Data Processing Agreement
Version: 0.1 (draft) · Effective date: [EFFECTIVE_DATE]
This Data Processing Agreement ("DPA") forms part of the Terms & Conditions (/legal/terms) between [OPERATING_BV_LEGAL_NAME], [REGISTERED_ADDRESS], KvK [KVK_NUMBER] ("Kyra", "we", the Processor) and the organisation that has accepted those Terms or signed an order form ("Customer", the Controller). It governs the processing of personal data by Kyra on the Customer's behalf in the course of providing the Kyra H.I. service (the "Service"). Where it conflicts with the Terms, this DPA prevails for data protection matters.
It is intended to satisfy Article 28 GDPR and, where personal data leaves the EEA, to incorporate the European Commission's Standard Contractual Clauses (SCCs).
1. Roles and scope
- For personal data processed in a Customer organisation/team workspace, the Customer is the Controller and Kyra is the Processor. Where a Customer end-user uses Kyra for purely personal purposes outside a workspace, Kyra acts as a controller under its Privacy Policy, and this DPA does not apply to that processing.
- Kyra processes Customer Personal Data only to provide and support the Service and only on the Customer's documented instructions (including this DPA, the Terms, and use of the Service's features and settings), unless required by EU or member-state law — in which case Kyra will inform the Customer first unless that law prohibits it.
2. Definitions
Terms such as "personal data", "processing", "controller", "processor", "sub-processor", "personal data breach", and "data subject" have the meanings given in the GDPR. "Customer Personal Data" means personal data Kyra processes on the Customer's behalf under the Service.
3. Subject-matter and details of processing
The subject-matter, duration, nature and purpose of the processing, the types of personal data, and categories of data subjects are set out in Annex 1.
4. Processor obligations (Art. 28(3))
Kyra will:
- process Customer Personal Data only on the Customer's documented instructions (§1);
- ensure persons authorised to process the data are under an appropriate duty of confidentiality;
- implement the technical and organisational measures in Annex 2 (Art. 32);
- respect the conditions for engaging sub-processors (§5);
- assist the Customer, taking into account the nature of processing, in responding to data-subject requests (§7) and in meeting its obligations under Arts. 32–36 (security, breach notification, DPIAs, prior consultation);
- at the Customer's choice, delete or return all Customer Personal Data at the end of the Service and delete existing copies, unless EU/member-state law requires storage (§8);
- make available information necessary to demonstrate compliance and allow for and contribute to audits (§9);
- immediately inform the Customer if, in its opinion, an instruction infringes data-protection law.
5. Sub-processors
- The Customer provides general authorisation for Kyra to engage the sub-processors listed in Annex 3 to deliver the Service.
- Kyra imposes data-protection obligations on each sub-processor that are no less protective than this DPA, and remains liable for their performance.
- Kyra will give the Customer at least [30] days' notice of any intended addition or replacement of a sub-processor (by updating Annex 3 and notifying the Customer's account contact). The Customer may object on reasonable data-protection grounds within that period; if the parties cannot resolve the objection, the Customer may terminate the affected part of the Service.
6. International transfers
Kyra hosts the core Service in the EU (Google Cloud, europe-west4,
Netherlands). Some sub-processors are located outside the EEA (notably the
United States). For any transfer of Customer Personal Data outside the EEA, the
parties rely on an adequacy decision or the SCCs (Module Two,
controller-to-processor, and Module Three for onward transfers), which are
incorporated by reference and completed by the details in the Annexes, together
with the supplementary measures described in Annex 2. [CONFIRM SCC modules,
docking clause, and per-sub-processor transfer mechanism with counsel.]
7. Data-subject requests
Taking into account the nature of the processing, Kyra will assist the Customer by appropriate technical and organisational measures, insofar as possible, to fulfil the Customer's obligation to respond to data-subject requests (access, rectification, erasure, restriction, portability, objection). If a data subject contacts Kyra directly about Customer Personal Data, Kyra will forward the request to the Customer and not respond directly except to confirm receipt, unless legally required.
8. Personal data breach
Kyra will notify the Customer without undue delay and in any case within [72] hours after becoming aware of a personal data breach affecting Customer Personal Data, and will provide the information the Customer reasonably needs to meet its own notification obligations (Arts. 33–34), including the nature of the breach, likely consequences, and measures taken or proposed.
9. Audits
Kyra will make available to the Customer the information necessary to demonstrate compliance with Art. 28 and allow for and contribute to audits, including inspections, conducted by the Customer or an auditor it mandates. To protect confidentiality and Service security, the parties will agree reasonable scope, notice, frequency [e.g. once per 12 months unless a breach or regulator requires more], and cost; Kyra may satisfy audit requests in the first instance by providing relevant third-party reports, certifications, or its security documentation.
10. Deletion and return
On termination or expiry of the Service, Kyra will, at the Customer's choice, delete or return Customer Personal Data and delete existing copies within [30] days, except to the extent EU/member-state law requires retention. In particular, billing and transaction records that form part of Kyra's own financial administration are retained for the Dutch fiscal-retention period (7 years — bewaarplicht, AWR art. 52), after which they are destroyed; such retained records are kept de-identified to the extent the fiscal purpose allows. Backups are purged on a rolling cycle (Annex 2).
11. Liability and precedence
Each party's liability under this DPA is subject to the limitations and exclusions in the Terms. This DPA does not limit any rights data subjects have under the GDPR. In case of conflict, this DPA prevails over the Terms on data-protection matters, and the SCCs prevail over this DPA on transfer matters.
12. Term
This DPA takes effect when the Customer accepts the Terms or signs an order form and continues for as long as Kyra processes Customer Personal Data.
Annex 1 — Description of processing
| Subject-matter | Provision of the Kyra H.I. voice-assistant and notes Service to the Customer |
| Duration | For the term of the Service plus the deletion period in §10 |
| Nature & purpose | Hosting, storage, transmission, indexing, speech-to-text and text-to-speech conversion, AI-assisted generation and organisation of Customer content, account and access management, billing |
| Types of personal data | Account/identity data (name, email, profile image, provider ID); user-generated content (notes, files, voice input, transcripts, summaries, memories); usage, device, and log data; billing metadata. Special-category data is not intended to be processed (see Privacy Policy §7) |
| Categories of data subjects | The Customer's authorised users (e.g. employees, members) and any individuals referenced in content they create |
Annex 2 — Technical and organisational measures (Art. 32)
Kyra applies, and keeps under review, measures appropriate to the risk, including:
- Encryption in transit — TLS for all client/server and inter-service traffic.
- Encryption of conversation content at rest — transcripts, session summaries, and memories are encrypted at the application layer (AES-256-GCM) with per-user data keys wrapped by a key-management service (KMS); keys are not stored in plaintext alongside the data.
- EU data residency — core hosting, database, and storage in Google Cloud
europe-west4(Netherlands). - Access control & least privilege — role-based access, deny-by-default tenant isolation between organisations/workspaces, and least-privilege service accounts; administrative access is restricted and authenticated.
- Secrets management — credentials and signing keys held in managed secret storage; refresh/API tokens stored only as one-way hashes.
- Logging & monitoring — operational logs exclude user content and secrets; security-relevant events are recorded for detection and response.
- Backups & resilience — encrypted backups in an EU region, purged on a rolling cycle (within [35] days); migration and restore procedures verify readability before cut-over.
- Secure development & vulnerability management — code review, dependency and container scanning, pinned build dependencies, and pre-deployment security checks.
- Personnel — confidentiality obligations and need-to-know access for staff.
Known limitation (alpha): end-to-end encryption of the central Kyra-managed notebook at rest is on the roadmap but not yet implemented; until it is, the central notebook must not be used for special-category or highly sensitive data (Privacy Policy §2.2, §7). [Keep this annex in sync with the project risk register as controls land.]
Annex 3 — Authorised sub-processors
| Sub-processor | Purpose | Location | Transfer safeguard |
|---|---|---|---|
| Google Cloud | Hosting, database, storage, KMS | EU (europe-west4) | EU |
| Anthropic | Language model (assistant responses, summaries) | US | SCCs |
| Deepgram | Speech-to-text | US | SCCs |
| Cartesia | Text-to-speech | US | SCCs |
| LiveKit | Real-time voice transport | [US/EU] | [SCCs] |
| Stripe | Payments & billing | US / EU | SCCs / adequacy |
| Google (Sign-In, FCM) | Authentication, push notifications | US | SCCs |
| GitHub (Microsoft) | Sign-in; optional notes destination | US | SCCs |
| [Email/SMTP provider] | Transactional email | [TBD] | [TBD] |
Contact
Data protection / DPA requests: hello@kyra-hi.com · [OPERATING_BV_LEGAL_NAME] · [REGISTERED_ADDRESS]