CleanRev
Features Pricing About Blog
Sign In Join Waitlist
Features Pricing About Blog
Sign In Join Waitlist

Data Processing Agreement (DPA)

Last updated: 2026-05-22

This Data Processing Agreement ("DPA") forms part of the CleanRev Terms of Service between CleanRev Inc. ("Processor") and the customer ("Controller") and governs the processing of Personal Data by Processor on behalf of Controller in connection with the CleanRev cleaning-business SaaS platform.

Effective date: the date Controller accepts this DPA (either by clicking "I agree" during onboarding or by executing the countersigned version below).

1. Definitions

  • "GDPR" means Regulation (EU) 2016/679 (the General Data Protection Regulation).
  • "CCPA" means the California Consumer Privacy Act (Cal. Civ. Code § 1798.100 et seq.) as amended by the California Privacy Rights Act (CPRA).
  • "Personal Data" has the meaning given in GDPR Art. 4(1) and the meaning of "personal information" in CCPA § 1798.140(v).
  • "Sub-processor" means any third party engaged by Processor to process Personal Data on behalf of Controller.
  • "Data Subject" has the meaning in GDPR Art. 4(1).

2. Subject-matter and duration (GDPR Art. 28(3))

Subject matter: Processor processes Personal Data submitted by Controller to the CleanRev platform to provide cleaning-business management services including scheduling, invoicing, payments, time tracking, customer relationship management, and ancillary features.

Duration: for the term of the underlying CleanRev Terms of Service, plus the retention period defined in §10.

3. Nature and purpose of processing

Processor processes Personal Data solely to provide the CleanRev SaaS platform to Controller. Processing operations include: storage; retrieval; transmission to Sub-processors necessary for service delivery; backup; and deletion or return at end of term.

4. Categories of Personal Data

  • End-customer contact information (name, address, phone, email) submitted by Controller about its own customers.
  • Worker identity and employment information (name, role, worker class, pay rate) submitted by Controller about its employees and subcontractors.
  • Booking, scheduling, and job history records.
  • Communication logs (SMS, email transmission records via Telnyx and SMTP2GO sub-processors).
  • Geo-location (worker GPS during a job; customer property address).
  • Bookkeeping data submitted via Plaid (bank-feed transactions) and Gusto (payroll integration).
  • Payment metadata (Stripe token IDs, not card numbers — see Privacy Notice).

5. Categories of Data Subjects

  • Controller's employees and subcontractors (cleaning workers).
  • Controller's end customers (homeowners and small-business proprietors).
  • Controller's authorized users of the CleanRev platform.

6. Processor obligations (GDPR Art. 28(3)(a)–(h))

  1. Documented instructions. Processor will process Personal Data only on documented instructions from Controller, including this DPA and Controller's use of the CleanRev platform features. If Processor believes an instruction violates GDPR or applicable data-protection law, it will notify Controller without delay.
  2. Confidentiality. Persons authorized to process Personal Data are subject to confidentiality obligations (contractual or statutory).
  3. Security measures. Processor implements the technical and organizational measures described in §7 to meet GDPR Art. 32.
  4. Sub-processors. Processor uses the Sub-processors listed in §8 and will notify Controller in advance of any change. Controller has 30 days to object in writing to a new Sub-processor.
  5. Data subject rights. Processor assists Controller with responding to data-subject requests via the DSR endpoints documented in the CleanRev API (/api/v1/compliance/tenant/export, /api/v1/portal/me/export, and the corresponding delete endpoints).
  6. Personal-data breach notification. Processor will notify Controller without undue delay (and within 72 hours of awareness) of any Personal Data breach affecting Controller's data.
  7. Data-protection impact assessment (DPIA). Processor will provide reasonable cooperation if Controller is required to conduct a DPIA under GDPR Art. 35.
  8. End of processing. At Controller's choice, Processor will delete or return all Personal Data at end of term, subject to legal retention requirements (see §10).

7. Security measures

Processor maintains the following technical and organizational measures. Cross-references point at the engineering artifacts that implement them.

  • Encryption in transit: TLS 1.2+ on all API and web traffic (Cloudflare-enforced).
  • Encryption at rest: Neon PostgreSQL provides transparent disk-level encryption.
  • Access control: JWT-authenticated, role-based access (owner/admin/manager/employee); per-tenant Row Level Security in Postgres. See apps/api/src/middleware/auth.ts.
  • Authentication: bcryptjs cost-factor 12 password hashing. See docs/operations/PASSWORD_POLICY_AUDIT.md.
  • Secret management: see docs/operations/SECRETS_ROTATION.md.
  • Backup: Neon continuous backup + point-in-time recovery 7 days. See docs/operations/DR_DRILL_SCHEDULER.md.
  • Incident response: see docs/operations/INCIDENT_RESPONSE.md.
  • Logging and monitoring: Axiom HEC observability with PII-aware reporter. See apps/api/src/lib/observability.ts.
  • Vulnerability management: dependency scanning via npm audit + GitHub Dependabot; pre-commit secret scanning.
  • Personnel: all personnel with production access bound by confidentiality obligations.

8. Sub-processors

The current Sub-processors are:

Sub-processorPurposeLocation
StripePayment processingUnited States
NeonPostgreSQL hostingUnited States (AWS regions)
CloudflareCDN, Workers, Pages, R2Global
TelnyxSMS deliveryUnited States
SMTP2GOTransactional emailUnited States / EU
PlaidBank-feed aggregation (opt-in)United States
GustoPayroll integration (opt-in)United States
AxiomApplication log storageUnited States / EU
Google WorkspaceInternal email / calendarGlobal

Processor will give Controller 30 days' advance notice of any new Sub-processor by updating this table and posting a notice on /changelog.

9. International data transfers

Where Processor or any Sub-processor transfers Personal Data from the EEA, UK, or Switzerland to a third country, the transfer is made under (a) an adequacy decision, (b) the EU Standard Contractual Clauses (SCC 2021/914), or (c) the UK International Data Transfer Addendum to the EU SCCs, as applicable. Processor will provide Controller with copies of executed SCCs on written request.

10. Audit rights

Controller may, no more than once per 12-month period, request reasonable information about Processor's compliance with this DPA. If Controller requires an on-site audit, the parties will agree on scope, timing, and cost in advance. Processor will provide audit reports, certifications, or third-party assessments (e.g., SOC 2, if available) in lieu of an on-site audit where reasonably acceptable to Controller.

11. Return or deletion (GDPR Art. 28(3)(g))

On termination of the underlying agreement, Processor will, at Controller's election, return Personal Data via the /api/v1/compliance/tenant/export endpoint or delete it via /api/v1/compliance/tenant/account, subject to legal-retention windows (typically 90 days for billing records). Backups containing Personal Data are retained for the backup-rotation window and then overwritten.

12. CCPA Service Provider terms

With respect to Personal Information of California residents, Processor acts as a "Service Provider" (and not a "Third Party") under the CCPA. Processor will not:

  • Sell or share Personal Information.
  • Retain, use, or disclose Personal Information for any purpose other than the specific purpose of performing the services described in this DPA.
  • Retain, use, or disclose Personal Information outside the direct business relationship between Processor and Controller.
  • Combine Personal Information received from Controller with Personal Information received from any other source, except as permitted by CCPA § 1798.140(e)(6).

Processor will notify Controller if it determines it can no longer meet its CCPA Service Provider obligations.

13. Liability

Each party's liability under this DPA is subject to the limitation and exclusion of liability set out in the underlying CleanRev Terms of Service.

14. Governing law

This DPA is governed by the laws specified in the underlying CleanRev Terms of Service.

15. Execution

To execute this DPA, send a signed copy to legal@cleanrev.io with the subject line "DPA Execution — [Your Company Name]". A countersigned copy will be returned within 5 business days.

This DPA is a template; specific deal-by-deal modifications must be in writing and signed by both parties.

CleanRev

Run your cleaning business smarter. Scheduling, invoicing, and customer management—all in one place.

Product

  • Features
  • Pricing

Company

  • About
  • Contact

Resources

  • Help Center
  • Blog
  • Status

Legal

  • Privacy Policy
  • Terms of Service
  • Data Protection
  • Accessibility
  • Security

© 2026 CleanRev, Inc. · All rights reserved.

Terms Privacy Refunds Cookies Accessibility Security Do Not Sell My Info

Cookie Preferences

We use essential cookies for authentication and payment processing through Stripe, plus first-party, cookieless analytics you can opt out of. Reject disables the analytics too. View cookie preferences

CleanRev

Pristina · AI Assistant

Leave your email and a CleanRev team member will reach out. Phone is optional.

Join the CleanRev waitlist

Be first in line for early access. Leave your name and email and we'll let you know the moment it opens.

No spam — just one note when early access opens.

You're on the list!

We'll email you the moment early access opens. Thanks for your interest in CleanRev.