Menu

Trust center

Data processing agreement

Drafted by the same generator our customers use, from facts we have confirmed. Where something is only planned, it says so.

Last updated 21 September 2026 · Trust center

Parties and roles

Processor

REALTY.TM GROUP sp. z o.o., registered in Poland (National Court Register (KRS) 0001219891), with registered address at ul. Bpa Albina Małysiaka 26/15, 30-389 Kraków, Poland (trading as clausebench, "the Processor").

Controller

The subscribing customer whose name, address, jurisdiction and breach-notification contact are completed when this agreement is signed ("the Controller").

Roles confirmed by the consultant

The Processor processes personal data on behalf of the Controller. The Controller determines the purposes and means of the processing of its end-user data. The Processor processes personal data of the Controller's end users in the course of providing the clausebench service, as confirmed by the consultant.

Subject matter and duration

Nature and purpose of processing

The Processor provides clausebench, a workspace for outsourced DPOs, privacy consultants and companies managing their own privacy work. The service enables the Controller to: conduct structured interviews with clients; draft the privacy documents those clients' regulatory regimes require from the confirmed interview answers; answer security questionnaires from documents held in the same workspace; maintain an answer library; and publish a trust page. clausebench prepares documentation and does not provide legal services.

Personal data is processed to the extent necessary to deliver those functions, as further described in the instruction obligations set out in this agreement.

Duration

This agreement remains in force for the duration of the Controller's subscription. Processing obligations survive termination to the extent required to perform the return and deletion obligations set out in the "Return and deletion" section of this agreement.

Processing on instructions

The Processor shall process personal data only on documented instructions from the Controller, unless required to do so by European Union or Member State law to which the Processor is subject. In such a case, the Processor shall inform the Controller of that legal requirement before processing, unless that law prohibits such information on important grounds of public interest.

The Controller's instructions are set out in this agreement and in any written instructions subsequently provided. The Processor shall immediately inform the Controller if, in the Processor's opinion, an instruction infringes applicable data protection law.

All persons authorised by the Processor to process the Controller's personal data are bound by appropriate confidentiality obligations.

Security measures

The Processor has implemented the following technical and organisational measures:

Encryption

  • All personal data is encrypted in transit.
  • All personal data is encrypted at rest.

Multi-factor authentication (MFA)

MFA is enforced for every route into production data through clausebench: each admin screen, each staff endpoint and each staff action refuses a session that has not passed a second factor. MFA is not yet in place for all accounts held with infrastructure providers (the database provider, the server provider and the code host); it is in the process of being switched on.

Access control

Access to production is granted by the CTO, and each grant is recorded as a Jira task. Devices used to reach production must be enrolled in an access-control tool. Production, source code and customer data are reached only from enrolled devices, whether company-owned or personal.

Audit logging

The Processor logs: every action taken by staff in the internal admin (who acted, in which role, on what, from which address and with which browser); every support session into a client's workspace (which firm, which staff member, start and end time, and screens opened); every successful sign-in (account, firm and method); and all changes to a client's facts, documents and vendors.

Environment separation

Development and test runs operate against a local database. The test suite refuses to run against a database that is not local. Production runs against the cloud project. There is no separate staging environment.

Code review

Code changes are subject to review before deployment.

Backups

Backups are taken daily, weekly and monthly and retained for 90 days, stored in the same region as the database (Frankfurt, Germany). A restore test has been carried out. Recovery time objective is one day; recovery point objective is one day. Only technical support staff may initiate a restore.

Incident response

The Processor maintains a documented incident-response procedure. Reports are received at [email protected]. Where the Processor acts as processor, affected controllers are notified without undue delay so they can meet their own obligations under Article 33 GDPR. Incident records are kept five years.

Independent penetration testing

The Processor does not hold SOC 2 or ISO 27001 certification and has not yet undergone an external penetration test. External penetration testing is planned on a monthly basis; no start date has been set.

Disaster-recovery testing

A full disaster-recovery test (containers, data and service verification) is planned monthly. It has not been carried out yet; no date has been set for the first test.

Policy review

Security and privacy policies are reviewed every quarter.

Personnel

All staff and contractors are bound by the Processor's acceptable-use policy and security policies. A breach of those policies is reviewed by the CTO and the CEO and may result in restricted or withdrawn access, disciplinary action or termination of contract. When a person leaves, their accounts, SSH keys, API tokens and staff access are revoked on their last day and any shared secret they could read is rotated.

Subprocessors

The Controller grants the Processor general authorisation to engage the subprocessors listed below. The Processor has entered into a data processing agreement with each subprocessor, imposing data protection obligations no less protective than those in this agreement.

SubprocessorLegal entityCountryPurposeEEA transfer mechanism
SupabaseSupabase Pte. LtdSingaporeDatabase, authentication and file storageStandard Contractual Clauses
ResendPlus Five Five, Inc.United StatesTransactional emailEU–US Data Privacy Framework
StripeStripe Payments Europe, LimitedIrelandPayments and invoicingEU–US Data Privacy Framework
AnthropicAnthropic Ireland, LimitedIrelandDrafting documents, interview replies and questionnaire answersStandard Contractual Clauses

Change notification

The Processor shall give the Controller 30 days' notice before engaging a new or replacement subprocessor, by email to all Controllers subscribed to subprocessor-change notices. During that period the Controller may object on reasonable grounds. If the parties cannot resolve the objection, either party may terminate the affected services on written notice without penalty.

Return and deletion

Upon expiry or termination of the Controller's subscription:

  1. Export window. Workspace data remains accessible to the Controller for 30 days following termination so that it may be exported.
  2. Deletion. At the end of that 30-day period, all workspace data is deleted.
  3. Financial records. Invoice and payment records are retained for five years as required by applicable accounting and tax law and are not subject to earlier deletion.
  4. Logs. Infrastructure and access logs are retained for 90 days from creation. Incident records and data-subject-request logs are retained for five years.
  5. Confirmation. Upon request, the Processor shall provide written confirmation that deletion has been carried out, unless retention is required by applicable law.

Article 28 GDPR terms

The following terms apply where the Processor processes personal data subject to Regulation (EU) 2016/679 ("GDPR") on behalf of the Controller.

In accordance with Article 28(3) GDPR, the Processor shall:

(a) Process on instructions only. Process personal data only on the documented instructions of the Controller, as set out in this agreement, and inform the Controller immediately if it believes any instruction infringes applicable data protection law.

(b) Confidentiality. Ensure that persons authorised to process the personal data have committed themselves to confidentiality or are under an appropriate statutory obligation of confidentiality.

(c) Security. Take all measures required pursuant to Article 32 GDPR, as described in the Security measures section of this agreement.

(d) Subprocessors. Not engage another processor without the prior written authorisation of the Controller, whether specific or general. Where general authorisation is given (as it is under this agreement), the Processor shall inform the Controller of any intended changes and give the Controller the opportunity to object, as set out in the Subprocessors section of this agreement.

(e) Assistance — data-subject rights. Taking into account the nature of the processing, assist the Controller by appropriate technical and organisational measures, insofar as possible, in fulfilling its obligation to respond to requests for the exercise of data-subject rights under Chapter III GDPR. Where a restriction on processing is accepted, the relevant data is marked with a flag that stops it being processed.

(f) Assistance — Articles 32–36. Assist the Controller in ensuring compliance with the obligations pursuant to Articles 32 to 36 GDPR (security, breach notification, data protection impact assessments and prior consultation), taking into account the nature of the processing and the information available to the Processor.

(g) Return and deletion. At the choice of the Controller, delete or return all personal data after the end of the provision of services, and delete existing copies unless Union or Member State law requires storage, as set out in the Return and deletion section of this agreement.

(h) Audit and information. Make available to the Controller all information necessary to demonstrate compliance with the obligations laid down in this Article, and allow for and contribute to audits, including inspections, conducted by the Controller or an auditor mandated by the Controller.

Lead supervisory authority: Urząd Ochrony Danych Osobowych (Personal Data Protection Office) — https://uodo.gov.pl/ — being the supervisory authority of the Processor's main establishment in Poland.

Privacy contact: [email protected]

International transfers (EEA)

Where personal data is transferred from the European Economic Area to a country not recognised by the European Commission as providing an adequate level of protection, the Processor relies on the following Chapter V mechanisms:

SubprocessorReceiving countryMechanism
Supabase (Supabase Pte. Ltd)SingaporeEU Standard Contractual Clauses (Commission Decision 2021/914)
Resend (Plus Five Five, Inc.)United StatesEU–US Data Privacy Framework (Commission adequacy decision of 10 July 2023)
Stripe (Stripe Payments Europe, Limited)Ireland (EEA)No transfer outside the EEA
Anthropic (Anthropic Ireland, Limited)Ireland (EEA)No transfer outside the EEA

The Processor shall not instruct a subprocessor to transfer personal data to a third country except where a valid Chapter V mechanism is in place. Where the European Commission withdraws or invalidates an adequacy decision or where Standard Contractual Clauses are suspended or declared invalid by a competent court or supervisory authority, the Processor shall notify the Controller without undue delay and co-operate in identifying an alternative transfer mechanism.

The Processor's vendor due-diligence process verifies the applicable transfer mechanism for each vendor before approval, and each annual vendor review confirms that the mechanism remains current.