Clauzy ← Legal documents

Data Processing Agreement

Version 1.5 · Last updated 2026-09-04 · legal@clauzy.ai

This Data Processing Agreement (this "DPA") governs Prestance Lab's processing of Personal Data carried out in the course of providing the Services under the Agreement. Capitalised terms not defined here have the meaning given to them in the General Terms and Conditions or, failing that, in the GDPR. It is incorporated by reference into the Agreement pursuant to GTC §14.3.

1. Roles and definitions

In order to provide the Services, Prestance Lab is required to process the Personal Data of Authorized Users. The Parties acknowledge that, with respect to the processing of such Personal Data carried out under the Agreement, the Customer acts as the data controller (the "Controller") and Prestance Lab acts as the data processor (the "Processor").

"Controller", "Data Subject", "Personal Data", "Process / Processing", "Processor", "Sub-processor", "Data Protection Impact Assessment", "Data Protection Officer" and "Personal Data Breach" have the same meaning as in the GDPR.

2. Applicable legislation

Each Party undertakes to comply with the provisions of any applicable legislation concerning the protection of Personal Data, in particular the French Data Protection Act No. 78-17 of 6 January 1978 in its latest version in force and Regulation (EU) 2016/679 of the European Parliament and of the Council of 27 April 2016 on the protection of individuals with regard to the processing of personal data and on the free movement of such data (the "GDPR"), together the "Applicable Data Protection Legislation".

3. Description of the processing

The Personal Data processing operations carried out by the Processor are described below.

Concerned service(s)
The Services as defined in the GTCs (Solution, Maintenance Services, and Professional Services where applicable).
Nature of the processing operations
Storage, consultation, organization, transmission, erasure, recording (voice), transcription (speech-to-text), automated analysis (LLM-as-judge), profiling within the meaning of Article 4(4) GDPR (skill mapping over time), and anonymization.
Purpose(s) of processing
Performance of the Agreement and provision of the Services, including: authentication of Authorized Users; delivery of voice-drill rehearsal sessions; generation of coaching letters; delivery of aggregated manager reporting; the telephone, SMS and email channels through which an Authorized User works with the assistant; preparation, electronic signature and delivery of property-visit forms (bons de visite) that the Authorized User has the assistant produce for a prospective buyer; technical support; and security monitoring.
Categories of Data Subjects
Authorized Users of the Customer (typically the Customer's employees or agents acting in a sales-advisor, manager, or administrator role); and, for the property-visit forms only, the Authorized User's prospective buyers named on a form as signatories.
Categories of Personal Data
Identity data (first name, last name); professional contact data (professional email address); authentication metadata (hashed password, MFA token state, session identifiers); voice and session content (voice recordings of client-conversation simulations, advisor → persona transcripts, coaching letters and Solution-generated feedback, performance scores and skill ratings); drill metadata (drill identifiers, timestamps, scenarios); channel content (recordings and transcripts of the Authorized User's calls with the assistant, SMS and email exchanges with the assistant and their attachments); property-visit form data (buyer's name and contact details, the property visited, date of visit, the electronic signature and its proof file); technical telemetry (IP address, browser user-agent, error logs).
Special categories of Personal Data
None processed by design. The Solution does not perform emotion recognition in the workplace within the meaning of Article 5(1)(f) of the EU AI Act.
Duration of the processing
Until deletion by the Authorized User or by the Customer administrator, and at the latest at the end of the Agreement followed by the deletion procedure described in Section 5 below and in the Security Policy (typically within 30 days; backups purged within 90 days).

4. Controller's undertakings

The Controller undertakes to:

5. Processor's undertakings

The Processor undertakes to:

6. International transfers

The Controller gives general consent to transfers of Personal Data outside the European Economic Area ("EEA") by the Processor, provided that such transfers are subject to the appropriate safeguards set out in Chapter V of the GDPR (including, where applicable, the European Commission's Standard Contractual Clauses and the UK Addendum, as well as any Transfer Impact Assessment required). The Sub-processor list in Section 7 below indicates the relevant transfer mechanism for each Sub-processor.

7. List of Sub-processors

As of the last-updated date at the top of this page, the following Sub-processors are engaged by the Processor for the provision of the Services.

Sub-processor Entity / address Activity Country of processing Transfer mechanism DPA
Nebius B.V. Amsterdam, the Netherlands Cloud infrastructure hosting our proprietary model for post-drill analysis (no third-party model provider) European Union (regions in Finland and France) Intra-EEA hosting Nebius DPA
Google LLC 1600 Amphitheatre Parkway, Mountain View, CA 94043, USA Live-drill voice-to-voice, coach, and intro-briefing voice synthesis (all languages) United States (no EU data residency) SCCs Google Cloud DPA
Supabase, Inc. 970 Toa Payoh North #07-04, Singapore 318992 (operating via Supabase Pte. Ltd.); hosting on AWS Ireland (eu-west-1) Authentication, PostgreSQL database, object storage Ireland (EU) Intra-EEA hosting; SCCs for any extra-EEA support operations Supabase DPA
LiveKit, Inc. 1 Bluxome Street, Suite 410, San Francisco, CA 94107, USA WebRTC media transport (SFU); session recording via Egress API to Prestance Lab-controlled storage Germany (EU, eu-central region); US transit for observability Intra-EEA media; SCCs for US-side observability data LiveKit DPA
Hetzner Online GmbH Industriestraße 25, 91710 Gunzenhausen, Germany Application hosting (backend, voice-agent worker) Germany (EU) Intra-EEA hosting Hetzner DPA
Langfuse GmbH Charlottenstrasse 2, 10969 Berlin, Germany LLM observability Ireland (EU, cloud.langfuse.com EU region) Intra-EEA Langfuse DPA
PostHog, Inc. 2261 Market Street #4008, San Francisco, CA 94114, USA Product analytics, logging, and error tracking Germany (EU, eu.i.posthog.com) Intra-EEA hosting; SCCs for any US-side support operations PostHog DPA
Eleven Labs Inc. 169 Madison Ave #2484, New York, NY 10016, USA Speech-to-text transcription of the Authorized User's calls with the assistant and of voice practice sessions (all languages), via the API under enterprise terms with no training on Customer Data and no retention of request content beyond the request (Zero Retention Mode) United States (EU data residency on Enterprise plans) SCCs; EU-U.S. Data Privacy Framework ElevenLabs DPA
Twilio Ireland Limited 70 Sir John Rogerson's Quay, Dublin 2, D02 R296, Ireland (Twilio Inc., 101 Spear Street, San Francisco, CA 94105, USA, acts as its sub-processor) Telephone channel (inbound and outbound calls between the Authorized User and the assistant, connected to the EU media transport over SIP) and SMS channel. Call signalling and message content in transit Ireland (Twilio IE1 region) for call and SMS content; United States for account and usage data Intra-EEA for IE1 content; Twilio Binding Corporate Rules, SCCs and the EU-U.S. Data Privacy Framework for US processing Twilio DPA
Plus Five Five, Inc. (Resend) 2261 Market Street #5039, San Francisco, CA 94114, USA Email channel: sending and receiving the Authorized User's emails with the assistant, including attachments United States (message content, logs and webhook payloads are stored in the US; the Ireland sending region governs dispatch only). Content retained 30 days SCCs; EU-U.S. Data Privacy Framework Resend DPA
Yousign SAS (Youtrust) Rue de Suède, 14000 Caen, France Electronic signature of property-visit forms: hosting of the document and signature request, identification of the signatory, timestamping and the legal proof file. Qualified trust service provider under eIDAS. The proof file is archived by its archiving sub-processor for 10 years, independently of the deletion of the document itself France (EU) Intra-EEA hosting Yousign DPA

Where an Authorized User subscribes to the Services individually, payment is collected by Armitage Labs OÜ (Creem), Rotermanni 14, 10111 Tallinn, Estonia, acting as merchant of record and as an independent controller of the billing data the subscriber enters at checkout. Creem is not a Sub-processor under this DPA; its processing is governed by its own privacy notice.

8. Updates to this DPA

Pursuant to GTC §2.7, Prestance Lab may update this DPA. Material changes will be notified to active Customers at least thirty (30) days in advance, unless a shorter period is required by law or to address a security risk. Changes to the Sub-processor list follow the procedure set out in Section 5 above.

9. Contact