows: Module Two (Controller-to-Processor), or Module Three (Processor-to-Processor) where the Customer is a processor; the docking clause is used; Clause 9 (Sub-processors) operates under the general authorization option consistent with Section 7; Clause 11 does not use the independent-dispute-resolution option; Annex I is populated by Annex A of this DPA and the parties' account records; Annex II is populated by Annex B; and Annex III is the Sub-processor list in Annex C. The UK International Data Transfer Addendum and, for Swiss-origin data, the Swiss adjustments, apply where relevant.