Data Processing Agreement (DPA)

Effective Date: December 27, 2025
Version: 1.0
Company: CLEPTO.IO SERVICES PRIVATE LIMITED
CIN: U62013PN2025PTC248011
Registered Address: SNO.107-108, PT-B, ROSEWOOD, SFL-J-603, PIMPLE SAUDAGAR, Sangavi, Pune-411027, Maharashtra, India
Contact: contact@clepto.io

1. Definitions

In this Data Processing Agreement (DPA), the following terms have the meanings set out below:

2. Scope and Applicability

2.1 When This DPA Applies

This DPA applies to the extent that Clepto.io processes Personal Data on your behalf when providing Automation Services, including:

2.2 Territorial Scope

This DPA complies with:

Important: This DPA is incorporated into your Master Service Agreement with Clepto.io. In case of conflict, this DPA takes precedence regarding Personal Data processing.

3. Data Controller and Processor Roles

3.1 You Are the Data Controller

As our Client, you determine:

You are responsible for:

3.2 Clepto.io Is the Data Processor

Clepto.io processes Personal Data:

Clepto.io is responsible for:

Clarity on Roles: You control what data and why. Clepto.io controls how to process it securely.

4. Processing Instructions

4.1 Scope of Processing

Processing Activity Description Data Categories
Workflow Automation n8n-based automation of your business processes Customer names, emails, phone numbers, identifiers
Email Automation Sending automated emails via n8n SMTP workflows Email addresses, subscriber preferences, message content
AI Processing Processing data through OpenAI, Anthropic, Google, Mistral, Perplexity APIs Chat messages, query text, user interactions
Data Storage Storing workflow and customer data on Hostinger VPS All data processed in workflows (as configured by you)
Chat Logs Logging interactions with AI chatbots for improvement Chat messages, timestamps, user identifiers

4.2 Purposes of Processing

Clepto.io processes Personal Data for:

4.3 Duration of Processing

Clepto.io processes Personal Data:

4.4 Your Instructions

You provide Processing Instructions through:

You must ensure: All instructions comply with applicable data protection laws and that you have legal authority to provide them.

5. Data Security and Protection

5.1 Technical Safeguards

Encryption in Transit

Encryption at Rest

Authentication & Access Control

5.2 Organizational Safeguards

5.3 Infrastructure Details

Hosting & Infrastructure:
  • Hostinger VPS (Europe-based, GDPR compliant)
  • Database: PostgreSQL on Hostinger managed infrastructure
  • Backups: Regular encrypted backups by Hostinger
  • Monitoring: 24/7 uptime monitoring
  • Updates: Regular security patches applied

5.4 Data Breach Notification

If a data breach occurs, Clepto.io will:

You are responsible for: Notifying affected data subjects and regulators (as required by law, typically within 72 hours).

6. Sub-Processors

6.1 Authorized Sub-Processors

You authorize Clepto.io to engage the following sub-processors:

Sub-Processor Location Function DPA Status
Hostinger Europe Hosting, database, backups DPA in place
n8n (Open-Source) Self-hosted on Hostinger Workflow automation platform Open-source (no DPA needed)
OpenAI USA AI model processing DPA signed
Anthropic USA AI model processing (Claude) DPA signed
Google USA AI model processing (Gemini) DPA signed
Mistral Europe AI model processing DPA signed
Perplexity USA Research & retrieval In progress (Q1 2026)
Perplexity Status: DPA with Perplexity is being finalized. We recommend using Perplexity only for non-sensitive queries until DPA is confirmed. We will notify you when it's completed.

6.2 Changes to Sub-Processors

If Clepto.io engages a new sub-processor, we will:

Notification channel: Email to contact@clepto.io or your registered account email.

Full list: See our Sub-Processors page for complete details.

7. Data Subject Rights

7.1 Your Obligations as Controller

You must provide data subjects with information about processing, including:

7.2 Data Subject Rights Support

Data subjects have the right to:

7.3 Clepto.io's Support

When you receive a data subject request, Clepto.io will:

Data Subject Requests: Forward all requests to contact@clepto.io with subject line "Data Subject Request - [Type]". We will prioritize and assist within 5 business days.

8. International Data Transfers

8.1 Data Location

Personal Data is stored and processed:

8.2 Transfer Mechanisms for USA Processors

For transfers to USA-based AI providers, Clepto.io relies on:

8.3 Your Obligations

You are responsible for:

Data Localization: If you require data to remain within the EU/UK only, please contact contact@clepto.io to discuss alternatives. Some features (e.g., OpenAI AI processing) may be unavailable with this restriction.

9. Liability and Indemnification

9.1 Limitation of Liability

Each party's total liability under this DPA is limited to the fees paid in the 12 months preceding the claim (or €500,000, whichever is greater), except for:

9.2 Indemnification

Clepto.io will indemnify you against claims arising from:

You will indemnify Clepto.io against claims arising from:

10. Term and Termination

10.1 Duration

This DPA remains in effect for the duration of your service agreement with Clepto.io, plus any applicable data retention period.

10.2 Termination Effects

Upon termination of your service:

Exceptions: Clepto.io may retain data if required by law (e.g., Indian tax law: 7-year retention for business records).

10.3 Data Return or Deletion

You can request:

Process: Email contact@clepto.io with "Data Return/Deletion Request" subject line. We will respond within 24 hours and complete within 30 days.

11. Contact Information

11.1 Data Protection Contact

11.2 Company Details

11.3 Regulatory Complaints

If you have concerns about data processing, you can file a complaint with:

11.4 Updates to This DPA

Clepto.io may update this DPA:

Continued use of Clepto.io services after notice constitutes acceptance of updates.

For Clepto.io:

Authorized Representative

Date: _______________

For Client (You):

Authorized Representative

Date: _______________

END OF DATA PROCESSING AGREEMENT