1. Purpose and Scope
This Data Processing Agreement ("DPA") supplements our Terms of Service and Privacy Policy. It governs the processing of personal data by Kiomon ("Processor") on behalf of its customers ("Controller"). It is designed to ensure compliance with applicable data protection laws, including the General Data Protection Regulation (GDPR) and the California Consumer Privacy Act (CCPA).
2. Nature and Purpose of Processing
Kiomon processes personal data solely to provide the Service (structuring context for AI agents) as instructed by the Controller. We act exclusively as a data processor for the content and context explicitly captured or ingested by the user.
The processing includes collection, structuring, storage, retrieval, and deletion of data as necessary to provide the intelligent knowledge base and context foraging tool.
3. Controller Obligations
The Controller agrees that it has all necessary rights, permissions, and lawful bases to collect and provide the personal data to Kiomon for processing. The Controller is responsible for responding to Data Subject requests and ensuring its own compliance with data protection laws.
4. Subprocessors
Kiomon engages third-party subprocessors to provide infrastructure, hosting, and operational services. By using our Service, the Controller provides general authorization for Kiomon to use these subprocessors. We ensure all subprocessors are bound by written agreements imposing equivalent data protection obligations.
A full list of our current subprocessors is available on our Subprocessors page. We will notify customers of any intended changes concerning the addition or replacement of subprocessors, providing the Controller the opportunity to object.
5. Security Measures
Kiomon implements and maintains appropriate technical and organizational measures to protect personal data against accidental or unlawful destruction, loss, alteration, unauthorized disclosure, or access. These measures include:
- Encryption of data in transit and at rest.
- Strict access controls and logical separation of Customer Data.
- Regular vulnerability scanning and security testing.
6. Data Breach and Incident Response
In the event of a confirmed personal data breach affecting the Controller's data, Kiomon will notify the Controller without undue delay after becoming aware of the breach. We will provide reasonable assistance to the Controller in fulfilling their obligation to notify data protection authorities and affected data subjects.
7. Data Subject Rights Assistance
We provide the Controller with the tools to export, delete, and manage their data directly from the Kiomon dashboard, allowing them to fulfill Data Subject Access Requests (DSARs) independently. If a data subject contacts Kiomon directly, we will promptly refer them to the Controller.
8. Data Transfer
If personal data originating from the European Economic Area (EEA), the UK, or Switzerland is transferred to a country not recognized as providing an adequate level of protection, we ensure appropriate safeguards are in place, such as executing Standard Contractual Clauses (SCCs), to protect the data.
9. Return or Deletion of Data
Upon termination of the Service, or upon the Controller's written request, Kiomon will securely delete or return all personal data to the Controller, unless further storage is required by applicable law.
10. Audits and Inspections
Kiomon will make available to the Controller all information necessary to demonstrate compliance with this DPA. Upon reasonable written request, Kiomon will allow for and contribute to audits or inspections conducted by the Controller or a mandated third-party auditor, subject to strict confidentiality obligations.