Data Processing Agreement

Standard Kodiac DPA, template summary

This page summarises the standard Data Processing Agreement (DPA) Kodiac executes with Enterprise customers under UK GDPR (Article 28) and EU GDPR. For the signed version, request one from legal@kodiac.ai; we'll send a counter-signed copy within 5 business days.

1. Roles

Customer is the data controller; Kodiac is the data processor. Sub-processors are listed in our Privacy Policy.

2. Subject matter & duration

Processing covers the personal data Customer uploads or generates through use of the Service, for the duration of the subscription and any post-termination retention window agreed in the order form.

3. Nature and purpose

Kodiac processes personal data solely to provide the Service: AI visibility monitoring, content management, brand-agent deployment, and the platform features bundled with each plan.

4. Categories of data subjects

  • Customer's employees and contractors (Workspace users)
  • Identifiable individuals named in Customer's content records, source-of-truth facts, or competitor lists
  • End-users whose queries reach Customer's deployed Brand Agent (transient, not retained beyond the Interaction record)

5. Categories of personal data

  • Identification data: name, email, role
  • Authentication data: hashed credentials, MFA factors
  • Usage telemetry: workspace activity, audit log entries
  • Communication content: support exchanges, in-product messages

6. Security measures

  • Encryption in transit (TLS 1.2+) and at rest (AES-256-GCM)
  • Multi-tenant isolation via Postgres row-level security policies
  • Role-based access controls with least-privilege
  • Mandatory MFA for Kodiac personnel with production access
  • Continuous logging and audit-trail retention
  • Annual independent SOC 2 Type II audit (planned)

7. Sub-processors

Current list: Vercel, Neon, Inngest, Resend, Stripe, and the AI providers you enable (Anthropic, OpenAI, Google, Perplexity). Updates are notified to Customer at least 30 days before the new sub-processor takes effect; Customer may object on reasonable grounds.

8. International transfers

Transfers outside the UK/EEA rely on the UK IDTA and EU SCCs (2021/914) with our sub-processors. Customer's region pin (set in Brand or Workspace settings) controls where primary processing occurs.

9. Customer rights

  • Customer may audit Kodiac's compliance no more than once per year, on 30 days' notice, at Customer's expense, covering technical and organisational measures.
  • Kodiac will provide reasonable assistance for data subject rights requests and DPIA preparation.
  • On termination, Kodiac will delete or return Customer personal data per the retention window in Section 5 of the Privacy Policy.

10. Breach notification

Kodiac notifies Customer within 72 hours of becoming aware of a personal-data breach affecting Customer data, with the information required by Article 33 GDPR.

11. Term & termination

The DPA runs concurrent with the subscription. Termination of the subscription terminates the DPA, subject to the post-term retention window agreed in the order form.


Request a signed DPA

Email legal@kodiac.ai with your legal entity name + signatory details. We'll send a counter-signed copy within 5 business days. Sample DPA PDF can be sent in advance for legal review.