Back to Articles & Documents

Data Processing Agreement

LegalAugust 29, 2026

This Data Processing Agreement template describes the baseline terms for processing personal data when Kairos acts as a processor for a client acting as controller.

Roles and instructions

The controller determines the purposes and means of processing. Kairos processes personal data only on documented instructions, including the agreed service description.

The parties should record the subject matter, duration, nature, purpose, data categories, and categories of data subjects in an order or schedule.

The controller remains responsible for lawful collection, notices, legal bases, and responding to data-subject requests.

Kairos will promptly tell the controller if an instruction appears to conflict with applicable data-protection law.

Processing security

Kairos maintains reasonable technical and organizational measures appropriate to the risk, including access control, confidentiality, secure development practices, backups, and incident procedures where relevant.

Measures should be reviewed when the service, threat environment, or processing risk changes.

Confidentiality and personnel

People authorized to process personal data must be bound by confidentiality obligations and receive appropriate instructions for their role.

Access should be limited to the minimum needed to deliver the service and removed when no longer necessary.

Subprocessors

Kairos may use subprocessors where permitted by the controller’s instructions and applicable agreement. The current list, notice process, and objection mechanism should be maintained in the project record.

Kairos remains responsible for subprocessors to the extent required by the agreement and law.

Assistance and incidents

Taking account of the processing, Kairos will provide reasonable assistance with rights requests, security assessments, impact assessments, and consultations.

Kairos will notify the controller without undue delay after becoming aware of a personal-data breach affecting the controller’s data, following the agreed communication channel.

The controller leads regulatory notifications unless the parties agree otherwise or the law requires a different action.

International transfers

Transfers outside the EEA should use an appropriate GDPR transfer mechanism and documented safeguards, with the relevant locations and vendors recorded.

Return, deletion, and audit

At the end of the service, Kairos will return or delete personal data as instructed, unless law requires continued storage. Audit information should be limited to what is reasonably necessary to demonstrate compliance.

Order of precedence

If this template conflicts with a signed agreement or mandatory law, the signed agreement and applicable law govern to the extent permitted.

This template should be completed with project-specific schedules and reviewed by qualified legal counsel before signature.

Conclusion

A useful processing agreement makes roles, instructions, safeguards, subprocessors, transfers, incidents, and end-of-service actions explicit.

We build and improve digital products for real operating workflows.

Tell us where the product is now and where it needs to go. We’ll help define the clearest next step. See all FAQs