Data Processing Addendum
The terms on which Cleanlist Inc. processes personal data on behalf of a customer, incorporated into the Terms of Service and read alongside the Privacy Policy.
Last Modified: September 6, 2026
- 1. Parties and Scope
- 2. Roles: Processor and Controller
- 3. Processing Instructions
- 4. Confidentiality of Personnel
- 5. Security Measures
- 6. Subprocessors
- 7. International Transfers
- 8. Assistance with Individual Rights
- 9. Personal Data Breach Notification
- 10. Return and Deletion
- 11. Audits and Information Rights
- 12. Details of Processing
- 13. How to Execute This DPA
1. Parties and Scope
This Data Processing Addendum (“DPA”) is between Cleanlist Inc., a corporation incorporated under the Canada Business Corporations Act, corporation number 1507534-3, of 240 Richmond St W, Toronto, Ontario M5V 2C5, Canada, and the Customer identified in the applicable order or account.
It forms part of the Terms of Service and applies whenever Cleanlist processes personal data on the Customer’s behalf in the course of providing the services. Where this DPA conflicts with the Terms, this DPA governs for data protection matters. Terms defined in the Terms of Service and the Privacy Policy carry the same meaning here.
2. Roles: Processor and Controller
The role depends on the data and the activity, and we do not claim a single role for everything.
- Cleanlist is a processor for Customer Data the Customer submits, imports or connects, including HubSpot Customer Data reached through an integration the Customer authorised. The Customer is the controller of that data.
- Cleanlist is an independent controller for Account Data, billing data, security and fraud prevention data, service usage data, and for Business Contact Data it sources independently from its contracted data providers.
Each party complies with the data protection law applicable to it in its own role. The Customer is responsible for the lawfulness of the instructions it gives and for having a lawful basis for the processing it directs.
3. Processing Instructions
Cleanlist processes Customer Data only on the Customer’s documented instructions, which comprise the Terms of Service, this DPA, the configuration choices the Customer makes in the services, and any further written instruction the parties agree. Cleanlist also processes where required by law, and in that case will inform the Customer before processing unless the law prohibits it.
Cleanlist will tell the Customer if, in its opinion, an instruction infringes applicable data protection law. Cleanlist does not sell Customer Data, does not use it for its own marketing or advertising, and does not use it to train general purpose or third party artificial intelligence models.
4. Confidentiality of Personnel
Cleanlist limits access to Customer Data to personnel who need it to provide or support the services, and those personnel are bound by written confidentiality obligations or an appropriate statutory duty of confidence that survives the end of their engagement.
5. Security Measures
Cleanlist implements technical and organisational measures appropriate to the risk, including:
- encryption of data in transit over public networks, and encryption at rest for stored data
- role-based access control and least-privilege access to production systems
- authentication controls for staff access, including multi-factor authentication
- logical separation of customer workspaces
- logging and monitoring of access to production systems
- backup and restoration procedures
- security review of vendors before they process customer data
- a documented process for handling suspected security incidents
These are the measures in place, described honestly. Cleanlist does not currently hold an ISO 27001 certification or a SOC 2 report, and does not claim one. If a certification is required for a procurement process, ask us and we will tell you the current position rather than point at a badge we do not have.
6. Subprocessors
The Customer gives general authorisation for Cleanlist to engage subprocessors to provide the services. Cleanlist imposes data protection obligations on each subprocessor that are no less protective than those in this DPA, and remains liable to the Customer for a subprocessor’s performance.
The current list of subprocessors and contracted data providers is published at cleanlist.ai/data-sources. Cleanlist will give the Customer notice before adding a new subprocessor that processes Customer Data, and the Customer may object on reasonable data protection grounds. If the parties cannot resolve an objection, the Customer may terminate the affected part of the services without penalty for the remainder of the term.
7. International Transfers
Cleanlist is established in Canada and uses subprocessors in Canada, the United States and the European Economic Area. Where Cleanlist transfers personal data out of the European Economic Area, the United Kingdom or Switzerland to a country without an adequacy decision, the transfer is made under the European Commission’s Standard Contractual Clauses, together with the United Kingdom International Data Transfer Addendum where the United Kingdom GDPR applies. Those clauses are incorporated into this DPA by reference and take effect on execution of this DPA.
Transfers from the European Economic Area and the United Kingdom to Cleanlist in Canada may rely on the adequacy decision covering Canadian commercial organisations where it applies to the processing in question.
8. Assistance with Individual Rights
Taking into account the nature of the processing, Cleanlist assists the Customer by appropriate technical and organisational measures, insofar as this is possible, in fulfilling the Customer’s obligation to respond to requests to exercise individual rights.
If Cleanlist receives a request that relates to Customer Data, it will not respond directly except to confirm receipt and to direct the individual to the Customer, unless the Customer instructs otherwise or the law requires a direct response. Cleanlist also assists the Customer with data protection impact assessments and prior consultations, on request and where the assistance is reasonably required.
Requests about Business Contact Data, for which Cleanlist is an independent controller, are handled by Cleanlist directly under the Privacy Policy. That is a separate route and does not depend on the Customer.
9. Personal Data Breach Notification
Cleanlist notifies the Customer without undue delay, and in any event within 72 hours, after becoming aware of a personal data breach affecting Customer Data. The notice describes the nature of the breach, the categories and approximate number of records affected so far as known, the likely consequences, the measures taken or proposed, and a contact point for further information.
Where the full picture is not available within that period, Cleanlist provides the information it has and supplies the remainder as it becomes available. Notification is not an acknowledgement of fault.
10. Return and Deletion
On termination of the services, the Customer may export Customer Data for 30 days. After that period Cleanlist deletes or deidentifies Customer Data, except where retention is required by law or is necessary for security, billing, dispute resolution or suppression.
Where the Customer disconnects an integration, Cleanlist stops new access and deletes or deidentifies Integration Data and the Customer Data reached through that integration, including HubSpot Customer Data, on the same basis.
Backups expire on Cleanlist’s backup cycle. Data in an expiring backup is not restored to production, and a record deleted from production is not reintroduced from a backup. Where Cleanlist retains a minimal suppression identifier to honour an objection, it is used only to prevent reintroduction and for nothing else.
11. Audits and Information Rights
Cleanlist makes available to the Customer the information reasonably necessary to demonstrate compliance with this DPA, and allows for and contributes to audits conducted by the Customer or an independent auditor the Customer mandates.
Audits are on reasonable written notice of at least 30 days, no more than once in any twelve month period unless a regulator requires otherwise or a personal data breach has occurred, during business hours, subject to confidentiality, and conducted so as not to disrupt the services or the data of other customers. The Customer bears its own costs.
12. Details of Processing
This section is the Annex required by Article 28(3) of the GDPR and its United Kingdom equivalent.
- Subject matter. Provision of the Cleanlist services: contact and company data enrichment, verification, list management, and integration with the Customer’s connected systems.
- Duration. The term of the Customer’s subscription, plus the export and deletion periods in section 10.
- Nature and purpose. Hosting, storage, transmission, enrichment, verification, deduplication, structuring, synchronisation with connected systems, and support, all on the Customer’s instructions.
- Categories of data subject. The Customer’s authorised users, and the business contacts whose records the Customer submits, imports or asks Cleanlist to enrich.
- Categories of personal data. Professional identity and contact data: name, job title, seniority, employer, business email address, business telephone number, professional profile URL, and company firmographics. Account and authentication data for authorised users.
- Special category data. None. The services are not intended for, and the Terms prohibit, the submission of special category data, government identifiers, financial account credentials, health data, precise location, biometric data, or data about children.
- Frequency. Continuous for the term.
13. How to Execute This DPA
This DPA applies automatically to a Customer using the services in a way that involves Cleanlist processing personal data on its behalf, and no signature is required for it to take effect between the parties.
If your procurement process requires a countersigned copy, or a copy of the Standard Contractual Clauses with the annexes completed for your organisation, write to support@cleanlist.ai with your legal entity name and address and we will return one.
Need a signed copy?
Send your legal entity name and address and we will return a countersigned DPA with the transfer clauses annexed.