Legal center

Privaata legal policy

Privaata Data Processing Agreement

The data processing terms that govern Privaata acting as a processor for customer workspace data.

Source document: Privaata Data Processing Agreement.docx

Privaata Data Processing Agreement

Effective Date: September 1, 2026 Last Updated: September 1, 2026

This Data Processing Agreement (“DPA”) forms part of the agreement governing the Customer’s use of Privaata, a software-as-a-service privacy management platform operated by Kinfolk Technologies Limited, of 18 Geranium Path, Mona Heights, Kingston 6, Jamaica (“Kinfolk Technologies,” “Kinfolk,” “Processor,” “we,” “us,” or “our”).

This DPA governs Kinfolk Technologies’ Processing of Personal Data on behalf of a Customer through Privaata.

Where a Customer has entered into a separate written services agreement, enterprise agreement, order form or other agreement governing its use of Privaata (the “Main Agreement”), this DPA forms part of that agreement.

1. Purpose

Privaata enables organizations to manage privacy, data-protection and related governance activities.

In providing the service, Kinfolk Technologies may Process Personal Data that the Customer uploads, submits, creates, imports, connects, scans, retrieves, analyzes or otherwise makes available through Privaata (“Customer Personal Data”).

This DPA establishes the respective obligations of the Customer and Kinfolk Technologies regarding that Processing.

PART I — DEFINITIONS AND ROLES

2. Definitions

For purposes of this DPA:

“Applicable Data Protection Law” means any privacy, data-protection or similar law applicable to the Processing of Customer Personal Data under the Main Agreement, including, where applicable, the Data Protection Act, 2020 of Jamaica, and other applicable national or international data-protection laws.

“Controller” means the person or organization that determines the purposes and means of Processing Personal Data, or the equivalent concept under Applicable Data Protection Law.

“Customer” means the organization or other legal person that has contracted to use Privaata.

“Customer Personal Data” means Personal Data Processed by Kinfolk Technologies on behalf of the Customer in connection with Privaata.

“Data Subject” means an identified or identifiable individual to whom Personal Data relates.

“Personal Data” means information relating to an identified or identifiable individual, or equivalent information protected as personal information under Applicable Data Protection Law.

“Personal Data Breach” means a breach of security leading to accidental or unlawful destruction, loss, alteration, unauthorized disclosure of, or access to Customer Personal Data, as defined or recognized under Applicable Data Protection Law.

“Process,” “Processing” or “Processed” means any operation or set of operations performed on Personal Data, whether by automated means or otherwise, including collection, recording, organization, structuring, storage, adaptation, retrieval, consultation, use, disclosure, transmission, combination, restriction, erasure or destruction.

“Processor” means an organization that Processes Personal Data on behalf of a Controller, or the equivalent concept under Applicable Data Protection Law.

“Subprocessor” means a third party engaged by Kinfolk Technologies to Process Customer Personal Data in connection with providing Privaata.

3. Roles of the Parties

For Customer Personal Data Processed through Privaata on behalf of the Customer:

the Customer generally acts as Controller; and

Kinfolk Technologies acts as Processor.

Where the Customer itself acts as a Processor for another Controller, Kinfolk Technologies may act as a Subprocessor in relation to that Processing.

Nothing in this DPA prevents Kinfolk Technologies from acting as an independent Controller for Personal Data that it processes for its own legitimate business purposes, such as certain account administration, contractual, billing, fraud-prevention, security, legal and business records.

Such independent Processing is governed by the Privaata Privacy Policy and applicable law rather than Kinfolk’s processor obligations under this DPA.

PART II — PROCESSING INSTRUCTIONS

4. Customer Instructions

Kinfolk Technologies will Process Customer Personal Data only:

on the Customer’s documented instructions;

as necessary to provide Privaata and functionality requested or configured by the Customer;

as necessary to comply with the Main Agreement; or

where otherwise required by applicable law.

The Customer’s documented instructions include the Main Agreement, this DPA, authorized configurations within Privaata, use of Privaata features and other written instructions agreed between the parties.

5. Connected Systems as Customer Instructions

Where the Customer voluntarily connects a third-party system to Privaata, the Customer instructs Kinfolk Technologies to perform the Processing reasonably necessary to provide the functionality the Customer has authorized.

This may include retrieving, transmitting, scanning, indexing, analyzing, organizing or otherwise Processing information from an authorized connected system.

The mere technical availability of an integration does not constitute authorization to access a third-party system.

The Customer remains responsible for ensuring that it has appropriate authority to establish the connection and instruct the resulting Processing.

6. Unlawful Instructions

If Kinfolk Technologies reasonably believes that a Customer instruction infringes Applicable Data Protection Law, Kinfolk may inform the Customer and, where appropriate, suspend the affected Processing while the issue is addressed.

Nothing in this DPA requires Kinfolk Technologies to knowingly perform unlawful Processing.

PART III — CUSTOMER RESPONSIBILITIES

7. Customer Authority and Lawful Processing

The Customer is responsible for ensuring that its collection and Processing of Customer Personal Data, and its instructions to Kinfolk Technologies, comply with Applicable Data Protection Law.

The Customer represents that it has the rights, permissions, notices, lawful bases, consents or other legal authority required, as applicable, to:

provide Customer Personal Data to Privaata;

instruct Kinfolk Technologies to Process it;

connect relevant third-party systems;

authorize users to access it;

use Privaata’s privacy-management functionality; and

otherwise Process the information for the Customer’s intended purposes.

Kinfolk Technologies does not become responsible for establishing the Customer’s lawful basis merely because Privaata provides technology used to perform the Processing.

8. Data Minimization

Customers should use reasonable efforts to limit Customer Personal Data provided to Privaata to information appropriate and reasonably necessary for the Customer’s legitimate use of the service.

Customers should avoid unnecessarily submitting Personal Data merely because Privaata technically permits it.

9. Customer Security Responsibilities

The Customer remains responsible for security matters within its reasonable control, including:

managing authorized users;

assigning appropriate permissions;

protecting account credentials;

managing administrative access;

configuring integrations appropriately;

removing access when no longer required; and

using Privaata in accordance with applicable security requirements.

PART IV — KINFOLK TECHNOLOGIES’ OBLIGATIONS

10. Confidentiality

Kinfolk Technologies will ensure that persons authorized to Process Customer Personal Data are subject to appropriate confidentiality obligations.

Access to Customer Personal Data will be limited to persons who require access for authorized purposes.

11. Security Measures

Kinfolk Technologies will implement and maintain appropriate technical and organizational measures designed to protect Customer Personal Data against accidental or unlawful:

destruction;

loss;

alteration;

unauthorized disclosure;

unauthorized access; or

other unlawful Processing.

Security measures will take into account matters such as the nature of the Processing, reasonably identifiable risks and the nature of the Personal Data involved.

No information system can be guaranteed to be completely secure, and this DPA does not constitute a guarantee that a Personal Data Breach can never occur.

12. Security Documentation

Kinfolk Technologies may maintain additional documentation describing relevant technical and organizational security measures.

Where appropriate and subject to reasonable confidentiality and security restrictions, Kinfolk may make relevant information available to Customers to assist them in evaluating Privaata’s security measures.

PART V — SUBPROCESSORS

13. Authorization to Use Subprocessors

The Customer provides general authorization for Kinfolk Technologies to engage Subprocessors reasonably necessary to provide, secure, maintain or support Privaata.

Subprocessors may provide services relating to areas such as:

cloud infrastructure;

hosting;

databases;

authentication;

communications;

email delivery;

artificial intelligence;

monitoring;

security;

analytics;

customer support; and

other infrastructure or service functionality.

14. Subprocessor Obligations

Before allowing a Subprocessor to Process Customer Personal Data, Kinfolk Technologies will impose appropriate contractual data-protection obligations consistent with the nature of the services being provided.

Kinfolk Technologies remains responsible for its obligations under this DPA where Processing is performed through an authorized Subprocessor, subject to the terms and limitations of the Main Agreement and applicable law.

15. Subprocessor List

Kinfolk Technologies will maintain a current Subprocessor List identifying applicable material Subprocessors.

The Subprocessor List may identify information such as:

Subprocessor name;

service provided;

Processing purpose; and

relevant Processing location or jurisdiction where appropriate.

The Subprocessor List may be maintained separately from this DPA so that infrastructure changes do not require rewriting the DPA itself.

16. Changes to Subprocessors

Kinfolk Technologies may add or replace Subprocessors as Privaata evolves.

Where appropriate under Applicable Data Protection Law or the applicable Customer agreement, Kinfolk Technologies will provide reasonable notice of a material new Subprocessor before that Subprocessor begins materially Processing Customer Personal Data.

17. Customer Objections

A Customer may raise a reasonable and documented objection to a new Subprocessor where the objection is based on legitimate data-protection concerns.

The parties will attempt in good faith to address the concern.

Where the concern cannot reasonably be resolved, Kinfolk Technologies may, where feasible:

provide an alternative;

modify the affected Processing;

restrict the affected functionality; or

permit termination of the affected service in accordance with the applicable agreement.

This provision does not give the Customer an unrestricted right to veto Kinfolk Technologies’ infrastructure or service providers.

PART VI — INTERNATIONAL DATA PROCESSING

18. Processing Locations

Customer Personal Data may be Processed in the United States and in other jurisdictions in which Kinfolk Technologies or its authorized Subprocessors operate.

The Customer acknowledges that use of a cloud-based service may involve international Processing.

19. International Transfer Safeguards

Where Applicable Data Protection Law requires a particular mechanism or safeguard for an international transfer of Customer Personal Data, Kinfolk Technologies will implement an appropriate legally recognized mechanism or safeguard where required for its Processing.

Nothing in this DPA should be interpreted as representing that a particular transfer mechanism applies where it is not legally required or has not been implemented.

PART VII — DATA SUBJECT RIGHTS

20. Data Subject Requests

Taking into account the nature of the Processing, Kinfolk Technologies will provide reasonable assistance to the Customer in responding to requests from Data Subjects to exercise rights available under Applicable Data Protection Law.

Such rights may include, where applicable:

access;

correction;

deletion;

restriction;

objection;

portability; and

other applicable rights.

21. Requests Received Directly by Kinfolk Technologies

If Kinfolk Technologies receives a Data Subject request relating to Customer Personal Data, Kinfolk will ordinarily:

identify, where reasonably possible, the relevant Customer;

notify or refer the request to that Customer where appropriate; and

avoid independently determining the substantive response unless authorized by the Customer or required by law.

Kinfolk Technologies may communicate with the Data Subject as reasonably necessary to identify the appropriate Customer or explain that the request should be directed to the relevant organization.

22. Customer Responsibility for Responses

The Customer remains responsible for determining:

whether a Data Subject request is valid;

whether the requester’s identity has been appropriately verified;

what legal rights apply;

whether an exemption applies;

what information should be disclosed; and

the final response to the Data Subject,

except where applicable law places a particular responsibility directly on Kinfolk Technologies.

PART VIII — PERSONAL DATA BREACHES

23. Breach Notification

If Kinfolk Technologies becomes aware of a confirmed Personal Data Breach involving Customer Personal Data, Kinfolk Technologies will notify the affected Customer without undue delay.

Notification may be made to the Customer’s designated administrator, security contact, privacy contact or other appropriate contact.

24. Breach Information

To the extent reasonably available, Kinfolk Technologies will provide information appropriate to assist the Customer in understanding the Personal Data Breach, which may include:

the nature of the incident;

categories of affected information;

categories or approximate number of affected Data Subjects where known;

approximate volume of affected records where known;

likely consequences where reasonably ascertainable;

measures taken or proposed to contain or remediate the incident; and

other reasonably available information necessary for the Customer’s applicable notification obligations.

Information may be provided in phases where all details are not immediately available.

25. Breach Cooperation

Kinfolk Technologies will provide reasonable cooperation regarding investigation, containment and remediation of a Personal Data Breach involving Customer Personal Data.

The Customer remains responsible for determining its own regulatory and Data Subject notification obligations unless applicable law provides otherwise.

Notification by Kinfolk Technologies does not constitute an admission of fault or liability.

PART IX — DPIAs AND REGULATORY ASSISTANCE

26. Data Protection Impact Assessments

Taking into account the nature of the Processing and information available to Kinfolk Technologies, Kinfolk will provide reasonable assistance where the Customer is legally required to conduct a data-protection impact assessment relating to its use of Privaata.

27. Regulatory Consultation

Where required by Applicable Data Protection Law and reasonably related to Kinfolk Technologies’ Processing, Kinfolk will provide reasonable assistance with prior consultation or inquiries from a competent data-protection authority.

This obligation does not require Kinfolk Technologies to provide the Customer with legal representation or independent legal advice.

PART X — ARTIFICIAL INTELLIGENCE

28. AI Processing

Where the Customer uses Privaata functionality involving artificial intelligence, Customer Personal Data submitted to or Processed through that functionality remains Customer Personal Data for purposes of this DPA.

Kinfolk Technologies may Process such information only as necessary to provide the Customer-authorized AI functionality, operate or secure the service, comply with documented Customer instructions or meet applicable legal requirements.

29. No General-Purpose AI Model Training

Kinfolk Technologies will not use Customer Personal Data to train general-purpose or publicly available artificial intelligence models.

Where an external AI provider Processes Customer Personal Data to provide an authorized Privaata feature, that Processing will be subject to applicable Subprocessor requirements under this DPA.

30. AI Subprocessors

An external AI service provider that receives Customer Personal Data in connection with Privaata’s authorized AI functionality will be treated as an applicable Subprocessor where required.

Kinfolk Technologies will take reasonable steps to ensure that appropriate contractual and data-protection safeguards govern such Processing.

The applicable provider should be identified on Privaata’s Subprocessor List.

PART XI — AUDITS AND COMPLIANCE INFORMATION

31. Demonstrating Compliance

Kinfolk Technologies will make available information reasonably necessary to demonstrate compliance with its obligations under this DPA, taking into account:

the nature of Privaata;

security considerations;

confidentiality obligations;

the rights of other Customers; and

available compliance documentation.

32. Customer Audits

Where reasonably necessary to satisfy applicable legal obligations and where available documentation is insufficient, a Customer may request an audit relating to Kinfolk Technologies’ Processing of Customer Personal Data.

Audits must:

be based on legitimate data-protection concerns;

be conducted on reasonable advance notice;

occur at a mutually reasonable time;

avoid unreasonable disruption;

be subject to appropriate confidentiality obligations;

avoid accessing another Customer’s information;

avoid compromising Privaata’s security; and

be limited to information reasonably relevant to Kinfolk Technologies’ obligations under this DPA.

The parties may agree to use an independent qualified auditor where appropriate.

33. Audit Costs

Unless required otherwise by applicable law or agreed between the parties, the Customer will bear reasonable costs associated with extraordinary Customer-specific audit requests beyond information Kinfolk Technologies ordinarily makes available.

This does not prevent Kinfolk Technologies from voluntarily providing compliance documentation without charge.

PART XII — GOVERNMENT AND LEGAL REQUESTS

34. Legally Binding Requests

If Kinfolk Technologies receives a legally binding request from a court, government authority, regulator or law-enforcement body requiring disclosure of Customer Personal Data, Kinfolk Technologies may comply with that request to the extent legally required.

Where legally permitted, Kinfolk Technologies will seek to notify the affected Customer before disclosure or otherwise within a legally permissible timeframe.

35. Limited Disclosure

Where reasonably possible and legally permitted, Kinfolk Technologies will seek to limit disclosure to information responsive to the valid legal requirement.

Nothing in this DPA requires Kinfolk Technologies to obstruct or violate a lawful order.

PART XIII — RETURN, EXPORT AND DELETION

36. Customer Access During Subscription

During an active subscription, Customers may access and export Customer Data using functionality made available through Privaata, subject to applicable plan, security and technical requirements.

37. Termination and Data Retrieval

Following termination or expiration of the applicable subscription, ordinary Customer Data will generally remain available or recoverable for up to 30 days, subject to the functionality and status of the account, to allow reasonable opportunity for retrieval or export.

Customers are responsible for exporting information they wish to retain before the applicable deletion period expires.

38. Deletion

After the applicable post-termination retention period, Kinfolk Technologies will delete or render inaccessible Customer Personal Data from active systems in accordance with its applicable deletion procedures, except where:

continued retention is required by law;

information must reasonably be retained for legitimate security, fraud-prevention, dispute, accounting or legal purposes; or

residual copies remain temporarily within backups.

Any retained information remains subject to applicable protections.

39. Backup Copies

Customer Personal Data may remain temporarily within backup systems after deletion from active production systems.

Residual backup copies will remain protected and will be deleted, overwritten or otherwise removed according to Kinfolk Technologies’ applicable backup-retention procedures.

Kinfolk Technologies will not restore deleted Customer Personal Data from backup for ordinary operational use except where reasonably necessary for disaster recovery, security or other legitimate restoration purposes.

The precise backup-retention lifecycle should be technically verified before this DPA is placed into production.

PART XIV — SPECIAL CATEGORIES AND SENSITIVE DATA

40. Sensitive Personal Data

Customers may use Privaata to Process sensitive or specially protected categories of Personal Data where necessary for legitimate privacy-management purposes.

The Customer remains responsible for ensuring that such Processing is lawful and appropriately safeguarded.

Kinfolk Technologies will apply its applicable security measures to Customer Personal Data in accordance with this DPA.

41. Children’s Personal Data

Where Customer Personal Data includes information relating to children or minors, the Customer remains responsible for ensuring that it has the necessary authority, lawful basis, consent, notice or other requirements applicable to that Processing.

The presence of children’s Personal Data within a Customer workspace does not by itself mean that Privaata is offered directly to children.

PART XV — CONFIDENTIALITY AND OWNERSHIP

42. Customer Ownership

As between Kinfolk Technologies and the Customer, the Customer retains its rights in Customer Data.

Kinfolk Technologies does not acquire ownership of Customer Personal Data merely because the information is stored or Processed through Privaata.

43. Limited Processing Rights

The Customer grants Kinfolk Technologies only those rights in Customer Personal Data reasonably necessary to provide, secure, maintain and support Privaata, carry out documented Customer instructions and satisfy applicable legal obligations.

PART XVI — LIABILITY AND CONTRACTUAL RELATIONSHIP

44. Liability

The liability of the parties arising from or relating to this DPA will be governed by the applicable limitations, exclusions and allocation of liability contained in the Main Agreement, Terms of Service or applicable enterprise agreement, except to the extent Applicable Data Protection Law prohibits such limitation.

Nothing in this DPA excludes liability that cannot lawfully be excluded.

45. Conflict With Other Agreements

If this DPA conflicts with the Main Agreement regarding the Processing of Customer Personal Data, this DPA will control to the extent of that conflict unless the parties expressly agree otherwise in writing.

An enterprise agreement may establish additional or more specific data-protection requirements.

46. Duration

This DPA becomes effective when Kinfolk Technologies begins Processing Customer Personal Data on behalf of the Customer and remains effective for as long as such Processing continues.

Relevant obligations concerning confidentiality, deletion, security and other matters that by their nature survive termination will continue as applicable.

47. Governing Law

Unless an applicable enterprise agreement provides otherwise, this DPA will be governed by the laws of Jamaica, subject to any mandatory provisions of Applicable Data Protection Law that apply irrespective of contractual choice of law.

48. Changes to the DPA

Kinfolk Technologies may update this DPA where reasonably necessary to reflect:

changes in law;

changes in Privaata’s Processing;

new functionality;

regulatory requirements;

changes to security or infrastructure; or

other legitimate operational requirements.

Where required by applicable law or contract, Kinfolk Technologies will provide appropriate notice of material changes.

SCHEDULE 1 — DETAILS OF PROCESSING

A. Subject Matter

The Processing of Customer Personal Data as necessary to provide Privaata and Customer-authorized privacy-management, data-protection, compliance, governance, AI-assisted and related functionality.

B. Duration of Processing

Processing will generally continue:

for the duration of the Customer’s subscription or other contractual relationship with Kinfolk Technologies, plus the applicable post-termination retention and deletion period.

Certain information may remain temporarily in protected backups or be retained where required by law or permitted under the applicable agreement.

C. Nature of Processing

Depending on Customer configuration and functionality used, Processing may include:

collection;

receipt;

recording;

organization;

structuring;

storage;

retrieval;

consultation;

searching;

scanning;

indexing;

classification;

analysis;

mapping;

comparison;

transmission;

generation of reports or drafts;

AI-assisted analysis;

access management;

export;

restriction;

deletion; and

other Processing reasonably necessary to provide Customer-authorized Privaata functionality.

D. Purposes of Processing

Processing may be performed to provide functions including:

privacy-management workflows;

Records of Processing Activities;

Data Protection Impact Assessments;

Data Subject Access Requests;

data inventories;

data mapping;

connected-system analysis;

privacy-risk identification;

incident and breach management;

consent-related records;

vendor and third-party governance;

compliance documentation;

reporting;

AI-assisted privacy analysis and recommendations;

security;

authentication;

administration;

support; and

other functionality requested or configured by the Customer.

E. Categories of Data Subjects

Depending on the Customer and its use of Privaata, Customer Personal Data may relate to:

employees;

former employees;

job applicants;

contractors;

consultants;

volunteers;

customers;

prospective customers;

clients;

service users;

website users;

vendors;

supplier personnel;

business contacts;

members;

students;

patients;

donors;

beneficiaries;

dependants;

children or minors where lawfully processed; and

other individuals whose Personal Data the Customer lawfully manages.

Not every category applies to every Customer.

F. Categories of Personal Data

Depending on the Customer’s activities and configuration, Customer Personal Data may include:

names;

contact information;

identification information;

organizational identifiers;

employment information;

applicant information;

customer information;

account information;

communications;

email-related information;

document information;

transaction-related records;

organizational records;

technical information;

online identifiers;

privacy requests;

consent information;

compliance records;

incident information;

risk assessments;

vendor information;

audit records;

information discovered through authorized connected systems; and

other Personal Data submitted or made available by the Customer.

G. Sensitive or Specially Protected Personal Data

Depending on the Customer’s use of Privaata, Customer Personal Data may include categories of information receiving enhanced protection under applicable law.

Such information may include, where applicable:

health information;

biometric information;

racial or ethnic information;

religious or philosophical information;

political information;

trade-union information;

sexual-life or sexual-orientation information;

criminal-offence information;

financial information;

government identification information; and

other sensitive or specially protected Personal Data.

Privaata does not require every Customer to Process these categories, and their inclusion depends upon the Customer’s own Processing activities.

H. Frequency of Processing

Processing may occur continuously, periodically, on demand or in response to Customer actions, depending upon:

features enabled;

integrations configured;

automated workflows;

scheduled operations;

user activity; and

Customer instructions.

SCHEDULE 2 — SUBPROCESSORS

Kinfolk Technologies will maintain a separate, current Privaata Subprocessor List.

The list should identify, as appropriate:

Information

Description

Subprocessor

Legal/company name

Service

Service supplied to Privaata

Purpose

Why Customer Personal Data may be Processed

Data involved

General categories where appropriate

Processing location

Relevant country/region where known

Transfer mechanism

Where legally applicable

The Subprocessor List should be made available to Customers through an appropriate Privaata legal, trust or privacy page.

Specific Subprocessors must be technically and contractually verified before publication rather than inferred or invented.

SCHEDULE 3 — TECHNICAL AND ORGANIZATIONAL MEASURES

Kinfolk Technologies will maintain appropriate technical and organizational measures designed to protect Customer Personal Data.

The definitive security schedule should reflect Privaata’s actual production architecture and should be verified before contractual publication.

Relevant areas may include, where actually implemented:

identity and access management;

authentication controls;

authorization and role-based access;

encryption in transit;

encryption at rest where implemented;

credential and secret management;

tenant isolation;

logging and monitoring;

audit logging;

vulnerability management;

secure software-development practices;

backup and recovery;

incident response;

infrastructure security;

Subprocessor management;

employee/personnel access controls;

data-retention and deletion controls;

availability and resilience measures; and

other safeguards appropriate to the Processing.

This Schedule must not be converted into contractual security guarantees until each control has been verified against Privaata’s actual production environment.

Contact

Kinfolk Technologies LimitedPrivaata18 Geranium PathMona HeightsKingston 6Jamaica

Privacy: privacy@kinfolktechnologies.comSecurity: security@kinfolktechnologies.comSupport: support@kinfolktechnologies.comTelephone: (876) 298-4018

End of Privaata Data Processing Agreement