Skip to content
Sections

Data Processing Agreement

Version 2026-10-05. The version you accepted when creating your channel is recorded with its date, and earlier versions are available on request.

This agreement describes how Claria processes personal data on behalf of your organization. It is part of the Terms & Conditions and applies from the moment you create your channel.

Parties and roles

Your organization is the data controller for the personal data in its channel: it decides why and how reports and the data of the people involved are used. The company that owns Claria, named in the Terms & Conditions, is the data processor: it handles that data only to provide the service and on your instructions.

For the data of your account, of your users as account holders and for billing, we act as controller under the Privacy Policy, not under this agreement.

On any matter about personal data, this agreement prevails over the Terms & Conditions.

Subject matter, duration and purpose

Subject matter: operating your alert and reporting channel, which means receiving reports, storing them, letting your team manage, investigate and answer them, exchanging messages with reporters, and exporting data. Purpose: only the purposes you define for your channel; we do not use the data for any other purpose.

Duration: as long as the agreement lasts, plus the export and deletion periods described below.

Data and people involved

Data: the content of reports and messages, dates, situation and category, attachments where enabled, identification details when a reporter chooses or is required to give them, and the data of the people a report mentions. Reports may contain sensitive data, such as data about health or sexual life, and data about alleged offences. You decide which data your portal asks for.

People involved: reporters, people a report refers to, witnesses, the members of your team and any other person mentioned in a report.

Our obligations

  • We process the data only on your documented instructions: this agreement, the Terms & Conditions and the settings you choose in your panel. If we believe an instruction breaks the law, we tell you.
  • We do not use the data for our own purposes, we do not sell it, and we do not share it with anyone other than the providers listed in this agreement and authorities when the law requires it.
  • The people we authorize to access the data are bound by confidentiality.
  • We apply the security measures described in this agreement and keep improving them.
  • We help you answer requests from the people whose data you process, assess risks and demonstrate how the data is handled.
  • At the end of the agreement we let you export the data and then delete it, as described below.

Your obligations

  • You confirm that you have a lawful basis to process the data in your channel and that you have informed the people involved as the law requires, including through a privacy notice in your portal.
  • You define your policies and settings, including whether a report can be anonymous, who in your team can access each case, the retention period and legal holds.
  • You answer requests from reporters and other people involved, and you decide on notifications to authorities and to affected people.
  • You keep your own obligations as controller; using Claria does not transfer them to us.

Security measures

Each organization has its own separate space; a report is tied to the organization that received it. Access to cases is limited by role and by assignment, and you control whether a second sign-in step is required. Tracking codes are stored only as a keyed hash. Our application does not keep device identifiers or connection data, and technical records contain only codes and opaque identifiers.

Design objectives being integrated into the product: protection of stored content with separate keys for each organization, an audit trail of actions, and controls that restrict and log any exceptional access by our operators. We inform you when each of them is in force. No system is risk-free, and these measures are not a promise of a result.

On request we give you a description of the measures in force at that time.

Providers (sub-processors)

You authorize us to use the providers listed in the annex below for the tasks indicated. Each provider is bound by a contract with data protection obligations, and we remain responsible to you for what they do.

Before adding or replacing a provider that will process your data, we notify you at least 30 days in advance by email or in the panel. If you have reasonable grounds to object, tell us within that period; if we cannot offer an alternative, you may end the agreement, export your data and receive a refund of any prepaid period not used.

Where data is processed

The application and the database run in a region in São Paulo, Brazil. Attachments, where enabled, are stored outside South America. Email, payment and sign-in providers process data in other countries. When data is processed outside your country, we rely on the providers' data processing terms and on the safeguards the law that applies to you requires, and we give you the information you need to document the transfer.

Help with requests and assessments

If a reporter or another person sends us a request about their data, we forward it to you and do not answer on your behalf. We give you the tools and the information you need to answer: case data, messages through the tracking page for reporters who do not identify themselves, and exports.

We also help you with risk and impact assessments and with requests from authorities, with the information we have about the service.

Security incidents

If we become aware of an incident that affects the personal data in your channel, we inform you without undue delay. Our internal objective is an initial notice within 24 hours of becoming aware, with what we know at that time: what happened, which data may be affected, what we have done, what we recommend and when we will update you. This objective is a commitment of ours, not a legal deadline.

You decide whether and how to notify authorities and affected people, and we cooperate with you.

Audits and evidence

On request, we give you the information needed to show how the data is handled, including descriptions of measures and summaries of independent assessments when they exist. Once every 12 months, with 30 days' notice and at your cost, you or an independent auditor bound by confidentiality may verify this remotely or at our premises, without disrupting the service or accessing other organizations' data. After an incident, or if an authority requires it, you may request an additional review.

Retention, export and deletion

While the agreement lasts, you decide the retention period for closed cases, you can place a legal hold on a case so it is not deleted, and every deletion is recorded. Deletion runs only when you have configured a period; there is no automatic deletion by default.

When the agreement ends, you have 30 days to export your data. After that period we delete the data from active systems within 90 days, and copies kept for recovery expire within a further 30 days. We keep only what the law obliges us to keep. On request we confirm the deletion in writing.

Liability, changes and term

Liability is governed by the Terms & Conditions. We may update this agreement with at least 30 days' notice; changes do not reduce the protection described here without your consent. This agreement lasts as long as the Terms & Conditions, and the deletion obligations survive its end.

Annex: processing summary

  • Subject matter: operating your alert and reporting channel.
  • Nature: receiving, storing, displaying, organizing, exchanging messages, exporting and deleting.
  • Purpose: the purposes you define for your channel; none of our own.
  • Data: report content and messages; situation, dates and status; attachments where enabled; identification details when given; data of people mentioned. May include sensitive data and data about alleged offences.
  • People involved: reporters, people referred to, witnesses, your team and other people mentioned.
  • Duration: the life of the agreement plus the export and deletion periods.

Annex: providers

List at the date of this version. Each provider processes data only for the task indicated. Payment and sign-in providers also handle, under their own terms, the data you enter directly with them.

  • Vercel: application hosting and execution, in a region in São Paulo, Brazil, with a global content delivery network and short-lived platform logs.
  • Neon: database, in a region in São Paulo, Brazil.
  • Cloudflare: domain name services and bot protection; file storage for attachments where enabled, outside South America.
  • Resend: transactional email (sign-in links, invitations and notices), with no open or click tracking.
  • Mercado Pago: subscription payments for organizations billed in Chile.
  • Paddle: payments for organizations billed outside Chile, as seller of record, if enabled.
  • Google and Microsoft: sign-in with an existing account, only if your organization enables it.