Data Processing Agreement

Last updated: 2026-07-26

This Data Processing Agreement ("DPA") is entered into by and between Kandir, Inc., a Delaware corporation with a principal place of business at 221 River Road, Saunderstown, Rhode Island 02874, United States of America ("Kandir," "Processor," or "we"), and the business entity that enters into an Order Form with Kandir or completes a Self-Service Subscription for the Services ("Customer," "Controller," or "you"), each as defined in the Kandir Terms of Service. Kandir and Customer are each a "Party" and together the "Parties."

This DPA is incorporated by reference into, and forms part of, the Kandir Terms of Service (available at www.kandir.io/terms) and any Order Form between the Parties (together, the "Agreement"). By entering into an Order Form, or by completing a Self-Service Subscription, Customer agrees to this DPA to the extent Kandir Processes Personal Data on Customer's behalf in the course of providing the Kandir platform and related services (the "Services"). No separate signature of this DPA is required for it to take effect; see the closing note for how Kandir handles requests for a countersigned copy. This DPA applies as of the date Kandir first Processes Personal Data on Customer's behalf under the Agreement (the "DPA Effective Date"). In the event of a conflict between this DPA and the Agreement with respect to the subject matter of data protection, this DPA controls. Capitalized terms not defined in this DPA have the meaning given in the Kandir Terms of Service or the applicable Order Form.

1. Definitions

"Applicable Laws" means the laws, rules, regulations, court orders, and other binding requirements of a relevant government authority that apply to or govern a party.

"Applicable Data Protection Laws" means the Applicable Laws that govern how the Services may Process Personal Data, including, as applicable, the EU General Data Protection Regulation 2016/679 ("GDPR"), the UK GDPR and Data Protection Act 2018, the Swiss Federal Act on Data Protection, the California Consumer Privacy Act as amended by the California Privacy Rights Act ("CCPA"), and other U.S. state comprehensive privacy laws, in each case to the extent applicable to the Processing of Personal Data under this DPA.

"Controller" means the entity that determines the purposes and means of the Processing of Personal Data (or "business" under the CCPA).

"Customer Data" has the meaning given in the Kandir Terms of Service (data submitted or made available by or on behalf of Customer or its Authorized Users to the Services, including data connected through Third-Party Integrations). References to Customer Data in this DPA are to the subset of Customer Data that constitutes Personal Data.

"Data Subject" means an identified or identifiable natural person to whom Personal Data relates.

"Personal Data" means any information relating to an identified or identifiable natural person that is Processed by Kandir on behalf of Customer as part of Customer Data (or "personal information" under the CCPA).

"Personal Data Breach" means a breach of security leading to the accidental or unlawful destruction, loss, alteration, unauthorized disclosure of, or access to, Personal Data transmitted, stored, or otherwise Processed by Kandir.

"Process" / "Processing" means any operation performed on Personal Data, whether or not by automated means, including collection, recording, organization, structuring, storage, adaptation, retrieval, use, disclosure, or erasure.

"Processor" means the entity that Processes Personal Data on behalf of the Controller (or "service provider" / "contractor" under the CCPA).

"Provider Security Contact" means Kandir's designated point of contact for security and compliance inquiries under this DPA: steve@kandir.io.

"Report" means the audit report(s) or certification(s) of compliance described in the Security Policy in Annex B, prepared on Kandir's behalf against the standards identified there.

"Security Measures" means the technical and organizational measures described in Annex B.

"Standard Contractual Clauses" or "SCCs" means the standard contractual clauses for the transfer of personal data to third countries pursuant to the GDPR, as annexed to European Commission Implementing Decision 2021/914.

"Sub-processor" means any Processor engaged by Kandir to Process Personal Data on Kandir's behalf in connection with the Services.

2. Scope of Processing and Roles of the Parties

2.1 Roles. Where Customer is a Controller of Personal Data, Kandir will be deemed a Processor Processing that Personal Data on Customer's behalf. Where Customer is itself a Processor of Personal Data on behalf of its own Controller, Kandir will be deemed a Sub-processor of that Personal Data, and Customer will comply with all Applicable Laws that apply to Customer as a Processor, including any Sub-processor requirements imposed by Customer's agreement with its Controller. In either case, Kandir will Process Personal Data only as a Processor or Sub-processor acting on behalf of Customer and not as a Controller or business in its own right, except as expressly set out in Section 8 (Aggregated and De-Identified Data).

2.2 Details of Processing. The subject matter, duration, nature and purpose of Processing, the types of Personal Data, and categories of Data Subjects are described in Annex A to this DPA. If Kandir updates the Services to add or change products, features, or functionality, Kandir may update the categories of Data Subjects, categories of Personal Data, and the nature and purpose of Processing described in Annex A as needed to reflect those updates, by notifying Customer of the change.

2.3 Customer Instructions. Kandir will Process Personal Data only in accordance with Customer's documented instructions, including as set out in the Agreement, this DPA, and Customer's use and configuration of the Services, unless required to do otherwise by Applicable Law. If Kandir believes an instruction violates Applicable Data Protection Laws, Kandir will promptly inform Customer, and Kandir may suspend performance of that instruction pending resolution. Customer represents that it has given, and will only give, instructions that comply with Applicable Laws.

2.4 No Sale or Sharing. Kandir does not sell or share Personal Data, and does not use Personal Data for any purpose other than to provide and improve the Services on Customer's behalf, as permitted under this DPA and Applicable Data Protection Laws.

2.5 Customer's Compliance. Customer represents and warrants that it has complied with, and will continue to comply with, all Applicable Data Protection Laws in connection with its provision of Personal Data to Kandir and its use of the Services, including making all disclosures, obtaining all consents, and implementing all safeguards required under Applicable Data Protection Laws before submitting Personal Data to the Services.

3. Confidentiality

Kandir will ensure that any person it authorizes to Process Personal Data (including employees, contractors, and Sub-processors) is subject to a binding written obligation of confidentiality (whether contractual or statutory) and Processes Personal Data only as necessary to perform their role in connection with the Services.

4. Security of Processing

4.1 Kandir will implement and maintain the technical and organizational Security Measures described in Annex B, designed to protect Personal Data against Personal Data Breaches and to ensure a level of security appropriate to the risk, taking into account the state of the art, the costs of implementation, and the nature, scope, context, and purposes of Processing.

4.2 Kandir may update the Security Measures over time, provided that any such update does not materially decrease the overall security of the Services.

5. Sub-processors

5.1 General Authorization. Customer provides Kandir with a general authorization to engage Sub-processors to Process Personal Data in connection with the Services, subject to the requirements of this Section 5. Kandir's current list of Sub-processors as of the DPA Effective Date is set out in Annex C.

5.2 Notice of New Sub-processors. Kandir will notify Customer (by email or by posting an update to a designated subprocessor page) before engaging a new Sub-processor to Process Personal Data, and will provide Customer at least 10 days to object on reasonable data protection grounds. If Customer objects and the Parties are unable to resolve the objection in good faith within 30 days, Customer may terminate the affected Services by written notice, without penalty, as its sole and exclusive remedy.

5.3 Sub-processor Obligations. Kandir will impose data protection terms on each Sub-processor that are substantially no less protective than those set out in this DPA, appropriate to the nature of the services provided by that Sub-processor, and Kandir remains liable to Customer for each Sub-processor's performance of its data protection obligations, including the acts and omissions of its Sub-processors in Processing Personal Data. Kandir will notify Customer of any failure by a Sub-processor to fulfill a material obligation regarding Personal Data. Upon Customer's request, Kandir will share a copy of its agreement with the relevant Sub-processor, which Kandir may redact to protect business or other confidential or personal information not relevant to Customer's review.

6. Data Subject Rights and Third-Party Inquiries

6.1 Taking into account the nature of the Processing, Kandir will provide reasonable assistance to Customer, through appropriate technical and organizational measures, to enable Customer to respond to requests from Data Subjects seeking to exercise their rights under Applicable Data Protection Laws (including rights of access, rectification, erasure, restriction, portability, and objection).

6.2 If Kandir receives any inquiry or request from anyone other than Customer about the Processing of Personal Data under this DPA — including a request from a Data Subject, or a judicial, administrative, or regulatory order — Kandir will notify Customer and will not respond to the request without Customer's prior consent, unless legally required to do so or prohibited by Applicable Law from notifying Customer. Where permitted, Kandir will follow Customer's reasonable instructions regarding the request, including providing status updates.

6.3 If a Data Subject makes a valid request under Applicable Data Protection Laws to delete or opt out of Customer's provision of Personal Data to Kandir, Kandir will assist Customer in fulfilling that request. Kandir will cooperate with and provide reasonable assistance to Customer, at Customer's expense, in connection with any legal response or procedural action Customer takes in response to a third-party request about Kandir's Processing of Personal Data under this DPA.

7. Personal Data Breach Notification

7.1 Kandir will notify Customer without undue delay, and in any event within 72 hours of becoming aware, after confirming a Personal Data Breach affecting Customer Data.

7.2 Such notification will include, to the extent then known, a description of the nature of the Personal Data Breach, the categories and approximate number of Data Subjects and records affected, the likely consequences, and the measures taken or proposed to address the breach and mitigate its effects. Kandir will provide updates as material new information becomes available.

7.3 Kandir will provide reasonable cooperation and information to Customer as necessary for Customer to fulfill its own breach notification obligations to regulators or Data Subjects under Applicable Data Protection Laws. Kandir's notification of, or response to, a Personal Data Breach under this Section will not be construed as an acknowledgment of fault or liability.

8. Data Protection Impact Assessments; Aggregated and De-Identified Data

8.1 Kandir will provide reasonable assistance to Customer, taking into account the nature of Processing and information available to Kandir, in connection with any data protection impact assessments, data transfer impact assessments, or prior consultations with supervisory authorities that Customer reasonably believes are required under Applicable Data Protection Laws.

8.2 Aggregated and De-Identified Data. Notwithstanding anything to the contrary, Kandir may use Customer Data to create aggregated, anonymized, or de-identified data that does not identify Customer or any Data Subject ("Aggregated Data") for purposes of operating, analyzing, supporting, and improving the Services, provided such Aggregated Data is not reasonably capable of being re-identified. Aggregated Data is not Personal Data and this DPA does not restrict Kandir's use of it.

8.3 CCPA Certification. To the extent Kandir Processes personal information subject to the CCPA as a service provider or contractor, Kandir certifies that it understands the restrictions in this Section 8 and Section 2.4 and will comply with them.

9. AI-Assisted Processing

9.1 Nature of AI Processing. Customer acknowledges that the Services use machine learning and generative AI models, including large language models provided by third-party AI subprocessors identified in Annex C, to analyze Customer Data and generate account intelligence, summaries, and recommendations ("AI Outputs").

9.2 No Training on Customer Data. Kandir will not use Customer Data to train, fine-tune, or improve any AI or machine learning model for the benefit of any party other than Customer, and will not permit its AI Sub-processors to retain or use Customer Data to train models for their own purposes, except where such Sub-processor contractually commits not to retain or train on the data (e.g., via an enterprise/API-tier agreement rather than a consumer product) or where Customer has separately opted in.

9.3 Human Oversight and Accuracy. AI Outputs are provided as decision-support and may contain inaccuracies. Customer remains responsible for reviewing AI Outputs before relying on them for consequential decisions. Kandir will maintain reasonable controls to allow Customer to review, correct, or disable specific AI-driven features within the Services where technically feasible.

9.4 Sub-processor Flow-Down. Kandir will ensure each AI Sub-processor Processing Personal Data is bound by data protection terms consistent with Section 5.3 and, where applicable, executes SCCs or another valid transfer mechanism consistent with Section 11.

10. Audit & Reports

10.1 Audit Rights. Kandir will give Customer information reasonably necessary to demonstrate its compliance with this DPA, and will allow for and contribute to audits, including inspections by Customer, to assess Kandir's compliance with this DPA. Kandir may restrict access to data or information where Customer's access would negatively impact Kandir's intellectual property rights, confidentiality obligations, or other obligations under Applicable Laws. Customer agrees that it will exercise its audit rights under this DPA and under Applicable Data Protection Laws by instructing Kandir to comply with Sections 10.2 and 10.3 below. Kandir will maintain records of its compliance with this DPA for 3 years after this DPA ends.

10.2 Security Reports. Kandir is regularly audited against the standards defined in the Security Policy in Annex B by independent third-party auditors. Upon written request, Kandir will give Customer, on a confidential basis, a summary copy of its then-current Report so Customer can verify Kandir's compliance with those standards.

10.3 Security Due Diligence. In addition to the Report, Kandir will respond to reasonable requests for information made by Customer to confirm Kandir's compliance with this DPA, including responses to information security, due diligence, and audit questionnaires. Requests must be in writing, directed to the Provider Security Contact, and may be made no more than once per 12-month period (except following a Personal Data Breach).

11. International Data Transfers

11.1 Authorization. Kandir primarily hosts and Processes Customer Data in the United States. Customer agrees that Kandir may transfer Personal Data outside the EEA, the United Kingdom, or other relevant territory as necessary to provide the Services. Where Kandir transfers Personal Data to a territory not covered by an adequacy decision, Kandir will implement appropriate safeguards for that transfer consistent with Applicable Data Protection Laws.

11.2 EEA Transfers. If the GDPR protects the transfer, the transfer is from Customer within the EEA to Kandir outside the EEA, and the transfer is not covered by a European Commission adequacy decision, the Parties are deemed to have signed the Standard Contractual Clauses annexed to European Commission Implementing Decision 2021/914 (the "EEA SCCs"), which are incorporated by reference and completed as follows: Module Two (Controller to Processor) applies where Customer is a Controller; Module Three (Processor to Sub-processor) applies where Customer is a Processor and Kandir is a Sub-processor. For each module: the optional docking clause in Clause 7 does not apply; in Clause 9, Option 2 (general written authorization) applies, with a minimum prior notice period for Sub-processor changes as set out in Section 5.2 of this DPA; the optional language in Clause 11 does not apply; all square brackets in Clause 13 are removed; in Clause 17 (Option 1), the EEA SCCs are governed by the laws of the Governing Member State; and in Clause 18(b), disputes will be resolved in the courts of the Governing Member State. Governing Member State (EEA): Ireland.

11.3 UK Transfers. If the UK GDPR protects the transfer, the transfer is from Customer within the United Kingdom to Kandir outside the United Kingdom, and the transfer is not covered by UK adequacy regulations, the Parties are deemed to have signed the UK International Data Transfer Addendum to the EEA SCCs (the "UK Addendum"), which is incorporated by reference. Annex A and Annex C of this DPA contain the information required by the UK Addendum's Tables 1 and 2. Neither Party may end the UK Addendum unilaterally under its Section 19; if the ICO issues a revised Addendum, the Parties will work in good faith to update this DPA accordingly. Governing Member State (UK): England and Wales.

11.4 Swiss and Other Transfers. For transfers to which Swiss law (rather than the law of an EEA member state or the United Kingdom) applies to the international nature of the transfer, references to the GDPR in the EEA SCCs are read, to the extent legally required, as references to the Swiss Federal Act on Data Protection, and the competent supervisory authority is the Swiss Federal Data Protection and Information Commissioner.

11.5 The Parties will complete the applicable annexes to the EEA SCCs and UK Addendum using the information in Annex A and Annex C of this DPA.

12. Return or Deletion of Personal Data

Upon termination or expiration of the Agreement, or upon Customer's written request, Kandir will, at Customer's election, delete or return all Customer Data (including Personal Data) in its possession, except to the extent applicable law requires Kandir to retain some or all of the Customer Data, or such data is contained in encrypted backups made in the ordinary course of business, in which case Kandir will continue to protect and isolate such retained data and will delete it in accordance with its standard data retention and deletion schedule.

13. Personnel

Kandir will ensure that its personnel authorized to Process Personal Data have received appropriate training on their responsibilities and are subject to confidentiality obligations, and that access to Personal Data is limited to personnel who require such access to perform their job functions in connection with the Services.

14. Cooperation with Regulators

Each Party will, upon request, provide the other Party with reasonable cooperation and information necessary for that Party to respond to inquiries from a supervisory authority or other data protection regulator relating to the Processing of Personal Data under this DPA.

15. Liability

15.1 Liability Caps. To the maximum extent permitted under Applicable Data Protection Laws, each Party's total cumulative liability arising out of or related to this DPA, whether in contract, tort, or under any other theory of liability, is subject to the limitations and exclusions of liability set out in the Agreement. Any reference in the Agreement to the liability of a Party means the aggregate liability of that Party under both the Agreement and this DPA together, and not separately.

15.2 Related-Party Claims. Any claim against Kandir or its affiliates arising out of or related to this DPA may only be brought by the Customer entity that is a party to the Agreement.

15.3 Exceptions. This Section 15 does not limit any liability to an individual regarding that individual's rights under Applicable Data Protection Laws, and does not limit any liability between the Parties for violations of the EEA SCCs or UK Addendum described in Section 11.

16. Term and Termination

This DPA will take effect on the DPA Effective Date and will remain in effect for as long as Kandir Processes Personal Data on behalf of Customer under the Agreement, notwithstanding the expiration or termination of the Agreement until such Processing ends.

17. General

17.1 Order of Precedence. In the event of a conflict between the SCCs (if and to the extent they apply), this DPA, and the Agreement, the SCCs will prevail with respect to transfers they govern, then this DPA, then the Agreement.

17.2 Governing Law. This DPA is governed by the same governing law and jurisdiction provisions as the Agreement, without regard to conflict-of-laws principles, except where the SCCs specify otherwise for the transfers they govern.

17.3 Amendments. Kandir may update this DPA from time to time to reflect changes in Applicable Data Protection Laws or Kandir's data processing practices, provided such updates do not materially reduce the protections afforded to Personal Data. Material changes will be communicated to Customer with reasonable advance notice.

17.4 Severability. If any provision of this DPA is held invalid or unenforceable, the remaining provisions will remain in full force and effect, and the invalid provision will be deemed modified to the minimum extent necessary to make it enforceable.

17.5 Entire Agreement. This DPA, together with its Annexes and the Agreement, constitutes the entire agreement between the Parties regarding its subject matter and supersedes all prior agreements relating to data processing between the Parties.

17.6 Notices. Notices to Kandir under this DPA should be sent to Kandir, Inc., 221 River Road, Saunderstown, Rhode Island 02874, United States of America, Attn: Ryan Bullard, CEO. Security and compliance inquiries under Section 10.3 should be directed to the Provider Security Contact: steve@kandir.io.

Acceptance

Customer agrees to this DPA by entering into an Order Form with Kandir or by completing a Self-Service Subscription; no separate signature of this DPA is required. Kandir will, on request, provide and countersign a copy of this DPA for Customers whose internal procurement or vendor-review process requires a signed copy — for example, using the optional signature block below. A countersigned copy does not change the substance of this DPA; it is the same terms in an executed form for Customer's records.

KANDIR, INC.

221 River Road, Saunderstown, RI 02874

Signature

Ryan Bullard, CEO — Name / Title

Date

[CUSTOMER LEGAL NAME]

 

Signature

Name / Title

Date

Annex A: Details of Processing

CategoryDescription
Subject matter Provision of the Kandir agentic account intelligence platform to Customer under the Agreement.
Duration For the term of the Agreement, plus any period during which Kandir retains Customer Data thereafter in accordance with Section 12 of this DPA.
Nature and purpose of Processing Collection, storage, analysis, and generation of AI-derived insights, summaries, and recommendations from account, contact, and CRM/collaboration-tool data connected by Customer, for the purpose of providing account intelligence to Customer's sales and customer success teams.
Categories of Data Subjects Customer's employees and authorized users of the Services; and the business contacts of Customer's customers/prospects contained in connected systems (e.g., names, business contact details, and account-related communications), as configured by Customer.
Categories of Personal Data Business contact information (name, title, company, email, phone); account and opportunity metadata; communication and engagement metadata (e.g., email/meeting activity) sourced from connected systems such as CRM and Microsoft 365; user credentials and platform usage data. Kandir does not intentionally collect special categories of data (e.g., health, financial account numbers, government IDs) and Customer agrees not to submit such data to the Services.
Frequency of transfer Continuous, for as long as Customer's connected integrations remain active.
Data exporter / importer (for SCCs) Exporter: Customer. Importer: Kandir, Inc. and applicable Sub-processors listed in Annex C.

Annex B: Technical and Organizational Security Measures

Control AreaMeasures
Certifications Kandir maintains, or is undergoing certification for, the following: SOC 2 Type I; CASA (Cloud Application Security Assessment) Security Certification. Upon written request to the Provider Security Contact (steve@kandir.io), no more than once per 12-month period, Kandir will provide Customer a confidential summary of its then-current Report.
Access control Role-based access control, unique user credentials, principle of least privilege, and periodic access reviews for systems Processing Customer Data.
Encryption Encryption of Personal Data in transit (TLS 1.2+) and at rest using industry-standard encryption.
Authentication Multi-factor authentication required for administrative and privileged access to production systems.
Network security Logical network segmentation, firewalls, and monitoring of production environments hosted with a reputable cloud infrastructure provider.
Vulnerability management Periodic vulnerability scanning and a process for prioritizing and remediating identified vulnerabilities.
Logging and monitoring Logging of access to production systems and monitoring for anomalous or unauthorized activity.
Incident response A documented incident response plan, including procedures for detecting, investigating, and notifying affected parties of a Personal Data Breach consistent with Section 7.
Business continuity Regular data backups and a business continuity / disaster recovery plan for production systems.
Personnel security Confidentiality obligations and security awareness training for personnel with access to Customer Data; background checks where permitted by law.
Vendor management Due diligence and contractual data protection requirements imposed on Sub-processors consistent with Section 5.
Data minimization Configuration of integrations to collect only the categories of data reasonably necessary to provide the Services, as configured by Customer.

Annex C: Authorized Sub-processors

Sub-processorPurposeLocation
Amazon Web Services, Inc. Cloud infrastructure — compute, storage, database, key management (KMS), and identity (Amazon Cognito) United States
Anthropic, PBC AI / large language model — powers product features United States
OpenAI, L.L.C. AI / large language model — powers product features and text embeddings United States
Stripe, Inc. Payment processing and subscription billing United States
MailerSend Transactional email delivery United States
Sentry Application performance and error monitoring United States
Google LLC Business email, productivity, and collaboration United States