In plain English
- This Addendum applies automatically if you use Kaer for business and personal data is processed through it. It applies on every plan, with nothing to sign or request.
- You decide why and how that personal data is processed (you are the controller). Kaer processes it only on your instructions (Kaer is your processor).
- Kaer uses the sub-processors listed in the Privacy Policy, including AI model providers based in China and the United States, and tells you at least 14 days before adding or replacing one.
- Kaer tells you without undue delay if a personal-data breach affects your data.
- Kaer never trains models on your personal data unless “Help improve Kaer” is switched on for your account, and then only on data from after it was switched on. It is off unless you turn it on.
- When your account is deleted, Kaer erases your data from its primary systems after a 30-day grace period, and from backups as they rotate out.
Parties & scope
This Data Processing Addendum (“DPA”) is between you (the “Customer”) and Kaer Labs Ltd (“Kaer”), company no. 16674310, registered in England and Wales, registered office 167–169 Great Portland Street, Fifth Floor, London W1W 5PF.
It forms part of the Terms of Service and applies automatically, without signature, whenever the Customer uses the Service for business purposes and Kaer processes Customer Personal Data on the Customer’s behalf. It applies on every plan. If you need a countersigned copy for your records, email [email protected].
“Customer Personal Data” means personal data in Customer Data (as defined in the Terms) that Kaer processes on the Customer’s behalf. “Data Protection Law” means the UK GDPR and the Data Protection Act 2018 and, where it applies, the EU GDPR (Regulation (EU) 2016/679). Controller, processor, data subject, personal-data breach and processing have the meanings given in Data Protection Law. This DPA sets out the terms required by Article 28(3) of the UK GDPR and the EU GDPR.
Roles
The Customer is the controller of Customer Personal Data (or a processor acting for its own clients), and Kaer is its processor (or sub-processor). Kaer is a controller only for the personal data it processes for its own purposes as described in the Privacy Policy, such as account, billing and security data.
The Customer is responsible for having a lawful basis for the processing, for the lawfulness of its instructions, and for giving data subjects any information the law requires.
Details of processing
| Subject matter | Providing the Service to the Customer under the Terms. |
| Duration | For as long as the Customer uses the Service, and then until deletion under section 11. |
| Nature & purpose | Hosting, storing, transmitting and otherwise processing Customer Personal Data to run the agents, AI employees, workflows, chat, Mail AI, computer-use sessions, connectors and other features the Customer uses, including sending it to AI model providers to generate outputs; and supporting, securing and fixing the Service. |
| Types of personal data | Whatever the Customer and its users submit or connect, which may include names, contact details, email content and metadata, messages, documents and files, calendar entries, screenshots, customer and supplier records, and any other personal data in prompts, files, mailboxes or connected services. |
| Special categories | None are required. The Customer should submit special-category or criminal-offence data only where it has a lawful basis and has assessed the risk. |
| Data subjects | The Customer’s users, staff and contractors; its customers, prospects, suppliers and correspondents; and anyone else whose personal data the Customer submits or connects. |
Documented instructions
Kaer processes Customer Personal Data only on the Customer’s documented instructions, including with regard to transfers outside the UK and EEA, unless UK, EU or EU member-state law requires otherwise; in that case Kaer will tell the Customer first, unless that law prohibits it. The Terms, this DPA, and the Customer’s use and configuration of the Service (its prompts, agent, workflow and connector settings) are the Customer’s documented instructions. Kaer will tell the Customer if, in its opinion, an instruction infringes Data Protection Law.
Confidentiality
Kaer ensures that anyone it authorises to process Customer Personal Data is bound by confidentiality, by contract or by law, and accesses it only as needed to provide, support or secure the Service.
Security
Kaer implements the technical and organisational measures required by Article 32, described on the Security page and in the Security section of the Privacy Policy: encryption in transit with TLS 1.2 or later; AES-256-GCM application-layer encryption for service secrets, connector and OAuth tokens and mail credentials; Argon2id password hashing; hashed refresh tokens and API keys; access controls; audit logging of security-sensitive events; and least-privilege production access. Not all Customer Personal Data is encrypted at the application layer; the Privacy Policy says which. Kaer may change these measures, provided the overall level of protection does not go down. Kaer holds no third-party security certification (such as SOC 2 or ISO 27001).
Sub-processors
The Customer gives Kaer general authorisation to engage sub-processors. The current list, with what each one does, the data it receives and the country of the company, is in the Sub-processors section of the Privacy Policy. Kaer may send a request to any AI model provider on that list other than OpenRouter, which never receives Customer Personal Data, including when it automatically switches to another provider because the one selected has failed.
Kaer will give notice of any intended addition or replacement of a sub-processor at least 14 days before it takes effect, by updating that list and emailing the account owner. The Customer may object on reasonable data-protection grounds by emailing [email protected] within that period. Kaer will then work with the Customer in good faith to resolve the objection, for example by not using the new sub-processor for the Customer’s data; if that is not reasonably possible, the Customer may stop using the affected feature or end the Service, with a refund as set out in Refunds & cancellation in the Terms.
Kaer imposes data-protection obligations on each sub-processor by written contract that are no less protective than those in this DPA, to the extent they apply to the service the sub-processor provides, and remains liable to the Customer for each sub-processor’s performance of them.
Data-subject requests
Taking into account the nature of the processing, Kaer will help the Customer by appropriate technical and organisational measures, where possible, to respond to requests from data subjects exercising their rights. Some requests the Customer can handle directly in the Service, for example by disconnecting a mailbox or deleting its account; for anything else, including exports, email [email protected]. If Kaer receives a request directly about Customer Personal Data, it will pass it to the Customer without undue delay and will not answer it itself, unless the law requires otherwise.
Assistance & impact assessments
Taking into account the nature of the processing and the information available to it, Kaer will give the Customer reasonable help with its obligations under Articles 32 to 36: security, notifying personal-data breaches, data-protection impact assessments, and prior consultation with a supervisory authority.
Personal-data breaches
Kaer will notify the Customer without undue delay after becoming aware of a personal-data breach affecting Customer Personal Data, by email to the account owner. The notice will describe, as far as then known, the nature of the breach, the categories and approximate number of data subjects and records concerned, its likely consequences, and the measures taken or proposed to address it; Kaer will send further information as it becomes available. A notice is not an admission of fault.
Deletion or return at the end
Until the Service ends, the Customer can ask [email protected] for an export of Customer Personal Data (return). When the Service ends — because the Customer deletes its account or Kaer closes it — the account enters a 30-day grace period during which the Customer can still ask for an export (and, if it deleted the account itself, cancel the deletion); at the end of it, Kaer erases Customer Personal Data from its primary systems, and copies in encrypted backups are removed as those backups age out on their normal rotation schedule, as set out in the Retention section of the Privacy Policy. Kaer keeps a copy only where UK or EU law requires it, and then only for as long as required.
Information & audits
Kaer will make available to the Customer the information reasonably necessary to demonstrate compliance with Article 28 and this DPA, and will allow for and contribute to audits, including inspections, by the Customer or an independent auditor it appoints. Kaer will first try to answer an audit request with written information and documents. An audit or inspection needs at least 30 days’ written notice, takes place no more than once a year (unless a supervisory authority requires it or following a personal-data breach), during UK business hours, under confidentiality, at the Customer’s cost, and in a way that does not expose other customers’ data or weaken Kaer’s security.
International transfers
Kaer’s own servers and primary storage are in Germany and Finland. Some sub-processors, including AI model providers, process Customer Personal Data outside the UK and EEA, including in China and the United States. Kaer transfers Customer Personal Data outside the UK and EEA only where Data Protection Law allows it: to a country covered by adequacy regulations or an adequacy decision, or under appropriate safeguards such as the UK International Data Transfer Agreement, the UK Addendum to the EU Standard Contractual Clauses, or the EU Standard Contractual Clauses, with supplementary measures where needed. The Customer authorises these transfers.
No training on Customer Personal Data
Kaer does not use Customer Personal Data to train or improve AI models unless “Help improve Kaer” is switched on in Settings for the user account concerned; it is off unless switched on. Only data from tasks started after a user switches it on is used; anything from before is never used. Each user controls the switch for their own account and there is no organisation-wide setting, so the Customer should tell its users whether they may switch it on. When a user switches it on, Kaer uses the resulting records for its own purposes, as a controller, as described in the Improving Kaer section of the Privacy Policy; the switch can be turned off at any time, which stops collection at once; records already prepared for training drop out within four weeks. Kaer never uses Customer Personal Data to train third-party foundation models.
Precedence, liability & changes
If this DPA conflicts with the Terms or the Privacy Policy on the protection of Customer Personal Data, this DPA prevails. Each party’s liability under this DPA is subject to the limits in the Terms, except where the law does not allow it to be limited. Kaer may update this DPA as Data Protection Law or the Service changes, giving at least 14 days’ email notice of material changes, as for the Terms.
Governing law
This DPA is governed by the laws of England and Wales, and the courts of England and Wales have jurisdiction over any dispute about it, except where Data Protection Law or a transfer safeguard requires otherwise.
Contact
Questions about this DPA, sub-processor objections and data-subject requests: [email protected]. Legal notices: [email protected]. Security reports: [email protected].