This Data Processing Agreement (the “DPA”) forms part of the Terms of Service(the “Agreement”) between Kapvel (“Processor”, “we”, “us”) — 353 Lexington Avenue, 4th Floor Ste 483, New York, NY 10016, United States — and the customer that uses Kapvel (“Controller”, “you”).
It applies when we process Personal Data on your behalf in connection with kapvel.com and its subdomains (the “Service”). It supplements our Privacy Policy, which covers data we process as a controller (for example account and billing information about your users as our customers).
By creating a workspace, inviting members, or otherwise using the Service in a way that involves Personal Data, you agree to this DPA. If you need a countersigned copy for procurement, contact us through our contact page.
1. Definitions
- Personal Data means any information relating to an identified or identifiable natural person that is processed under this DPA.
- Customer Content means content you and your authorized users submit to the Service — projects, issues, comments, documents, spreadsheets, whiteboards, attachments, service-desk requests, and data imported from other tools.
- Subprocessor means a third party engaged by us to process Personal Data on your behalf in connection with the Service.
- Applicable Data Protection Law means privacy and data-protection laws that apply to the processing of Personal Data under this DPA, including where applicable the EU/UK GDPR and similar laws.
- Terms such as “controller”, “processor”, “processing”, “data subject”, and “personal data breach” have the meanings given in Applicable Data Protection Law.
2. Roles of the parties
For Personal Data in Customer Content, you are the controller (or processor acting on behalf of a third-party controller) and Kapvel is the processor. You determine the purposes and means of that processing; we process it only to provide and support the Service as described in the Agreement and this DPA.
For account registration, authentication, billing, product analytics necessary to operate Kapvel as a business, and similar processing about you as our customer, Kapvel acts as an independent controller. That processing is described in our Privacy Policy and is outside the scope of this DPA.
3. Subject matter, nature, and purpose
- Subject matter: processing of Personal Data contained in Customer Content in connection with the Service.
- Duration: for the term of the Agreement and until Personal Data is deleted or returned under Section 11.
- Nature and purpose: hosting, storage, transmission, display, backup, support, security, and related technical processing solely to provide, maintain, secure, and support the Service at your direction.
- Types of Personal Data: whatever you and your users choose to include in Customer Content — which may include names, email addresses, job titles, contact details, support request content, and other identifiers or content you upload.
- Categories of data subjects: your employees, contractors, and other authorized users; and, where you use service-desk or similar features, your own customers or end users who interact with your workspace.
You are responsible for the accuracy of Personal Data you submit and for ensuring you have a lawful basis and the necessary rights to process it through the Service.
4. Processor obligations
We will:
- process Personal Data only on your documented instructions, which include use of the Service’s configuration and features, the Agreement, and this DPA, unless Applicable Data Protection Law requires otherwise (in which case we will notify you unless legally prohibited);
- ensure persons authorized to process Personal Data are bound by confidentiality obligations;
- implement appropriate technical and organizational measures to protect Personal Data (see Section 6);
- engage Subprocessors only as described in Section 7;
- assist you, taking into account the nature of processing, with responding to data-subject requests and with your obligations around security, breach notification, data-protection impact assessments, and consultations with regulators, insofar as reasonably possible;
- at your choice, delete or return Personal Data after the end of the provision of services relating to processing, and delete existing copies unless retention is required by law;
- make available information reasonably necessary to demonstrate compliance with this DPA and allow audits as described in Section 10.
We will not sell Personal Data in Customer Content, use it for advertising, or use it to train machine-learning models for our own products.
5. Your obligations
You will:
- ensure that your instructions to us comply with Applicable Data Protection Law;
- configure the Service, manage user access, and handle Customer Content in a manner consistent with your obligations as controller;
- not instruct us to process Personal Data in a way that would cause us to violate Applicable Data Protection Law;
- be solely responsible for the content of notices to data subjects and for obtaining any consents or authorizations required for your use of the Service.
6. Security measures
Taking into account the state of the art, costs of implementation, and the nature, scope, context, and purposes of processing, we maintain appropriate technical and organizational measures designed to protect Personal Data against unauthorized or unlawful processing and against accidental loss, destruction, or damage. These include, without limitation:
- encryption of data in transit (TLS) and at rest by our infrastructure providers;
- access controls and credential protection for production systems;
- workspace access enforced by role-based permissions and row-level security in the database;
- logging of staff access to customer data when needed for support or incident response;
- password checks against known-breach corpora at signup;
- backup and recovery practices operated by our infrastructure providers.
No method of transmission or storage is perfectly secure. Report suspected vulnerabilities through our contact page.
7. Subprocessors
You authorize us to engage Subprocessors to process Personal Data as needed to provide the Service. Our current Subprocessors include:
- Supabase — database, authentication, file storage, and realtime infrastructure (hosted on AWS, US region).
- Vercel — application hosting and content delivery.
- Stripe — payment processing and subscription management (primarily account/billing data).
- Resend — transactional email delivery.
Each Subprocessor is bound by data-protection obligations substantially no less protective than those in this DPA with respect to the processing they perform. We remain responsible to you for Subprocessor performance under this DPA.
We will give notice of material changes to Subprocessors (for example by updating this page or the Privacy Policy, or by email for significant additions). If you reasonably object to a new Subprocessor on data-protection grounds, notify us through our contact page within 30 days of notice. We will work in good faith to address the objection; if we cannot, you may terminate the affected Service as your sole remedy.
8. International transfers
We are a US company and process Personal Data in the United States. Where Applicable Data Protection Law requires a transfer mechanism for Personal Data transferred from the EEA, UK, or Switzerland to the United States (or another country without an adequacy decision), the parties rely on the European Commission’s Standard Contractual Clauses (and UK / Swiss equivalents where applicable) Module Two (controller to processor), completed as follows:
- Data exporter: you (the Controller).
- Data importer: Kapvel (the Processor).
- Annex I details: as described in Section 3 of this DPA.
- Annex II technical and organizational measures: as described in Section 6.
- Annex III subprocessors: as listed in Section 7 (as updated from time to time).
If you require a separately executed copy of the Standard Contractual Clauses, request it through our contact page.
9. Personal data breaches
We will notify you without undue delay after becoming aware of a personal data breach affecting Personal Data we process under this DPA, and will provide information reasonably available to us to help you meet your own notification obligations. Our notice will describe, where known: the nature of the breach, the categories and approximate number of data subjects and records concerned, likely consequences, and measures taken or proposed to address it.
Notification of a breach is not an admission of fault or liability.
10. Audits and information
Upon written request, and no more than once per twelve-month period (unless required by a regulator or following a personal data breach), we will provide information reasonably necessary to demonstrate compliance with this DPA — for example summaries of relevant security practices or third-party reports we are permitted to share. Any on-site or intrusive audit is subject to reasonable advance notice, confidentiality, and our security policies, and you bear your own costs unless the audit reveals a material breach of this DPA by us.
11. Return and deletion
During the term of the Agreement, you may export or delete Customer Content using the Service’s features where available. After termination or upon written request through our contact page, we will delete Personal Data in Customer Content within 30 days, except for residual copies in backups that expire on a rolling basis, and except for records we must retain under Applicable Data Protection Law or other legal obligation. At your written request before deletion completes, we will make Customer Content available for export in a reasonable format.
12. Liability
Each party’s liability under this DPA is subject to the limitations and exclusions of liability in the Agreement, except to the extent Applicable Data Protection Law prohibits such limitation.
13. Term and conflict
This DPA remains in effect for as long as we process Personal Data on your behalf under the Agreement. If there is a conflict between this DPA and the Agreement regarding the processing of Personal Data, this DPA controls. If Applicable Data Protection Law requires additional terms, the parties will negotiate them in good faith.
14. Changes
We may update this DPA from time to time to reflect changes in the Service, Subprocessors, or Applicable Data Protection Law. For material changes we will give reasonable notice by email or in the product before they take effect. The “Last updated” date above always reflects the current version. Continuing to use the Service after that means you accept the updated DPA, unless you terminate under the Agreement.
15. Contact
Questions about this DPA, Subprocessor changes, audit requests, or signed copies: reach us through our contact page or write to Kapvel, 353 Lexington Avenue, 4th Floor Ste 483, New York, NY 10016, United States. See also our Privacy Policy and Terms of Service.