Cover Page
This Data Processing Agreement (the “DPA”), available at https://www.clave.restaurant/legal/dpa, is incorporated into and forms part of the Clave Cloud Service Terms available at https://www.clave.restaurant/legal/terms (together with the Orders and policies referenced therein, the "Agreement") between Arialy Inc. d/b/a Clave AI ("Provider") and the entity accepting the Agreement ("Customer"). This Cover Page incorporates and is governed by the DPA Standard Terms below. If there is any inconsistency between this Cover Page and the DPA Standard Terms, this Cover Page will control.
Provider: Arialy Inc. d/b/a Clave AI, 5966 S Dixie Hwy Ste 300, South Miami, FL 33143.
Customer: the entity identified in Customer’s account at signup.
Effective Date: the date Customer accepts the Agreement (including by click-through acceptance or by accessing or using the Cloud Service).
Governing Law: the laws of Delaware.
Governing Member State for the EEA SCCs: the EU Member State in which Customer is established. If Customer is not established in an EU Member State, Ireland.
Notice Period for Subprocessor Changes: at least 10 business days’ prior written notice, given by email to the account owner email address on Customer’s account and reflected in the subprocessor list maintained at https://trust.tryclave.ai/.
CCPA Applicability: if the CCPA applies to the Processing of Customer Personal Data, Provider is a "service provider" as defined in the CCPA. Provider will not sell or share Customer Personal Data, and will not retain, use, or disclose Customer Personal Data for any purpose other than performing the services specified in the Agreement, or as otherwise permitted by the CCPA. Provider will notify Customer without undue delay if Provider determines that it can no longer meet its obligations under the CCPA.
Annex I: Details of Processing
A. List of Parties
Data Exporter (Controller): Customer, as identified in Customer’s account, with the contact details and company address provided at signup or maintained in Customer’s account.
Data Importer (Processor): Arialy Inc. d/b/a Clave AI (Provider). Contact: carlos@tryclave.ai. 5966 S Dixie Hwy Ste 300, South Miami, FL 33143.
B. Description of Processing
Subject Matter: provision of AI-powered analytics, operational intelligence, and automated actions for QSR franchise operations via the Clave platform.
Duration: for the term of the Agreement, plus any period required for data deletion following termination.
Nature & Purpose: Processing Customer Personal Data to deliver the Cloud Service, including: ingesting and analyzing POS transaction data, labor and inventory data; generating AI-driven insights and recommendations; executing automated actions (WhatsApp, email, voice calls) on Customer’s behalf; integrating with Customer’s third-party platforms (QuickBooks, POS systems, delivery platforms).
Categories of Data Subjects: Customer’s employees and staff (store managers, team members); Customer’s end customers (as reflected in POS transaction data); Customer’s vendors and suppliers; Customer’s authorized users of the Cloud Service.
Categories of Personal Data: contact information (names, email addresses, phone numbers); employee/staff identifiers and roles; transaction data (sales records, order details, payment amounts, not payment card numbers); financial records from accounting integrations (QuickBooks); conversation content (chat messages, WhatsApp messages, email content, voice call transcripts); operational data (inventory levels, labor schedules, delivery metrics); device and usage data (IP addresses, browser info, session data); integration account identifiers and authentication data supplied or authorized by Customer for connected systems.
Sensitive Data: none intentionally processed. Customer must not submit special categories of data (health, biometric, racial/ethnic origin, political opinions, religious beliefs, sexual orientation) to the Cloud Service.
Annex II: Technical and Organizational Security Measures
Provider implements and maintains the following security measures to protect Customer Personal Data. These measures apply across the Cloud Service; the additional controls described for isolated analytical environments and key-managed credential custody apply to the environments and integrations enabled for Customer.
Encryption: Customer Personal Data is encrypted in transit and at rest using industry-standard cryptography. Connections to the Cloud Service use TLS 1.2 or later. Integration credentials enrolled in Provider's key-managed custody platform use authenticated symmetric encryption under tenant-specific managed encryption keys. Encryption-key material is maintained separately from stored ciphertext, and permission to read stored ciphertext does not, by itself, authorize decryption.
Access Control: Provider restricts access through authenticated identities, role-based permissions, tenant-aware authorization, and database access controls. Shared datastores use tenant scoping and row-level restrictions as applicable to the data and access path. Personnel access is restricted to authorized personnel with a business need, and privileged access is subject to multi-factor authentication. Authorized service identities receive permissions appropriate to their assigned functions.
Isolated Analytical Environments: Provider's isolated analytics service uses separate analytical databases and customer-scoped access credentials. Automatically provisioned customer analytical environments use a dedicated service identity, with separately scoped reader and writer credentials, and validation of database identity and reader access before activation. Analytical compute is isolated at the service-identity level. Related organizations within a configured customer organizational hierarchy may share an analytical environment, with access restricted to their authorized data scope. These controls do not imply dedicated physical hardware or a separate deployment of the entire Cloud Service for each Customer.
Shared Service Components and Data Segregation: Account administration, transactional features, connector orchestration, and other service components may operate on shared infrastructure. Depending on the integration and its ingestion path, source data or copies used for ingestion, synchronization, backup, logging, or delivery may also be processed outside the isolated analytical environment. Provider applies access controls and tenant scoping to these processing paths; an isolated analytical database does not make all service components single-tenant. Customer data and analytical access are restricted to the authorized Customer and organizational scope.
Integration Credential Custody: For integrations enrolled in Provider's key-managed custody platform, Provider stores encrypted credential material and controls credential intake, authorized runtime use, and exceptional disclosure through distinct permissions. Ordinary application access does not itself confer permission to decrypt stored credentials. Authorized connector software may decrypt credentials when required to authenticate to Customer-authorized systems or perform an authorized connection task. OAuth, platform-token, and legacy credential mechanisms remain subject to their applicable encryption and access controls; they are not represented as enrolled in this per-tenant-key custody system. Credentials are handled separately from AI analytical prompts; AI-assisted connection workflows use controlled credential injection and redaction to limit exposure of authentication material to model requests.
Support and Configuration Access: For supported integrations, Customer administrators can grant and revoke time-limited, credential-scoped support access through the Cloud Service. The grant records its purpose, scope, and expiry. The disclosure workflow requires authenticated access and a valid grant, uses bounded decryption permissions, and records disclosure activity and outcomes. Configuration and routine connector operation use separately authorized machine workflows and do not require a new human support grant for every connection. Revocation or expiry prevents further disclosure under that grant; it cannot reverse an access that has already occurred.
Network Security: CORS restricted to specific authorized domains. Helmet security headers (CSP, X-Frame-Options, X-Content-Type-Options, Referrer-Policy). Webhook signature validation for all inbound webhooks (Twilio, Resend/Svix, VAPI).
Monitoring & Incident Response: Error monitoring with alerting, application performance monitoring, and security-relevant credential access records. Incident response procedures are documented in Provider's Incident Response Policy. Notification of Security Incidents is governed by Section 4.1 of this DPA.
Personnel: Background checks for employees with access to Customer Personal Data. Confidentiality obligations in employment agreements. Security awareness training.
Business Continuity: Provider uses cloud infrastructure providers identified in the Subprocessor List, maintains automated backups, and documents recovery procedures in its Business Continuity and Disaster Recovery Policy. Backup and recovery mechanisms vary by service component; tenant-isolated analytical processing does not imply a separate backup infrastructure for every Customer.
Annex III: Approved Subprocessors
Provider’s Approved Subprocessors are the subprocessors listed at https://trust.tryclave.ai/ (the “Subprocessor List”), which Provider maintains as its complete and current list of Subprocessors, including each Subprocessor’s location and processing function, and which is incorporated into this DPA by reference. Provider will update the Subprocessor List and provide notice of any addition or replacement of a Subprocessor in accordance with the Notice Period for Subprocessor Changes on the Cover Page and Section 2.6(a). The Subprocessor List in effect as of the version date of this DPA is deemed approved by Customer.
AI Model Training Restriction: Provider configures its OpenRouter account with model training opt-out enabled and Zero Data Retention (ZDR) where available. Provider will not use Customer Personal Data or Customer Content to train, improve, or develop any AI or machine learning models. Provider will use commercially reasonable efforts to ensure upstream model providers do not use Customer Content for training purposes.
DPA Standard Terms
1. Processor and Subprocessor Relationships
1.1 Provider as Processor. In situations where Customer is a Controller of the Customer Personal Data, Provider will be deemed a Processor that is Processing Personal Data on behalf of Customer.
1.2 Provider as Subprocessor. In situations where Customer is a Processor of the Customer Personal Data, Provider will be deemed a Subprocessor of the Customer Personal Data.
2. Processing
2.1 Processing Details. Annex I(B) on the DPA Cover Page describes the subject matter, nature, purpose, and duration of this Processing, as well as the Categories of Personal Data collected and Categories of Data Subjects.
2.2 Processing Instructions. Customer instructs Provider to Process Customer Personal Data: (a) to provide and maintain the Service; (b) as may be further specified through Customer’s use of the Service; (c) as documented in the Agreement; and (d) as documented in any other written instructions given by Customer and acknowledged by Provider about Processing Customer Personal Data under this DPA. Provider will abide by these instructions unless prohibited from doing so by Applicable Laws. Provider will immediately inform Customer if it is unable to follow the Processing instructions. Customer has given and will only give instructions that comply with Applicable Laws.
2.3 Processing by Provider. Provider will only Process Customer Personal Data in accordance with this DPA, including the details in the Cover Page. If Provider updates the Service to update existing or include new products, features, or functionality, Provider may change the Categories of Data Subjects, Categories of Personal Data, Special Category Data, Special Category Data Restrictions or Safeguards, Frequency of Transfer, Nature and Purpose of Processing, and Duration of Processing as needed to reflect the updates by notifying Customer of the updates and changes. Customer will not provide any Customer Personal Data to Provider under the Agreement, other than the types of Personal Data described in Annex I(B).
2.4 Customer Processing. Where Customer is a Processor and Provider is a Subprocessor, Customer will comply with all Applicable Laws that apply to Customer’s Processing of Customer Personal Data. Customer’s agreement with its Controller will similarly require Customer to comply with all Applicable Laws that apply to Customer as a Processor. In addition, Customer will comply with the Subprocessor requirements in Customer’s agreement with its Controller.
2.5 Consent to Processing. Customer has complied with and will continue to comply with all Applicable Data Protection Laws concerning its provision of Customer Personal Data to Provider and/or the Service, including making all disclosures, obtaining all consents, providing adequate choice, and implementing relevant safeguards required under Applicable Data Protection Laws, including in relation to the cross-border transfer of Customer Personal Data.
2.6 Subprocessors. (a) Provider will not provide, transfer, or hand over any Customer Personal Data to a Subprocessor unless Customer has approved the Subprocessor. The current list of Approved Subprocessors is maintained at https://trust.tryclave.ai/ and includes the identities of the Subprocessors, their country of location, and their anticipated Processing tasks. Provider will provide at least 10 business days’ prior written notice of any intended changes to the Approved Subprocessors whether by addition or replacement of a Subprocessor, by email to the account owner email address on Customer’s account and by updating the Approved Subprocessors list at https://trust.tryclave.ai/. The notice will include information necessary to allow Customer to exercise its right to object to the change to Approved Subprocessors. Customer may object during the 10-business-day notice period; otherwise Customer will be deemed to accept the changes. If Customer objects during the 10-business-day notice period, Customer and Provider will cooperate in good faith to resolve Customer’s objection or concern. (b) When engaging a Subprocessor, Provider will have a written agreement with the Subprocessor that ensures the Subprocessor only accesses and uses Customer Personal Data (i) to the extent required to perform the obligations subcontracted to it, and (ii) consistent with the terms of the Agreement. (c) If the GDPR applies to the Processing of Customer Personal Data, (i) the data protection obligations described in this DPA (as referred to in Article 28(3) of the GDPR, if applicable) are also imposed on the Subprocessor, and (ii) Provider’s agreement with the Subprocessor will incorporate these obligations, including details about how Provider and its Subprocessor will coordinate to respond to inquiries or requests about the Processing of Customer Personal Data. In addition, Provider will share, at Customer’s request, a copy of its agreements (including any amendments) with its Subprocessors. To the extent necessary to protect business secrets or other confidential information, including personal data, Provider may redact the text of its agreement with its Subprocessor prior to sharing a copy. (d) Provider remains fully liable for all obligations subcontracted to its Subprocessors, including the acts and omissions of its Subprocessors in Processing Customer Personal Data. Provider will notify Customer of any failure by its Subprocessors to fulfill a material obligation about Customer Personal Data under the agreement between Provider and the Subprocessor.
3. Restricted Transfers
3.1 Authorization. Customer agrees that Provider may transfer Customer Personal Data outside the EEA, the United Kingdom, or other relevant geographic territory as necessary to provide the Service. If Provider transfers Customer Personal Data to a territory for which the European Commission or other relevant supervisory authority has not issued an adequacy decision, Provider will implement appropriate safeguards for the transfer of Customer Personal Data to that territory consistent with Applicable Data Protection Laws.
3.2 Ex-EEA Transfers. Customer and Provider agree that if the GDPR protects the transfer of Customer Personal Data, the transfer is from Customer from within the EEA to Provider outside of the EEA, and the transfer is not governed by an adequacy decision made by the European Commission, then by entering into this DPA, Customer and Provider are deemed to have signed the EEA SCCs and their Annexes, which are incorporated by reference. Any such transfer is made pursuant to the EEA SCCs, which are completed as follows: (a) Module Two (Controller to Processor) of the EEA SCCs apply when Customer is a Controller and Provider is Processing Customer Personal Data for Customer as a Processor; (b) Module Three (Processor to Sub-Processor) of the EEA SCCs apply when Customer is a Processor and Provider is Processing Customer Personal Data on behalf of Customer as a Subprocessor; (c) for each module, the following applies (when applicable): (i) the optional docking clause in Clause 7 does not apply; (ii) in Clause 9, Option 2 (general written authorization) applies, and the minimum time period for prior notice of Subprocessor changes is 10 business days; (iii) in Clause 11, the optional language does not apply; (iv) all square brackets in Clause 13 are removed; (v) in Clause 17 (Option 1), the EEA SCCs will be governed by the laws of the Governing Member State; (vi) in Clause 18(b), disputes will be resolved in the courts of the Governing Member State; and (vii) the DPA Cover Page to this DPA contains the information required in Annex I, Annex II, and Annex III of the EEA SCCs.
3.3 Ex-UK Transfers. Customer and Provider agree that if the UK GDPR protects the transfer of Customer Personal Data, the transfer is from Customer from within the United Kingdom to Provider outside of the United Kingdom, and the transfer is not governed by an adequacy decision made by the United Kingdom Secretary of State, then by entering into this DPA, Customer and Provider are deemed to have signed the UK Addendum and their Annexes, which are incorporated by reference. Any such transfer is made pursuant to the UK Addendum, which is completed as follows: (a) Section 3.2 of this DPA contains the information required in Table 2 of the UK Addendum; (b) Table 4 of the UK Addendum is modified as follows: neither party may end the UK Addendum as set out in Section 19 of the UK Addendum; to the extent ICO issues a revised Approved Addendum under Section 18 of the UK Addendum, the parties will work in good faith to revise this DPA accordingly; (c) the DPA Cover Page contains the information required by Annex 1A, Annex 1B, Annex II, and Annex III of the UK Addendum.
3.4 Other International Transfers. For Personal Data transfers where Swiss law (and not the law in any EEA member state or the United Kingdom) applies to the international nature of the transfer, references to the GDPR in Clause 4 of the EEA SCCs are, to the extent legally required, amended to refer to the Swiss Federal Data Protection Act or its successor instead, and the concept of supervisory authority will include the Swiss Federal Data Protection and Information Commissioner.
4. Security Incident Response
4.1 Upon becoming aware of any Security Incident, Provider will: (a) notify Customer without undue delay when feasible, but no later than 72 hours after becoming aware of the Security Incident; (b) provide timely information about the Security Incident as it becomes known or as is reasonably requested by Customer; and (c) promptly take reasonable steps to contain and investigate the Security Incident. Provider’s notification of or response to a Security Incident as required by this DPA will not be construed as an acknowledgment by Provider of any fault or liability for the Security Incident.
5. Audit & Reports
5.1 Audit Rights. Provider will give Customer all information reasonably necessary to demonstrate its compliance with this DPA and Provider will allow for and contribute to audits, including inspections by Customer, to assess Provider’s compliance with this DPA. However, Provider may restrict access to data or information if Customer’s access to the information would negatively impact Provider’s intellectual property rights, confidentiality obligations, or other obligations under Applicable Laws. Customer acknowledges and agrees that it will only exercise its audit rights under this DPA and any audit rights granted by Applicable Data Protection Laws by instructing Provider to comply with the reporting and due diligence requirements below. Provider will maintain records of its compliance with this DPA for 3 years after the DPA ends.
5.2 Security Reports. Provider maintains an information security program and makes its current independent-audit status available at https://trust.tryclave.ai/. Upon written request, Provider will give Customer, on a confidential basis, a summary copy of its then-current Report, to the extent a completed Report is available, together with reasonable information about the status and scope of any audit in progress. The availability of information about an audit in progress does not constitute a representation that a completed Report has been issued.
5.3 Security Due Diligence. In addition to the Report, Provider will respond to reasonable requests for information made by Customer to confirm Provider’s compliance with this DPA, including responses to information security, due diligence, and audit questionnaires, or by giving additional information about its information security program. All such requests must be in writing and made to the Provider Security Contact and may only be made once a year.
6. Coordination & Cooperation
6.1 Response to Inquiries. If Provider receives any inquiry or request from anyone else about the Processing of Customer Personal Data, Provider will notify Customer about the request and Provider will not respond to the request without Customer’s prior consent. Examples of these kinds of inquiries and requests include a judicial or administrative or regulatory agency order about Customer Personal Data where notifying Customer is not prohibited by Applicable Law, or a request from a data subject. If allowed by Applicable Law, Provider will follow Customer’s reasonable instructions about these requests, including providing status updates and other information reasonably requested by Customer. If a data subject makes a valid request under Applicable Data Protection Laws to delete or opt out of Customer’s giving of Customer Personal Data to Provider, Provider will assist Customer in fulfilling the request according to the Applicable Data Protection Law. Provider will cooperate with and provide reasonable assistance to Customer, at Customer’s expense, in any legal response or other procedural action taken by Customer in response to a third-party request about Provider’s Processing of Customer Personal Data under this DPA.
6.2 DPIAs and DTIAs. If required by Applicable Data Protection Laws, Provider will reasonably assist Customer in conducting any mandated data protection impact assessments or data transfer impact assessments and consultations with relevant data protection authorities, taking into consideration the nature of the Processing and Customer Personal Data.
7. Deletion of Customer Personal Data
7.1 Deletion by Customer. Provider will enable Customer to delete Customer Personal Data in a manner consistent with the functionality of the Services. Provider will comply with this instruction as soon as reasonably practicable except where further storage of Customer Personal Data is required by Applicable Law or permitted under the Agreement’s backup or record-retention provisions.
7.2 Deletion at DPA Expiration. (a) After the DPA expires, Provider will return or delete Customer Personal Data at Customer’s instruction unless further storage of Customer Personal Data is required or authorized by Applicable Law or permitted under the Agreement’s backup or record-retention provisions. If return or destruction is impracticable or prohibited by Applicable Laws, or if Customer Personal Data is retained in ordinary-course backup or record-retention systems as permitted under the Agreement, Provider will make reasonable efforts to prevent additional Processing of Customer Personal Data and will continue to protect the Customer Personal Data remaining in its possession, custody, or control. For example, Applicable Laws may require Provider to continue hosting or Processing Customer Personal Data. (b) If Customer and Provider have entered the EEA SCCs or the UK Addendum as part of this DPA, Provider will only give Customer the certification of deletion of Personal Data described in Clause 8.1(d) and Clause 8.5 of the EEA SCCs if Customer asks for one.
8. Limitation of Liability
8.1 Liability Caps and Damages Waiver. To the maximum extent permitted under Applicable Data Protection Laws, each party’s total cumulative liability to the other party arising out of or related to this DPA will be subject to the waivers, exclusions, and limitations of liability stated in the Agreement.
8.2 Related-Party Claims. Any claims made against Provider or its Affiliates arising out of or related to this DPA may only be brought by the Customer entity that is a party to the Agreement.
8.3 Exceptions. This DPA does not limit any liability to an individual about the individual’s data protection rights under Applicable Data Protection Laws. In addition, this DPA does not limit any liability between the parties for violations of the EEA SCCs or UK Addendum.
9. Conflicts Between Documents
9.1 This DPA forms part of and supplements the Agreement. If there is any inconsistency between this DPA, the Agreement, or any of their parts, the part listed earlier will control over the part listed later for that inconsistency: (1) the EEA SCCs or the UK Addendum, (2) this DPA, and then (3) the Agreement.
10. Term of Agreement
10.1 This DPA will start when Customer accepts the Agreement (including by click-through acceptance or by accessing or using the Cloud Service) and will continue until the Agreement expires or is terminated. However, Provider and Customer will each remain subject to the obligations in this DPA and Applicable Data Protection Laws until Customer stops transferring Customer Personal Data to Provider and Provider stops Processing Customer Personal Data.
11. Definitions
Capitalized terms used but not defined in this DPA have the meanings given to them in the Agreement.
11.1 "Controller" will have the meaning(s) given in the Applicable Data Protection Laws for the company that determines the purpose and extent of Processing Personal Data.
11.2 "Customer Personal Data" means Personal Data that Customer uploads or provides to Provider as part of the Service and that is governed by this DPA.
11.3 "DPA" means these DPA Standard Terms, the DPA Cover Page, and the policies and documents referenced in or attached to the Cover Page.
11.4 "DPA Cover Page" means the Cover Page above, which is accepted by Customer together with, and by the same electronic acceptance as, the Agreement, incorporates these DPA Standard Terms, and identifies Provider, Customer, and the subject matter and details of the data processing.
11.5 "EEA SCCs" means the standard contractual clauses annexed to the European Commission’s Implementing Decision 2021/914 of 4 June 2021 on standard contractual clauses for the transfer of personal data to third countries pursuant to Regulation (EU) 2016/679 of the European Parliament and of the European Council.
11.6 "European Economic Area" or "EEA" means the member states of the European Union, Norway, Iceland, and Liechtenstein.
11.7 "Processing" or "Process" will have the meaning(s) given in the Applicable Data Protection Laws for any use of, or performance of a computer operation on, Personal Data, including by automatic methods.
11.8 "Processor" will have the meaning(s) given in the Applicable Data Protection Laws for the company that Processes Personal Data on behalf of the Controller.
11.9 "Report" means audit reports prepared by another company according to the standards defined in the Security Policy described at https://trust.tryclave.ai/ on behalf of Provider.
11.10 "Restricted Transfer" means (a) where the GDPR applies, a transfer of personal data from the EEA to a country outside of the EEA which is not subject to an adequacy determination by the European Commission; and (b) where the UK GDPR applies, a transfer of personal data from the United Kingdom to any other country which is not subject to adequacy regulations adopted pursuant to Section 17A of the United Kingdom Data Protection Act 2018.
11.11 "Security Incident" means a Personal Data Breach as defined in Article 4 of the GDPR.
11.12 "Service" means the product and/or services described in the Agreement.
11.13 "Special Category Data" will have the meaning given in Article 9 of the GDPR.
11.14 "Subprocessor" will have the meaning(s) given in the Applicable Data Protection Laws for a company that, with the approval and acceptance of Controller, assists the Processor in Processing Personal Data on behalf of the Controller.
11.15 "UK GDPR" means European Union Regulation 2016/679 as implemented by section 3 of the United Kingdom’s European Union (Withdrawal) Act of 2018 in the United Kingdom.
11.16 "UK Addendum" means the international data transfer addendum to the EEA SCCs issued by the Information Commissioner for Parties making Restricted Transfers under S119A(1) Data Protection Act 2018.