Last updated: June 7, 2026
This Data Processing Addendum ("DPA") forms part of the agreement between Clear Flow, Inc. ("Clear Flow", "Processor") and the customer ("Controller") for the provision of payment services. It governs the processing of personal data on the Controller's behalf. This page is a plain-language summary and does not constitute legal advice.
Clear Flow acts as a processor (and, for certain regulated activities, an independent controller) of personal data submitted through the services. The Controller determines the purposes and means of processing within the platform.
Clear Flow processes personal data only on documented instructions from the Controller, including with regard to transfers, unless required to do otherwise by applicable law.
Personnel authorized to process personal data are bound by confidentiality obligations.
Clear Flow maintains technical and organizational measures appropriate to the risk, including encryption, access controls, and PCI DSS Level 1 and SOC 2 Type II controls. See our Security page.
The Controller authorizes Clear Flow to engage sub-processors (e.g., cloud infrastructure and banking partners) subject to equivalent data-protection obligations. A current list is available on request.
Where personal data is transferred internationally, Clear Flow relies on appropriate safeguards such as Standard Contractual Clauses and offers regional data residency options.
Clear Flow assists the Controller in responding to data-subject requests (access, rectification, erasure, portability) to the extent legally required.
Upon termination, Clear Flow deletes or returns personal data except where retention is required by law or card-network rules.
To execute a countersigned DPA or request our sub-processor list, email privacy@clearflow.io or use our contact page.
Our team can countersign a DPA and share our full compliance pack.