Legal
Data Processing Agreement
Last updated: July 18, 2026
This Data Processing Agreement (“DPA”) forms part of the Terms & Conditions between Clientish Co Inc (“Clientish”, “Processor”, “we”) and the customer using the Clientish platform (“Customer”, “Controller”), and applies to the extent Clientish processes Personal Data on Customer’s behalf in the course of providing the Service.
1. Roles of the Parties
For Customer Data — the client records, orders, invoices, files, messages, and tickets uploaded into a workspace — Customer acts as the Data Controller and Clientish acts as the Data Processor. Clientish only hosts this data on Customer’s behalf and does not access, review, or use it for its own purposes. For Customer’s own account information (name, email, billing details), Clientish acts as an independent Data Controller as described in our Privacy Policy.
2. Subject Matter & Duration
Processing covers the Personal Data contained within Customer Data, for the duration Customer maintains an active workspace, plus the retention period described in Section 5 (Data Retention & Deletion) of our Privacy Policy following termination.
3. Nature & Purpose of Processing
Clientish processes Personal Data solely to store, host, and make available Customer Data as directed by Customer through use of the Service — including database storage, backups, file hosting, and transmission of transactional notifications (invoices, ticket updates) that Customer configures.
4. Categories of Data Subjects & Data
Data subjects may include Customer’s team members, remote members, and their own clients or leads. Categories of data typically include names, contact details, communication records, order and billing history, and files uploaded to the workspace, depending on what Customer chooses to store.
5. Sub-Processors
Customer authorizes Clientish to engage the following categories of sub-processors: cloud infrastructure and database hosting providers, email delivery providers, and payment gateways (Stripe, PayPal, Paddle, Aamarpay, SSLCommerz) used to process transactions Customer initiates. Clientish remains responsible for sub-processors’ compliance with data protection obligations equivalent to those in this DPA, and will provide notice of any new sub-processor upon request.
6. Security Measures
Clientish maintains technical and organizational measures appropriate to the risk, including encrypted passwords, HTTPS transport encryption, two-factor authentication, session management controls, and role-based access controls, as described further in our Privacy Policy.
7. Assistance with Data Subject Requests
Where Clientish receives a request from a data subject relating to Customer Data, Clientish will promptly forward it to Customer. Clientish will provide reasonable assistance to Customer in responding to data subject access, correction, or deletion requests using the export, correction, and deletion tools built into the Service.
8. International Transfers
Where Personal Data is transferred outside the data subject’s home jurisdiction, Clientish relies on appropriate safeguards, such as standard contractual clauses, consistent with applicable data protection law.
9. Data Breach Notification
Clientish will notify Customer without undue delay after becoming aware of a Personal Data breach affecting Customer Data, and will provide reasonably available information to help Customer meet its own notification obligations.
10. Deletion & Return of Data
Upon termination of Customer’s subscription, Clientish will delete or make available for export the Customer Data in accordance with the retention period described in our Privacy Policy, unless applicable law requires continued storage.
11. Contact Us
Questions about this DPA can be sent to support@clientish.co.