Data Processing Addendum
Last updated: 01 September 2026
This Data Processing Addendum, including its Annexes (the “DPA”), is entered into between Kroolo Labs, Inc., a Delaware corporation, together with its affiliates (“Kroolo”), and Customer, as defined in the Agreement. It forms part of the Agreement and takes effect on the effective date of the Agreement or, if later, the date the parties sign it. If Customer and Kroolo have signed a data processing agreement for the Services, the signed agreement replaces this DPA.
The Services involve Kroolo processing Personal Data on Customer’s behalf. This DPA sets the terms on which Kroolo does so, so that each party meets the Data Protection Laws that apply to it.
1. Subject Matter, Duration and Precedence
1.1 Subject matter. This DPA applies to Personal Data that Kroolo processes on Customer’s behalf in providing the Services. Annex I describes the processing.
1.2 Duration. This DPA applies until Kroolo no longer holds Personal Data on Customer’s behalf under Section 11.
1.3 Precedence. Capitalized terms not defined here have the meaning given in the Agreement. If this DPA conflicts with the Agreement on the processing of Personal Data, this DPA controls. If the Standard Contractual Clauses or the UK Addendum apply and conflict with this DPA, they control.
2. Definitions
“Agreement” means the agreement between Kroolo and Customer for the Services, being the Kroolo Terms of Service, the Kroolo Customer Agreement or the Master Software and Services Agreement, as applicable.
“Controller” means the person that decides the purposes and means of processing Personal Data, including a “business”, “organization” or “data fiduciary” under Data Protection Laws. In this DPA it means Customer.
“Data Breach” means a breach of security that leads to accidental or unlawful destruction, loss, alteration, unauthorized disclosure of, or access to, Personal Data that Kroolo processes on Customer’s behalf.
“Data Protection Laws” means the data protection, privacy and cybersecurity laws that apply to the processing of Personal Data under this DPA, which may include: the EU General Data Protection Regulation 2016/679 (“GDPR”) and national laws implementing it; the UK General Data Protection Regulation and Data Protection Act 2018 (“UK GDPR”); the Swiss Federal Act on Data Protection; the California Consumer Privacy Act as amended (“CCPA”) and other US state privacy laws; Singapore’s Personal Data Protection Act 2012 (“PDPA”); the DIFC Data Protection Law (Law No. 5 of 2020) and the UAE Federal Decree-Law No. 45 of 2021; and India’s Digital Personal Data Protection Act, 2023, each as amended.
“Data Subject” means an identified or identifiable individual to whom Personal Data relates.
“Personal Data” means Customer Data that relates to a Data Subject and that Kroolo processes on Customer’s behalf, as defined in the Data Protection Laws.
“Process” and “Processing” have the meaning given in the Data Protection Laws.
“Processor” means the person that processes Personal Data on behalf of a Controller, including a “service provider” or “data intermediary” under Data Protection Laws. In this DPA it means Kroolo.
“Restricted Transfer” means a transfer of Personal Data that Data Protection Laws restrict unless a transfer mechanism applies.
“Security Policy” means Kroolo’s security policy at kroolo.com/legal/security.
“Standard Contractual Clauses” means the clauses in the Annex to Commission Implementing Decision (EU) 2021/914 of 4 June 2021, as amended or replaced. “UK Addendum” means the International Data Transfer Addendum to those clauses issued by the UK Information Commissioner’s Office.
“Subprocessor” means a third party, including a Kroolo affiliate, that Kroolo engages to process Personal Data in providing the Services.
3. Roles and Instructions
3.1 Roles. Customer is the Controller and Kroolo is the Processor of Personal Data. If Customer processes Personal Data for another Controller, Customer is a Processor and Kroolo is its subprocessor, and Customer confirms that it has that Controller’s authority to give Kroolo these instructions.
3.2 Instructions. Kroolo will process Personal Data only on Customer’s documented instructions. Those instructions are: the Agreement; this DPA; Customer’s use and configuration of the Services, including AI Features and Connectors; and any further written instructions the parties agree. Kroolo may also process Personal Data as the law requires, and will tell Customer first where the law allows. Kroolo will tell Customer if it reasonably believes an instruction infringes Data Protection Laws, unless the law prohibits it.
3.3 Customer responsibilities. Customer is responsible for: the lawfulness of its instructions and of the Personal Data it submits; having the notices, consents and lawful bases that Data Protection Laws require; the accuracy and quality of Personal Data; and compliance with the restrictions on data types in the Agreement. Customer will not use the Services to process Personal Data in a way that needs terms this DPA does not provide, such as special categories of personal data, unless the parties have agreed in writing.
3.4 Personnel. Kroolo will make sure that everyone it authorizes to process Personal Data is bound by a duty of confidentiality, by contract or by law.
3.5 No sale or sharing. Kroolo does not sell Personal Data or share it for cross-context behavioral advertising, and processes it only to provide the Services.
3.6 Partners. If Customer buys through a Partner, Kroolo does not give the Partner access to Customer Data unless Customer asks it to. The Partner’s own processing for Customer is governed by Customer’s agreement with the Partner.
4. AI Features
4.1 No training. Kroolo does not use Personal Data in Customer Data, Input or Output to train or fine-tune Kroolo’s models or any third party’s models, and requires its model providers not to. This applies unless Customer opts in in writing to a specific program.
4.2 Model providers. Model providers that process Personal Data are Subprocessors. They process it only to return the result of a request, under written terms that limit its use and retention, and Section 8 applies to them.
4.3 Data minimization. Kroolo sends a model provider only the content a request needs and not unrelated account information.
4.4 Automated decisions. Kroolo does not use the AI Features to make decisions that have legal or similarly significant effects on Data Subjects. If Customer configures AI Features or automations to support such decisions, Customer is responsible for the legal basis, human review, and the information and rights that Data Protection Laws require, and the Kroolo AI Policy applies.
4.5 Kroolo Search. Kroolo Search indexes only the sources that Customer connects, within the scope Customer grants. It is designed to respect the permissions of each source. Customer is responsible for configuring Connectors and the permissions in its source systems.
4.6 Logs. Kroolo keeps logs and metadata about AI requests to detect abuse and security incidents, and keeps prompt content no longer than that purpose needs.
5. Assistance
5.1 Data Subject requests. Kroolo will give Customer tools within the Services to respond to Data Subject requests, and will give reasonable further assistance on Customer’s instruction. If a Data Subject contacts Kroolo about Personal Data, Kroolo will pass the request to Customer within 5 business days and will not respond, unless the law requires or Customer asks it to.
5.2 Impact assessments. Where Data Protection Laws require, and taking into account the nature of the processing and the information Kroolo holds, Kroolo will give Customer reasonable assistance with data protection impact assessments and prior consultations with regulators.
5.3 Demonstrating compliance. On reasonable request, Kroolo will give Customer the information needed to show that Kroolo complies with this DPA.
5.4 Regulators. If a regulator contacts Kroolo about Customer’s Personal Data, Kroolo will tell Customer first, unless the law prohibits it, and will cooperate with Customer’s reasonable requests.
5.5 Costs. Kroolo may charge for assistance that goes beyond its standard support and the tools in the Services, at reasonable rates and after telling Customer.
6. Security
6.1 Measures. Kroolo will keep the technical and organizational measures in Annex II and the Security Policy, which are designed to protect Personal Data from Data Breaches.
6.2 Updates. Kroolo may update its measures as technology and threats change, but will not materially reduce the overall protection of Personal Data during the term of the Agreement.
6.3 Customer responsibilities. Customer is responsible for its use and configuration of the Services, including credentials, single sign-on, multi-factor authentication, user permissions and Connectors, and for the security of its own systems and devices.
7. Data Breaches
7.1 Notice. After confirming a Data Breach, Kroolo will notify Customer without undue delay and within 72 hours, at the security contact in Customer’s Account. To the extent known, the notice will describe: the nature of the Data Breach, including the categories and approximate number of Data Subjects and records; its likely consequences; the measures taken or proposed; and a contact for more information. If Kroolo cannot give all of this at once, it will give it in phases.
7.2 Investigation and remediation. Kroolo will use reasonable efforts to investigate the Data Breach, tell Customer about its scope, cause and impact, and fix it in the systems it controls.
7.3 No admission. A notice or Kroolo’s help under this Section is not an admission of fault or liability.
7.4 Exceptions. Section 7.1 does not apply to unsuccessful attempts that do not compromise Personal Data. Sections 7.2 and 7.3 do not require Kroolo to act on a Data Breach that Customer or its Users cause.
7.5 Notifying others. Customer decides whether and how to notify regulators and Data Subjects. Kroolo will not notify them about a Data Breach affecting Customer’s Personal Data without Customer’s approval, except where the law requires it.
8. Subprocessors
8.1 Authorization. Customer gives Kroolo general authorization to use Subprocessors, including those on the Sub-processor List.
8.2 Obligations. Kroolo will bind each Subprocessor by a written contract with data protection obligations no less protective than this DPA, and remains responsible for its Subprocessors’ performance.
8.3 Notice of changes. Kroolo will update the Sub-processor List and notify Customer, by email to subscribers and to the Account’s Admins, at least 30 days before a new Subprocessor starts processing Personal Data. Where urgent replacement is needed for security or continuity, Kroolo will notify Customer as soon as practical.
8.4 Objection. Customer may object in writing within 15 days of the notice, on reasonable data-protection grounds, such as that the Subprocessor would put Customer in breach of Data Protection Laws or Kroolo in breach of Section 8.2. Kroolo will work with Customer to resolve the objection, for example by changing the processing, offering an alternative, or not using the Subprocessor for Customer’s Personal Data. If the parties cannot resolve it within 30 days, Customer may terminate the affected Services on written notice and receive a pro-rated refund of prepaid, unused Charges. That is Customer’s only remedy for the objection.
9. International Transfers
9.1 Locations. Kroolo stores Personal Data in the hosting region stated in the Order Form or the Security Policy. Kroolo, its affiliates and its Subprocessors may also process Personal Data in other countries, as the Sub-processor List shows. Customer authorizes those transfers, subject to this Section.
9.2 EEA, Switzerland and the UK. For a Restricted Transfer from the European Economic Area, Switzerland or the United Kingdom, the Standard Contractual Clauses, supplemented by Annex IV, apply. Module Two applies where Customer is a Controller, and Module Three applies where Customer is a Processor. For the UK, the UK Addendum applies as Annex IV sets out. Each party’s acceptance of the Agreement or this DPA is treated as its signature of those clauses.
9.3 Other jurisdictions. For Personal Data subject to Singapore law, Kroolo gives it a standard of protection comparable to the PDPA through this DPA. For Personal Data subject to the DIFC or UAE data protection laws, or the laws of India or another country that requires specific transfer terms, the parties will incorporate those terms, and Kroolo will sign them on request. Kroolo will not make a transfer that the law of the originating country prohibits.
9.4 Alternative mechanisms. If a transfer mechanism in this Section stops being valid, the parties will work in good faith to adopt a valid alternative.
9.5 Government requests. If a public authority asks Kroolo for Personal Data, Kroolo will check that the request is lawful, tell Customer unless the law prohibits it, challenge a request it reasonably believes is unlawful or overbroad, and disclose only the minimum needed.
10. Audits and Assessments
10.1 Reports first. To show that it meets this DPA, Kroolo will make available, on request and under confidentiality, relevant independent audit reports, certifications and penetration-test summaries.
10.2 Audit. Where Data Protection Laws give Customer an audit right, Customer may audit, itself or through an independent auditor bound by confidentiality, Kroolo’s policies, procedures and records relevant to the processing of Personal Data. The audit must be: on at least 30 days’ written notice; during business hours; conducted so as not to disrupt Kroolo’s business or reach other customers’ data; at Customer’s cost; and no more than once in any 12 months, unless a regulator requires otherwise or after a Data Breach.
10.3 Scope. Kroolo may first satisfy the request with the reports in Section 10.1 and written answers. An on-site audit or an interview with Kroolo’s security staff is available only if those are not enough, at a time and scope Kroolo reasonably agrees.
10.4 Confidentiality. Information that Kroolo gives under this Section is Kroolo’s Confidential Information, and Customer may not share an audit report with others, except as the law or a regulator requires. Customer is responsible for its auditor’s actions.
11. Return and Deletion
11.1 Retrieval. During the term of the Agreement, Customer may export Personal Data using the Services’ tools.
11.2 Deletion. After the term ends, Kroolo will keep Personal Data available for export in read-only mode for at least 30 days, and will delete it from active systems within 90 days. Backups are overwritten on Kroolo’s normal cycle, which does not exceed 90 days. Kroolo may keep Personal Data longer only where the law requires, and will then protect it and not process it further except as the law requires.
11.3 Confirmation. Kroolo will confirm deletion in writing on Customer’s written request.
12. Regional Terms
12.1 United States. Where the CCPA or another US state privacy law applies, Kroolo is Customer’s service provider or processor and: processes Personal Data only for the limited and specified purposes in the Agreement and this DPA; does not sell or share it; does not retain, use or disclose it outside the direct business relationship with Customer, or for any other commercial purpose; does not combine it with personal data it receives from others or collects itself, except as the law permits; provides the level of protection the law requires; and tells Customer if it can no longer meet its obligations. Customer may take reasonable steps, as the parties agree, to make sure Kroolo uses Personal Data consistently with Customer’s obligations, and, on notice, to stop and remediate unauthorized use.
12.2 EEA, UK and Switzerland. This DPA is intended to contain the terms that Article 28(3) of the GDPR and the UK GDPR require, including on instructions (Section 3.2), confidentiality (Section 3.4), security (Section 6), Subprocessors (Section 8), assistance (Section 5), return and deletion (Section 11), and audits (Section 10).
12.3 Singapore. Where the PDPA applies, Kroolo acts as Customer’s data intermediary. Kroolo will protect Personal Data with reasonable security arrangements, will not keep it longer than needed for the purposes in this DPA, and will tell Customer without undue delay if it has reason to believe a Data Breach has occurred. Customer remains responsible for its own obligations as the organization.
12.4 DIFC and UAE. Where the DIFC Data Protection Law or the UAE Federal Decree-Law No. 45 of 2021 applies, Customer is the Controller and Kroolo is the Processor, and the terms of this DPA apply as those laws require. Section 9.3 covers transfer terms.
12.5 India. Where India’s Digital Personal Data Protection Act, 2023 applies, Customer is the Data Fiduciary and Kroolo is its Data Processor. Kroolo will process Personal Data only under Customer’s instructions, keep reasonable security safeguards, and help Customer meet its obligations to Data Principals as the Act and its rules require, as they take effect.
13. Liability
Each party’s liability under this DPA is subject to the limits and exclusions in the Agreement. Nothing in this DPA limits liability that cannot be limited by law, or a Data Subject’s rights under the Standard Contractual Clauses.
14. Term, Changes and Conflict
14.1 Term. This DPA lasts as long as the Agreement and until Section 11 is complete.
14.2 Changes. Kroolo may update this DPA to reflect changes in law, new versions of the Standard Contractual Clauses or other transfer terms, or changes to the Services, by giving at least 30 days’ notice. Customer may object in writing within that time if the change materially reduces its protection, and the parties will discuss in good faith.
14.3 Conflict. Except as this DPA amends it, the Agreement remains in force. If they conflict on the processing of Personal Data, this DPA controls.
15. Governing Law
This DPA is governed by the law that governs the Agreement, unless the Data Protection Laws require otherwise. For the Standard Contractual Clauses and the UK Addendum, Annex IV states the governing law and competent authorities.
16. Contacts
- Privacy and data protection: privacy@kroolo.com