The terms reference a separate Data Processing Agreement applicable to users who process personal data of EU or UK residents, establishing Klaviyo's role as a data processor and the user's role as data controller under GDPR and UK GDPR.
This analysis describes what Klaviyo's agreement states, permits, or reserves. It does not constitute a legal determination about enforceability. Regulatory applicability and practical outcomes may vary by jurisdiction, enforcement context, and individual circumstances. Read our methodology
This provision establishes that EU and UK data protection obligations are addressed in a separate contractual instrument rather than within the ToS itself, creating a multi-document compliance framework that requires users to locate, review, and execute the DPA separately.
Interpretive note: The specific content of the referenced DPA was not available in the provided document; the adequacy of its transfer mechanisms and sub-processor provisions cannot be assessed from the ToS alone.
Under this clause, EU and UK data protection compliance for personal data processed through Klaviyo is governed by the separate DPA rather than the ToS, which means users must execute the DPA to establish the GDPR-required data processing agreement with Klaviyo.
How other platforms handle this
Your organization may allow you to access and export your data in order to back it up or transfer it to a service outside of Google.
If you are an end user in a Workspace not owned by you and wish to update, delete, or receive any information we have about you, you may do so by contacting the organization who owns your ClickUp Workspace.
to request that your data be transferred to a third party (data portability)
1) REGULATORY LANDSCAPE: GDPR Article 28 requires that data controllers enter into a binding contract with data processors that specifies the subject matter, duration, nature, and purpose of processing, as well as processor obligations and …
Enforcement risk, jurisdiction flags, contract triggers, and due diligence action items.
Ad personalization controls removed. Contact scanning added. Advertiser data partnerships quietly dropped. A timeline of every change.
Get the research letter
Companies change their terms quietly. We read every version and catch what actually changed. One email a week on the changes that matter and what they mean.
This provision establishes that EU and UK data protection obligations are addressed in a separate contractual instrument rather than within the ToS itself, creating a multi-document compliance framework that requires users to locate, review, and execute the DPA separately.
Under this clause, EU and UK data protection compliance for personal data processed through Klaviyo is governed by the separate DPA rather than the ToS, which means users must execute the DPA to establish the GDPR-required data processing agreement with Klaviyo.
ConductAtlas has identified this type of provision across 289 platforms. See the full comparison.
No. ConductAtlas is an independent monitoring service. We are not affiliated with, endorsed by, or sponsored by Klaviyo.