Legal

Data Processing Addendum.

Last updated: June 14, 2026

1. Scope and roles

This Data Processing Addendum (“DPA”) forms part of the agreement between you (the “Customer”) and Clark (“we” or “us”) for use of the Clark service (the “Agreement”). It applies where Clark processes personal data on the Customer's behalf. For that processing, the Customer is the controller and Clark is the processor. Where there is a conflict, this DPA controls over the Agreement on the subject of data processing.

2. Definitions

  • Personal data is information relating to an identified or identifiable person that Clark processes on the Customer's behalf under the Agreement.
  • Processing is any operation performed on personal data.
  • Controller and processor have the meanings given under applicable data protection law.
  • Subprocessor is a third party engaged by Clark to process personal data.

3. Details of processing

  • Purpose. To provide the analytics service described in the Agreement: connecting, syncing, cleaning, analyzing, and presenting the Customer's business data, and generating briefings and answers.
  • Duration. For the term of the Agreement and any period needed to return or delete data afterward.
  • Types of data. Business and operational records the Customer connects, which may include client names, contact details, appointment and transaction history, membership and credit activity, and feedback or satisfaction responses.
  • Data subjects. The Customer's clients and staff, and the Customer's own users of Clark.

No special-category or health data. The service is not intended to process special categories of data or Protected Health Information (PHI). The Customer must not submit such data unless the parties have signed a separate written agreement covering it. See Section 5 of our Terms of Service.

4. Clark's obligations

Clark will:

  • Process personal data only on the Customer's documented instructions, including as set out in the Agreement and this DPA, unless required to do otherwise by law.
  • Ensure that personnel authorized to process personal data are bound by confidentiality.
  • Implement appropriate technical and organizational security measures (Section 5).
  • Assist the Customer, taking into account the nature of the processing, with data subject requests, security, breach notification, and impact assessments.

5. Security measures

Clark maintains technical and organizational measures designed to protect personal data, including:

  • Encryption of data in transit and at rest.
  • Tenant isolation so that one customer's data is not exposed to another, enforced at the database layer.
  • Role-based access controls and least-privilege access.
  • Application security review and dependency management.
  • Logging, monitoring, and an incident response process.

See our Security overview for more detail.

6. Subprocessors

The Customer authorizes Clark to engage the subprocessors listed at clark's subprocessors page. Clark imposes data protection obligations on each subprocessor that are no less protective than those in this DPA, and remains responsible for their performance. Clark will update that page before adding or replacing a subprocessor; the Customer may object on reasonable data protection grounds by contacting clark@kenanali.com.

7. Data subject requests

Taking into account the nature of the processing, Clark will assist the Customer with appropriate measures to respond to requests from data subjects to exercise their rights, including access, correction, deletion, restriction, portability, and objection. If Clark receives such a request directly, it will refer the individual to the Customer.

8. Personal data breach notification

Clark will notify the Customer without undue delay after becoming aware of a personal data breach affecting the Customer's personal data, and will provide reasonable information and assistance to help the Customer meet its own notification obligations.

9. International transfers

Where Clark transfers personal data across borders, it will rely on an appropriate transfer mechanism, such as the Standard Contractual Clauses or another lawful safeguard, where required by applicable law.

10. Audits

On reasonable written request, and no more than once per year unless required by a regulator, Clark will make available information reasonably necessary to demonstrate compliance with this DPA, subject to confidentiality and to protecting the security and data of other customers.

11. Return and deletion of data

On termination of the Agreement, Clark will, at the Customer's choice, delete or return the personal data it processes on the Customer's behalf, and delete existing copies, unless retention is required by law. This is subject to the timelines in our Privacy Policy.

12. US state privacy laws

Where Clark acts as a “service provider” or “processor” under US state privacy laws such as the California Consumer Privacy Act, Clark will: process personal data only to provide the service and as permitted by those laws; not sell or share personal data; not retain, use, or disclose it for any purpose other than the service; and not combine it with data from other sources except as permitted. Clark certifies that it understands and will comply with these restrictions.

13. Liability

Each party's liability under this DPA is subject to the limitations and exclusions of liability set out in the Agreement.

14. Governing law

This DPA is governed by the same law as the Agreement, except where applicable data protection law requires otherwise.

15. How to execute this DPA

If you need a countersigned copy of this DPA for your records, email clark@kenanali.com with your legal entity name and the signer's details.

Clark · Data Processing Addendum