Home

Data Processing Addendum

Last updated: July 6, 2026

This Data Processing Addendum ("DPA") forms part of the KaiTask Terms of Service between the Customer (Controller) and KaiTask (Processor) and governs the processing of Personal Data by KaiTask on behalf of the Customer under Article 28 GDPR and the UK GDPR.

1. Roles and scope

Customer is the Controller. KaiTask is the Processor. KaiTask processes Personal Data only on documented instructions from the Customer, including with regard to international transfers, unless required to do so by EU or Member-State law.

2. Subject-matter and duration

Subject-matter: provision of the KaiTask task-management and collaboration service. Duration: the term of the Terms of Service and applicable retention windows in the Privacy Policy.

3. Nature and purpose of processing

Hosting, storing, transmitting and displaying Customer Content; sending transactional email (invites, digests, reminders); operating scheduled workflow automations; providing authentication, backup, security monitoring and support.

4. Categories of data subjects and data

Data subjects: Customer's staff, vendors, students, and their invitees. Categories: identification data (name, email, avatar), authentication data (hashed credentials), organization data (tasks, checklists, messages, attachments) and diagnostic data.

5. Sub-processors

Customer authorises KaiTask to engage sub-processors listed at /legal/subprocessors. KaiTask will notify Customer of any intended addition or replacement of sub-processors, providing an opportunity to object.

6. International transfers

Where Personal Data is transferred outside the EEA or the UK, transfers are covered by the EU Standard Contractual Clauses (Commission Decision 2021/914) and, for UK data, the UK International Data Transfer Addendum. Modules and clauses are incorporated by reference.

7. Security measures (Art. 32)

Technical and organisational measures include: encryption in transit (TLS 1.2+) and at rest, role-based access control, row-level security in the database, principle-of-least-privilege for KaiTask personnel, secret rotation, audit logging, backup with encryption, incident-response runbook, and staff confidentiality obligations.

8. Assistance to Controller

KaiTask will assist Customer, taking into account the nature of the processing, in fulfilling requests to exercise data-subject rights and in complying with Articles 32-36 GDPR (security, breach notification, DPIA).

9. Personal-data breach

KaiTask will notify Customer without undue delay, and in any event within 72 hours, after becoming aware of a Personal Data breach, providing information required by Article 33(3) GDPR to the extent then available.

10. Deletion or return of data

On termination, and at Customer's choice, KaiTask will delete or return all Personal Data unless retention is required by law. Backups are purged within 35 days.

11. Audits

KaiTask will make available to Customer information necessary to demonstrate compliance with Article 28 and allow for audits, including inspections, conducted by the Customer or a mutually agreed auditor, on reasonable notice and subject to confidentiality.

12. Order of precedence

In the event of conflict, this DPA prevails over the Terms of Service with respect to the processing of Personal Data.

13. Signature

Customer accepts this DPA by clicking "I agree" at sign-up, or by continuing to use the service. A counter-signed PDF is available on request from legal@kaitask.app.