Data Processing Agreement
This agreement governs how Cladior processes personal data on behalf of developers who integrate the Cladior SDK. Last updated: June 2026.
Definitions
Controller means the Developer: the person or entity that determines the purposes and means of processing personal data of their end users.
Processor means Cladior: the entity that processes personal data on behalf of the Controller by operating the SDK proxy and billing infrastructure.
Data Subject means a User: any natural person whose data is processed when they authenticate with Cladior and use a developer-registered app.
Personal Data means any information relating to an identified or identifiable natural person. In the context of the Cladior SDK, this includes a user's email address, opaque user ID, and session records.
Sub-processor means any third party engaged by Cladior to process personal data in connection with operating the SDK.
Scope and purpose
This agreement applies where a developer integrates the Cladior SDK into their product. By doing so, the developer instructs Cladior to process personal data on their behalf for the following limited purpose: authenticating data subjects, metering API usage at the kilobyte level, and debiting the data subject's wallet accordingly.
Cladior shall process personal data only on documented instructions from the developer. Cladior shall not process personal data for any other purpose, including advertising, profiling, or sale to third parties.
The categories of personal data processed are: email address (at account creation and authentication), opaque user ID (a non-reversible identifier), kilobyte-level usage counts per session, session timestamps, and wallet transaction records. No request or response content is stored.
Developer obligations
The developer, as Controller, is responsible for ensuring there is a lawful basis for transmitting personal data to Cladior for processing. This includes obtaining informed consent from data subjects prior to integrating the SDK, or otherwise relying on a lawful basis under the Nigerian Data Protection Regulation (NDPR), GDPR, or applicable local law.
The developer shall inform data subjects of the use of Cladior in a manner consistent with applicable privacy law. Developers are encouraged to reference this agreement and the Cladior Privacy Policy in their own privacy documentation.
The developer shall not use the SDK in a manner that causes Cladior to process personal data for unlawful purposes or in contravention of any applicable data protection law.
Cladior obligations
Cladior shall implement and maintain technical and organisational measures appropriate to the risk of processing. These include: TLS encryption for data in transit, row-level security on all database tables containing personal data, access controls on a need-to-know basis, and logging of access to production systems.
Cladior shall not engage sub-processors without prior notification to developers. Cladior imposes data protection obligations on all sub-processors equivalent to those set out in this agreement.
In the event of a personal data breach affecting data processed under this agreement, Cladior shall notify the developer by email to the registered developer account address within 72 hours of becoming aware of the breach.
Sub-processors
Cladior currently relies on the following sub-processors:
| Sub-processor | Location | Role |
|---|---|---|
| Supabase, Inc. | United States | Database hosting and auth infrastructure. Stores email addresses, user IDs, session records, wallet transactions. |
| Cloudflare, Inc. | United States | Edge network and CDN. IP addresses pass through but are not stored beyond 24-hour edge log retention. |
| Flutterwave Technology Solutions | Nigeria | Payment processing for wallet top-ups and developer payouts. Receives email address and, for payouts, developer payment details. |
Cladior will provide developers with at least 14 days notice before engaging a new sub-processor. If a developer objects on reasonable data protection grounds, they may terminate use of the platform within the notice period without penalty.
International data transfers
Personal data may be transferred to and processed in the United States by Supabase and Cloudflare. These transfers are made on the basis of standard contractual clauses or equivalent transfer mechanisms where required by applicable law.
Retention and deletion
Session records are retained for 12 months then deleted. Wallet transaction records are retained for 7 years as required by Nigerian financial record-keeping law. Email addresses and user IDs are retained for as long as an account is active.
Upon account deletion, Cladior will delete or anonymise all personal data within 30 days, except where retention is required by law. Developers may request deletion of all data associated with their apps by contacting privacy@cladior.com.
Audit rights
Cladior shall make available all information necessary to demonstrate compliance with this agreement, and shall allow for audits by the developer or a mandated auditor, provided they are conducted with reasonable notice, no more than once per year, at the developer's expense, and without unreasonably disrupting Cladior's operations.
Term and termination
This agreement is effective from the date the developer first integrates the SDK and remains in force for the duration of their use of the platform. Upon termination, Cladior shall return or delete all personal data processed under this agreement within 30 days, except where retention is required by law.
Governing law
This agreement is governed by the laws of the Federal Republic of Nigeria. Where the developer operates in the European Economic Area and is subject to GDPR, the provisions of this agreement shall be interpreted to meet the requirements of GDPR Article 28.
Questions: privacy@cladior.com