Data Processing Agreement
Where you store your own clients’ personal data in cluein.me, you act as controller and we act as processor. This agreement sets out that relationship under Art. 28 GDPR. Download it as a PDF for your own records.
Data Processing Agreement
This agreement describes how cluein.me processes personal data on behalf of customer organizations under Art. 28 GDPR. The customer acts as controller, cluein.me as processor. Processing takes place only on documented instructions from the customer.
Subject matter
cluein.me provides a client portal for project briefings, file uploads, approvals, and project handoff exports.
Categories of data
Contact details, project briefing answers, uploaded assets, portal audit events, billing identifiers, and account metadata. Categories of data subjects are the customer’s own clients and their staff, plus the customer’s team members.
Location of processing
All application data is processed on a single server in Germany that we operate ourselves. Database, authentication and file storage run on that same server as a self-hosted Supabase installation — no data is transmitted to Supabase Inc. The server infrastructure is provided by Hostinger International Ltd.
Sub-processors
Hostinger International Ltd., 61 Lordou Vironos Street, 6023 Larnaca, Cyprus (server infrastructure in Germany); Stripe Payments Europe, Ltd., Dublin, Ireland (billing); Brevo (Sendinblue GmbH), Berlin, Germany (transactional email); Upstash, Inc., Palo Alto, USA (rate limiting — receives only a one-way hash of the requesting IP address and a counter, never portal content); Anthropic PBC, San Francisco, USA (optional briefing quality scoring, can be disabled per organization). Reach measurement runs on our own server and involves no sub-processor. Transfers to processors in the USA are based on EU Standard Contractual Clauses under Art. 46(2)(c) GDPR. We inform customers before adding or replacing a sub-processor, and the customer may object.
Security measures
Row-level security, organization isolation, private storage, hashed portal tokens, hashed IP logging, MFA support, signed Stripe webhooks, and server-side plan enforcement.
Retention
Deleted organizations enter a read-only grace period, then soft-delete and hard-delete according to the retention schedule documented in the product.
Assistance and export
Organization owners can export workspace data from settings. cluein.me assists with data subject requests where required by applicable data protection law, and supports the customer in meeting the obligations under Art. 32 to 36 GDPR, including notification of personal data breaches without undue delay.
Confidentiality and audits
Everyone authorised to process personal data is bound to confidentiality. On request the customer receives the information necessary to demonstrate compliance with Art. 28 GDPR and may carry out inspections, which we support with reasonable notice and without disproportionate disruption to operations.
Contact
Kristian Hoffmann, Karl-Kraut-Strasse 15, 30177 Hanover, Germany, moin@kristianhoffmann.de. To conclude this agreement in signed form, send us a short message and we will return a countersigned copy.