Last updated: July 6, 2026
This Data Processing Addendum ("DPA") forms part of the KaiTask Terms of Service between the Customer (Controller) and KaiTask (Processor) and governs the processing of Personal Data by KaiTask on behalf of the Customer under Article 28 GDPR and the UK GDPR.
Customer is the Controller. KaiTask is the Processor. KaiTask processes Personal Data only on documented instructions from the Customer, including with regard to international transfers, unless required to do so by EU or Member-State law.
Subject-matter: provision of the KaiTask task-management and collaboration service. Duration: the term of the Terms of Service and applicable retention windows in the Privacy Policy.
Hosting, storing, transmitting and displaying Customer Content; sending transactional email (invites, digests, reminders); operating scheduled workflow automations; providing authentication, backup, security monitoring and support.
Data subjects: Customer's staff, vendors, students, and their invitees. Categories: identification data (name, email, avatar), authentication data (hashed credentials), organization data (tasks, checklists, messages, attachments) and diagnostic data.
Customer authorises KaiTask to engage sub-processors listed at /legal/subprocessors. KaiTask will notify Customer of any intended addition or replacement of sub-processors, providing an opportunity to object.
Where Personal Data is transferred outside the EEA or the UK, transfers are covered by the EU Standard Contractual Clauses (Commission Decision 2021/914) and, for UK data, the UK International Data Transfer Addendum. Modules and clauses are incorporated by reference.
Technical and organisational measures include: encryption in transit (TLS 1.2+) and at rest, role-based access control, row-level security in the database, principle-of-least-privilege for KaiTask personnel, secret rotation, audit logging, backup with encryption, incident-response runbook, and staff confidentiality obligations.
KaiTask will assist Customer, taking into account the nature of the processing, in fulfilling requests to exercise data-subject rights and in complying with Articles 32-36 GDPR (security, breach notification, DPIA).
KaiTask will notify Customer without undue delay, and in any event within 72 hours, after becoming aware of a Personal Data breach, providing information required by Article 33(3) GDPR to the extent then available.
On termination, and at Customer's choice, KaiTask will delete or return all Personal Data unless retention is required by law. Backups are purged within 35 days.
KaiTask will make available to Customer information necessary to demonstrate compliance with Article 28 and allow for audits, including inspections, conducted by the Customer or a mutually agreed auditor, on reasonable notice and subject to confidentiality.
In the event of conflict, this DPA prevails over the Terms of Service with respect to the processing of Personal Data.
Customer accepts this DPA by clicking "I agree" at sign-up, or by continuing to use the service. A counter-signed PDF is available on request from legal@kaitask.app.