Data Processing Addendum
Last updated: 1 October 2026
This Data Processing Addendum (“DPA”) forms part of the TellData Terms of Use or other written agreement governing use of the TellData service (the “Agreement”), entered into between:
Registration Number: HE 478941
Private Limited Company registered in Cyprus
(“Company”, “Processor”, “Service Provider”, “we”, “us”)
and the customer using the TellData service (“Customer”, “Controller”, “Business”, “you”).
This DPA applies to the extent Company processes Personal Data on behalf of Customer in connection with the TellData platform (the “Service”). If there is a conflict between this DPA and the Agreement regarding Personal Data processing, this DPA shall control.
1. Definitions
“Personal Data” means any information relating to an identified or identifiable individual processed under this DPA.
“Processing” means any operation performed on Personal Data, including collection, storage, use, disclosure, or deletion.
“Customer Data” means Personal Data submitted by or on behalf of Customer into the Service, as well as data processed by the Service in order to generate informational outputs.
“Data Protection Laws” means applicable privacy and data protection laws, including, where applicable:
- U.S. state privacy laws, including the California Consumer Privacy Act as amended by the CPRA
- The EU General Data Protection Regulation (GDPR) and UK GDPR, where applicable
2. Roles of the parties
2.1 Customer as Controller / Business
Customer acts as the controller, or “business” under applicable U.S. privacy laws, with respect to Customer Data.
2.2 Company as Processor / Service Provider
Company acts as a service provider or processor, processing Customer Data only:
- To provide, operate, and maintain the Service
- To generate informational outputs based on user-provided and third-party data
- To ensure security, integrity, and functionality of the Service
2.3 No independent use
Company does not:
- Sell Customer Data
- Use Customer Data for advertising
- Use Customer Data for independent profiling or decision-making purposes
3. Scope and purpose of processing
3.1 Company processes Customer Data solely as necessary to:
- Provide access to the TellData platform
- Generate and deliver informational reports based on available data sources
- Administer accounts, billing, and support
- Ensure system functionality, security, and fraud prevention
- Comply with applicable legal obligations
3.2 Company does not process Customer Data to:
- Make decisions about individuals
- Provide recommendations regarding individuals
- Determine eligibility for employment, housing, credit, insurance, or other regulated purposes
4. Customer responsibilities
Customer is solely responsible for:
- Determining the lawful basis for processing personal data
- Ensuring that its use of the Service complies with applicable laws
- Obtaining any required notices, disclosures, or permissions
- Verifying the accuracy and appropriateness of data submitted
Customer shall not use the Service in a manner that violates applicable data protection or consumer protection laws, and agrees not to use the Service for:
- Employment decision-making
- Tenant screening
- Credit eligibility determinations
- Insurance underwriting
- Any other purpose regulated under the Fair Credit Reporting Act (FCRA) or similar laws
5. Confidentiality
Company ensures that all personnel authorised to process Customer Data are subject to confidentiality obligations appropriate to the nature of the data and their access.
6. Security measures
6.1 Company maintains appropriate technical and organisational measures designed to protect Customer Data against accidental or unlawful destruction, loss, alteration, unauthorised disclosure, or access.
6.2 Security measures are proportionate to the nature of the Service and its risk profile, and are described at a high level in Exhibit C.
7. Subprocessors
7.1 Authorisation. Customer provides general authorisation for Company to engage subprocessors as necessary to provide the Service.
7.2 List of subprocessors. Company’s current subprocessors are listed in Exhibit B.
7.3 Changes. Company may update subprocessors from time to time and will make updated information available upon request.
7.4 Flow-down obligations. Company enters into written agreements with subprocessors imposing data protection obligations no less protective than those in this DPA.
7.5 Responsibility. Company remains responsible for subprocessors’ compliance with their processing obligations.
8. Personal data breach
8.1 Company will notify Customer without undue delay after becoming aware of a personal data breach affecting Customer Data.
8.2 Company will provide reasonable information and cooperation to assist Customer in meeting any breach notification obligations under applicable law.
8.3 Notification does not constitute an admission of fault or liability.
9. Data subject requests
9.1 If Company receives a request from a data subject relating to Customer Data, Company will, where legally permitted, refer the request to Customer.
9.2 Company will provide reasonable assistance to Customer in responding to such requests where technically feasible and legally permitted.
Company does not independently respond to data subject requests regarding Customer Data except as instructed by Customer or required by applicable law.
10. Retention and deletion
10.1 Company retains Customer Data only for the period necessary to provide and operate the Service, maintain system security and integrity, and comply with legal, regulatory, and accounting obligations.
10.2 Upon termination of the Agreement, Company will delete or return Customer Data upon Customer’s written request, unless retention is required by applicable law or necessary for legitimate operational purposes such as security, fraud prevention, or backup systems.
10.3 Customer acknowledges that certain data may persist in backup systems for a limited period consistent with standard data retention practices.
11. Audits
11.1 Upon reasonable written request, Company will provide information reasonably necessary to demonstrate compliance with this DPA, including summaries of security measures.
11.2 Any audit rights shall be exercised:
- No more than once per 12-month period
- With at least 30 days’ prior written notice
- During normal business hours
- In a manner that does not disrupt Company operations
11.3 Company may satisfy audit obligations by providing third-party certifications, reports, or independent assessments where available.
11.4 All audits are subject to confidentiality obligations and reasonable security restrictions.
12. US state privacy (CCPA / CPRA)
To the extent applicable:
12.1 Company acts as a Service Provider or Contractor with respect to Customer Data.
12.2 Company will not:
- Sell or share Customer Data
- Retain, use, or disclose Customer Data for any purpose other than providing the Service
- Combine Customer Data with data obtained from other sources except as necessary to operate the Service
12.3 Company certifies that it understands and will comply with the restrictions applicable to Service Providers under U.S. state privacy laws.
12.4 Company processes Customer Data solely to provide informational outputs, and does not process Customer Data to make decisions about individuals or determine eligibility for employment, housing, credit, insurance, or other regulated purposes.
13. International transfers
Customer acknowledges that Customer Data may be processed in the European Union and other jurisdictions where Company or its subprocessors operate.
Where required by applicable Data Protection Laws, Company will implement appropriate safeguards, including contractual protections such as Standard Contractual Clauses.
14. Order of precedence
In the event of a conflict between any applicable data transfer mechanism, this DPA, and the Agreement, the order of precedence shall apply in the sequence listed, unless otherwise required by applicable law.
15. Contact
Privacy contact: [email protected]
Company: CLEARCHECK LTD
Exhibit A — Processing details
Service: TellData informational data platform.
Nature of processing: collection, storage, organisation, and analysis of Customer-provided data and data obtained from public and third-party sources in order to generate informational reports.
Purpose: provision of informational reports and related platform functionality, including account management, billing, support, and security. Processing does not include making decisions about individuals or determining eligibility for employment, housing, credit, insurance, or other regulated purposes.
Categories of data subjects:
- Individuals whose information is submitted by Customer
- Authorised users of the Service
Categories of personal data:
- Name
- Phone number
- Email address
- Address information, where available
- Public record data
- Report output data
- Technical and usage data
Special categories: Customer is solely responsible for ensuring that any sensitive personal data submitted is lawful and appropriate.
Exhibit B — Subprocessors
| Function | Subprocessor | Location |
|---|---|---|
| Payment processing | PayPro Global | As determined by provider |
| Hosting & infrastructure | Hetzner Online GmbH | Finland (EU) |
| Transactional email | Google LLC (Gmail) | As determined by provider |
Company may engage subprocessors to support operation of the Service, including hosting, payments, communications, and infrastructure providers. All subprocessors are subject to contractual obligations consistent with this DPA.
Exhibit C — Security measures (high level)
Company implements appropriate technical and organisational measures, including:
- Role-based access controls
- Encrypted data transmission
- Secure hosting infrastructure
- Monitoring and logging of system activity
- Backup and recovery procedures
- Internal access restrictions and change management
These measures are designed to protect personal data against unauthorised access, loss, misuse, or alteration.