Loading…
Loading…
This Data Processing Agreement ("DPA") supplements the Kyrospect Terms of Service. Kyrospect is the data controller for the account, billing, and product-usage data it collects directly. The Customer (employer) is the data controller for employee activity data, and Kyrospect acts as a processorof that activity data on the Customer's documented instructions.
The DPA covers obligations under: EU/UK GDPR Article 28; India Digital Personal Data Protection Act 2023; US CCPA/CPRA; and equivalent local data-protection regimes. In case of conflict, the regime granting the data subject greater protection prevails.
This DPA governs Kyrospect's processing of employee activity data on the Customer's behalf. Account, billing, and product-usage data that Kyrospect collects directly is processed by Kyrospect as a controller under its Privacy Policy and falls outside the processor obligations in this DPA.
Kyrospect processes personal data only on Customer's documented instructions, including the configuration of workspace policies, retention windows, and integration choices. Where required by law, Kyrospect will inform Customer before complying with a legal obligation that requires processing beyond Customer's instructions.
All Kyrospect personnel with access to systems are bound by written confidentiality obligations, which survive termination. Access is granted strictly on a least-privilege basis.
Kyrospect implements technical and organisational measures appropriate to the risk, including:
Kyrospect engages sub-processors for infrastructure, payments, deliverability, and analytics. Each sub-processor is bound by data-protection obligations equivalent to those in this DPA. The current sub-processor list is provided to Customers on request and via the Trust Center. Customer will receive 30 days' notice of material additions and may object on reasonable grounds; if no acceptable resolution is reached, Customer may terminate the affected Subscription with pro-rata refund.
Customer data is hosted with leading cloud infrastructure providers. Data for customers in India is hosted in an India (Mumbai) region. As Kyrospect expands, data for customers in the United States and United Kingdom will be hosted in their respective regions. Where data is accessed or transferred across borders (for example, operational or support access from India), Kyrospect relies on appropriate safeguards, including Standard Contractual Clauses where applicable.
Where personal data is transferred from the EEA, UK, or Switzerland to a country without an adequacy decision, transfers are governed by the EU Standard Contractual Clauses (Module 2 — Controller to Processor) and the UK International Data Transfer Addendum where applicable. For Indian data, transfers comply with the cross-border transfer regime under the DPDP Act 2023 and any restrictions notified by the central government in respect of restricted destinations. Customer authorises transfers necessary to deliver the Service.
Kyrospect provides reasonable assistance to enable the Customer to respond to data-subject requests (access, rectification, erasure, restriction, portability, objection). Where Kyrospect receives such a request directly, it forwards the request to Customer without responding to the data subject, except as required by law.
Kyrospect notifies the Customer-controller without undue delay, and where feasible within 72 hours, of becoming aware of a personal data breach affecting Customer Data, providing information sufficient to enable Customer to meet its own breach-notification obligations.
Kyrospect makes available the information necessary to demonstrate compliance, including security overviews and current control notes. On reasonable advance notice and at Customer's expense, Customer or its independent third-party auditor (subject to confidentiality) may conduct an audit limited to verifying compliance with this DPA, no more than once per calendar year, except where required by law or following a substantiated security incident.
On termination of the Subscription, Kyrospect makes Customer Data available for export for 30 days, after which it is permanently deleted from primary systems within 30 days and from backups within 90 days, unless retention is required by law.
Liability under this DPA is subject to the limitations in the Terms of Service. Nothing in this DPA limits liability that cannot be limited under applicable data-protection law.
In the event of conflict, the order of precedence is: (1) the SCCs and equivalent transfer mechanisms, (2) this DPA, (3) the Terms of Service.
For DPA queries, sub-processor lists, or to request a signed countersigned DPA package:
legal@kyrospect.com