KavaCore.aiAI products, tools and managed intelligence.
KavaCore

Trust & Legal

Data Processing Addendum

Processor terms for customer personal data handled by KavaCore on behalf of a business customer.

Effective August 26, 2026Updated August 26, 2026KavaCore LLC · Illinois, USA

This DPA applies when KavaCore processes personal data on behalf of a customer as a processor, service provider, or contractor and the applicable agreement incorporates this DPA.

This public policy applies unless a signed agreement, order form, statement of work, data processing addendum, or product-specific terms expressly provide otherwise.

01

Roles and scope

The customer is the controller or business, and KavaCore is the processor, service provider, or contractor, as those roles are defined by applicable data-protection law, except where KavaCore independently determines purposes and means of processing.

KavaCore will process Customer Personal Data only to provide and secure the contracted services, follow documented customer instructions, comply with law, and perform obligations permitted by the agreement.

02

Customer instructions and responsibilities

The agreement, SOW, product configuration, support requests, and documented use of the service constitute the customer’s processing instructions. The customer is responsible for the lawfulness of Customer Personal Data, notices, consents, instructions, data-subject communications, and use of the service.

03

Confidentiality and personnel

KavaCore will limit access to Customer Personal Data to personnel and approved providers who need access for the service and who are subject to appropriate confidentiality obligations.

04

Security

KavaCore will maintain reasonable administrative, technical, and organizational safeguards appropriate to the nature of the service and Customer Personal Data. General measures are described in the Security Overview. Customer-specific controls may be stated in a signed agreement.

05

Subprocessors

The customer authorizes KavaCore to use subprocessors to provide the services. KavaCore remains responsible for imposing data-protection obligations on subprocessors appropriate to the services they perform.

The current public subprocessor list is maintained on the Subprocessors page. Where required by an applicable agreement or law, KavaCore will provide a mechanism for notice of material new subprocessors and good-faith discussion of reasonable objections.

06

Data-subject requests

Taking into account the nature of processing, KavaCore will provide reasonable assistance to help the customer respond to verified data-subject requests where Customer Personal Data is not directly accessible to the customer through the service. KavaCore may charge reasonable fees for exceptional assistance not included in the service, as permitted by the agreement.

07

Security incidents

KavaCore will notify the customer without undue delay after confirming a security incident involving unauthorized access to or acquisition, disclosure, alteration, loss, or destruction of Customer Personal Data for which notification is required by applicable law or contract.

Notification is not an admission of fault or liability. KavaCore will provide information reasonably available to support the customer’s incident response and legal obligations.

08

Deletion and return

At the end of the service, KavaCore will delete or return Customer Personal Data as provided by the service, agreement, or customer instruction, unless retention is required or permitted by law. Backup copies may remain for a limited period until overwritten or securely expired, subject to continuing protections.

09

Audits and compliance information

On reasonable request and subject to confidentiality and security restrictions, KavaCore will provide information reasonably necessary to demonstrate compliance with this DPA. Formal audits, questionnaires, or onsite reviews are subject to reasonable scope, frequency, security, and cost controls unless applicable law requires otherwise.

10

International transfers

If Customer Personal Data is transferred across borders and applicable law requires a transfer mechanism, the parties will cooperate in good faith to implement an appropriate lawful mechanism, which may include standard contractual clauses or another recognized safeguard.

11

Processing details

  • Subject matter: personal data processed to provide the contracted technology, software, AI, automation, hosting, managed, support, or professional services.
  • Duration: for the term of the applicable service plus any permitted retention period.
  • Data subjects: customer personnel, contractors, customers, prospects, users, or other individuals whose data the customer submits.
  • Data categories: business contact information, account identifiers, usage data, support data, documents, prompts, project data, and other data selected by the customer.
  • Sensitive data: not intended unless expressly authorized by the applicable service and agreement.
12

Order of precedence

If this DPA conflicts with the agreement on a data-protection issue, this DPA controls unless the parties expressly agree otherwise in writing. Customer-specific terms may supplement this DPA.

Need help? Contact [email protected]. Privacy-rights requests can also be submitted through the Privacy Requests page.