Data Processing Addendum (DPA)
Last updated: August 4, 2026
This Data Processing Addendum ("DPA") forms part of the agreement between Adsero, LLC, a Florida limited liability company doing business as Kraitos and providing the Kraitos AIDR service ("Processor", "we", "us"), and the customer that subscribes to the Service ("Customer", "Controller", "you") (together, the "Agreement"). It governs the processing of personal data by the Processor on behalf of the Controller in connection with Kraitos AIDR (aidr.kraitos.io).
Capitalized terms not defined here have the meaning given in the Agreement or in applicable data-protection law, including the EU/UK General Data Protection Regulation ("GDPR") and the California Consumer Privacy Act as amended ("CCPA/CPRA"). Where the Agreement and this DPA conflict on data-protection matters, this DPA controls.
1. Roles of the Parties
1.1 For the AI-tool telemetry, endpoint/device telemetry, and secret findings that the endpoint agent collects from the Customer's devices, the Customer is the Controller and Kraitos AIDR is the Processor (a "service provider" under CCPA/CPRA).
1.2 For the account, billing, and administrative data of the Customer and its authorized users, Kraitos AIDR acts as an independent controller under its Privacy Policy; that processing is outside the scope of this DPA except where expressly stated.
1.3 The Processor shall process personal data only as a processor/service provider and shall not "sell" or "share" personal data (as defined by CCPA/CPRA) or retain, use, or disclose it for any purpose other than performing the Service or as otherwise permitted by law.
2. Subject-Matter, Duration, Nature, and Purpose
2.1 Subject-matter. The processing of personal data necessary to provide the Kraitos AIDR AI-governance and endpoint-security service to the Customer.
2.2 Duration. For the term of the Agreement, plus the period required to return or delete personal data under Section 9.
2.3 Nature and purpose. Collection, recording, organization, structuring, storage, analysis, correlation, display, alerting, export, and deletion of personal data for the purposes of AI-usage governance, endpoint security monitoring, threat detection, secret-exposure detection, incident response, and compliance reporting, as directed by the Controller.
2.4 Categories of data subjects. The Controller's personnel and other users whose devices run the endpoint agent (for example employees and contractors), and, incidentally, individuals referenced within captured content.
2.5 Categories of personal data.
- AI-tool telemetry: prompts, responses, tool calls, file paths accessed, token counts, cost estimates, MCP server/tool usage, and models used (which may contain sensitive content entered by data subjects).
- Endpoint/device telemetry: hostname, username, operating system, agent version, running processes, outbound connections to LLM APIs, installed AI tools, browser extensions, file-integrity events, malware/threat detections, IOC matches, and software/dependency inventory.
- Secret findings: detected credentials/secrets stored in redacted form plus raw form for the finding view, with entropy and severity metadata.
2.6 Special categories. The Service is not intended to process special categories of data (GDPR Art. 9); however, free-text AI prompts and responses may inadvertently contain such data. The Controller is responsible for governing what its personnel enter.
3. Controller Instructions
3.1 The Processor shall process personal data only on the documented instructions of the Controller, including with regard to international transfers, unless required to act by applicable law (in which case the Processor shall inform the Controller unless legally prohibited).
3.2 The Agreement, this DPA, and the Controller's use and configuration of the Service (including retention and collection settings) constitute the Controller's complete documented instructions. Additional instructions must be agreed in writing.
3.3 The Processor shall promptly inform the Controller if, in its opinion, an instruction infringes applicable data-protection law.
4. Confidentiality
The Processor shall ensure that persons authorized to process the personal data are bound by an appropriate duty of confidentiality (contractual or statutory) and are trained on their data-protection obligations. Access is granted on a least-privilege, need-to-know basis.
5. Security of Processing (Art. 32)
5.1 Taking into account the state of the art, the costs of implementation, and the nature, scope, context, and purposes of processing, as well as the risks to data subjects, the Processor shall implement appropriate technical and organizational measures ("TOMs") to ensure a level of security appropriate to the risk. A description of current TOMs is set out in Annex B.
5.2 Measures include encryption of personal data in transit and at rest, tenant isolation via row-level security, access controls, resilience of processing systems, and processes for regularly testing and evaluating the effectiveness of the measures.
6. Sub-Processors
6.1 The Controller provides general written authorization for the Processor to engage the sub-processors listed in Annex A to process personal data in connection with the Service.
6.2 The Processor shall impose data-protection obligations on each sub-processor that are no less protective than those in this DPA, by written contract, and shall remain liable to the Controller for the performance of each sub-processor's obligations.
6.3 Change notice. The Processor shall notify the Controller of any intended addition or replacement of a sub-processor with reasonable advance notice (for example, by updating Annex A and providing notice via the Service or email), giving the Controller the opportunity to object on reasonable data-protection grounds. If the parties cannot resolve a legitimate objection, the Controller may terminate the affected portion of the Service.
7. Assistance to the Controller
7.1 Data-subject requests. Taking into account the nature of the processing, the Processor shall assist the Controller by appropriate technical and organizational measures, insofar as possible, to respond to requests from data subjects exercising their rights (access, rectification, erasure, restriction, portability, and objection). The Service provides self-service export and delete functionality (GDPR export/delete endpoints) that the Controller may use directly. Where a data subject contacts the Processor, the Processor shall, without undue delay, refer the request to the relevant Controller.
7.2 DPIAs and prior consultation. The Processor shall provide reasonable assistance to the Controller with data-protection impact assessments and any prior consultation with supervisory authorities (GDPR Arts. 35–36), taking into account the information available to the Processor.
8. Personal Data Breach Notification
8.1 The Processor shall notify the Controller without undue delay after becoming aware of a personal data breach affecting the Controller's personal data.
8.2 The notification shall, to the extent known, describe the nature of the breach, the categories and approximate number of data subjects and records concerned, the likely consequences, and the measures taken or proposed to address and mitigate it. The Processor shall provide reasonable cooperation and further information as it becomes available to help the Controller meet its own notification obligations.
9. Return and Deletion of Data
9.1 On termination or expiry of the Agreement, and at the Controller's choice, the Processor shall delete or return all personal data processed on the Controller's behalf and delete existing copies, unless applicable law requires continued storage.
9.2 The Processor shall also delete personal data in accordance with the Controller's configured retention settings during the term. The Controller may export its data using the Service's export functionality prior to deletion.
10. Audit and Compliance
10.1 The Processor shall make available to the Controller information reasonably necessary to demonstrate compliance with this DPA and shall allow for and contribute to audits, including inspections, conducted by the Controller or an auditor it mandates.
10.2 The parties shall agree in advance on the reasonable scope, timing, and duration of any audit. To minimize disruption, the Processor may satisfy audit requests by providing relevant third-party certifications, reports, or questionnaire responses where available.
11. International Transfers
11.1 The Processor may transfer and process personal data outside the country of collection, including in the United States, as necessary to provide the Service via the sub-processors in Annex A.
11.2 Where such transfers involve personal data subject to GDPR/UK GDPR and are made to a country without an adequacy decision, the parties agree that the European Commission's Standard Contractual Clauses ("SCCs") (Module 2, controller-to-processor, and Module 3 where onward transfers occur) are incorporated by reference and completed as follows: the Controller is the "data exporter" and the Processor is the "data importer"; the optional docking clause applies; the governing law and forum are as stated in the SCCs consistent with the State of Florida; and Annexes A and B to this DPA populate the corresponding SCC annexes. For UK transfers, the UK International Data Transfer Addendum to the SCCs applies. Where the SCCs conflict with this DPA, the SCCs prevail as to transfer matters.
12. Liability and Term
This DPA takes effect on August 4, 2026 and remains in force for as long as the Processor processes personal data on the Controller's behalf. Each party's liability under this DPA is subject to the limitations and exclusions of liability set out in the Agreement. This DPA is governed by the laws of the State of Florida, without prejudice to the SCCs.
Annex A — Sub-Processors
The Processor engages the following sub-processors. "Location" indicates the principal region(s) where processing may occur; providers may operate globally.
| Sub-processor | Purpose | Location |
|---|---|---|
| Stripe | Payment processing and subscription billing | United States (global) |
| Mailgun / Anymail | Transactional email delivery | United States / EU |
| DigitalOcean | Cloud hosting, managed PostgreSQL databases, and Spaces object storage (including data exports) | United States / EU |
| Slack | Only where the Controller configures alert delivery to its own Slack workspace | United States (global) |
| Sentry | Application error and performance monitoring | United States |
| Cloudflare | Content delivery network and secure tunnel/reverse proxy | Global edge network |
Google Analytics runs on the public marketing website only. It processes no personal data covered by this DPA and is therefore not a sub-processor of the Service.
The Controller acknowledges that the specific processing location for managed hosting and storage may be configurable and is set out in the Service configuration or ordering documentation.
Annex B — Technical and Organizational Measures (TOMs)
The Processor maintains, at a minimum, the following measures, which may be updated to keep pace with evolving security practices provided the overall level of protection is not reduced:
- Encryption. TLS encryption for data in transit; encryption at rest for stored personal data, databases, and object storage.
- Tenant isolation. Logical segregation of Customer data using row-level security (RLS), enforcing per-tenant access boundaries at the database layer.
- Access control. Role-based access control, least-privilege and need-to-know principles, unique credentials, strong authentication for administrative access, and prompt revocation on role change or departure.
- Secret handling. Detected secrets are stored redacted for general viewing, with raw values access-controlled for the finding-detail view; application secrets are managed through a dedicated secrets-management process.
- Network and infrastructure security. Firewalling and network segmentation, CDN/edge protection, and secure tunneling for administrative access.
- Logging and monitoring. Centralized application logging, error monitoring, and alerting to detect and respond to anomalous or unauthorized activity.
- Resilience and recovery. Managed-database backups and documented restore procedures to preserve availability and integrity of personal data.
- Secure development. Change management, code review, dependency and vulnerability management, and separation of environments.
- Personnel. Confidentiality obligations and security-awareness training for staff with access to personal data.
- Vendor management. Due diligence and contractual data-protection commitments for sub-processors consistent with Section 6.
- Incident response. Documented breach-response procedures supporting the notification obligations in Section 8.
- Data minimization and retention. Controller-configurable collection and retention controls, and deletion/return procedures on termination per Section 9.