1. Legal Context & Role Allocation
This DPA applies to all personal data processing activities conducted by Kaya in providing the Marketing OS platform to the Customer.
The Customer retains full ownership, instruction authority, and custody over all uploaded data. Kaya processes customer personal data solely upon documented customer instructions.
2. Scope & Categories of Processed Data
Customer data handled by Kaya on the Customer's behalf includes:
• Prospect and End-User Telemetry: session tokens, trial account emails, and anonymized conversion journey logs.
• Acquisition Campaign Records: campaign performance statistics, high-intent query patterns, and approval audit records.
Data subjects consist of visitors, prospects, and end-users of the Customer's software.
3. Kaya's Obligations as Data Processor
Pursuant to Article 28 of the GDPR, Kaya undertakes to:
• Process data exclusively for the agreed purpose of operating the Marketing OS platform.
• Guarantee that personnel authorized to handle personal data are bound by strict professional confidentiality.
• Deploy state-of-the-art security measures commensurate with processing risks (end-to-end encryption, access controls, automated backups).
• Assist the Customer in fulfilling data subject requests under GDPR Chapter III.
4. Authorized Sub-processing
The Customer grants general written authorization to Kaya to engage specialized third-party sub-processors (cloud hosting, payment gateways, zero-retention LLM providers).
Kaya warrants that every sub-processor is bound by data protection obligations at least as protective as those contained in this DPA.
Kaya will notify the Customer at least 15 days in advance of any material change or addition of a sub-processor.
5. Security Breach Notification
Kaya shall notify the Customer without undue delay and, at the latest, within forty-eight (48) hours of becoming aware of any confirmed personal data breach affecting Customer data.
The notification shall detail the nature of the breach, affected data categories, likely consequences, and immediate remedial actions deployed.
6. Data Return & Secure Deletion
Upon termination of the service agreement, Kaya shall, at the Customer's election, securely delete or export all Customer personal data in a standard structured format (JSON / CSV / SQL dump).
All backup copies are permanently and irrecoverably purged from our storage within a maximum window of thirty (30) calendar days.