If your jurisdiction requires a data processing agreement (GDPR, UK GDPR, CCPA, etc.), this addendum forms part of your Kinventory contract. It explains how we process personal data on your behalf, in plain English.
Terms used in this DPA mirror the GDPR and UK GDPR. "Customer" is you (the data controller). "Kinventory" is us (the data processor). "Personal Data" means any data relating to an identified or identifiable person you submit to the Service.
This DPA applies whenever we process Personal Data on your behalf as part of the Service. It's effective for the duration of your Kinventory subscription.
We process Personal Data only on your documented instructions, including with regard to transfers to third countries.
We ensure personnel authorized to process Personal Data are bound by confidentiality.
We assist you, on request, with: responding to data subject requests, security incident notifications, and privacy impact assessments.
You authorize us to engage sub-processors. Current sub-processors are listed on the Security page. We'll give you 30 days' notice before adding a new sub-processor; you can object within that window, in which case we'll work in good faith to resolve.
For Personal Data transferred from the EEA, the UK, or Switzerland to the US, the Standard Contractual Clauses (Module Two, Commission Decision 2021/914) are incorporated by reference.
If a data subject contacts us directly with a request related to your data, we'll forward it to you within 5 business days. We won't respond to the subject ourselves except to acknowledge.
We'll notify you of a confirmed personal-data breach without undue delay, and no later than 72 hours after we become aware of it, with the information you need to meet your own regulatory notifications.
On termination of the Service, we will, at your choice, return or delete all Personal Data within 90 days, unless retention is required by law.
We'll make our SOC 2 Type II report available, under NDA, in lieu of on-site audits. On reasonable request and notice, we'll cooperate with an on-site audit by an independent third-party auditor, no more than once per year.
DPA questions: privacy@kin.cafe.
Connect Square, import your catalog, and have your back of house humming by tomorrow's open.