Privacy preferences

Choose optional measurement and messages separately. Service and purchase emails are unaffected. How measurement works

← Back to Clerva

Data Processing Agreement

Last updated: 9 September 2026

Privacy PolicyTerms of ServiceRefund PolicyData Processing Agreement

1. Parties and when this Agreement applies

This Data Processing Agreement (DPA) is between Onmo for Services LLC, operating the Clerva brand (Processor), and the business customer identified in a written services agreement that incorporates this DPA (Customer). It takes effect when that agreement is accepted by both parties and applies only to personal information processed on the Customer’s behalf for the agreed Clerva services.

A person buying their own Clerva report is ordinarily a data subject, not a Customer acting as controller under this DPA. Onmo’s processing for consumer accounts, its own billing, security, and legal obligations is described in the Privacy Policy. This DPA does not authorize third-party uploads or business access unless separately agreed in writing. To arrange an applicable agreement, contact privacy@clerva.cc.

2. Definitions and priority

Personal information, controller, processor, data subject, processing, and personal data breach have the meanings given by applicable data protection law. Applicable law includes Qatar’s personal data privacy law and, to the extent each applies to the processing, the GDPR, UK data protection law, Saudi PDPL, and other relevant privacy laws. A Subprocessor is a provider processing Customer personal information for Onmo.

The Customer is the controller, or a processor authorized by its controller to appoint Onmo. Written instructions include the services agreement and authorized written requests. This DPA controls over conflicting service terms on processing of Customer personal information; mandatory law and any applicable standard contractual clauses take priority. The processing schedule below forms part of this DPA.

3. Instructions and purpose limits

Onmo will process Customer personal information only on documented lawful instructions to provide, secure, and support the agreed service, including instructions about international transfers, unless required by law. Onmo will inform the Customer of a legal requirement before processing unless prohibited, and promptly flag an instruction it believes infringes applicable data protection law. The affected processing may be suspended until the issue is resolved.

Onmo will not sell the information, use it for advertising, combine it for unrelated purposes, or train general-purpose models on Customer photographs under this DPA. The Customer is responsible for lawful instructions, necessary notices and consents, and authorization to provide the data, including any additional basis or explicit consent required for sensitive information.

4. Confidentiality and security

Onmo will limit access to personnel who need it for the agreed work and are bound by confidentiality obligations. Safeguards will be appropriate to the sensitivity and risks of facial images and related information, and include access controls, encryption in transit and at rest for stored photos and reports, separation of customer data, protected credentials, logging, incident handling, and procedures for deletion and recovery.

Authorized reviewers may inspect photos and generated output for quality assurance. Security measures will be reviewed and maintained during processing. This DPA does not represent that Onmo holds a particular certification or promises an independent audit report that has not been obtained.

5. Subprocessors

The Customer gives general written authorization for the Subprocessors identified for its service in the agreed processing schedule. Before processing starts, Onmo will supply their legal identities, functions, and processing countries. Onmo will give at least 30 days’ advance written notice of intended additions or replacements, allowing the Customer to object on reasonable data protection grounds. If an objection cannot be resolved, the affected processing will not be transferred to that provider and either party may end the affected service with a refund of prepaid, unprovided service.

Onmo will impose written data protection obligations on each Subprocessor no less protective than those applicable to its processing under this DPA, and remains responsible to the Customer for the Subprocessor’s performance of those obligations. Advertising and analytics providers are not authorized to receive Customer photos, reports, or questionnaire information under this DPA.

6. International transfers

The parties will identify processing countries and any required transfer mechanism in writing before a restricted transfer begins. Onmo will not make a restricted transfer without the safeguards required by applicable law, such as applicable standard contractual clauses, a UK transfer instrument, or another permitted mechanism, together with any required assessment and supplementary measures. This published DPA alone does not execute or complete those instruments or establish local data residency.

7. Personal data breaches

Onmo will notify the Customer without undue delay after becoming aware of a personal data breach affecting Customer personal information. The notice will describe the known nature of the breach, affected information and individuals where ascertainable, likely consequences, containment and remedial steps, and a contact for follow-up. Incomplete information may be provided in phases without delaying the initial notice.

Onmo will take reasonable steps to contain, investigate, and remedy the breach, preserve relevant evidence, and assist the Customer with legally required notifications. Each party remains responsible for its own legal duties. Notification is not an admission of liability.

8. Rights requests, assessments, and audits

Taking account of the processing and information available, Onmo will assist the Customer with data subject requests, security obligations, breach notifications, impact assessments, and regulator consultations. Onmo will promptly forward relevant requests received directly and will not respond on the Customer’s behalf unless instructed or legally required.

Onmo will make available information necessary to demonstrate compliance and allow and contribute to audits, including inspections, by the Customer or an independent auditor it appoints. Reasonable confidentiality, security, notice, and scope arrangements may protect other customers and systems, but must not prevent audits required by law or a regulator. Onmo will cooperate with competent supervisory authorities.

9. Duration, return, and deletion

This DPA lasts for as long as Onmo processes Customer personal information under the services agreement. At the Customer’s choice, Onmo will return or delete the information after the service ends and delete existing copies unless law requires retention. Legally retained data will remain protected, used only for the required purpose, and deleted when the requirement ends. Backup copies will be isolated from ordinary use and deleted under the agreed retention schedule. Onmo will confirm completion on written request.

The Customer may require suspension of unlawful processing. A material breach that cannot be remedied permits termination of affected processing. Contractual liability provisions apply only to the extent lawful and cannot exclude statutory responsibilities or data subject rights. Qatar law and courts govern subject to applicable mandatory law and any controlling transfer clauses. Notices: privacy@clerva.cc for data protection and legal@onmo.ai for company legal matters; Customer notices go to its designated agreement contact.

Appendix A. Clerva processing schedule

Subject and purpose: the Clerva facial aesthetics analysis and optional visual services expressly ordered in the written business agreement. Operations: receipt, storage, photo preparation, measurement, AI analysis and image generation, authorized human review, report delivery, support, return, and deletion. Processing occurs for the agreed service duration and retention period.

Data subjects: adults aged 18 or over whose information the Customer is authorized to provide. Data: facial photos and derived measurements, demographic and preference inputs, relevant questionnaire answers, generated reports and images, and identifiers and support records needed for the agreed service. Sensitive information may include ancestry, health-related or religious inputs and, where legally classified as such, biometric information. Processing of these categories requires a documented lawful basis and appropriate safeguards agreed before submission.

Potential service providers: Cloudflare R2 (storage), Railway and Vercel (hosting), Google and Anthropic (AI), Modal (segmentation when used), Clerk (authentication where acting on instructions), and Resend (service messages). Only providers actually required and identified in the agreed schedule are authorized. Lemon Squeezy’s independent merchant-of-record processing falls under its own role and policies.

Before business processing begins, the parties must record the Customer’s legal identity and authorized contact, agreed services, actual Subprocessor legal names and countries, processing and retention periods, sensitive-data safeguards, and any required transfer instruments. Contact privacy@clerva.cc to complete that record; do not submit third-party data under an incomplete business arrangement.

Clerva is a brand owned and operated by Onmo for Services LLC.