← Back to home

Data Processing Agreement

Last updated: 10 July 2026

When you use cln.wiki for your team, your organisation is the data controller and we are the processor acting on your instructions. This agreement sets out what that means: what we process, the sub-processors we rely on (including the AI model providers behind the librarian), how we secure it, and how we handle breaches and deletion.

1. Parties

This Data Processing Agreement (“DPA”) is entered into between:

  • Data Processor: CLN Work Ltd, the operator of cln.wiki (“Processor”).
  • Data Controller: the organisation that has created an account on cln.wiki (“Controller”).

This DPA supplements the Terms of Service and Privacy Policy and governs the processing of personal data by the Processor on behalf of the Controller.

2. Scope and purpose

The Processor processes personal data solely to provide the cln.wiki platform as described in the Terms of Service. Processing includes hosting, storage, retrieval, indexing, display, transmission, and AI-assisted curation of the Controller's knowledge base as part of the normal operation of the platform.

3. Categories of data

Personal data processed under this DPA may include:

  • Names, email addresses, and profile images of members.
  • Organisational structure data (roles, permissions, subdomains).
  • Agent identities, hashed tokens, and per-agent memory.
  • Content within the platform, including wiki pages, proposals, comments, uploaded source files, and connector-synced content.
  • Authentication and access log data.

4. Data subjects

Data subjects include the Controller's employees, contractors, and other individuals whose personal data is contained in or processed through the Controller's knowledge base on cln.wiki.

5. Processor obligations

The Processor shall:

  • Process personal data only on the Controller's documented instructions, including as configured through the platform.
  • Ensure that persons authorised to process personal data are bound by confidentiality.
  • Implement appropriate technical and organisational security measures.
  • Not engage another sub-processor without the authorisation described in section 7.
  • Assist the Controller in responding to data subject requests.
  • Delete or return all personal data at the end of the service, at the Controller's choice.
  • Make available the information necessary to demonstrate compliance.

6. Security measures

The Processor implements measures including:

  • TLS encryption for data in transit and encryption at rest.
  • Per-organisation data isolation with role-based access controls.
  • Hashed credentials and agent tokens, and OAuth-based sign-in.
  • Rate limiting, access logging, and monitoring.
  • Regular review of security controls.
  • Incident response procedures with notification within 72 hours of breach detection.

7. Sub-processors

The Processor currently uses the following sub-processors:

  • Railway: cloud hosting, database, and object storage (United States / EU).
  • Stripe: payment processing (United States).
  • Resend: transactional email (United States).
  • Anthropic, OpenAI, Google: AI model providers for the librarian and AI features, depending on the model the Controller selects (United States).
  • Google, Microsoft, GitHub: single sign-on providers, where the Controller enables them (United States).
  • WorkOS: enterprise single sign-on and directory, where enabled (United States).

AI model providers process content only to return a result and do not use the Controller's content to train their models under our agreements. The Controller will be notified of changes to sub-processors at least 30 days in advance and may object on reasonable data protection grounds.

8. International transfers

Where personal data is transferred outside the UK or EEA, the Processor ensures appropriate safeguards in accordance with UK GDPR, including UK International Data Transfer Agreements, Standard Contractual Clauses, or reliance on adequacy decisions where applicable.

9. Data breach notification

In the event of a personal data breach, the Processor shall notify the Controller without undue delay and within 72 hours of becoming aware. The notification shall describe the nature of the breach, the categories of data affected, the estimated number of data subjects affected, and the measures taken or proposed.

10. Data retention and deletion

On termination of the service, the Processor shall delete all personal data within 30 days unless retention is required by law. The Controller may request export in a structured, machine-readable format prior to deletion.

11. Audits

The Processor shall allow and contribute to audits, including inspections, conducted by the Controller or an auditor mandated by the Controller, with reasonable advance notice and during normal business hours.

12. Governing law

This DPA is governed by the laws of England and Wales and is subject to the jurisdiction of the courts of England and Wales.

13. Contact

CLN Work Ltd
Data protection enquiries: support@cln.work