Data Processing Agreement
This Data Processing Agreement template describes the baseline terms for processing personal data when Kairos acts as a processor for a client acting as controller.
Roles and instructions
The controller determines the purposes and means of processing. Kairos processes personal data only on documented instructions, including the agreed service description.
The parties should record the subject matter, duration, nature, purpose, data categories, and categories of data subjects in an order or schedule.
The controller remains responsible for lawful collection, notices, legal bases, and responding to data-subject requests.
Kairos will promptly tell the controller if an instruction appears to conflict with applicable data-protection law.
Processing security
Kairos maintains reasonable technical and organizational measures appropriate to the risk, including access control, confidentiality, secure development practices, backups, and incident procedures where relevant.
Measures should be reviewed when the service, threat environment, or processing risk changes.
- Process data only for documented purposes
- Limit access to authorized personnel
- Protect credentials and secrets
- Support secure deletion and return
- Maintain appropriate operational records
Confidentiality and personnel
People authorized to process personal data must be bound by confidentiality obligations and receive appropriate instructions for their role.
Access should be limited to the minimum needed to deliver the service and removed when no longer necessary.
Subprocessors
Kairos may use subprocessors where permitted by the controller’s instructions and applicable agreement. The current list, notice process, and objection mechanism should be maintained in the project record.
Kairos remains responsible for subprocessors to the extent required by the agreement and law.
Assistance and incidents
Taking account of the processing, Kairos will provide reasonable assistance with rights requests, security assessments, impact assessments, and consultations.
Kairos will notify the controller without undue delay after becoming aware of a personal-data breach affecting the controller’s data, following the agreed communication channel.
The controller leads regulatory notifications unless the parties agree otherwise or the law requires a different action.
International transfers
Transfers outside the EEA should use an appropriate GDPR transfer mechanism and documented safeguards, with the relevant locations and vendors recorded.
- Documented controller instructions
- Defined data, purposes, and retention
- Confidentiality and role-based access
- Security and breach-notification process
- Subprocessor and transfer controls
- Return or deletion at the end of services
Return, deletion, and audit
At the end of the service, Kairos will return or delete personal data as instructed, unless law requires continued storage. Audit information should be limited to what is reasonably necessary to demonstrate compliance.
Order of precedence
If this template conflicts with a signed agreement or mandatory law, the signed agreement and applicable law govern to the extent permitted.
This template should be completed with project-specific schedules and reviewed by qualified legal counsel before signature.
Conclusion
A useful processing agreement makes roles, instructions, safeguards, subprocessors, transfers, incidents, and end-of-service actions explicit.
We build and improve digital products for real operating workflows.
Tell us where the product is now and where it needs to go. We’ll help define the clearest next step. See all FAQs
