Back to home

Data Processing Agreement

DPA — GDPR Article 28Effective date: March 2026

This Data Processing Agreement ("DPA") forms part of the Terms of Service between the Client (Controller) and CLARK MEDIA (Processor) and governs the processing of personal data in connection with the Justera platform, in compliance with GDPR Article 28.

1. Parties

Controller: The company or individual registered as a client on the Justera platform (hereinafter: "Client" or "Controller").
Processor: CLARK MEDIA, ul. Mazowiecka 58-62, 87-100 Toruń, Poland, VAT: PL8792694429, REGON: 387964063 (hereinafter: "CLARK MEDIA" or "Processor").

2. Subject Matter and Duration

  • Subject matter: Processing of personal data in connection with the provision of the Justera transport dispute management and legal document generation SaaS platform.
  • Duration: This DPA is in force for the duration of the subscription agreement and terminates automatically upon account closure or termination of the Terms of Service.
  • Nature of processing: Collection, storage, organisation, structuring, use, disclosure by transmission, erasure, or destruction of personal data as required to provide the Justera services.
  • Purpose: Providing dispute management, document generation, compliance monitoring, and legal workflow automation services.

3. Categories of Personal Data

The following categories of personal data may be processed:

  • Contact data: names, email addresses, phone numbers, job titles of company representatives and contact persons.
  • Company data: legal entity name, registered address, VAT number, REGON, court registration number.
  • Dispute-related data: names of parties to transport disputes, driver details, counterparty information, addresses.
  • Document data: personal data contained in uploaded contracts, CMR documents, invoices, delivery notes.
  • Account data: login credentials (hashed passwords), account activity logs, session data.
  • Payment data: limited billing information processed by Stripe (CLARK MEDIA does not store card numbers).

4. Categories of Data Subjects

  • Representatives and employees of the Client company.
  • Counterparties to transport disputes (carriers, shippers, recipients).
  • Third parties named in uploaded documents (drivers, consignees, agents).
  • Lawyers and legal professionals using the Justera marketplace.

5. Obligations of the Processor

GDPR Article 28 Compliance

CLARK MEDIA, as Processor, commits to the following obligations in accordance with GDPR Article 28(3).

  • Process personal data only on documented instructions from the Controller (the Client), unless required to do so by Union or Member State law.
  • Ensure that persons authorised to process personal data have committed themselves to confidentiality or are under an appropriate statutory obligation of confidentiality.
  • Implement appropriate technical and organisational measures (TOMs) to ensure a level of security appropriate to the risk, in accordance with GDPR Article 32.
  • Not engage sub-processors without prior specific or general written authorisation of the Controller. A list of current sub-processors is provided in Section 8.
  • Assist the Controller in fulfilling obligations to respond to requests by data subjects exercising their rights under Chapter III of GDPR.
  • Assist the Controller in ensuring compliance with GDPR Articles 32–36 (security, breach notification, DPIA, prior consultation).
  • At the choice of the Controller, delete or return all personal data to the Controller after the end of provision of services, and delete existing copies unless Union or Member State law requires storage.
  • Make available to the Controller all information necessary to demonstrate compliance with Article 28, and allow for and contribute to audits and inspections.

6. Technical and Organisational Measures

  • Encryption of personal data in transit (TLS 1.3) and at rest (AES-256).
  • Access controls: role-based access control (RBAC) limiting data access to authorised personnel only.
  • Pseudonymisation: where technically feasible, personal data is pseudonymised for AI processing.
  • Audit logging: all access to personal data is logged with timestamps and user identifiers.
  • Regular penetration testing and security assessments of the platform.
  • Incident response plan: CLARK MEDIA maintains a documented procedure for detecting, reporting, and investigating personal data breaches.
  • All employees with access to personal data receive regular data protection training.

7. International Transfers

  • Personal data is stored and processed primarily within the EU/EEA on OVH infrastructure located in France and Poland.
  • Where sub-processors involve transfers outside the EU/EEA, CLARK MEDIA ensures adequate safeguards are in place, including Standard Contractual Clauses (SCCs) approved by the European Commission.
  • Anthropic (Claude API, USA): Standard Contractual Clauses applied. Data Processing Agreement in place. No data used for model training.
  • Stripe (payment processing, USA): Standard Contractual Clauses applied. Stripe is certified under appropriate transfer mechanisms.
  • Resend (transactional email, USA): Standard Contractual Clauses applied.

8. Sub-processors

CLARK MEDIA uses the following sub-processors in connection with the Justera platform:

NameLocation / RegionPurpose
OVH SASFrance / EUServer hosting and infrastructure
PostgreSQL / SupabaseEUDatabase storage
Anthropic PBCUSA (SCCs applied)AI language model for document generation
Stripe Inc.USA (SCCs applied)Payment processing
Resend Inc.USA (SCCs applied)Transactional email delivery
Google LLCUSA (SCCs applied)Analytics (only with user consent)

9. Data Subject Rights Assistance

  • CLARK MEDIA will promptly notify the Controller of any data subject request received and will assist the Controller in responding within the statutory timeframe (1 month under GDPR Article 12).
  • Supported rights: access (Art. 15), rectification (Art. 16), erasure (Art. 17), restriction (Art. 18), portability (Art. 20), objection (Art. 21).
  • Data subject requests can be submitted to privacy@justera.eu.

10. Data Breach Notification

  • CLARK MEDIA will notify the Controller without undue delay, and no later than 48 hours after becoming aware of a personal data breach likely to result in risk to data subjects.
  • Notification will include: nature of the breach, categories and approximate number of data subjects concerned, likely consequences, measures taken or proposed.
  • CLARK MEDIA will cooperate fully with the Controller in fulfilling the Controller's notification obligations to supervisory authorities (72-hour deadline under GDPR Article 33) and data subjects (Article 34).

11. Return and Deletion of Data

  • Upon termination of the agreement, CLARK MEDIA will, at the Controller's choice, securely delete or return all personal data within 30 days.
  • Backup copies will be deleted within 90 days of termination.
  • CLARK MEDIA will provide written confirmation of deletion upon request.
  • Data required to be retained under applicable law (e.g., accounting records, tax records) will be retained only for the legally required period and then deleted.

Contact

For DPA-related queries, data subject requests, or to exercise your rights:

CLARK MEDIA

ul. Mazowiecka 58-62, 87-100 Toruń, Poland

NIP: PL8792694429 | REGON: 387964063

Email: privacy@justera.eu

See also: Privacy Policy · Terms of Service

© 2026 CLARK MEDIA. All rights reserved.Back to platform