Data Processing Agreement

This Data Processing Agreement (DPA) sets out how KAZI processes personal data on behalf of business customers, in line with GDPR. It supplements our Terms of Service.

Key points

  • You are the Controller; KAZI is the Processor acting on your instructions.
  • Our sub-processors are listed, with 30-day advance notice of any change.
  • Data is encrypted in transit (TLS 1.3) and at rest (AES-256).
  • We notify you of any personal data breach within 48 hours.
On this page

Introduction

This Data Processing Agreement ("DPA") forms part of the agreement between you ("Customer", "Controller") and KAZI ("Processor") for the provision of services. This DPA reflects the parties' agreement regarding the processing of Personal Data in accordance with GDPR requirements.

For Business Customers

This DPA is intended for business customers who process personal data using the KAZI platform. If you are an individual user, please refer to our Privacy Policy.

1. Definitions

  • Personal Data: Any information relating to an identified or identifiable natural person as defined in GDPR Article 4(1)
  • Processing: Any operation performed on Personal Data as defined in GDPR Article 4(2)
  • Controller: The entity that determines the purposes and means of processing Personal Data
  • Processor: The entity that processes Personal Data on behalf of the Controller
  • Sub-processor: Any third party engaged by the Processor to process Personal Data
  • Data Subject: An identified or identifiable natural person
  • GDPR: Regulation (EU) 2016/679 - General Data Protection Regulation
  • Supervisory Authority: An independent public authority established by an EU Member State

2. Scope and Roles

Under this DPA:

  • The Customer acts as the Controller and determines the purposes and means of processing Personal Data
  • KAZI acts as the Processor and processes Personal Data on behalf of the Customer according to documented instructions
  • Processing is limited to the provision of services as described in the Terms of Service

3. Details of Processing

Subject Matter and Duration

  • Subject Matter: Provision of project management, collaboration, and freelance workflow services
  • Duration: For the term of the subscription or service agreement
  • Nature and Purpose: To provide the Platform's features including project management, client collaboration, file storage, and communication tools

Types of Personal Data

  • Contact information (names, email addresses, phone numbers)
  • Account credentials and authentication data
  • Professional information (company name, role, work details)
  • Project and task data created by users
  • Communication content (messages, comments, files)
  • Payment information (processed through third-party payment processors)
  • Financial-account data (balances and transactions) accessed read-only via bank-data aggregators, only when a user chooses to connect a bank account
  • Usage data and analytics

Categories of Data Subjects

  • Customer's employees and contractors
  • Customer's clients and end users
  • Third parties communicating with Customer through the Platform

4. Processor's Obligations

KAZI, as Processor, shall:

  • Process Only on Instructions: Process Personal Data only on documented instructions from the Customer, unless required by law
  • Ensure Confidentiality: Ensure that persons authorized to process Personal Data have committed to confidentiality
  • Implement Security Measures: Implement appropriate technical and organizational measures (as detailed in Section 6)
  • Respect Sub-processor Requirements: Engage Sub-processors only with prior written consent (general or specific)
  • Assist with Data Subject Rights: Assist the Customer in responding to Data Subject requests
  • Assist with Compliance: Assist the Customer in ensuring compliance with GDPR obligations
  • Delete or Return Data: At Customer's choice, delete or return all Personal Data after termination
  • Demonstrate Compliance: Make available information necessary to demonstrate compliance
  • Notify of Breaches: Notify the Customer without undue delay upon becoming aware of a Personal Data breach

5. Sub-processors

The Customer provides general authorization for KAZI to engage the following Sub-processors:

Sub-processorServiceLocation
Supabase Inc.Database and authentication servicesUSA (AWS infrastructure)
Vercel Inc.Hosting and CDN servicesUSA (Global CDN)
Paystack Payments LtdPayment processing (PCI DSS Level 1)Nigeria / South Africa
Plaid Inc.Read-only bank-account data aggregation (US, Canada, UK, Europe) — engaged only when a user connects a bank accountUSA
Stitch Money (Pty) LtdRead-only bank-account data aggregation (South Africa) — engaged only when a user connects a bank accountSouth Africa
OpenAI, L.L.C.AI inference — processes prompts and content you submit to AI features. Not used to train models.USA
OpenRouter, Inc.AI model routing and inference — routes AI feature prompts to model providers. Not used to train models.USA
Anthropic PBCAI inference (Claude models) — processes prompts and content you submit to AI features. Not used to train models.USA
Resend, Inc.Transactional and marketing email deliveryUSA
PostHog Inc.Product analytics and usage measurementUSA
Google LLCWeb analytics (Google Analytics)USA
Wasabi Technologies, Inc.Object storage for uploaded files and mediaUSA

Sub-processor Changes: KAZI will inform the Customer of any intended changes concerning the addition or replacement of Sub-processors at least 30 days in advance. The Customer may object to such changes on reasonable grounds relating to data protection.

Sub-processor Obligations: KAZI will impose the same data protection obligations on Sub-processors as set out in this DPA through a contract or other legal act.

6. Technical and Organizational Measures

KAZI implements the following security measures to protect Personal Data:

Access Control

  • Multi-factor authentication (MFA) for user accounts
  • Role-based access control (RBAC) for administrative functions
  • Regular access reviews and revocation of unnecessary permissions
  • Unique user credentials and audit logging of access

Data Encryption

  • TLS 1.3 encryption for data in transit
  • AES-256 encryption for data at rest
  • Encrypted backups with secure key management

Infrastructure Security

  • Firewalls and intrusion detection/prevention systems
  • Regular security updates and patch management
  • Network segmentation and isolation
  • DDoS protection and traffic monitoring

Organizational Measures

  • Background checks for employees with data access
  • Mandatory data protection training for all staff
  • Confidentiality agreements with employees and contractors
  • Incident response plan and security incident management
  • Regular security audits and penetration testing
  • Business continuity and disaster recovery plans

Data Integrity and Availability

  • Daily automated backups with 30-day retention
  • Redundant infrastructure and failover capabilities
  • High availability infrastructure commitment
  • Regular backup testing and restoration procedures

7. Data Subject Rights

KAZI will assist the Customer in fulfilling Data Subject rights requests, including:

  • Right of access to Personal Data
  • Right to rectification of inaccurate data
  • Right to erasure ("right to be forgotten")
  • Right to restriction of processing
  • Right to data portability
  • Right to object to processing

Upon receiving a Data Subject request, KAZI will:

  • Forward the request to the Customer within 48 hours
  • Provide reasonable assistance in responding to the request
  • Comply with Customer's instructions regarding the request
  • Not respond directly to the Data Subject unless authorized by the Customer

8. Data Breach Notification

In the event of a Personal Data breach, KAZI will:

  • Notify Promptly: Notify the Customer without undue delay and no later than 48 hours after becoming aware
  • Provide Details: Provide available information about the breach, including:
    • Nature of the breach and categories of data affected
    • Approximate number of Data Subjects and records affected
    • Likely consequences of the breach
    • Measures taken or proposed to address the breach
  • Cooperate: Cooperate with the Customer in investigating and remedying the breach
  • Assist with Notifications: Assist the Customer in complying with notification obligations to supervisory authorities and Data Subjects

9. International Data Transfers

Personal Data may be transferred to and processed in countries outside the European Economic Area (EEA). KAZI ensures appropriate safeguards for such transfers:

  • Standard Contractual Clauses (SCCs): KAZI has implemented the European Commission's Standard Contractual Clauses with Sub-processors located outside the EEA
  • Adequacy Decisions: Where possible, data is transferred to countries deemed by the European Commission to provide adequate protection
  • Supplementary Measures: Additional technical and organizational measures are implemented to ensure data protection equivalent to GDPR standards

10. Audits and Compliance

The Customer has the right to audit KAZI's compliance with this DPA:

  • Information Requests: KAZI will provide reasonable information about its data protection practices upon request
  • Audit Rights: The Customer may conduct audits or appoint an independent auditor, subject to:
    • Reasonable advance notice (at least 30 days)
    • No more than once per year unless required by supervisory authority
    • Execution of a confidentiality agreement
    • No disruption to KAZI's business operations
    • Customer bears the cost of the audit
  • Security Certifications: KAZI pursues relevant security certifications and will provide certificates upon request as they are obtained

11. Data Deletion and Return

Upon termination of services or at Customer's request, KAZI will:

  • Customer Choice: At the Customer's option, delete or return all Personal Data
  • Deletion Timeline: Complete deletion within 30 days of termination or request
  • Export Capability: Provide data export functionality for Customer to retrieve data
  • Secure Deletion: Ensure secure deletion methods that prevent data recovery
  • Exceptions: Retain data only where required by law, with notification to Customer
  • Certification: Provide written certification of deletion upon request

12. Limitation of Liability

Each party's liability under this DPA is subject to the limitations of liability set forth in the Terms of Service. For GDPR purposes, each party shall be liable for damages caused by processing where:

  • It has not complied with GDPR obligations specifically directed to processors/controllers, or
  • It has acted outside or contrary to lawful instructions from the Controller

13. Term and Termination

This DPA:

  • Comes into effect on the date of the Customer's acceptance of the Terms of Service
  • Remains in effect for the duration of the service agreement
  • Survives termination to the extent necessary to allow the parties to comply with their obligations under the GDPR

14. Governing Law

This DPA shall be governed by and construed in accordance with the laws applicable to the Terms of Service. For matters not addressed in this DPA, the GDPR and applicable data protection laws shall apply.

15. Contact Information

For questions or concerns regarding this DPA or data processing practices:

Acceptance

By using KAZI's services, the Customer acknowledges that it has read and understood this DPA and agrees to be bound by its terms. This DPA forms an integral part of the Terms of Service.

Last Updated: January 2026

Version: 1.0