Data Processing Addendum

Last modified:

This Data Processing Addendum (“Addendum”) is subject to and forms part of the Agreement between (i) kapa.ai, Inc. (“Processor” or “Service Provider”), having its place of business 1111B S Governors Ave #6248 Dover, DE 19904, US and (ii) the Subscriber that executed the Agreement (“Controller”), solely to the extent that Controller submits Personal Data to kapa through the Services.

Capitalized terms not otherwise defined herein shall have the meaning given to them in the Agreement.  Except as modified below, the terms of the Agreement shall remain in full force and effect. To the extent this Addendum is inconsistent with or conflicts with the Agreement, the Addendum shall control.

AGREEMENT

1.          Definitions 

1.1.      In this Addendum, the following terms shall have the meanings set out below:

1.1.1. “Anonymous Data” means information that relates to a group or category of consumers and/or individuals, from which: (i) the Controller cannot be identified as the source of the information; (ii) personally identifiable information allowing the identification of individuals is removed; and (iii) the information is not reasonably identifiable or linkable to any consumer, individual, household, or device. 

1.1.2.  "Applicable Laws" means (i) the GDPR, (ii) the Swiss Federal Act on Data Protection (“Swiss FADP”), (iii) the EU GDPR as amended and incorporated into UK law under the UK European Union (Withdrawal) Act of 2018 and UK Data Protection Act of 2018 (“UK GDPR”), and (iv) the CCPA, each solely to the extent applicable to Processor’s Services on behalf of Controller pursuant to the Agreement in jurisdictions where the Services are provided.

1.1.3.  "Personal Data" means any information that is reasonably associated or linked with an identified or identifiable person, and which is Processed by the Processor on behalf of the Controller pursuant to the Agreement.

1.1.4.    “CCPA” means the California Consumer Privacy Act of 2018.

1.1.5.  "EEA" means the European Economic Area.

1.1.6.  "GDPR" means EU General Data Protection Regulation 2016/679 and the EU GDPR as it forms part of the law of England and Wales by virtue of section 3 of the European Union (Withdrawal) Act of 2018.

1.1.7. “Processor Affiliate" means an entity that owns or controls, is owned or controlled by or is or under common control or ownership with Processor, where control is defined as the possession, directly or indirectly, of the power to direct or cause the direction of the management and policies of an entity, whether through ownership of voting securities, by contract or otherwise.

1.1.8.  “Restricted Transfer” means the disclosure, grant of access, or other transfer of Personal Data to: (i) in the context of the European Economic Area (“EEA”), any country or territory outside the EEA that does not benefit from an adequacy decision from the European Commission (an “EEA Restricted Transfer”); (ii) in the context of the United Kingdom (“UK”), any country or territory outside the UK that does not benefit from an adequacy decision from the UK government (a “UK Restricted Transfer”); and (iii) in the context of Switzerland, any country or territory outside of Switzerland that does not benefit from an adequacy decision from the Swiss Federal Council (a “Swiss Restricted Transfer”).

1.1.9.  "Services" means the services and other activities to be supplied to or carried out by or on behalf of Processor for Controller pursuant to the Agreement.

1.1.10.  “Standard Contractual Clauses” or “SCCs” means Commission Decision of 4 June 2021 on standard contractual clauses for the transfer of personal data to third countries pursuant to Regulation (EU) 2016/679 of the European Parliament and of the Council.

1.1.11.   "Subprocessor" means any person (including any third party but excluding an employee of Processor or any of its sub-contractors) appointed by or on behalf of Processor to Process Personal Data on behalf of any Controller in connection with the Agreement.

1.1.12. “UK Addendum” means Version B1.0 of the International Data Transfer Addendum to the EU Commission’s Standard Contractual Clauses, as issued by the UK’s Information Commissioner’s Office under S119A(1) Data Protection Act 2018 and in force 21 March 2022.

1.1.13.   The terms “Data Protection Impact Assessments,” "Data Subject," "Process," “Sell,” “Share,” and “Supervisory Authority” shall have the same meaning as in Applicable Laws.

  

2.          Interpretation 

2.1.      To the extent that a term of this Addendum requires the performance by a party of an obligation in accordance with, or as required by, Applicable Laws (or similar), this required performance shall be conducted in accordance with such Applicable Laws as are in force and applicable at the time of performance to the relevant party and, if the relevant obligation is not then a requirement under Applicable Laws, it shall not apply until such time as it is so required.

2.2.      Controller acknowledges that the Services are not intended to Process sensitive data or sensitive personal information as defined in Applicable Laws. Controller shall not provide such sensitive Personal Data to Processor without Processor’s express written consent. For External Chat, Controller is responsible for displaying any notifications it deems necessary to discourage the submission of Personal Data.

2.3. Controller acknowledges and authorizes Processor to engage its Processor Affiliate to Process Personal Data on behalf of Controller under this Addendum. Processor shall remain responsible for the acts or omissions of the Processor Affiliate under this Addendum.

 

3.          Processing of Personal Data

3.1.      Processor shall comply with Applicable Laws in the Processing of Personal Data; and not Process Personal Data other than on the Controller’s documented instructions (including as part of the provision of the Services) unless Processing is required by Applicable Laws to which the relevant Processor is subject.

3.2. Controller shall instruct Processor (and authorizes Processor to instruct each Subprocessor) to Process Personal Data as described in the Agreement. 

3.3.      The Parties acknowledge that, for the purposes of the Agreement, the description of the Personal Data Processed is as set out in Annex I, and notwithstanding anything in the Agreement, may be updated from time to time by the Processor.

3.4.      Controller represents and warrants that:

3.4.1.  it has complied, and will continue to comply, with all Applicable Laws in respect of its Processing of Personal Data and any Processing instructions issued to Processor;

3.4.2.  it has all necessary rights to provide the Personal Data to the Processor for the Processing to be performed in relation to the Services;

3.4.3.  all necessary privacy notices are provided to Data Subjects;

3.4.4.  any necessary Data Subject consents to the Processing are obtained and a record of such consents is maintained;

3.4.5.  should such a consent be revoked by a Data Subject, and no other lawful basis remains to keep the Data Subject’s Personal Data, it will communicate the fact of such revocation to the Processor;

3.4.6.    it is and will at all relevant times remain duly and effectively authorized to give the instructions set out in this Section; and,

3.4.7.     one or more lawful bases set forth in the Applicable Laws support the lawfulness of the Processing.

3.5.      Controller will ensure that Processor’s Processing of the Personal Data in accordance with Controller’s instructions (including as part of the provision of the Services) will not cause Processor to violate any Applicable Law, regulation, or rule.

3.6.      Processor acknowledges that, where the CCPA applies

3.6.1. it is a Service Provider, and Personal Data shall be held as confidential by the Processor;

3.6.2. Processor shall not directly or indirectly Sell or Share any Personal Data, or retain, use, or disclose any Personal Data for any purpose other than the purpose of performing Services for Controller; or retain, use, or disclose any Personal Data outside the scope of this Addendum or as set forth in the Agreement; and,

3.6.3.      Processor shall not combine Personal Data received from Controller with other Personal Data from any other source, including Personal Data obtained from other persons or Personal Data obtained by Processor itself from its own interactions with the Data Subject with which the Personal Data is associated, unless permitted by Applicable Laws (e.g., detection of security incidents).

3.9.      Processor may use Anonymous Data for its own business purposes, provided that Processor will not attempt to re-identify the information, except that the Processor may attempt to re-identify the information solely for the purpose of determining whether its de-identification processes satisfy the requirements of Applicable Laws.

3.10.      Processor will notify Controller if it cannot materially meet any of its obligations under this Addendum.

   

4.          Processor Personnel

4.1. Processor shall take reasonable steps to ensure the reliability of any employee, agent or contractor who may have access to the Personal Data, and take reasonable steps to ensure in each case that access is limited to those individuals who need to know or access the relevant Personal Data.

 

5.          Security

5.1.      Taking into account the state of the art, the costs of implementation and the nature, scope, context and purposes of Processing as well as the risk of varying likelihood and severity for the rights and freedoms of natural persons, Processor shall in relation to the Personal Data implement appropriate technical and organizational measures to ensure a level of security appropriate to that risk. Such measures are set forth in Annex II.

5.2. The Parties acknowledge that security requirements are constantly changing, and that effective security may require improvements of outdated security measures. Processor may update its security measures at any time and in its sole discretion.

5.3.      Processor may amend this Addendum at any time and in its sole discretion, and Processor will notify Controller about such changes, which may be done by updating the date at the top of this Addendum.

 

6.          Restricted Transfers

6.1.      Where Processor transfers Personal Data in/from a country which constitutes a Restricted Transfer, Processor shall take the appropriate guarantees to ensure such transfer is in compliance with Applicable Laws. Such appropriate guarantees may consist of: (i) participation in the Data Privacy Frameworks or other adequacy decisions; (ii) applicable standard data protection clauses pursuant to Article 46.2 c) or d) of the GDPR; (iii) binding corporate rules pursuant to Article 46.2 b) of the GDPR; (iv) derogations for specific situations under Article 49 of the GDPR; or, (v) any other instrument recognized by the GDPR and approved by the European Commission or a Supervisory Authority.

6.1.1    To the extent there is no adequacy decision and an EEA Restricted Transfer or Swiss Restricted Transfer rely on the Standard Contractual Clauses, the Parties hereby agree to and incorporate the Standard Contractual Clauses in full, as follows:

6.1.1.1.    Module Two will apply;

6.1.1.2.    in Clause 7, the optional docking clause will apply;

6.1.1.3.   in Clause 9, option 2 (general written authorization) will apply, and the time period for prior notice of Subprocessor changes shall be 30 days;

6.1.1.4.   in Clause 17, the Standard Contractual Clauses will be governed by Irish law;

6.1.1.5.   in Clause 18(b), disputes shall be resolved before the courts of Ireland;

6.1.1.6.   Annexes I, II, and III of the Standard Contractual Clauses shall be deemed completed with the information set out in Annexes I, II, and III to this Addendum;

6.1.2.    To the extent there is no adequacy decisions and a UK Restricted Transfer relies on the UK Addendum, the Parties hereby agree to and incorporate the UK Addendum in full, as follows:

6.1.2.1. Table 1 (Parties) shall be deemed completed with the information set out in Annex I to this Addendum;

6.1.2.2. in Table 2 (Selected SCCs, Modules and Selected Clauses), the Addendum EU SCCs shall be the Approved EU SCCs, including the Appendix Information and with only the following modules, clauses or optional provisions of the Approved EU SCCs brought into effect for the purposes of the UK Addendum:

6.1.2.2.1. Module Two will apply;

6.1.2.2.2. in Clause 7, the optional docking clause will apply; and,

6.1.2.2.3. in Clause 9, option 2 (general written authorization) will apply, and the time period for prior notice of Subprocessor changes shall be as set out in Clause 6.2.1.3 of this Addendum;

6.1.2.3. in Table 3 (Appendix Information), Annexes I, II, and III shall be deemed completed with the information set out in Annexes I, II, and III to this DPA; and,

6.1.2.4. in Table 4 (Ending this Addendum when the Approved Addendum Changes), both the Importer and Exporter may end the UK Addendum.

 

7.          Subprocessing

7.1.      Controller authorizes Processor to appoint (and permit each Subprocessor appointed in accordance with this section to appoint) Subprocessors in accordance with this section and any restrictions in the Agreement.

7.2.      Processor may continue to use those Subprocessors already engaged by Processor as of the date of this Addendum, as set forth in at https://docs.kapa.ai/security-subprocessors.  

7.3.      Processor may update the list of Subprocessors from time to time.

7.4.      With respect to each Subprocessor, Processor shall ensure that the arrangement between Processor, on the one hand, and the Subprocessor, on the other hand, is governed by a written contract containing provisions substantially protective as the obligations set forth in this Addendum, to the extent applicable to the nature of the service provided by such Subprocessor.


8.          Data Subject Rights

8.1.      Taking into account the nature of the Processing, Processor shall assist Controller by implementing appropriate technical and organizational measures, insofar as this is feasible, for the fulfillment of the Controller’s obligations to respond to requests to exercise Data Subject rights under the Applicable Laws.

8.2.      Processor shall:

8.2.1.  notify Controller if Processor receives a request from a Data Subject under any Applicable Laws in respect of Personal Data; and

8.2.2.  ensure that Processor does not respond to that request except as required by Applicable Laws to which the Processor is subject.

8.3.      Controller shall be responsible for responding to a request from a Data Subject as required under any Applicable Laws in respect of Personal Data.

8.4.      If a Data Subject exercises the right to delete under the CCPA, Processor shall, at the written direction of Controller, delete or enable Controller to delete, and shall notify its Subprocessors to delete, original Personal Data about the Data Subject collected, used, Processed, or retained by the Subprocessor. Processor shall also notify all other parties who may have accessed such Personal Data from or through the Subprocessor to delete the Data Subject’s Personal Data, unless the Data Subject’s Personal Data was accessed at the direction of Controller.

 

9.          Assistance to Data Controller

9.1. To the extent required under Applicable Laws and taking into account the nature of Processing and the information available to the Processor, the Processor shall reasonably assist the Controller in (i) Data Protection Impact Assessments and (ii) consultations with Supervisory Authorities.

 

10.       Personal Data Breach

10.1. Processor shall notify Controller after confirming that there has been a Personal Data Breach affecting Personal Data provided by Controller to Processor.

 

11.       Audits

11.1. Controller acknowledges that Processor will maintain a certification for compliance with SOC 2 Type 2 standards, issued by independent third-party auditors. Upon written request, Processor shall supply, on a confidential basis, a summary copy of its most current audit report(s) to Controller, so that Controller can verify Processor’s compliance with the audit standards against which it has been assessed and this Addendum.


12.       Deletion or Return of Personal Data

12.1.   Within 30 days of the termination date, Controller may by written notice request that Processor delete Personal Data Processed by Processor. Processor may retain Personal Data to the extent required by Applicable Laws and shall ensure that such Personal Data is only Processed as necessary for the purpose(s) specified in the Applicable Laws.


13. Export Controls

13.1.   Controller agrees that applicable export, import, and sanctions laws govern the use of the Services. Controller shall not export or re-export, directly, or indirectly, the Services in violation of these laws, or use the Services for any purpose prohibited by these laws including, without limitation, (i) into any country for which the United States has a trade embargo, or (ii) to anyone on the U.S. Treasury Department’s list of Specially Designated Nationals or the U.S. Commerce Department’s Table of Denial Orders. Controller represents and warrants that it is not located in, under the control of, or a national or resident of any such country or on any such list.


14.       Governing Law and Jurisdiction 

14.1.   The Parties to this Addendum hereby submit to the choice of jurisdiction stipulated in the Agreement; and

14.2.   This Addendum and all non-contractual or other obligations arising out of or in connection with it are governed by the laws of the country or territory stipulated for this purpose in the Agreement.  

ANNEX I

  1. LIST OF PARTIES

Data Exporter(s) 


Name 

Subscriber that is party to the Agreement with kapa.

Address

Subscriber’s address.

Contact details 

The name, position and contact details provided by the Subscriber.

Activities relevant to the data transferred under these Clauses 

For the Services as specified in the Agreement.

Role (controller/processor) 

Controller 

Data Importer(s)  


Name 

kapa.ai, Inc. 

Address

1111B S Governor’s Ave. #6248 Dover, DE 19904

Contact details 

Kapa support team, founders@kapa.ai 

Activities relevant to the data transferred under these Clauses 

As described in the Addendum 

Role (controller/processor) 

Processor  

  1. DESCRIPTION OF PROCESSING AND RELEVANT TRANSFERS

Categories of Data Subjects whose Personal Data is transferred

  • End users of Controller

  • Employees of Controller

  • Contractors, Agents, or Representatives of Controller

Categories of Personal Data transferred 

  • Controller Subscriber

    • Name

    • Email

    • Phone number

  • Controller Employee/ Contractor/ Agent/ Representative

    • Name

    • Email address and other business contact data

    • Name and location of employer

    • Unique User IDs

Special categories of Personal Data transferred (if applicable) and applied restrictions or safeguards that fully take into consideration the nature of the data and the risks involved, such as for instance strict purpose limitation, access restrictions (including access only for staff having followed specialised training), keeping a record of access to the data, restrictions for onward transfers or additional security measures. 

  • N/A

The frequency of the transfer (e.g. whether the data is transferred on a one-off or continuous basis).

  • Continuous

Nature and Purpose of the Processing

  • The Processing of Personal Data is for the purpose of providing and improving the Services as set out in the Agreement, which is solely with respect to Internal Chat services. External Chat (as defined in the Agreement) services do not require or request the sharing of Personal Data described hereunder.

The period for which the Personal Data will be retained, or, if that is not possible, the criteria used to determine that period.

  • The Personal Data transferred will be retained for as long as necessary for the provision of the Services as specified in the Agreement, or as required under Applicable Law.

For transfers to (sub-) processors, also specify subject matter, nature and duration of the Processing.

  • Please refer to Annex III

C. COMPETENT SUPERVISORY AUTHORITY

Identify the competent Supervisory Authority/ies in accordance with Clause 13

  • Irish Data Protection Commission


ANNEX II 

TECHNICAL AND ORGANISATIONAL MEASURES INCLUDING TECHNICAL AND ORGANISATIONAL MEASURES TO ENSURE THE SECURITY OF THE DATA 

Data Importer will, at a minimum, satisfy the security controls in their SOC 2 Type 2 report. Upon written request from Data Exporter, Data Importer shall supply, on a confidential basis, pursuant to kapa’s NDA, a summary copy of its most current SOC 2 Type 2 report.

ANNEX III

LIST OF SUB-PROCESSORS

The Controller has authorised the use of the following sub-processors:

 https://docs.kapa.ai/security-subprocessors