Roles and scope
For personal data in a customer-authorized CRM, the customer is controller or business and CleanIQ is processor or service provider. CleanIQ processes that data only on documented instructions necessary to provide, secure, support, and improve and develop the service, unless law requires otherwise.
Customer instructions and responsibility
The customer instructs CleanIQ through the Terms, its order, product configuration, connected CRM, scans, approvals, and support requests. The customer is responsible for lawful collection, notices, consents, data-subject handling, and ensuring its instructions comply with applicable law.
Confidentiality and security
CleanIQ limits access to personnel and providers with a service need and applies the technical and organizational measures described in the Security Overview, including TLS, encrypted connector credentials, access controls, tenant isolation, audit, rate controls, and approval gates.
Subprocessors
The customer generally authorizes the providers on the Subprocessor List. CleanIQ remains responsible for requiring appropriate data-protection obligations and will provide notice of material changes where required. Customer-directed CRM providers remain governed by the customer’s relationship with them.
Assistance and incidents
Taking account of the processing and information available, CleanIQ will reasonably assist with verified rights requests, security incidents, regulatory inquiries, and data-protection assessments required by applicable law. CleanIQ will notify affected customers of a personal-data breach where and within the time required by law or contract.
Return, deletion, and audits
At the end of service, CleanIQ will delete or return eligible customer personal data upon verified instruction, subject to legal retention, security evidence, billing, disputes, backups, and technical limitations. Reasonable compliance information may be provided before any narrowly scoped audit is considered.
International transfers
If restricted-transfer law applies, the parties may incorporate the then-current European Commission Standard Contractual Clauses or another lawful mechanism. Required annexes, transfer details, governing terms, and signatures must be completed in an executed DPA; this public text alone is not an executed transfer agreement.
