Legal
Last updated: 2026-07-07 — finalised
This Data Processing Agreement (“DPA”) is entered into between the customer identified in the applicable Cleera account (“Customer”) and Seringa Ltd, trading as Cleera, a company registered in England and Wales (company number 15449830) with its registered office at 71-75 Shelton Street, Covent Garden, London, WC2H 9JQ (“Cleera”, “we”, “us”). This DPA supplements, and is incorporated by reference into, the Cleera Terms of Service. By creating a Cleera account, or by continuing to use Cleera after being notified of an updated version of this DPA, an authorised representative of the Customer (an ORG_ADMIN) accepts this DPA on the Customer's behalf, as recorded in Cleera's systems (see Privacy Policy for how acceptance records are kept).
Capitalised terms not defined in this DPA have the meaning given in the Terms. In this DPA:
For Customer Data, the Customer is the Controller and Cleera is the Processor, processing Customer Data only on the Customer's documented instructions. The Customer's instructions are given by its use and configuration of the Services (see Terms §6) and by this DPA. Cleera will promptly inform the Customer if, in Cleera's reasonable opinion, an instruction given by the Customer infringes Data Protection Laws, without obligation to actively monitor the Customer's instructions for this purpose.
The Customer, not Cleera, determines the lawful basis for each processing activity carried out through the Customer's use of the Services (for example contract, legitimate interests, or consent), issues privacy notices to its own clients, leads and introducers, and remains responsible for its own compliance with FCA rules (including SYSC 9 record-keeping and COBS 9A suitability documentation requirements) that apply to its regulated activities.
Subject matter: the provision of the Services to the Customer, involving the processing of Customer Data as necessary to deliver case management, client and introducer portals, document collection, e-signature, AI-assisted features (where enabled), outbound integrations the Customer chooses to connect, and related functionality.
Duration: this DPA applies for as long as Cleera processes Customer Data under the Agreement, being the Customer's subscription term plus (a) a 30-day post-termination export window, and (b) any further period during which Cleera is required to retain specific records under Clause 15 (Term, termination and deletion).
Cleera processes Customer Data to provide: hosting and secure storage of case and client documents; branded client and introducer portals; case and workflow management; dynamic forms and fact-finds; document collection and e-signature; AI-assisted document analysis, extraction, suitability-note drafting and case chat (only where the Customer's plan includes AI features and a Customer user actively triggers them); outbound sync to third-party systems the Customer connects (for example Intelliflo Office); transactional email delivery; property and address look-ups; and audit logging and reporting. Full detail of each processing activity is set out in Annex 1.
The categories of Data Subjects and Personal Data processed are set out in Annex 1. The Customer must not submit special category data (as defined in UK GDPR Article 9) or criminal offence data through the Services other than incidentally, and must take reasonable steps to minimise such data at source. Cleera does not intentionally process special category data through any AI-assisted feature.
The Customer warrants that it will:
Cleera shall, in respect of Customer Data:
The Customer generally authorises Cleera to engage the Sub-processors listed in Annex 2 to process Customer Data, provided Cleera imposes data protection obligations on each Sub-processor that are no less protective than this DPA.
Cleera will give the Customer at least 30 days' written notice (by email to the Customer's registered ORG_ADMIN contact, or an in-app or website notice) before appointing a new Sub-processor or replacing an existing one, other than an emergency security-critical change, which will be notified as soon as reasonably practicable afterwards.
The Customer may object to a new Sub-processor on reasonable data protection grounds within 30 days of notice. If the parties cannot resolve the objection, the Customer's sole remedy is to terminate the affected feature of the Services or, if the Sub-processor is fundamental to the Services, the Agreement, without further liability for the unexpired term.
Cleera remains liable for the acts and omissions of its Sub-processors to the same extent Cleera would be liable if it had performed the relevant processing itself.
Cleera uses OpenAI as a Sub-processor for AI-assisted features (chat assistant, suitability note generation, document checklist generation, document analysis, and fact-find extraction), only where the Customer's plan includes AI features and a Customer user actively triggers the relevant feature.
store: false parameter on every individual request; OpenAI does not retain, and does not train models on, Customer Data submitted through the Services.Where Cleera or a Sub-processor transfers Customer Data outside the United Kingdom, Cleera will ensure an appropriate transfer mechanism recognised under Data Protection Laws is in place before the transfer occurs, such as the UK International Data Transfer Agreement, UK-recognised Standard Contractual Clauses, or an applicable UK adequacy regulation.
Cleera implements and maintains the technical and organisational security measures summarised in Annex 3, and will not materially decrease the overall level of security during the term of the Agreement.
On the Customer's reasonable written request, no more than once in any 12-month period (save following a Personal Data Breach affecting Customer Data, or at the request of the FCA or ICO), Cleera will provide information reasonably necessary to demonstrate compliance with this DPA. Given Cleera's reliance on its own Sub-processors' independent audit programmes (for example SOC 2 reports maintained by infrastructure providers), Cleera may satisfy this obligation by providing a summary of relevant third-party audit reports in place of a direct on-site audit of Cleera's own systems, except where the Customer reasonably demonstrates this is insufficient.
Cleera will notify the Customer without undue delay, and in any event within 72 hours of becoming aware, of a Personal Data Breach affecting Customer Data, providing such details of the breach, its likely consequences, and the measures taken or proposed as are available to Cleera at the time, updating that information as it becomes available.
Cleera provides self-service tools (including a system-admin erasure endpoint) that allow the Customer to respond to most Data Subject requests directly. Where the Customer cannot reasonably do so using those tools, Cleera will provide reasonable assistance, at the Customer's cost, taking into account the nature of the processing.
This DPA takes effect on the date the Customer accepts it (or the date the Customer is deemed to accept the current version under the Terms) and continues for as long as Cleera processes Customer Data under the Agreement.
On termination, the Customer may export Customer Data for 30 days. After that period, Cleera will delete or anonymise Customer Data, save that case-shell, timestamp, and adviser-assignment records will be retained where FCA SYSC 9 requires an audit trail (currently up to 7 years from case close), during which such retained records are restricted from further processing except as required by law.
Liability arising under or in connection with this DPA is subject to the limitation and exclusion of liability provisions in the Terms (§10), which apply to claims under this DPA as if set out in full in this document.
Cleera may update this DPA to reflect changes in Data Protection Laws, Sub-processors, or the Services. Material changes will be notified to the Customer's ORG_ADMINs, who will be prompted to re-accept the current version before continuing to use AI features or inviting new clients, per Terms §13.
This DPA is governed by the laws of England and Wales and is subject to the same dispute resolution provisions as the Terms (§14).
| Activity | Data categories | Data subjects | Lawful basis (Customer to confirm) | Sub-processors involved | Retention |
|---|---|---|---|---|---|
| Mortgage casework | Financial and identity data | Clients | Contract (B2B); legitimate interests | Vercel, BoldSign, Brevo, Intelliflo | 7 years from case close (FCA SYSC 9) |
| AI-assisted casework | Financial and identity data (minimised) | Clients | Legitimate interests | OpenAI (ZDR) | 90 days (AI conversation log) |
| Lead intake | Name, email, form answers | Prospects | Consent | Vercel, Brevo, Cloudflare | 48 hours unconfirmed |
| Document storage | Identity and financial documents | Clients | Contract / legal obligation | Vercel Blob (private) | Duration of case + 7 years |
| Email delivery | Name, email, message content | Clients, advisers | Contract / legitimate interests | Brevo | 100 days post-termination (DPA); log tier per account volume |
| E-signing | Client name, email, signed document | Clients | Contract | BoldSign | Duration of case + 7 years |
| Outbound sync | Full client profile and address | Clients | Legitimate interests / Customer instruction | Intelliflo | Not stored by Cleera post-sync |
| Audit logging | IP address, user agent | Advisers, clients | Legitimate interests / legal obligation | Vercel | 12 months |
This table is the master sub-processor list, kept consistent with Cleera's Records of Processing Activities, Privacy Policy, and processor DPA tracker.
| Sub-processor | Function | Location | DPA status (as of 7 July 2026) |
|---|---|---|---|
| OpenAI | AI-assisted features (chat, suitability notes, document analysis, extraction) | US (ZDR; SCCs / UK IDTA) | Signed 26 June 2026 |
| Vercel | Hosting, blob storage, log drains, bot management | Global infrastructure | Confirmed — Pro plan; DPA auto-incorporated |
| Neon | PostgreSQL database hosting | London, UK (West) | Confirmed — DPA auto-incorporated via ToS |
| Stripe | Billing and subscription payments | Global (PCI-DSS) | Confirmed — DPA auto-incorporated via Services Agreement |
| Brevo | Transactional email delivery | EU | Confirmed — Annex 2 DPA auto-incorporated |
| BoldSign | Electronic signature | EU | In progress — DPA request submitted, awaiting confirmation |
| Cloudflare | Turnstile bot protection on public forms | Global | Confirmed — DPA auto-incorporated via ToS |
| Intelliflo | Outbound CRM sync (Customer-authorised) | UK | In progress — written confirmation requested, awaiting reply |
| Ideal Postcodes | Postcode / address lookups | UK | Confirmed — published standing DPA |
store: false).