Data processing addendum

Last updated [EFFECTIVE DATE]

This Data Processing Addendum ("DPA") forms part of the Terms of service between you ("Customer", "Controller") and [COMPANY LEGAL NAME] ("Kamu", "Processor"). It governs Kamu's processing of personal data on your behalf when providing the service.

1. Roles

For prospect and outreach data that Kamu processes to perform growth work you configure, you are the Controller and Kamu is the Processor. Each party will comply with applicable data protection law, including GDPR where relevant.

2. Subject matter and duration

The subject matter is the provision of the Kamu service. Processing continues for the term of your subscription and until data is deleted or returned under Section 9.

3. Nature and purpose of processing

Kamu processes personal data to discover and manage prospects, send and receive outreach, publish content, and produce activity records and reporting — in each case on your documented instructions (which include your configuration of the service).

4. Categories of data and data subjects

  • Data subjects — your prospects and business contacts.
  • Personal data — business-contact details such as name, work email, company, role, and the public source where information was found; message content; and related activity metadata.

5. Processor obligations

Kamu will: (a) process personal data only on your documented instructions; (b) ensure personnel are bound by confidentiality; (c) implement appropriate technical and organizational security measures (Section 7); (d) assist you, taking into account the nature of processing, with data-subject requests and with your security, breach-notification, and impact-assessment obligations; and (e) make available information reasonably necessary to demonstrate compliance.

6. Sub-processors

You authorize Kamu to engage the sub-processors listed on our Sub-processors page. Kamu imposes data-protection obligations on each sub-processor and remains responsible for their performance. We will give reasonable notice of new sub-processors so you may object on reasonable grounds.

7. Security

Kamu maintains measures appropriate to the risk, including encryption of data in transit, encryption of stored channel credentials, access controls, and logging. Details are summarized in our Privacy policy.

8. International transfers

Where personal data is transferred across borders, the transfer is made under an appropriate safeguard such as the Standard Contractual Clauses or an equivalent mechanism. [TRANSFER MECHANISM — confirm with counsel]

9. Deletion and return

On termination, or on your request, Kamu will delete or return personal data processed on your behalf within a reasonable period, except where retention is required by law.

10. Data-subject requests and breaches

Kamu will promptly notify you of a personal-data breach affecting your data and will reasonably assist you in responding to data-subject requests and regulators.

11. Liability and governing law

Liability under this DPA is subject to the limitations in the Terms of service, which also govern the applicable law and jurisdiction.

12. Contact

To raise a data-processing question or request this DPA countersigned, contact hello@kamu.so.