Data Processing Addendum
Version 1.0 · 18 July 2026.
This Data Processing Addendum (“DPA”) forms part of our Terms and applies whenever you, as a creator running a school on Clienteles, have us process personal data of your students on your behalf. In that relationship you are the controller and SS Ventures (“Clienteles”) is your processor. For a countersigned copy, email hello@clienteles.co.
What processing this covers
Subject matter and duration: hosting and operating your school for the life of your subscription. Nature and purpose: storing and serving course content; managing student accounts, enrolments and progress; issuing certificates; running your community; sending transactional and, where you use them, broadcast emails. Categories of data: student name, email, password hash, enrolment and payment references, course progress, community posts and messages, certificates. Data subjects: your students, who may include minors — you are responsible for the lawful basis and any parental consent their age requires.
Our commitments as your processor
- We process student data only to run your school and on your documented instructions, not for our own purposes, and never sell it.
- Everyone with access is bound by confidentiality.
- We protect the data with appropriate measures: encryption in transit, hashed passwords, per-tenant isolation, encrypted storage of connected provider keys (AES-GCM), and restricted, audited internal access.
- We assist you, taking into account the nature of the processing, in answering data-subject requests (access, correction, deletion, portability) and in meeting your security and breach obligations.
- We notify you without undue delay after becoming aware of a personal-data breach affecting your school.
- On termination, when your school is deleted its records are removed from our database; uploaded media is removed on request while we complete automated storage cleanup. You can request an export of your student data beforehand.
- We make available the information reasonably necessary to demonstrate compliance with this DPA.
- Where student data is transferred outside the EEA/UK, the transfer is covered by our sub-processors’ data-processing agreements incorporating recognised safeguards (EU Standard Contractual Clauses or an adequacy mechanism).
Sub-processors
We use these sub-processors to run every school:
| Sub-processor | What for | Where |
|---|---|---|
| Cloudflare | Hosting, database, file storage, CDN, security | Global (US HQ) |
| Resend | Transactional email (used when you haven’t connected your own sender) | US |
| Slack | Internal operational alerts to our team | US |
Providers you connect yourself — your own Razorpay or Stripe account for payments, or your own Resend account for email — act for you directly under your agreements with them and are not our sub-processors. We will notify account holders by email before adding or replacing a sub-processor, giving you the opportunity to object.
Certificates
Certificates you issue can be verified publicly by certificate number, which displays the holder’s name to prove authenticity. Ask us to remove a certificate at any time.
Contact
Privacy questions or instructions about your students’ data: hello@clienteles.co. See also our Privacy Policy.