CLOCOT DATA PROCESSING ADDENDUM
Effective Date: October 2, 2026 Last Updated: October 2, 2026
This Data Processing Addendum, or DPA, forms part of the agreement between LexLupi LLC and a customer where LexLupi processes Customer Personal Data on behalf of that customer in connection with Clocot.
By using Clocot to process Customer Personal Data in a context where applicable Data Protection Law requires a processor agreement, the parties agree to this DPA unless they have signed a separate DPA that expressly supersedes it.
1. PARTIES
The Customer is the entity or person that determines the purposes and means of the relevant processing or that acts as a processor for another controller.
LexLupi LLC, a Delaware limited liability company, is the provider of Clocot and acts as the processor or subprocessor for the Customer Personal Data covered by this DPA.
2. DEFINITIONS
Applicable Data Protection Law means privacy or data-protection law applicable to the processing, including where relevant the GDPR, UK GDPR, Swiss data-protection law, Serbian data-protection law, U.S. state privacy laws, and comparable laws.
Customer Personal Data means personal data contained in Customer Content that LexLupi processes on behalf of Customer.
Controller, Processor, Data Subject, Personal Data, Processing, and Supervisory Authority have the meanings given by applicable law.
Subprocessor means a third party appointed by LexLupi to process Customer Personal Data on behalf of Customer.
3. APPLICABILITY
This DPA applies only to processing in which LexLupi acts as a processor, service provider, contractor, or subprocessor for Customer.
It does not govern processing for which LexLupi independently determines purposes and means, such as certain account administration, security, fraud prevention, billing records, legal compliance, and product-level operational analytics described in the Privacy Policy.
4. ROLES OF THE PARTIES
Where Customer is a controller, Customer is the controller and LexLupi is the processor.
Where Customer is a processor acting for another controller, Customer is the processor and LexLupi is a subprocessor.
Each party will comply with the obligations applicable to its role.
5. CUSTOMER INSTRUCTIONS
Customer instructs LexLupi to process Customer Personal Data to provide the Services, execute configured workflows, operate Offices, Directors, Agents, memory and integrations, provide requested support, maintain security and availability, and comply with Customer's documented instructions.
The agreement, Customer's configuration of the Services, authorized support requests, and documented product settings constitute Customer's instructions.
If LexLupi believes an instruction violates applicable Data Protection Law, LexLupi may inform Customer and suspend the affected processing to the extent legally permitted.
6. SUBJECT MATTER OF PROCESSING
The subject matter is the processing of Customer Personal Data in connection with Clocot's software, AI, automation, integration, CRM, communication, file, memory, API, and related functions selected by Customer.
7. DURATION
Processing continues for the duration of Customer's use of the relevant Services and for any additional period required to delete, return, secure, back up, or lawfully retain Customer Personal Data.
8. CATEGORIES OF DATA SUBJECTS
Data Subjects may include Customer users, administrators, employees, contractors, customers, prospects, leads, suppliers, business contacts, communication recipients, website users, end users, client personnel, and other individuals whose data Customer submits to Clocot.
9. TYPES OF PERSONAL DATA
Customer Personal Data may include names, email addresses, phone numbers, company and job information, CRM records, account identifiers, communications, files, documents, images, audio, video, transcripts, prompts, workflow records, customer notes, IP addresses, identifiers, integration data, business records, and other data Customer chooses to process.
10. SENSITIVE DATA
Customer may submit sensitive or specially protected data only where Customer has an appropriate lawful basis and the relevant use is permitted by the agreement and applicable law.
Customer is responsible for determining whether additional contractual, technical, regulatory, or consent requirements apply.
11. PURPOSES OF PROCESSING
LexLupi processes Customer Personal Data only for purposes necessary to provide contracted functionality, execute instructions, operate integrations, process AI tasks, store Customer Content, deliver communications requested by Customer, maintain workspace context, troubleshoot requested support issues, secure the Services, and meet legal processor obligations.
12. CONFIDENTIALITY
LexLupi will ensure that persons authorized to process Customer Personal Data are subject to appropriate confidentiality obligations.
Access is limited according to role and operational need.
13. SECURITY
LexLupi will implement appropriate technical and organizational measures designed to protect Customer Personal Data against accidental or unlawful destruction, loss, alteration, unauthorized disclosure, or access.
Measures are further described in Annex II and the Security & Data Retention Policy.
14. ACCESS CONTROL
Where technically applicable, Clocot uses controls designed to limit access by tenant, account, role, permission, workspace, credential, integration, and administrative function.
Customer remains responsible for configuring its users, administrators, permissions, and integrations appropriately.
15. SUBPROCESSORS
Customer authorizes LexLupi to use subprocessors to provide the Services.
LexLupi will require subprocessors that process Customer Personal Data to be bound by data-protection obligations appropriate to the services they provide.
The current published list is available on the Clocot Subprocessor List page.
16. CHANGES TO SUBPROCESSORS
Where applicable law or contract requires notice of a new material Subprocessor, LexLupi will provide reasonable notice through the Legal Center, account notice, email, or another appropriate channel.
A Customer with a legally valid objection may contact LexLupi promptly and explain the specific data-protection concern.
The parties will work in good faith on a commercially reasonable resolution, which may include configuration changes, alternative processing where available, or termination of the affected Service if no reasonable solution exists.
17. INTERNATIONAL TRANSFERS
Customer authorizes LexLupi and approved Subprocessors to process Customer Personal Data in countries where they operate, subject to applicable transfer restrictions.
Where a legally recognized transfer mechanism is required, the parties will use an applicable mechanism such as an adequacy decision, Standard Contractual Clauses, the UK transfer addendum or equivalent mechanism, or another lawful safeguard.
18. EEA STANDARD CONTRACTUAL CLAUSES
Where the GDPR applies to a restricted transfer and no other lawful transfer mechanism applies, the European Commission Standard Contractual Clauses adopted under Commission Implementing Decision (EU) 2021/914 are incorporated by reference.
The applicable module is Module Two, Controller to Processor, when Customer is a controller, or Module Three, Processor to Processor, when Customer is a processor.
For purposes of the SCCs:
• Customer is the data exporter;
• LexLupi LLC is the data importer;
• the docking clause applies where legally available;
• the competent supervisory authority is determined under the SCCs and applicable law;
• Annex I information is completed by this DPA and the parties' Order;
• Annex II is completed by the security measures in this DPA; and
• Annex III is completed by the published Subprocessor List.
19. UK RESTRICTED TRANSFERS
Where UK law applies to a restricted transfer, the parties incorporate the then-valid UK transfer addendum, international data transfer agreement, or other mechanism recognized by UK law, as applicable.
References to GDPR concepts will be interpreted consistently with UK law for that transfer.
20. SWISS TRANSFERS
Where Swiss data-protection law applies, the SCCs are adapted as necessary so that references to the GDPR and EU authorities include the corresponding Swiss law and competent Swiss authority to the extent required.
21. U.S. STATE PRIVACY COMMITMENTS
Where LexLupi acts as a service provider, processor, or contractor under applicable U.S. state privacy law, LexLupi will process personal data only for permitted business purposes and Customer instructions, will not sell Customer Personal Data, will not retain, use, or disclose it outside the direct business relationship except as legally permitted, and will provide the level of protection required of a processor or service provider.
22. DATA SUBJECT REQUESTS
If LexLupi receives a request from a Data Subject concerning Customer Personal Data and Customer is the relevant controller, LexLupi may direct the requester to Customer.
Taking into account the nature of processing, LexLupi will provide reasonable assistance to Customer with legally required requests for access, correction, deletion, restriction, portability, objection, or related rights.
23. ASSISTANCE WITH COMPLIANCE
Taking into account the nature of processing and information available to LexLupi, LexLupi will provide reasonable assistance with security obligations, breach notifications, Data Subject requests, data-protection impact assessments, prior consultation with regulators where required, and other processor obligations required by applicable law.
24. PERSONAL DATA BREACH
LexLupi will notify Customer without undue delay after becoming aware of a Personal Data Breach affecting Customer Personal Data where processor notification is required by applicable law.
The notice will include information reasonably available to LexLupi that Customer needs to meet its own legal obligations.
Notification does not constitute an admission of fault or liability.
25. GOVERNMENT REQUESTS
Where legally permitted, LexLupi will seek to verify the validity and scope of compulsory government or law-enforcement requests for Customer Personal Data.
LexLupi may notify Customer where legally permitted and appropriate.
26. RECORDS AND COOPERATION
LexLupi will maintain records and information reasonably necessary to demonstrate compliance with processor obligations applicable to the Services.
LexLupi will cooperate with competent supervisory authorities as required by law.
27. AUDITS
Upon reasonable written request and subject to confidentiality, security, and operational safeguards, LexLupi will make available information reasonably necessary to demonstrate compliance with this DPA.
Where legally required and reasonable, Customer may request an audit.
Audits must avoid unnecessary disruption, protect other customers' information, preserve security, be conducted during reasonable hours, use an independent qualified auditor where appropriate, and avoid accessing information unrelated to Customer.
LexLupi may satisfy an audit request through current independent reports, certifications, questionnaires, or other appropriate evidence where permitted by law.
28. RETURN AND DELETION
Upon termination of the relevant Services, LexLupi will delete or return Customer Personal Data as required by Customer's instructions, the agreement, and applicable law.
LexLupi may retain information where legally required or where limited copies remain temporarily in backups or security logs.
Retained data remains protected by this DPA for as long as it remains Customer Personal Data.
29. NO SALE OF CUSTOMER PERSONAL DATA
LexLupi does not sell Customer Personal Data received in its processor capacity.
LexLupi does not use Customer Personal Data in its processor capacity for unrelated cross-context behavioral advertising.
30. CUSTOMER OBLIGATIONS
Customer represents that it has a lawful basis for Customer Personal Data, its instructions are lawful, required notices have been provided, required consents have been obtained, data submitted is appropriate for the intended Service, administrators are authorized, and Customer will not instruct LexLupi to violate applicable law.
31. LIABILITY AND PRECEDENCE
Liability under this DPA is subject to the liability framework in the Terms of Service or the applicable negotiated agreement, except where applicable law requires otherwise.
If this DPA conflicts with the main agreement on data-processing obligations, this DPA controls for the conflicting data-processing matter.
If the SCCs conflict with this DPA, the SCCs control to the extent of the conflict.
32. ANNEX I — PROCESSING DETAILS
Data exporter: Customer, as identified in the relevant Clocot Account, Order, or enterprise agreement.
Data importer: LexLupi LLC, Delaware, United States.
Frequency: Continuous or as initiated by Customer during the Service term.
Nature: Hosting, storage, retrieval, organization, AI processing, automation, transmission, integration, analysis, generation, communications, support, and deletion.
Purpose: To provide the Clocot Services selected by Customer.
Duration: The Service term plus the limited retention periods described in the agreement and applicable law.
33. ANNEX II — TECHNICAL AND ORGANIZATIONAL MEASURES
Depending on the Service and deployment, measures may include encryption in transit, encryption at rest where technically appropriate, role-based access, tenant isolation, row-level database access controls, separate runtime and administrative database privileges, hashed or encrypted credentials, encrypted provider credentials and OAuth tokens, authentication controls, multi-factor authentication functionality, security logging, audit trails, secret scanning, environment separation, backups, incident response, vulnerability management, provider access controls, least-privilege principles, secure software development practices, credential rotation, rate limiting, monitoring, and deletion procedures.
No security measure eliminates all risk.
34. ANNEX III — SUBPROCESSORS
The current Subprocessor List published by Clocot is incorporated into this DPA.
Customer-selected third-party integrations may operate as independent controllers, processors engaged directly by Customer, or onward recipients depending on the relevant relationship.
35. CONTACT
DPA questions may be sent to office@clocot.com.
LexLupi LLC Privacy and Legal Contact: Tatjana Sindjelic