Trust · DPA

Data processing, between the lines.

Effective
June 3, 2026
Last reviewed
June 3, 2026
Entity
Kairo Labs LLC · Chicago, IL
TL;DR

The DPA supplements the Terms for customers processing personal data on Kairo. It defines roles (Kairo as Processor, you as Controller), scope, sub-processors, security obligations, breach notification, and data return/deletion. Email legal@heykairo.io to countersign or opt in.

The full document below is the legal version. The TL;DR is our reading of it, in plain English.

This Data Processing Agreement (DPA) supplements the Terms of Service between Kairo Labs LLC (Kairo, the Processor) and the Customer (the Controller) and governs Kairo's processing of personal data on the Customer's behalf. Email legal@heykairo.io to countersign or opt in for your workspace.

1. Definitions

Terms have the meanings given in applicable data-protection law (GDPR for EEA/UK customers, CCPA/CPRA for California customers, and analogous frameworks elsewhere). "Customer Data" means any personal data that Customer or its users submit to Kairo via the service.

2. Subject matter and duration

Subject matter: processing of Customer Data as necessary to provide Kairo to Customer under the Terms of Service. Duration: the period of the subscription, plus the retention windows in Section 8.

3. Nature and purpose of processing

Kairo processes Customer Data to host, store, transmit, organize, search, and reason over the content Customer or its users create in Kairo, and to provide AI-assisted features (Kairo AI, semantic retrieval, auto-extraction) at the user's request.

4. Categories of data subjects

  • Customer employees, contractors, and other authorized users.
  • Customer's collaborators, contacts, and the people they reference inside captured content.

5. Categories of personal data

  • Account data: name, email, profile photo, preferences.
  • Workspace content: notes, tasks, decisions, polls, documents, calendar items, messages, comments.
  • Usage data: feature interactions, timestamps, IP addresses (operational logs).
  • Integration data: items Customer chooses to sync from connected calendars / docs / chat tools.

Kairo does not knowingly process special-category data (health, biometric, genetic, religious, or political affiliation). Customer is responsible for not introducing such data without a lawful basis.

6. Customer obligations

Customer warrants that it has the legal basis to provide the Customer Data to Kairo and to instruct Kairo's processing. Customer is the Controller; Kairo acts only on documented Customer instructions (which include the configuration choices made in the product).

7. Sub-processors

Customer authorizes Kairo to engage sub-processors as listed in our Sub-processors page. We will give 30 days' advance notice before adding or replacing a category of sub-processor, by email to the Customer billing contact. Customer may object on reasonable grounds; if we can't resolve the objection, either party may terminate the affected portion of the service.

8. Security

Kairo implements the technical and organizational measures described in our Security page: encryption in transit (TLS 1.2+) and at rest (AES-256), row-level access controls, least-privilege production access, audit logging, time-bound session tokens, secret rotation, dependency scanning, and incident response.

9. Personal data breach

Kairo will notify Customer without undue delay (and in any event within 72 hours) after becoming aware of a personal-data breach affecting Customer Data. Notice will include what we know about scope, affected data, likely consequences, and the steps we are taking.

10. Data subject rights

Kairo will provide reasonable assistance to Customer in responding to requests from data subjects to exercise their rights (access, rectification, erasure, restriction, portability, objection). The product's export, deletion, and member-removal tooling generally suffices; Customer can escalate to privacy@heykairo.io for anything the tooling doesn't cover.

11. International transfers

Customer Data is processed primarily in the United States. For any cross-border transfer of personal data from the EEA/UK/Switzerland, the parties incorporate the European Commission's Standard Contractual Clauses (Module Two, Controller to Processor) by reference.

12. Audit

Customer may, no more than once per twelve months, request a copy of Kairo's most recent third-party security report under NDA. Kairo is not currently SOC 2 audited and will indicate this on request. On-site audits can be discussed by contacting legal@heykairo.io.

13. Deletion at end of services

Upon termination, Kairo will, at Customer's choice, return or delete all Customer Data within 30 days, except where retention is required by law. Backups are purged on their normal rotation (≤ 90 days).

14. Liability

Each party's liability under this DPA is subject to the limitations of liability in the Terms of Service.

15. Signing the DPA

This DPA can be incorporated into Customer's subscription on request. If your procurement process requires a countersigned copy, email legal@heykairo.io from your billing contact and we'll issue one.

Questions?

Legal questions: legal@heykairo.io. General questions: hello@heykairo.io. We read every message.

Browse the rest of the trust center: Trust Center.

Data Processing Agreement · Kairo