Data Processing Addendum
This addendum is being finalized ahead of general availability and is subject to change; it is not the final DPA and is not legal advice.
Roles & scope
For customer/utility data, your organization is the data controller and Polish Clover Solutions is the processor. We process that data only to provide the service and only on your documented instructions, including those in the Terms of Service and Privacy Policy.
Security measures
Technical and organizational measures include field-level encryption at rest, pseudonymization, role-based access with MFA and a gated PII Steward role, append-only audit logging, statistical disclosure control, and encrypted backups with a tested restore process — see Security.
Subprocessors
We engage the following US-based subprocessors, and will give notice of changes so you may object:
- Render — hosting, database, and encrypted storage.
- Google Workspace — transactional email.
- Sentry — error monitoring (configured to exclude PII).
- Stripe — payments, only if and when billing is enabled.
Data subject requests
We will assist you, taking into account the nature of the processing, in responding to requests from individuals to exercise their rights.
Personal-data breach notice
We will notify you without undue delay after becoming aware of a personal-data breach affecting data we process on your behalf, with the information reasonably available to us.
Return & deletion
On termination, we return or delete the data we process on your behalf at your choice, subject to legal retention requirements.
International transfers
Data is hosted and processed in the United States.
Contact
support@polishcloversolutions.com
Polish Clover Solutions · Effective July 21, 2026.