Effective Date: February 5, 2026
This Data Processing Agreement ("DPA") forms part of the Terms of Service between Evostera LLC dba Klyverity ("Klyverity," "we," "us," or "our") and the Customer ("you" or "Customer"). This DPA governs the processing of personal data by Klyverity on behalf of the Customer in connection with the provision of Klyverity's electronic signature and document management services (the "Services").
For the purposes of this DPA:
Processing of personal data in connection with Klyverity's electronic signature and document management services.
For the term of the Service Agreement between Klyverity and Customer.
Electronic signature capture, document management, audit trail maintenance, and user authentication.
To enable Customer to obtain compliant electronic signatures for regulated industries, including clinical research and healthcare.
Klyverity agrees to:
Customer agrees to:
Customer grants Klyverity general authorization to engage Subprocessors to process Personal Data on Customer's behalf. Klyverity maintains a current list of Subprocessors at klyverity.com/subprocessors.
Klyverity will provide Customer with at least 30 days' advance notice before adding or replacing any Subprocessor. Customer may object to the engagement of a new Subprocessor within 30 days of such notice on reasonable grounds relating to data protection. If Customer objects and the parties cannot resolve the objection within a reasonable timeframe, Customer may terminate the affected Services.
Klyverity ensures that all Subprocessors are bound by written agreements that require them to provide at least the same level of data protection as required by this DPA.
Personal Data processed under this DPA is stored and processed in the United States. Where Personal Data is transferred from the European Economic Area, the United Kingdom, or Switzerland to countries that do not provide an adequate level of data protection, such transfers will be governed by Standard Contractual Clauses or other appropriate transfer mechanisms as required by applicable data protection law.
Klyverity will cooperate with Customer to implement appropriate transfer mechanisms and provide such information and assistance as Customer may reasonably require to ensure compliant international data transfers.
Klyverity has implemented and will maintain appropriate technical and organizational measures to protect Personal Data against accidental or unlawful destruction, loss, alteration, unauthorized disclosure, or access. These measures include:
Klyverity will regularly review and update these security measures to maintain appropriate protection for Personal Data.
In the event of a personal data breach affecting Customer's Personal Data, Klyverity will notify Customer without unreasonable delay and in no event later than 72 hours after becoming aware of the breach.
The notification will include, to the extent available:
Klyverity will cooperate with Customer in investigating the breach and will provide reasonable assistance in Customer's breach response efforts, including any required notifications to supervisory authorities or Data Subjects.
Klyverity will assist Customer in fulfilling its obligations to respond to requests from Data Subjects exercising their rights under applicable data protection law, including rights of access, rectification, erasure, restriction of processing, data portability, and objection.
Customer may export Personal Data via the Service interface at any time. If Klyverity receives a request directly from a Data Subject, Klyverity will redirect the Data Subject to Customer and will not respond to the request without Customer's prior written authorization.
Customer is responsible for responding to Data Subject requests in accordance with applicable data protection law. Klyverity will provide reasonable assistance to Customer in fulfilling such requests, and Customer will reimburse Klyverity for any costs associated with providing such assistance beyond Klyverity's standard obligations under this DPA.
Customer may audit Klyverity's compliance with this DPA once per year, upon providing at least 30 days' written notice to Klyverity. Audits will be conducted during normal business hours and will be designed to minimize disruption to Klyverity's operations.
Upon reasonable request, Klyverity will provide Customer with completed security questionnaires, Klyverity's system validation documentation (IQ/OQ/PQ protocols and executed reports), and the SOC 2 Type II and ISO 27001 reports published by its infrastructure provider, Amazon Web Services, to demonstrate compliance with this DPA. Klyverity does not itself hold a SOC 2 attestation; the SOC 2 Type II coverage described in this DPA is that of the underlying AWS infrastructure. Such reports and questionnaires are confidential and subject to the confidentiality provisions of the Service Agreement.
Customer is responsible for all costs associated with any audit, including any fees charged by Klyverity for time and materials required to support the audit. Klyverity reserves the right to charge reasonable fees for audit support beyond providing standard compliance documentation.
This DPA is effective as of the date Customer first accesses or uses the Services and will remain in effect for the duration of the Service Agreement between Klyverity and Customer.
Upon termination or expiration of the Service Agreement, Personal Data is retained. Klyverity does not delete it automatically and does not delete it on a fixed schedule. Customer may export Personal Data from the Services. Klyverity will delete Personal Data on Customer's documented request, except to the extent that Klyverity is required by applicable law or by regulatory record retention obligations to retain it. Deletion is carried out manually, and this DPA does not commit Klyverity to a fixed period for completing it.
Klyverity will certify in writing to Customer that it has complied with its obligations under this section, subject to any legal retention requirements.
Each party's liability arising out of or related to this DPA, whether in contract, tort, or under any other theory of liability, is subject to the limitations and exclusions of liability set forth in the Terms of Service between Klyverity and Customer.
Nothing in this DPA limits or excludes either party's liability for matters that cannot be limited or excluded under applicable law.
This section applies to Processing of Personal Data governed by the State Privacy Laws, and is in addition to the obligations set out elsewhere in this DPA. For the purposes of this section, the terms business, commercial purpose, contractor, processor, sell, service provider and share have the meanings given to them in the applicable State Privacy Laws, and personal information means Personal Data to the extent it is governed by those laws.
The parties intend that, with respect to personal information, Customer acts as the business or controller and Klyverity acts as a service provider, contractor, or processor, as applicable. Klyverity receives personal information from Customer solely to perform the Services described in the Terms of Service and for no other purpose.
Klyverity will not:
Klyverity certifies that it understands the restrictions in this section and will comply with them.
Klyverity will provide the same level of privacy protection to personal information as the State Privacy Laws require of Customer, and will comply with the obligations those laws place on a service provider, contractor, or processor. Klyverity will notify Customer in writing if it determines that it can no longer meet those obligations.
Customer may take reasonable and appropriate steps to confirm that Klyverity's Processing of personal information is consistent with Customer's own obligations under the State Privacy Laws, and, on reasonable notice, to stop and remediate any unauthorized use of personal information. The audit rights in Section 11 are available for this purpose, and the Subprocessor notice and objection process in Section 6 satisfies Klyverity's obligation under the State Privacy Laws to give notice of, and an opportunity to object to, Subprocessor engagements.
Nothing in this section limits Customer's rights or Klyverity's obligations under the remainder of this DPA. Where the State Privacy Laws and the GDPR both apply to the same Processing, the provision affording the Data Subject greater protection controls.
Klyverity will not use Personal Data to train, fine-tune, develop, evaluate, or improve any artificial intelligence or machine learning model, whether Klyverity's own or a third party's, unless the use is reasonably necessary to provide the Services in accordance with Customer's documented instructions, or Customer has authorized it in writing.
Klyverity will not disclose Personal Data to any third-party provider of artificial intelligence or machine learning services except as a Subprocessor engaged under Section 6, and any such Subprocessor is contractually bound by the restriction in this section.
The Services do not carry out automated decision-making, including profiling, that produces legal effects concerning a Data Subject or similarly significantly affects a Data Subject. Signature workflow routing, reminders, and audit trail generation are deterministic functions of the configuration Customer supplies and are not automated decision-making for this purpose.
For questions or concerns regarding this Data Processing Agreement, please contact us at:
Email: privacy@klyverity.com
Mailing Address:
Evostera LLC dba Klyverity
1519 E Chapman Ave. #278
Fullerton, CA 92831
This Data Processing Agreement was last updated on August 26, 2026.