Legal
Data Processing Addendum
How Kairev processes personal data on behalf of customers as a processor, including security measures, subprocessors, transfers and assistance with data subject requests.
Roles
For personal data contained in the accounts and content a customer connects, the customer is the controller and Kairev is the processor. This addendum forms part of the Terms of service. A signed copy for your records is available on request from hello@kairev.ai.
Processing instructions
Kairev processes personal data only to provide the service as configured by the customer, including the goals, guardrails and approvals the customer sets, and as otherwise instructed in writing. Kairev will inform the customer if it believes an instruction infringes data protection law.
Security measures
- Isolated runtime per customer workspace, with separate storage and retrieval namespaces.
- Encryption in transit (TLS) and at rest (AES-256).
- Connected-account credentials held in a secrets vault, never inside the agent environment.
- Least-privilege access scopes for every connected service.
- Append-only audit log of every action the agent takes.
- Access to customer data by Kairev staff only with customer consent and audited.
Subprocessors
Kairev uses the subprocessors listed at /subprocessors and will give customers notice before adding a new one, with the opportunity to object.
International transfers
Where personal data is transferred outside the customer’s jurisdiction, Kairev relies on appropriate safeguards such as standard contractual clauses. An EU data residency option is planned.
Assistance
Kairev assists the customer with data subject requests, security assessments and breach notifications. Kairev will notify the customer of a personal data breach affecting their data without undue delay.
Deletion and return
On termination, the customer may export workspace data. Kairev deletes the customer’s data within 30 days of workspace closure unless retention is required by law.