Data Processing Agreement · GDPR Article 28·Last updated : September 18, 2026

Data Processing Agreement (DPA)

This Data Processing Agreement (DPA) governs the processing of personal data conducted by Kaya on behalf of customers in accordance with the standards of Article 28 of the GDPR.

1. Legal Context & Role Allocation

Key takeaway :The Customer acts as Data Controller. Kaya Technologies SAS acts as Data Processor.

This DPA applies to all personal data processing activities conducted by Kaya in providing the Marketing OS platform to the Customer.

The Customer retains full ownership, instruction authority, and custody over all uploaded data. Kaya processes customer personal data solely upon documented customer instructions.

2. Scope & Categories of Processed Data

Customer data handled by Kaya on the Customer's behalf includes:

• Prospect and End-User Telemetry: session tokens, trial account emails, and anonymized conversion journey logs.

• Acquisition Campaign Records: campaign performance statistics, high-intent query patterns, and approval audit records.

Data subjects consist of visitors, prospects, and end-users of the Customer's software.

3. Kaya's Obligations as Data Processor

Pursuant to Article 28 of the GDPR, Kaya undertakes to:

• Process data exclusively for the agreed purpose of operating the Marketing OS platform.

• Guarantee that personnel authorized to handle personal data are bound by strict professional confidentiality.

• Deploy state-of-the-art security measures commensurate with processing risks (end-to-end encryption, access controls, automated backups).

• Assist the Customer in fulfilling data subject requests under GDPR Chapter III.

4. Authorized Sub-processing

The Customer grants general written authorization to Kaya to engage specialized third-party sub-processors (cloud hosting, payment gateways, zero-retention LLM providers).

Kaya warrants that every sub-processor is bound by data protection obligations at least as protective as those contained in this DPA.

Kaya will notify the Customer at least 15 days in advance of any material change or addition of a sub-processor.

5. Security Breach Notification

Key takeaway :Incident notice provided within 48 hours maximum upon verification of any confirmed security breach.

Kaya shall notify the Customer without undue delay and, at the latest, within forty-eight (48) hours of becoming aware of any confirmed personal data breach affecting Customer data.

The notification shall detail the nature of the breach, affected data categories, likely consequences, and immediate remedial actions deployed.

6. Data Return & Secure Deletion

Upon termination of the service agreement, Kaya shall, at the Customer's election, securely delete or export all Customer personal data in a standard structured format (JSON / CSV / SQL dump).

All backup copies are permanently and irrecoverably purged from our storage within a maximum window of thirty (30) calendar days.