Skip to content
Cleva
HomeBarbaraThe teamMeeting Cost MeterRequest early access

Legal

Data processing agreement

How Cleva processes personal data for its clients, as required by Article 28 of the UK GDPR. It forms part of our terms of service.

Last updated 3 October 2026

Contents

  1. Parties and scope
  2. Details of the processing
  3. Instructions
  4. Confidentiality
  5. Security
  6. Sub-processors
  7. International transfers
  8. Assistance and breaches
  9. Return and deletion
  10. Information and audits
  11. Liability and precedence

1. Parties and scope

1.1 This agreement is between the business using the Service (the "Client", the controller) and Cleva Ltd, company 13999699, registered office 86-90 Paul Street, London, England, EC2A 4NE ("Cleva", the processor). It forms part of the terms of service and applies whenever Cleva processes personal data on the Client's behalf.

1.2 Words such as "personal data", "processing", "controller", "processor", "data subject" and "personal data breach" have the meanings given in the UK GDPR. "Data protection law" means the UK GDPR, the Data Protection Act 2018 and related UK law.

2. Details of the processing

  • Subject matter and purpose: providing the Service: reading documents and messages, preparing drafts in the Client's Xero, sending approvals and answers, and related support, security and record keeping.
  • Duration: the term of the contract, plus the deletion period in section 9.
  • Nature: collection, storage, extraction by AI, organisation, retrieval, transmission to the Client's systems, and deletion.
  • Data subjects: the Client's users (staff); the Client's suppliers and customers and their contacts; other people named in documents or messages the Client sends. For the Meeting Cost Meter: the Client's staff who use it, identified only by a one-way coded Microsoft ID.
  • Types of personal data: names, phone numbers, WhatsApp user IDs, email addresses, job roles; invoice and statement details, which may include bank details of sole traders; message content and voice note transcripts; accounting records read from Xero. For the Meeting Cost Meter: coded user IDs, meeting IDs, optional meeting names and departments, attendee counts by pay band, and meeting times.
  • Special category data: none intended. The Client must not send it.

3. Instructions

3.1 Cleva processes personal data only on the Client's documented instructions. The terms of service, the Client's configuration of the Service and its users' use of it are the Client's instructions.

3.2 Cleva will tell the Client if it believes an instruction breaks data protection law, unless the law forbids telling it. Cleva may process personal data where the law requires it, and will tell the Client first unless the law forbids it.

3.3 The Client confirms it has a lawful basis for the processing and has given data subjects the information the law requires.

4. Confidentiality

4.1 Cleva ensures that everyone authorised to process the personal data is bound by a duty of confidentiality and accesses it only as needed to provide the Service.

5. Security

5.1 Cleva maintains appropriate technical and organisational measures, including:

  • encryption of data in transit (TLS) between all components, and encryption at rest where provided by our hosting providers;
  • a database locked down so only Cleva's service credentials can read or write it, with row level security on every table;
  • verification of each user's phone number with a personal join code before they can use the Service, and role-based permissions so users see and do only what their role allows;
  • approval required before any draft becomes final; no ability for the assistants to pay, move money or change bank details;
  • secrets held in credential stores, never in code; separate credentials per provider; Xero access tokens refreshed and stored in a restricted table;
  • multi-factor authentication on Cleva's administrative accounts, and least-privilege access for Cleva personnel;
  • logging of messages and actions, duplicate detection, and automated deletion in line with the retention periods in our privacy notice;
  • regular backups by our hosting provider and tested restoration;
  • hosting of Cleva's database and workflow engine in London, UK.

5.2 Cleva may update these measures provided overall protection is not reduced.

6. Sub-processors

6.1 The Client gives general authorisation for Cleva to use the sub-processors listed on our sub-processors page.

6.2 Cleva will give at least 30 days' notice of a new or replacement sub-processor, by email and on that page. The Client may object on reasonable data protection grounds within that period; if the parties cannot resolve the objection, the Client may end the contract and receive a refund of prepaid fees for the period after it ends.

6.3 Cleva puts data protection terms in place with each sub-processor that give at least equivalent protection, and remains responsible to the Client for its sub-processors.

7. International transfers

7.1 Some sub-processors process personal data outside the UK. Cleva will only transfer personal data outside the UK under UK adequacy regulations (including the UK-US data bridge for certified US companies), the ICO's International Data Transfer Agreement or the UK Addendum to the EU Standard Contractual Clauses, with supplementary measures where needed.

8. Assistance and breaches

8.1 Taking into account the nature of the processing, Cleva will help the Client respond to requests from data subjects, and with security, breach notification, data protection impact assessments and consultation with the ICO.

8.2 Cleva will notify the Client without undue delay, and in any case within 48 hours, after becoming aware of a personal data breach affecting the Client's personal data, with the information the Client needs to meet its obligations, and will take reasonable steps to contain and remedy it.

9. Return and deletion

9.1 When the contract ends, Cleva will remove its access to the Client's Xero on the first daily run after cancellation and delete the Client's personal data within 90 days, unless the law requires Cleva to keep it. Before deletion the Client may ask for an export of its data held by Cleva. Bills already created in Xero remain in the Client's Xero.

9.2 Records Cleva must keep for its own legal obligations, such as billing records, are kept under our privacy notice.

10. Information and audits

10.1 Cleva will make available the information reasonably needed to show compliance with this agreement and Article 28 of the UK GDPR, and will allow and contribute to audits by the Client or its auditor, on at least 30 days' notice, during working hours, no more than once a year unless there has been a breach, and subject to confidentiality. Each party bears its own costs.

11. Liability and precedence

11.1 The limits of liability in the terms of service apply to this agreement, except where data protection law does not allow them to.

11.2 If this agreement conflicts with the terms of service on data protection, this agreement prevails.

Cleva
© 2026 Cleva Ltd · Registered in England and Wales 13999699 · Registered office: 86-90 Paul Street, London, England, EC2A 4NE
PrivacyCookiesTermsData processingSub-processorsContact