This Data Processing Agreement ("DPA") forms part of the CleanRev Terms of Service between CleanRev Inc. ("Processor") and the customer ("Controller") and governs the processing of Personal Data by Processor on behalf of Controller in connection with the CleanRev cleaning-business SaaS platform.
Effective date: the date Controller accepts this DPA (either by clicking "I agree" during onboarding or by executing the countersigned version below).
1. Definitions
- "GDPR" means Regulation (EU) 2016/679 (the General Data Protection Regulation).
- "CCPA" means the California Consumer Privacy Act (Cal. Civ. Code § 1798.100 et seq.) as amended by the California Privacy Rights Act (CPRA).
- "Personal Data" has the meaning given in GDPR Art. 4(1) and the meaning of "personal information" in CCPA § 1798.140(v).
- "Sub-processor" means any third party engaged by Processor to process Personal Data on behalf of Controller.
- "Data Subject" has the meaning in GDPR Art. 4(1).
2. Subject-matter and duration (GDPR Art. 28(3))
Subject matter: Processor processes Personal Data submitted by Controller to the CleanRev platform to provide cleaning-business management services including scheduling, invoicing, payments, time tracking, customer relationship management, and ancillary features.
Duration: for the term of the underlying CleanRev Terms of Service, plus the retention period defined in §10.
3. Nature and purpose of processing
Processor processes Personal Data solely to provide the CleanRev SaaS platform to Controller. Processing operations include: storage; retrieval; transmission to Sub-processors necessary for service delivery; backup; and deletion or return at end of term.
4. Categories of Personal Data
- End-customer contact information (name, address, phone, email) submitted by Controller about its own customers.
- Worker identity and employment information (name, role, worker class, pay rate) submitted by Controller about its employees and subcontractors.
- Booking, scheduling, and job history records.
- Communication logs (SMS, email transmission records via Telnyx and SMTP2GO sub-processors).
- Geo-location (worker GPS during a job; customer property address).
- Bookkeeping data submitted via Plaid (bank-feed transactions) and Gusto (payroll integration).
- Payment metadata (Stripe token IDs, not card numbers — see Privacy Notice).
5. Categories of Data Subjects
- Controller's employees and subcontractors (cleaning workers).
- Controller's end customers (homeowners and small-business proprietors).
- Controller's authorized users of the CleanRev platform.
6. Processor obligations (GDPR Art. 28(3)(a)–(h))
- Documented instructions. Processor will process Personal Data only on documented instructions from Controller, including this DPA and Controller's use of the CleanRev platform features. If Processor believes an instruction violates GDPR or applicable data-protection law, it will notify Controller without delay.
- Confidentiality. Persons authorized to process Personal Data are subject to confidentiality obligations (contractual or statutory).
- Security measures. Processor implements the technical and organizational measures described in §7 to meet GDPR Art. 32.
- Sub-processors. Processor uses the Sub-processors listed in §8 and will notify Controller in advance of any change. Controller has 30 days to object in writing to a new Sub-processor.
- Data subject rights. Processor assists Controller with
responding to data-subject requests via the DSR endpoints documented in
the CleanRev API (
/api/v1/compliance/tenant/export,/api/v1/portal/me/export, and the corresponding delete endpoints). - Personal-data breach notification. Processor will notify Controller without undue delay (and within 72 hours of awareness) of any Personal Data breach affecting Controller's data.
- Data-protection impact assessment (DPIA). Processor will provide reasonable cooperation if Controller is required to conduct a DPIA under GDPR Art. 35.
- End of processing. At Controller's choice, Processor will delete or return all Personal Data at end of term, subject to legal retention requirements (see §10).
7. Security measures
Processor maintains the following technical and organizational measures. Cross-references point at the engineering artifacts that implement them.
- Encryption in transit: TLS 1.2+ on all API and web traffic (Cloudflare-enforced).
- Encryption at rest: Neon PostgreSQL provides transparent disk-level encryption.
- Access control: JWT-authenticated, role-based access
(owner/admin/manager/employee); per-tenant Row Level Security in
Postgres. See
apps/api/src/middleware/auth.ts. - Authentication: bcryptjs cost-factor 12 password hashing.
See
docs/operations/PASSWORD_POLICY_AUDIT.md. - Secret management: see
docs/operations/SECRETS_ROTATION.md. - Backup: Neon continuous backup + point-in-time recovery
7 days. See
docs/operations/DR_DRILL_SCHEDULER.md. - Incident response: see
docs/operations/INCIDENT_RESPONSE.md. - Logging and monitoring: Axiom HEC observability with
PII-aware reporter. See
apps/api/src/lib/observability.ts. - Vulnerability management: dependency scanning via npm audit + GitHub Dependabot; pre-commit secret scanning.
- Personnel: all personnel with production access bound by confidentiality obligations.
8. Sub-processors
The current Sub-processors are:
| Sub-processor | Purpose | Location |
|---|---|---|
| Stripe | Payment processing | United States |
| Neon | PostgreSQL hosting | United States (AWS regions) |
| Cloudflare | CDN, Workers, Pages, R2 | Global |
| Telnyx | SMS delivery | United States |
| SMTP2GO | Transactional email | United States / EU |
| Plaid | Bank-feed aggregation (opt-in) | United States |
| Gusto | Payroll integration (opt-in) | United States |
| Axiom | Application log storage | United States / EU |
| Google Workspace | Internal email / calendar | Global |
Processor will give Controller 30 days' advance notice of any new Sub-processor by updating this table and posting a notice on /changelog.
9. International data transfers
Where Processor or any Sub-processor transfers Personal Data from the EEA, UK, or Switzerland to a third country, the transfer is made under (a) an adequacy decision, (b) the EU Standard Contractual Clauses (SCC 2021/914), or (c) the UK International Data Transfer Addendum to the EU SCCs, as applicable. Processor will provide Controller with copies of executed SCCs on written request.
10. Audit rights
Controller may, no more than once per 12-month period, request reasonable information about Processor's compliance with this DPA. If Controller requires an on-site audit, the parties will agree on scope, timing, and cost in advance. Processor will provide audit reports, certifications, or third-party assessments (e.g., SOC 2, if available) in lieu of an on-site audit where reasonably acceptable to Controller.
11. Return or deletion (GDPR Art. 28(3)(g))
On termination of the underlying agreement, Processor will, at
Controller's election, return Personal Data via the
/api/v1/compliance/tenant/export endpoint or delete it via
/api/v1/compliance/tenant/account, subject to legal-retention
windows (typically 90 days for billing records). Backups containing
Personal Data are retained for the backup-rotation window and then
overwritten.
12. CCPA Service Provider terms
With respect to Personal Information of California residents, Processor acts as a "Service Provider" (and not a "Third Party") under the CCPA. Processor will not:
- Sell or share Personal Information.
- Retain, use, or disclose Personal Information for any purpose other than the specific purpose of performing the services described in this DPA.
- Retain, use, or disclose Personal Information outside the direct business relationship between Processor and Controller.
- Combine Personal Information received from Controller with Personal Information received from any other source, except as permitted by CCPA § 1798.140(e)(6).
Processor will notify Controller if it determines it can no longer meet its CCPA Service Provider obligations.
13. Liability
Each party's liability under this DPA is subject to the limitation and exclusion of liability set out in the underlying CleanRev Terms of Service.
14. Governing law
This DPA is governed by the laws specified in the underlying CleanRev Terms of Service.
15. Execution
To execute this DPA, send a signed copy to legal@cleanrev.io with the subject line "DPA Execution — [Your Company Name]". A countersigned copy will be returned within 5 business days.
This DPA is a template; specific deal-by-deal modifications must be in writing and signed by both parties.