Clikta
Legal

Data Processing Agreement

Last updated: 13 June 2026

This Data Processing Agreement ("DPA") supplements the Clikta Terms of Service and governs the processing of personal data by Clikta on behalf of its business customers, as required by GDPR Article 28.

Need a signed DPA? Email us at [email protected] with your company details and we will provide a signed DPA within 5 business days.

1. Definitions

"Controller" means you, the business customer that has entered into a subscription agreement with Clikta.

"Processor" means Clikta, Lda., Lisbon, Portugal.

"Personal Data" means any information as defined in GDPR Article 4(1) that the Controller submits to the Service.

"GDPR" means Regulation (EU) 2016/679 of the European Parliament and of the Council.

2. Subject matter and duration

This DPA governs the processing of Personal Data by Clikta as a Processor on behalf of the Controller for the purpose of providing the Clikta platform and related services. The DPA is in effect for the duration of the subscription agreement and terminates automatically upon its expiry or termination.

3. Nature and purpose of processing

Clikta processes Personal Data to:

  • Store and process recordings, screenshots, and documentation created by Controller's users
  • Generate AI-based guides, interactive demos, and narrated videos from Controller's recordings
  • Host and serve published demos via shareable public links
  • Provide analytics on demo viewing statistics
  • Send transactional emails on behalf of Controller's workspace

4. Categories of data subjects and data

Data subjects may include:

  • The Controller's employees, contractors, and agents (who create recordings)
  • End users of the Controller's products (who view published demos)

Categories of Personal Data processed: names, email addresses, authentication credentials, IP addresses (of demo viewers), and any personal data incidentally captured in screen recordings.

5. Processor obligations (Clikta)

Clikta shall:

  • Process Personal Data only on documented instructions from the Controller (including those set out in the Terms of Service), unless required to do so by EU or Portuguese law
  • Ensure that persons authorised to process Personal Data have committed themselves to confidentiality
  • Implement appropriate technical and organisational security measures as described in Art. 32 GDPR
  • Assist the Controller in responding to data subject rights requests within the timeframes required by GDPR
  • Delete or return all Personal Data to the Controller upon termination of the DPA, and delete existing copies within 90 days
  • Make available to the Controller all information necessary to demonstrate compliance with this DPA
  • Notify the Controller without undue delay after becoming aware of a personal data breach

6. Sub-processors

Clikta uses the following sub-processors. The Controller provides general written authorisation for their use:

Sub-processorPurposeLocation
Hetzner Online GmbHInfrastructure and database hostingGermany, EU
Resend, Inc.Transactional emailEU region under SCCs
Stripe, Inc.Payment processingEU region under SCCs

Clikta will notify the Controller of any intended changes to sub-processors, giving the Controller opportunity to object within 10 business days.

7. International transfers

Clikta stores all Personal Data within the European Union. Any transfers to sub-processors outside the EU/EEA (e.g. for email delivery) are protected by Standard Contractual Clauses (SCCs) approved by the European Commission.

8. Security measures

Clikta maintains the following technical and organisational measures:

  • TLS 1.2+ encryption for all data in transit
  • AES-256 encryption for data at rest
  • Bcrypt hashing for all passwords (12 rounds)
  • Role-based access control with principle of least privilege
  • Regular automated security scans
  • Access logs and audit trails
  • Intrusion detection monitoring

9. Audit rights

The Controller may audit Clikta's compliance with this DPA once per year on 30 days' written notice, or at any time in the event of a personal data breach. Audits shall be conducted at the Controller's expense and during normal business hours without unreasonably disrupting Clikta's operations.

10. Contact

For DPA requests, privacy queries, or data subject assistance: [email protected]
Clikta, Lda. · Lisbon, Portugal