Data Processing Addendum (DPA)
Last updated: September 9, 2026
This Data Processing Addendum ("DPA") forms part of the agreement between Kraitos, Inc., a Delaware corporation providing the Kraitos AIDR service ("Processor", "we", "us"), and the customer that subscribes to the Service ("Customer", "Controller", "you") (together, the "Agreement"). It governs the processing of personal data by the Processor on behalf of the Controller in connection with Kraitos AIDR (aidr.kraitos.io).
Capitalized terms not defined here have the meaning given in the Agreement or in applicable data-protection law, including the EU/UK General Data Protection Regulation ("GDPR") and the California Consumer Privacy Act as amended ("CCPA/CPRA"). Where the Agreement and this DPA conflict on data-protection matters, this DPA controls.
1. Roles of the Parties
1.1 For the AI-tool telemetry, endpoint/device telemetry, data-loss-prevention and egress telemetry, secret findings, and quarantined file samples that the endpoint agent collects from the Customer's devices, the Customer is the Controller and Kraitos AIDR is the Processor (a "service provider" under CCPA/CPRA).
1.2 For the account, billing, and administrative data of the Customer and its authorized users, Kraitos AIDR acts as an independent controller under its Privacy Policy; that processing is outside the scope of this DPA except where expressly stated.
1.3 The Processor shall process personal data only as a processor/service provider and shall not "sell" or "share" personal data (as defined by CCPA/CPRA) or retain, use, or disclose it for any purpose other than performing the Service or as otherwise permitted by law.
2. Subject-Matter, Duration, Nature, and Purpose
2.1 Subject-matter. The processing of personal data necessary to provide the Kraitos AIDR AI-governance and endpoint-security service to the Customer.
2.2 Duration. For the term of the Agreement, plus the period required to return or delete personal data under Section 9.
2.3 Nature and purpose. Collection, recording, organization, structuring, storage, analysis, correlation, display, alerting, export, and deletion of personal data for the purposes of AI-usage governance, data loss prevention, endpoint security monitoring, threat detection and response, secret-exposure detection, incident response, and compliance reporting, as directed by the Controller.
2.4 Categories of data subjects. The Controller's personnel and other users whose devices run the endpoint agent (for example employees and contractors), and, incidentally, individuals referenced within captured content.
2.5 Categories of personal data.
- AI-tool telemetry: prompts, responses, tool calls, file paths accessed, token counts, cost estimates, MCP server/tool usage, and models used, including local models (which may contain sensitive content entered by data subjects).
- Data-loss-prevention events: redaction or block events, the matched rule, and redacted excerpts of the content involved.
- Endpoint/device telemetry: hostname, username, hardware identifier, operating system, agent version, running processes, outbound connections and destination classification (egress telemetry), installed AI tools, browser extensions, device posture, file-integrity events, malware/threat detections, IOC matches, software/dependency inventory, and records of response actions taken on the device.
- Secret findings: detected credentials/secrets stored in redacted form plus raw form for the finding view, with entropy and severity metadata.
- Quarantined file samples: where the Controller enables sample upload, files quarantined as suspected malware, which may incidentally contain personal data.
2.6 Special categories. The Service is not intended to process special categories of data (GDPR Art. 9); however, free-text AI prompts and responses may inadvertently contain such data. The Controller is responsible for governing what its personnel enter.
3. Controller Instructions
3.1 The Processor shall process personal data only on the documented instructions of the Controller, including with regard to international transfers, unless required to act by applicable law (in which case the Processor shall inform the Controller unless legally prohibited).
3.2 The Agreement, this DPA, and the Controller's use and configuration of the Service (including retention and collection settings) constitute the Controller's complete documented instructions. Additional instructions must be agreed in writing.
3.3 The Processor shall promptly inform the Controller if, in its opinion, an instruction infringes applicable data-protection law.
4. Confidentiality
The Processor shall ensure that persons authorized to process the personal data are bound by an appropriate duty of confidentiality (contractual or statutory) and are trained on their data-protection obligations. Access is granted on a least-privilege, need-to-know basis.
5. Security of Processing (Art. 32)
5.1 Taking into account the state of the art, the costs of implementation, and the nature, scope, context, and purposes of processing, as well as the risks to data subjects, the Processor shall implement appropriate technical and organizational measures ("TOMs") to ensure a level of security appropriate to the risk. A description of current TOMs is set out in Annex B.
5.2 Measures include encryption of personal data in transit and at rest, tenant isolation via row-level security, access controls, resilience of processing systems, and processes for regularly testing and evaluating the effectiveness of the measures.
6. Sub-Processors
6.1 The Controller provides general written authorization for the Processor to engage the sub-processors listed in Annex A to process personal data in connection with the Service.
6.2 The Processor shall impose data-protection obligations on each sub-processor that are no less protective than those in this DPA, by written contract, and shall remain liable to the Controller for the performance of each sub-processor's obligations.
6.3 Change notice. The Processor shall notify the Controller of any intended addition or replacement of a sub-processor with reasonable advance notice (for example, by updating Annex A and providing notice via the Service or email), giving the Controller the opportunity to object on reasonable data-protection grounds. If the parties cannot resolve a legitimate objection, the Controller may terminate the affected portion of the Service.
7. Assistance to the Controller
7.1 Data-subject requests. Taking into account the nature of the processing, the Processor shall assist the Controller by appropriate technical and organizational measures, insofar as possible, to respond to requests from data subjects exercising their rights (access, rectification, erasure, restriction, portability, and objection). The Service provides self-service data export and account-deletion functionality that the Controller may use directly. Where a data subject contacts the Processor, the Processor shall, without undue delay, refer the request to the relevant Controller.
7.2 DPIAs and prior consultation. The Processor shall provide reasonable assistance to the Controller with data-protection impact assessments and any prior consultation with supervisory authorities (GDPR Arts. 35–36), taking into account the information available to the Processor.
8. Personal Data Breach Notification
8.1 The Processor shall notify the Controller without undue delay after becoming aware of a personal data breach affecting the Controller's personal data.
8.2 The notification shall, to the extent known, describe the nature of the breach, the categories and approximate number of data subjects and records concerned, the likely consequences, and the measures taken or proposed to address and mitigate it. The Processor shall provide reasonable cooperation and further information as it becomes available to help the Controller meet its own notification obligations.
9. Return and Deletion of Data
9.1 On termination or expiry of the Agreement, and at the Controller's choice, the Processor shall delete or return all personal data processed on the Controller's behalf and delete existing copies, unless applicable law requires continued storage.
9.2 The Processor shall also delete personal data in accordance with the retention period applicable to the Controller's tenant during the term (365 days by default, adjustable on request). Account deletion requested by the Controller takes effect after a 30-day grace period. The Controller may export its data using the Service's export functionality prior to deletion.
10. Audit and Compliance
10.1 The Processor shall make available to the Controller information reasonably necessary to demonstrate compliance with this DPA and shall allow for and contribute to audits, including inspections, conducted by the Controller or an auditor it mandates.
10.2 The parties shall agree in advance on the reasonable scope, timing, and duration of any audit. To minimize disruption, the Processor may satisfy audit requests by providing relevant third-party certifications, reports, or questionnaire responses where available.
11. International Transfers
11.1 The Processor may transfer and process personal data outside the country of collection, including in the United States, as necessary to provide the Service via the sub-processors in Annex A.
11.2 Where such transfers involve personal data subject to GDPR/UK GDPR and are made to a country without an adequacy decision, the parties agree that the European Commission's Standard Contractual Clauses ("SCCs") (Module 2, controller-to-processor, and Module 3 where onward transfers occur) are incorporated by reference and completed as follows: the Controller is the "data exporter" and the Processor is the "data importer"; the optional docking clause applies; the governing law and forum are as stated in the SCCs consistent with the State of Florida; and Annexes A and B to this DPA populate the corresponding SCC annexes. For UK transfers, the UK International Data Transfer Addendum to the SCCs applies. Where the SCCs conflict with this DPA, the SCCs prevail as to transfer matters.
12. Liability and Term
This DPA takes effect on September 9, 2026 and remains in force for as long as the Processor processes personal data on the Controller's behalf. Each party's liability under this DPA is subject to the limitations and exclusions of liability set out in the Agreement. This DPA is governed by the laws of the State of Florida, without prejudice to the SCCs.
Annex A — Sub-Processors
The Processor engages the following sub-processors. "Location" indicates the principal region(s) where processing may occur; providers may operate globally.
| Sub-processor | Purpose | Location |
|---|---|---|
| Stripe | Payment processing and subscription billing | United States (global) |
| Amazon Web Services (AWS) | Cloud hosting (EKS), managed PostgreSQL (RDS), caching (ElastiCache), and S3 object storage (including data exports and quarantined file samples); AWS Marketplace billing where the Controller purchases through it | United States (us-east-2, Ohio) |
| Mailgun | Transactional email delivery | United States / EU |
| Sentry | Application error and performance monitoring | United States |
| Cloudflare | DNS, content delivery network, and edge security (reverse proxy) | Global edge network |
Slack and Controller-specified webhooks receive alert data only where the Controller configures those integrations; they are Controller-controlled recipients rather than sub-processors. Google Analytics runs on the public marketing website only. It processes no personal data covered by this DPA and is therefore not a sub-processor of the Service.
The current list is also published at https://www.kraitos.io/legal/subprocessors. Personal data is hosted in the United States; alternative hosting regions are not currently offered.
Annex B — Technical and Organizational Measures (TOMs)
The Processor maintains, at a minimum, the following measures, which may be updated to keep pace with evolving security practices provided the overall level of protection is not reduced:
- Encryption. TLS encryption for data in transit, with authenticated agent enrollment for agent-to-service traffic; encryption at rest for stored personal data, databases, and object storage; field-level encryption for stored integration credentials.
- Tenant isolation. Logical segregation of Customer data using row-level security (RLS), enforcing per-tenant access boundaries at the database layer.
- Access control. Role-based access control, least-privilege and need-to-know principles, unique credentials, strong authentication for administrative access, and prompt revocation on role change or departure.
- Secret handling. Detected secrets are stored redacted for general viewing, with raw values access-controlled for the finding-detail view; application secrets are managed through a dedicated secrets-management process.
- Network and infrastructure security. Private-subnet workloads, security groups and Kubernetes network policies, CDN/edge protection, and restricted administrative access.
- Logging and monitoring. Centralized application logging, error monitoring, and alerting to detect and respond to anomalous or unauthorized activity.
- Resilience and recovery. Managed-database backups and documented restore procedures to preserve availability and integrity of personal data.
- Secure development. Change management, code review, dependency and vulnerability management, separation of environments, and code-signed agent releases with verified automatic updates.
- Personnel. Confidentiality obligations and security-awareness training for staff with access to personal data.
- Vendor management. Due diligence and contractual data-protection commitments for sub-processors consistent with Section 6.
- Incident response. Documented breach-response procedures supporting the notification obligations in Section 8.
- Data minimization and retention. Controller-configurable collection (including optional sample upload), local redaction of sensitive content before it leaves the device where policy requires, tenant-level retention periods, and deletion/return procedures on termination per Section 9.