
Clientify is an EU-based Customer Relationship Management (CRM) platform providing marketing automation, sales processes, and customer communication tools with ISO/IEC 27001:2022 certification. Headquarters in Spain with independently reviewed Comply.org Trust Center featuring verified data protection principles and comprehensive Information Security Management System certified by Bureau Veritas.
Independent legal assessment conducted by CIPP/E certified attorney validating data protection principles, DPA compliance, data processing activities, breach notification obligations, data subject request handling, and regulatory alignment with privacy frameworks.
Independent legal assessment by CIPP/E certified attorney (IE4322) validating data protection principles (Data Minimization, Accountability, Security, Individual Participation, Purpose Limitation, Storage Limitation), DPA compliance, data processing activities, and regulatory alignment with GDPR and EU privacy frameworks. Latest review: August 2024.
Independent technical assessment conducted by CIPT certified privacy engineer validating security measures, technical controls, architecture security, subprocessor management, auditing capabilities, and implementation of security best practices across infrastructure and operations.
Independent technical assessment by CIPT certified privacy engineer (PE4951) validating security measures, technical controls, infrastructure security, subprocessor management (13 vendors), auditing capabilities, and implementation of security best practices aligned with ISO 27001 requirements. Latest review: August 2024.
Third-party audited certification validating comprehensive information security management system implementation with annual surveillance audits and 3-year recertification, covering 114 security controls across organizational security, human resources, operations, and access management domains.
ISO/IEC 27001:2022 certification by Bureau Veritas covering Information Security Management System supporting development, support, maintenance, and hosting of digital marketing platform. Original approval March 2021, current certificate valid July 2025 through March 2027. Demonstrates systematic approach to managing sensitive information security.
Governance framework establishing data lifecycle management procedures including collection, storage, processing, sharing, retention, and secure disposal with data classification standards, quality controls, and privacy protection measures.
Governance framework for data lifecycle management including collection, storage, processing, sharing, retention, and disposal. Implements Data Quality and Data Minimization principles verified through Comply.org review with classification standards and privacy protection measures aligned with ISO 27001.
Executive-approved security framework establishing incident detection, analysis, containment, eradication, and recovery procedures with defined roles, communication protocols, and post-incident review processes for effective security incident management.
Established procedures for handling data subject requests including access, rectification, erasure, portability, and objection rights. Defines response timelines, verification processes, and escalation procedures for GDPR compliance with Individual Participation principles required by ISO 27001.
Executive-approved governance framework establishing security objectives, risk management approach, and mandatory controls for data protection, access management, incident response, and security awareness across all organizational functions and personnel.
Executive-approved SGSI Information Security Policy (SGSI-PSI-01) establishing security objectives, risk management approach, and mandatory controls verified through Comply.org review and ISO 27001:2022 certification. Covers Security core principle validation including access controls, incident response, and security awareness aligned with certification scope.
Comprehensive privacy policy outlining data collection, processing, storage, and sharing practices, user rights, and privacy safeguards to ensure transparent and compliant data handling practices.
Privacy policy outlining data collection practices for CRM operations, marketing automation, and customer communications. Emphasizes GDPR compliance with Transparency principle implementation. EU-based processing with Spanish headquarters ensuring adherence to European data protection standards.
Organizational policy establishing framework for identifying, assessing, and managing security risks across all business operations, defining risk tolerance levels and mitigation strategies to protect organizational assets and objectives.
Organizational policy for identifying, assessing, and managing security risks across CRM operations and customer data processing. Supports Accountability principle verified through Comply.org review with defined risk tolerance levels and mitigation strategies required by ISO 27001 certification.
Formal process for notifying affected parties and authorities in the event of a data breach, including notification timelines, content requirements, and regulatory compliance procedures for breach response.
Documented obligations and procedures for notifying data breaches to supervisory authorities and affected data subjects. Includes incident response timelines, breach assessment criteria, and communication protocols aligned with GDPR Article 33/34 requirements verified through DPA analysis.
Legal agreement establishing data processing terms, responsibilities, and safeguards between data controller and processor, ensuring compliance with data protection regulations and defining data handling requirements.
Comprehensive Data Processing Agreement (DPA) covering data processing activities, data types and categories, processor responsibilities, and controller-processor relationship. Establishes legal framework for GDPR compliance with documented safeguards. Publicly available for review with downloadable PDF version.
Designated data protection officer (DPO) responsible for overseeing data protection compliance, providing privacy guidance, and serving as a point of contact for data protection matters and regulatory inquiries.
Data Protection Officer (DPO) designated for privacy compliance oversight and data subject inquiries. Contact: dpo@clientify.com. Headquarters: Almeria, Spain (EU jurisdiction). Supports GDPR data subject rights including access, rectification, erasure, and objection with documented response procedures.
Configurable data retention policies enabling organizations to control data lifecycle, including zero data retention options for compliance requirements and data sovereignty needs.
Data retention policies aligned with storage limitation principle ensuring data is kept only as necessary for CRM and marketing automation purposes. Implements retention schedules, deletion procedures, and regular data lifecycle reviews verified through Comply.org review for compliance with GDPR and ISO 27001.
Regular systematic evaluations of potential threats and vulnerabilities that could impact organizational objectives, including asset identification, threat analysis, vulnerability assessment, impact analysis, and risk treatment recommendations with documented methodology and review processes.
Regular systematic evaluations of potential threats and vulnerabilities including asset identification, threat analysis, and impact analysis required by ISO 27001. Supports Accountability principle and Auditing Options from Comply.org review with documented methodology and annual certification audits.
Mandatory employee education program covering cybersecurity best practices, threat recognition, and incident reporting, required within 30 days of hire and annually thereafter to maintain security-conscious workforce.
Employee security training program covering cybersecurity best practices, data privacy, and incident reporting. Supports Security principle verified through Comply.org technical review with training requirements mandated by ISO 27001:2022 certification for maintaining security-conscious workforce.
Comprehensive supply chain risk management program including security controls governing third-party relationships, vendor security assessments, and ongoing monitoring of external parties to ensure security posture compliance.
Comprehensive supply chain risk management program governing relationships with payment processors (GoCardless, PayPal, Stripe), analytics providers (Google Analytics), communication tools (Intercom), and infrastructure providers (AWS, Digital Ocean). Supports Subprocessors management validation from Comply.org technical review.
Formal contractual agreements with external vendors, suppliers, and service providers that include security requirements, data protection clauses, compliance obligations, and accountability measures to ensure comprehensive third-party risk management and governance.
Formal contractual agreements with 13 external vendors and service providers including security requirements, data protection clauses, and compliance obligations. Supports Subprocessors and Data Transfers verification from Comply.org DPA analysis with comprehensive third-party governance.
Formal vulnerability management process including regular vulnerability assessments, patch management with documented SLAs, vulnerability prioritization and remediation based on severity levels, and continuous monitoring of security vulnerabilities.
Formal vulnerability management process with regular assessments, patch management, and remediation procedures. Supports Security Measures verification from Comply.org technical review with continuous monitoring required by ISO 27001 Information Security Management System certification.
Primary cloud infrastructure provider hosting all application services, databases, and data storage. Critical infrastructure supporting 99.99% uptime requirements with global data residency controls.
Cloud infrastructure provider for hosting CRM platform services. Provides compute, storage, and database services verified through Comply.org subprocessor review. Part of ISO 27001 certified infrastructure with documented security controls and data processing agreements.
Website and application analytics tracking user interactions, page views, and conversion events. Collects behavioral data for marketing optimization and product improvement insights.
Analytics platform for website and application usage tracking. Collects behavioral data for product improvement insights. Managed under supply chain risk management program verified through Comply.org technical review with GDPR compliance measures.
Customer communication platform managing live chat, support tickets, and user messaging. Processes customer conversations, support interactions, and user engagement data for customer success operations.
Customer communication and support platform. Processes customer interaction data for support and engagement purposes. EU and US operations with appropriate data transfer mechanisms verified through Comply.org subprocessor analysis.
Email delivery infrastructure handling transactional and marketing emails. Processes email content, recipient data, and delivery analytics for customer communication and marketing campaigns.
Email delivery service for transactional and marketing emails. Processes email addresses and communication content under data processing agreements verified through Comply.org review with Standard Contractual Clauses for international transfers.
Payment processing infrastructure handling credit card transactions, subscription billing, and financial data. Processes sensitive payment information including card details, billing addresses, and transaction metadata.
Payment processing service for subscription billing and transactions. Handles payment card data under PCI DSS compliance. Documented in Comply.org subprocessor review with appropriate security and privacy safeguards for financial data.
Payment processing infrastructure handling online payments, digital wallet transactions, and financial data. Processes sensitive payment information including account details and transaction metadata.
Alternative payment processing service for transactions. Processes payment information under PayPal's data protection framework. Verified through Comply.org subprocessor management with documented security controls and compliance measures.
Direct debit payment processing service for recurring billing in UK and EU markets. Handles bank account information under strict regulatory frameworks. Documented in Comply.org subprocessor review with appropriate security controls and data protection measures for financial services.
Email marketing and transactional email delivery service. EU-based provider processing email addresses and communication content. Verified through Comply.org subprocessor review with GDPR compliance measures and EU data residency.
Contact data enrichment and identity resolution service. Processes contact information to enhance CRM data quality. Managed under supply chain risk management program with data processing agreements and Standard Contractual Clauses verified through Comply.org review.
Cloud infrastructure provider hosting applications, databases, and data storage. Critical infrastructure supporting compute, storage, and AI/ML services with global data residency controls.
G-Suite (Google Workspace) services for internal collaboration and productivity. Processes organizational data under Google's enterprise agreements. Documented in Comply.org subprocessor review with comprehensive security controls and compliance certifications.
Tax compliance and invoicing automation service for EU and international transactions. EU-based provider processing billing and tax information. Verified through Comply.org subprocessor review with GDPR compliance and appropriate data protection measures.