Data Processing Agreement
Last updated 21 August 2026
Acceptance
This Data Processing Agreement is accepted electronically when Customer accepts the Clueso Terms of Service or enables a paid plan. No signature is required and no field is left blank. A record of acceptance, including the accepting account and timestamp, is retained and available to Customer on request.
1. Key terms
Item: Provider
Value: Desklamp, Inc. d/b/a Clueso, a Delaware corporation
Item: Customer
Value: the entity accepting the Clueso Terms of Service
Item: Approved sub-processors
Value: as published in the sub-processor list, incorporated by reference
Item: Data residency
Value: as elected by Customer
Item: Provider security contact
Value: security@clueso.io
Item: Privacy contact
Value: privacy@clueso.io
Item: Security standards
Value: SOC 2 Type II; ISO/IEC 27001
Item: Sub-processor change notice
Value: 10 business days, with a 10 business day objection window
Item: Security incident notice
Value: without undue delay, no later than 72 hours
Item: Governing member state
Value: EEA transfers: Netherlands · UK transfers: England and Wales
2. Service provider relationship — CCPA
To the extent the California Consumer Privacy Act applies, the parties agree that Provider is a service provider receiving Personal Data from Customer to provide the Service, which constitutes a limited and specified business purpose. Provider will not sell or share any Personal Data provided by Customer, and will not retain, use or disclose it except as necessary to provide the Service or as permitted by Applicable Data Protection Laws. Provider certifies that it understands the restrictions in this Section and will comply with them. Provider will notify Customer if it can no longer meet its obligations under the CCPA.
3. Processor and sub-processor relationships
• Provider as Processor. Where Customer is a Controller of the Customer Personal Data, Provider is a Processor Processing on Customer's behalf.
• Provider as Sub-processor. Where Customer is a Processor of the Customer Personal Data, Provider is a Sub-processor.
4. Processing
• Processing details. Annex I(B) describes the subject matter, nature, purpose and duration of Processing, the Categories of Personal Data and the Categories of Data Subjects.
• Processing instructions. Customer instructs Provider to Process Customer Personal Data: (a) to provide and maintain the Service; (b) as further specified through Customer's use of the Service; (c) as documented in the Agreement; and (d) as documented in any other written instructions given by Customer and acknowledged by Provider. Provider will abide by these instructions unless prohibited by Applicable Laws, and will immediately inform Customer if unable to follow them.
• Processing by Provider. Provider will Process Customer Personal Data only in accordance with this DPA. If Provider updates the Service to include new products, features or functionality, Provider may change the details in Annex I(B) as needed to reflect those updates, by notifying Customer.
• Customer Processing. Where Customer is a Processor and Provider a Sub-processor, Customer will comply with all Applicable Laws governing its own Processing.
• Consent to Processing. Customer has made all disclosures, obtained all consents and implemented all safeguards required under Applicable Data Protection Laws.
5. Sub-processors
• Provider will not transfer Customer Personal Data to a Sub-processor unless Customer has approved that Sub-processor. The current list of Approved Sub-processors — their identities, countries of location and anticipated Processing tasks — is maintained in the published sub-processor list and is incorporated into this DPA by reference.
• Provider gives notice of any intended addition or replacement of a Sub-processor by updating the published sub-processor list at least ten (10) business days in advance, together with the information necessary for Customer to exercise its right to object. Customer may subscribe at that page to be notified of changes. Customer may object within ten (10) business days of the update; if Customer does not object within that period, Customer will be deemed to accept the change. If Customer objects, the parties will cooperate in good faith to resolve the concern.
• When engaging a Sub-processor, Provider will have a written agreement ensuring the Sub-processor accesses and uses Customer Personal Data only to the extent required to perform the subcontracted obligations and consistent with this DPA.
• Where the GDPR applies, the obligations in this DPA under Article 28(3) are imposed on the Sub-processor. Provider will share, at Customer's request, a copy of its agreements with Sub-processors, redacted as necessary to protect confidential information.
• Provider remains fully liable for all obligations subcontracted to its Sub-processors, including their acts and omissions.
6. Restricted transfers
• Authorisation. Customer agrees Provider may transfer Customer Personal Data outside the EEA, the United Kingdom or other relevant territory as necessary to provide the Service, implementing appropriate safeguards where no adequacy decision applies.
• Ex-EEA transfers. Where the GDPR protects the transfer, the parties are deemed to have signed the EEA SCCs, incorporated by reference, completed as follows: Module Two (Controller to Processor) applies where Customer is a Controller; Module Three (Processor to Sub-processor) applies where Customer is a Processor. The docking clause in Clause 7 does not apply. In Clause 9, Option 2 applies, and the minimum time period for prior notice of Sub-processor changes is ten (10) business days. In Clause 11 the optional language does not apply. All square brackets in Clause 13 are removed. In Clause 17 (Option 1) the EEA SCCs are governed by the law of the Governing Member State, and under Clause 18(b) disputes are resolved in its courts. This document contains the information required by Annexes I, II and III.
• Ex-UK transfers. Where the UK GDPR protects the transfer, the parties are deemed to have signed the UK Addendum. Neither party may end the UK Addendum under its Section 19. If the ICO issues a revised Approved Addendum, the parties will revise this DPA in good faith.
• Other international transfers. Where Swiss law applies to the international nature of the transfer, references to the GDPR in Clause 4 of the EEA SCCs are amended to refer to the Swiss Federal Data Protection Act, and supervisory authority includes the Swiss Federal Data Protection and Information Commissioner.
7. Security incident response
Upon becoming aware of any Security Incident, Provider will: (a) notify Customer without undue delay and no later than seventy-two (72) hours after becoming aware; (b) provide timely information as it becomes known or is reasonably requested; and (c) promptly take reasonable steps to contain and investigate. Notification is not an acknowledgment of fault or liability.
Notifications made under this Section will, to the extent then known: (i) describe the nature of the Security Incident, including where possible the categories and approximate number of Data Subjects and Customer Personal Data records concerned; (ii) provide the name and contact details of a point of contact at Provider; (iii) describe the likely consequences of the Security Incident; and (iv) describe the measures taken or proposed to address it and mitigate its effects.
Notification to third parties
Except to the extent required by Applicable Data Protection Laws, Provider will not notify any third party or supervisory authority of a Security Incident involving Customer Personal Data without Customer's prior written consent, other than notice to law enforcement, to Provider's affected Sub-processors, or to Provider's insurers and professional advisers.
8. Audit and reports
• Audit rights. Provider will give Customer the information reasonably necessary to demonstrate compliance with this DPA and will allow for and contribute to audits. Provider may restrict access where it would compromise intellectual property, confidentiality obligations or other legal obligations. Customer will exercise audit rights by instructing Provider to comply with the reporting and due-diligence requirements below. Provider will maintain compliance records for three (3) years after this DPA ends.
• Security reports. Provider is audited annually by independent third-party auditors against SOC 2 Type II and ISO/IEC 27001. On written request Provider will provide, on a confidential basis, a summary copy of its then-current report.
• Security due diligence. Provider will respond to reasonable written requests for information confirming compliance, made to the Provider security contact, no more than once per year.
9. Coordination and cooperation
• Response to inquiries. If Provider receives an inquiry or request from a third party about the Processing of Customer Personal Data — including a data-subject request or a judicial, administrative or regulatory order — Provider will notify Customer where not legally prohibited and will not respond without Customer's prior consent. Provider will assist Customer in fulfilling valid data-subject requests.
• DPIAs and DTIAs. Where required by Applicable Data Protection Laws, Provider will reasonably assist Customer in conducting data protection impact assessments and data transfer impact assessments, and in consultations with supervisory authorities.
10. Deletion of customer personal data
• Deletion by Customer. Provider will enable Customer to delete Customer Personal Data consistent with the functionality of the Service, and will comply as soon as reasonably practicable except where further storage is required by Applicable Law.
• Deletion at expiration. Within thirty (30) days of the expiration or termination of the Agreement, Provider will delete or return Customer Personal Data from its systems, without requiring a separate request from Customer, unless further storage is required or authorised by Applicable Law. On Customer's request, Provider will provide written certification of that deletion. Where return or destruction is impracticable or prohibited, Provider will prevent further Processing and continue to protect the data.
• Where the EEA SCCs or UK Addendum apply, Provider will provide the certification of deletion described in Clause 8.1(d) and Clause 8.5 if Customer asks for one.
11. Limitation of liability
• Liability caps and damages waiver. To the maximum extent permitted under Applicable Data Protection Laws, each party's total cumulative liability arising out of or related to this DPA is subject to the waivers, exclusions and limitations of liability stated in the Agreement.
• Related-party claims. Claims arising out of this DPA may only be brought by the Customer entity that is party to the Agreement.
• Exceptions. This DPA does not limit liability to an individual regarding their data protection rights, nor liability between the parties for violations of the EEA SCCs or UK Addendum.
12. Order of precedence
Applies across the whole agreement
Where there is any inconsistency, the part listed earlier controls: (1) the EEA SCCs or UK Addendum, (2) the Order Form, (3) a module annex to this DPA, (4) the Service Level Agreement, (5) this DPA, (6) the Master Services Agreement or Terms of Service. A module annex may vary scope of service only, and may not vary liability, intellectual property, confidentiality or governing law.
13. Additional modules
If Customer enables an additional module, the module annex for that module in effect at the time of enablement applies from that date, as referenced in an Order Form or by Customer's written or in-product acceptance, without further amendment of this DPA. Provider will make the applicable module annex available to Customer on or before enablement. Modules not enabled by Customer are not part of this DPA and none of the Processing they describe occurs.
14. Term
This DPA begins when the parties sign or electronically accept it and continues until the Agreement expires or terminates. Both parties remain subject to its obligations until Customer stops transferring Customer Personal Data to Provider and Provider stops Processing it.
15. Annex I(A) — List of parties
Role: Data exporter
Details: the Customer accepting this DPA. Role: Controller, or Processor where Customer processes on behalf of its own controller. Activities: see Annex I(B).
Role: Data importer
Details: Desklamp, Inc. d/b/a Clueso. Role: Processor.Contact: Information Security Officer, privacy@clueso.io.Address: 1111B S Governors Ave #90974, Dover, DE 19904, United States.Tel: +1 628 997 7427.Activities: see Annex I(B).
16. Annex I(B) — Description of transfer and processing
The service
Clueso is a cloud-based platform that converts screen recordings into articles and editable professional videos, and hosts the resulting content.
Categories of data subjects
• Customer's personnel who use the Service
• Any other individual whose personal data is contained in content Customer records, uploads or submits to the Service
Categories of personal data
• Name and contact information such as email address
• Account and organisation identifiers, including identifiers issued by a federated identity provider where Customer uses single sign-on
• User activity and analysis data, including device information and IP address
• Audio, video, screen-recording and transcript content submitted by Customer, and any personal data contained in it
Special category data
Provider does not require Special Category Data to deliver the Service and does not intentionally Process it. Customer is responsible for ensuring content it submits does not contain Special Category Data unless it has established a lawful basis and notified Provider in writing.
Frequency of transfer
Continuous, for the duration of the Agreement — data is collected when Customer interacts with the Service to create, edit, organise or host content.
Nature and purpose of processing
• Receiving data, including collection, access, retrieval, recording and data entry
• Using data to generate articles, videos, voiceovers and translations, including transmission to the AI sub-processors in the published sub-processor list
• Erasing data, including destruction and deletion
Duration of processing
Provider will Process Customer Personal Data for as long as required to conduct the Processing instructed in Section 4, or as required by Applicable Laws. Content marked for deletion is securely deleted or anonymised within a maximum of thirty (30) days.
17. Annex I(C) — Competent supervisory authority
The supervisory authority of the data exporter, determined in accordance with Clause 13 of the EEA SCCs or the relevant provision of the UK Addendum.
18. Annex II — Technical and organisational measures
Measure: Access control
Implementation: All endpoints handling user data are authenticated via secure tokens issued through secure login mechanisms. Role-based access control, least-privilege provisioning, and access reviewed on a defined cadence.
Measure: Tenant isolation
Implementation: All Customer data is logically segregated by organisation. Every access is scoped to the organisation boundary; there is no cross-organisation data access or data passing between tenants.
Measure: Encryption at rest
Implementation: Customer content is stored with AES-256 encryption at rest.
Measure: Encryption in transit
Implementation: All transmission, including to sub-processors, is encrypted over HTTPS / TLS 1.2 or higher.
Measure: Credential handling
Implementation: Sub-processor calls are made server-side by the application backend. Provider credentials never leave the backend. API keys and tokens follow managed key-handling and rotation practice.
Measure: Resilience
Implementation: Production databases are deployed for high availability, with automated backups and point-in-time recovery. Restoration and disaster recovery are exercised periodically in accordance with Provider's Business Continuity Plan.
Measure: Data residency
Implementation: Customer content and the stores holding it are localised to the region Customer elects: Mumbai (ap-south-1), Frankfurt (eu-central-1) or California (us-west-1). Account identity data — name, work email and organisation, with no customer content — is held in a single global store.
Measure: Monitoring and logging
Implementation: API interactions are monitored and recorded for accountability and reliability. Security events are logged and retained.
Measure: Organisational measures
Implementation: Provider is SOC 2 Type II certified and ISO/IEC 27001 certified, and maintains a documented information security management system including access control, incident management, business continuity, vendor management and secure development policies.
Measure: Personnel
Implementation: All personnel sign confidentiality agreements at hire and undergo background screening. Security training is delivered on a defined cadence.
Measure: Sub-processor diligence
Implementation: Before engagement, each sub-processor is assessed for security posture, certifications, data-residency arrangements and contractual data-protection commitments. AI sub-processors must confirm in writing that Customer content will not be used to train any generalised model.
19. Annex III — List of sub-processors
The current list of Approved Sub-processors, including identities, countries of location and anticipated Processing tasks, is maintained in the published sub-processor list and is incorporated into this DPA by reference. Changes are notified in accordance with Section 5.
Why this annex is a reference rather than a fixed table
Incorporating the list by reference, backed by the advance notice and objection right in Section 5, gives Customer the same protection while keeping a single maintained source of truth — rather than requiring the agreement to be re-executed whenever a vendor changes. The period is stated once, in Section 5, so it cannot drift between clauses.
20. Definitions
Term: Applicable Laws
Meaning: the laws, rules, regulations, court orders and other binding requirements of a relevant government authority that apply to a party.
Term: Applicable Data Protection Laws
Meaning: the Applicable Laws governing how the Service may process personal information or personal data.
Term: Controller
Meaning: the meaning given in Applicable Data Protection Laws for the company determining the purpose and extent of Processing.
Term: Customer Personal Data
Meaning: Personal Data that Customer uploads or provides to Provider as part of the Service and that is governed by this DPA.
Term: Agreement
Meaning: the Master Services Agreement, Order Form or Terms of Service under which Provider supplies the Service to Customer, of which this DPA forms part.
Term: EEA, or European Economic Area
Meaning: the member states of the European Union, together with Norway, Iceland and Liechtenstein.
Term: EEA SCCs
Meaning: the standard contractual clauses annexed to European Commission Implementing Decision 2021/914 of 4 June 2021.
Term: Governing Member State
Meaning: the jurisdiction identified in Section 1 for EEA and UK transfers, whose law governs the EEA SCCs under Clause 17 and whose courts hear disputes under Clause 18(b).
Term: GDPR
Meaning: Regulation (EU) 2016/679 of the European Parliament and of the Council, as implemented by local law in the relevant EEA member state.
Term: Personal Data
Meaning: the meaning given in Applicable Data Protection Laws.
Term: Processing
Meaning: any use of, or operation performed on, Personal Data, including by automated means.
Term: Processor
Meaning: the company that Processes Personal Data on behalf of the Controller.
Term: Security Incident
Meaning: a Personal Data Breach as defined in Article 4 of the GDPR.
Term: Service
Meaning: the product and services described in the Agreement and any Order Form.
Term: Special Category Data
Meaning: the meaning given in Article 9 of the GDPR.
Term: Sub-processor
Meaning: a company that, with the approval of Controller, assists the Processor in Processing Personal Data on behalf of the Controller.
Term: UK GDPR
Meaning: Regulation (EU) 2016/679 as implemented by section 3 of the United Kingdom's European Union (Withdrawal) Act 2018.
Term: UK Addendum
Meaning: the international data transfer addendum to the EEA SCCs issued by the Information Commissioner under S119A(1) Data Protection Act 2018.