This Data Processing Agreement ("DPA") applies where Clovert processes personal data on behalf of a customer organisation, and forms part of the Terms of Service.
It is made between the customer organisation using Clovert (the "Customer" or "Controller") and Clovert, operated from Croatia (the "Processor").
Jump to section
Roles Scope & duration Nature of processing Data subjects Data categories Instructions Security Subprocessors Transfers Data subject rights Breach notification Audits DeletionThe Customer determines the purposes and means of processing personal data entered into Clovert and acts as the data controller.
Clovert processes that personal data on the Customer's behalf and acts as the data processor.
Both parties will comply with applicable data protection law, including Regulation (EU) 2016/679 ("GDPR").
The subject matter of processing is the provision of the Clovert performance management platform.
Processing continues for the duration of the Customer's use of the Service, and for the limited period afterwards necessary to complete export, deletion and backup expiry.
Clovert processes personal data to provide functionality including:
Clovert will not process Customer Data for purposes unrelated to providing the Service, unless required by law.
Depending on the Customer's use of the Service, data subjects may include employees, managers, HR personnel, administrators, and contractors or other workers whose information the Customer chooses to process through Clovert.
Personal data processed through Clovert may include: name; work email address; employee ID; job title; department; manager relationship; employment-related organisational information; goals and goal progress; performance ratings; self-evaluations; manager evaluations; peer and 360° feedback; skills and competency data; development plans; 9-Box ratings; audit and activity records; and other information the Customer chooses to enter.
Clovert processes Customer Data only to provide the Service, in accordance with the Customer's documented instructions, as necessary to maintain security and functionality, and as required by law.
The Customer's configuration and use of the Service constitutes its instructions for the ordinary processing necessary to provide the Service.
If Clovert believes an instruction infringes applicable data protection law, it will inform the Customer where legally permitted to do so.
Persons authorised to process Customer Data are subject to appropriate confidentiality obligations. Clovert will not disclose Customer Data to third parties except as necessary to provide the Service, with the Customer's authorisation, or where required by law.
Clovert implements appropriate technical and organisational measures, including:
These measures may be updated as technology and practice evolve, provided the level of protection is not reduced.
The Customer authorises Clovert to engage subprocessors reasonably necessary to provide the Service. Current subprocessors are:
Clovert requires its subprocessors to provide appropriate data protection safeguards through contractual arrangements.
Clovert may add or replace subprocessors where necessary to operate or improve the Service, and will inform Customers of intended changes, giving a reasonable opportunity to object.
PostHog is used for analytics on the clovert.eu marketing website only and does not process Customer Data from the application.
Application data is hosted within the European Union. Where a subprocessor processes personal data outside the European Economic Area, Clovert ensures an appropriate transfer mechanism is in place — an adequacy decision, Standard Contractual Clauses, or another safeguard recognised under applicable law.
Information about relevant transfer safeguards is available on reasonable request.
Taking into account the nature of the processing, Clovert provides reasonable assistance to the Customer in responding to data subject requests concerning access, rectification, erasure, restriction, portability and objection.
The platform includes GDPR tooling that allows HR administrators to export and anonymise employee data directly.
Where a data subject contacts Clovert directly about Customer Data, Clovert will redirect the request to the Customer unless law requires otherwise.
Clovert will notify the Customer without undue delay after becoming aware of a personal data breach affecting Customer Data.
Where available, the notification will describe the nature of the incident, the categories of data and data subjects affected, likely consequences, and the measures taken or proposed to address it.
Clovert will cooperate reasonably to help the Customer meet its own obligations under applicable law.
Clovert will make available information reasonably necessary to demonstrate compliance with the obligations applicable to processors under Article 28 GDPR, including information about its technical and organisational security measures.
Where legally required, the parties will cooperate with audits or inspections. Audits must be requested with reasonable advance notice, take place during normal business hours, minimise disruption, and respect confidentiality and security requirements.
Following termination, the Customer may export Customer Data for a reasonable period. Customer Data is then deleted within 30 days of account closure, unless the Customer requests a different arrangement or retention is required by law.
Backup copies are deleted or overwritten in accordance with our infrastructure provider's backup retention cycle.
Data Protection Officer. Clovert has not appointed a Data Protection Officer. Privacy and data protection requests may be sent to the contact address below and will be handled directly.
Conflict. If this DPA conflicts with the Terms of Service on data protection matters, this DPA prevails.
Governing law. This DPA is governed by the laws of the Republic of Croatia and applicable European Union law.
Full legal entity details, including registered name and tax identification number, will be published here once business registration is complete.