Legal · Data Processing

Data Processing Addendum

Effective: August 3, 2026Last updated: August 3, 2026

This Addendum forms part of the agreement between KPI360 and a Customer and governs KPI360’s processing of personal data on the Customer’s behalf. It supplements the Terms of Service.

1.Roles and scope

For personal data contained in Customer Data, the Customer is the controller and KPI360 is the processor. KPI360 processes such personal data only to provide the Service and on the Customer’s documented instructions (including as set out in the Terms and this Addendum), unless required to act otherwise by law. This Addendum applies where the Customer is subject to data-protection laws such as the GDPR, UK GDPR, or U.S. state privacy laws (e.g., CCPA/CPRA).

2.Definitions

“Personal Data,” “processing,” “controller,” “processor,” and “data subject” have the meanings given by applicable data-protection law. “Subprocessor” means a third party engaged by KPI360 to process Personal Data. Capitalized terms not defined here have the meaning in the Terms.

3.Details of processing (Annex A)

  • Subject matter: provision of the KPI360 analytics platform.
  • Duration: the term of the agreement plus any limited retention period.
  • Nature & purpose: hosting, storing, organizing, analyzing, and displaying Customer Data to produce dashboards, forecasts, and insights.
  • Categories of data subjects: the Customer’s Authorized Users and staff (e.g., managers, employees referenced in labor data).
  • Categories of Personal Data: business-contact details of Authorized Users; and, within operational data, limited employee-related figures such as hours and pay by location. KPI360 does not require special-category data and asks that none be submitted.

4.Processor obligations

KPI360 will: (a) process Personal Data only per the Customer’s instructions; (b) ensure persons authorized to process it are bound by confidentiality; (c) implement appropriate technical and organizational measures (Annex B); (d) assist the Customer, taking into account the nature of processing, with data-subject requests and with security, breach-notification, and impact-assessment obligations; and (e) make available information reasonably necessary to demonstrate compliance.

5.Security measures (Annex B)

KPI360 maintains measures including: encryption of data in transit and at rest; per-tenant logical isolation; role-based access control and least-privilege access; authentication and secret management; use of managed, patched infrastructure; and monitoring and incident response. See our Security page for details, which may be updated as measures evolve, provided the overall level of protection is not reduced.

6.Subprocessors

The Customer authorizes KPI360 to engage the subprocessors listed on our Security page. KPI360 imposes data-protection obligations on subprocessors substantially similar to those in this Addendum and remains responsible for their performance. KPI360 will give notice of intended additions or replacements of subprocessors with a reasonable opportunity to object on reasonable data-protection grounds.

7.Data-subject requests

Taking into account the nature of the processing, KPI360 will assist the Customer by appropriate technical and organizational measures, insofar as possible, to respond to requests from data subjects to exercise their rights. If KPI360 receives such a request directly, it will, where legally permitted, direct the data subject to the Customer.

8.Personal-data breach

KPI360 will notify the Customer without undue delay after becoming aware of a personal-data breach affecting the Customer’s Personal Data, and will provide information reasonably available to help the Customer meet its notification obligations.

9.Return and deletion

Upon termination and expiry of any export window, KPI360 will, at the Customer’s choice, delete or return the Personal Data and delete existing copies, unless retention is required by law.

10.Audits

KPI360 will make available information necessary to demonstrate compliance with this Addendum and will allow for and contribute to audits, including inspections, conducted by the Customer or an auditor mandated by the Customer, subject to reasonable confidentiality, scheduling, and scope limitations.

11.International transfers

Where Personal Data is transferred from a jurisdiction that restricts transfers, the parties will rely on a lawful transfer mechanism (such as the applicable standard contractual clauses), which are incorporated by reference to the extent required.

12.Liability and governing law

Each party’s liability under this Addendum is subject to the limitations of liability in the Terms. This Addendum is governed by the law and jurisdiction stated in the Terms (New York), except where applicable data-protection law requires otherwise. In case of conflict between this Addendum and the Terms regarding processing of Personal Data, this Addendum controls.

13.Contact

To request a countersigned copy of this Addendum or ask questions: privacy@kpi360.ai.