Part of the Terms on every plan: how Clemali processes the personal data it handles for your company, under Article 28 of the GDPR. Last updated September 2026.
This agreement is part of the Terms of service between the company that uses Clemali, which is the controller, and Clemali which is its processor. It applies on every plan to the personal data Clemali processes on the company's behalf: what its connected sources, its document index and its conversations contain. For the accounts of its people, billing and the website, Clemali is the controller, as the privacy policy describes. Where this agreement and the Terms differ on personal data, this agreement prevails.
Clemali processes this data only on the company's documented instructions: the Terms, this agreement and the settings its admins choose in the console (sources, folders, access, retention). Where EU or French law requires otherwise, Clemali tells the company first, unless that law forbids it. Clemali tells the company when it believes an instruction infringes data protection law.
The people at Clemali who can reach this data are bound by confidentiality. They do not read customer content except to investigate a security incident or at the company's request. Staff screens show counts, not the text of indexed documents; staff sign in with two-factor authentication, and their actions on a company are recorded.
Clemali keeps the measures described on the security page, among them:
The company authorizes Clemali to use the sub-processors listed on the sub-processors page, each bound by data protection terms as a processor. Clemali emails the owners of every company at least 30 days before adding or replacing one. The company may object during that time, in writing to [email protected]; if Clemali cannot meet the objection, the company may cancel before the change takes effect. Some sub-processors may process data outside the EU, as the list shows: those transfers rely on an adequacy decision of the European Commission, including the EU-US Data Privacy Framework for certified providers, or on the Commission's standard contractual clauses. Clemali remains responsible to the company for its sub-processors.
The company ends the service by deleting its assistants, or by removing its members and deleting the last account, which deletes the company and cancels its subscription at once. At its choice, Clemali deletes its data or, on a request to [email protected] before the end, returns its conversations and settings in a machine-readable format; the documents themselves stay in the company's own sources, which Clemali only reads. Deletion follows these times, unless EU or French law requires Clemali to keep something longer:
Clemali makes available the information needed to show that it meets its obligations under Article 28 of the GDPR: this agreement, the sub-processors list, the security page and answers to the company's questions. It allows and contributes to audits by the company, or by an auditor it mandates who is bound by confidentiality, on 30 days' notice and at most once a year, unless a breach or an authority requires otherwise.
This agreement exists in French and in English; if they differ, the French version prevails.
With your consent, Google Analytics counts the pages you visit on this site, and the support chat loads with the page. Refusing changes nothing else: the chat still opens when you click it. You can change your choice at any time from Cookies, at the bottom of every page. Privacy policy