Data Processing Agreement
Version: 1.0 · August 19, 2026
This page states how CLAJAMA processes personal data as a processor on behalf of customers (controllers), including GDPR (Article 28) and CCPA service-provider terms. A full executed DPA is available on request: help@clajama.com.
1. Roles
- Controller: you (the customer) decide what business and customer data to put into your CLAJAMA sites and workspace.
- Processor: CLAJAMA processes that data only to build, host, and operate your service, and only on your documented instructions.
2. What we process
- Account data: name, email, and authentication data (passwords hashed; 2FA codes encrypted).
- Business data: your site content, intake answers, CRM records, and chat history with our builder.
- Payment metadata: order references and status via Square. We never see or store card numbers.
- Usage data: pages visited and system events, used to operate and secure the service.
3. Processor commitments
- Process personal data only for the Services and documented instructions.
- Maintain technical and organizational security: TLS in transit, access control with 2FA, role-based access, audit logging, backups, incident response.
- Assist with data-subject requests (access, correction, erasure, portability, objection) via account tools or support.
- Notify controllers without undue delay (within 72 hours) of a personal-data breach affecting their data.
- Delete or return data on termination, except where law requires retention (billing records are kept for tax/legal periods).
4. Subprocessors
We use a small, disclosed set of subprocessors. Each is bound by a data processing agreement. We will notify you of changes to this list.
| Provider | Purpose | Data |
|---|---|---|
| OVH | Cloud hosting (servers) | All platform data at rest |
| Square (Block) | Card payments | Payment status & order refs (no card numbers) |
| DeepSeek | AI model provider | Prompts (transient; not used for training) |
| Google Gemini | AI model provider + vision QA | Prompts / QA screenshots (not persisted) |
| Kimi (Moonshot) | AI model provider | Prompts (transient) |
| OpenAI | AI model fallback | Prompts (transient; API data not used for training) |
| Pexels | Stock imagery | Image URLs only |
5. International transfers
Data is hosted in OVH datacenters. Where data is transferred to subprocessors outside your region, we rely on appropriate safeguards (EU Standard Contractual Clauses / adequacy decisions / DPA terms).
6. HIPAA (Business Associate Addendum)
CLAJAMA is HIPAA-ready. For customers who are covered entities or business associates handling protected health information, we execute a Business Associate Agreement before any PHI is processed. We do not store PHI without an executed BAA. Request one at help@clajama.com.
7. Contact
Data protection questions: help@clajama.com · CLAJAMA, Macon, Georgia.