This Data Processing Addendum (“DPA”) is a working draft prepared to establish structure and cover the required Article 28 GDPR terms. It has not yet been reviewed by qualified data-protection counsel and should not be offered to customers or signed until that review is complete. It draws on the structure common to peer vendors (e.g. controller-processor SCC incorporation, Module Two/Three selection, subprocessor flow-down).
This DPA forms part of the Subscription Terms of Service (the “Agreement”) between Kyroco, LLC (“Kyroco,” “we,” the “Processor”) and the customer identified in the Agreement (“Customer,” the “Controller”) for the provision of Korium (the “Service”). It applies to the extent Kyroco processes Personal Data on Customer’s behalf that is subject to Data Protection Laws, and prevails over any conflicting term in the Agreement with respect to such processing.
For Customer Content that Customer stores in Korium, Customer is the controller (or itself a processor acting for a third-party controller) and Kyroco is the processor (or subprocessor). Kyroco processes that data only on Customer’s documented instructions. Kyroco is an independent controller for the limited account, billing, security, and operational data described in the Privacy Policy, which that policy - not this DPA - governs.
Capitalized terms not defined here have the meaning in the Agreement. “Data Protection Laws” means all laws applicable to the processing of Personal Data under the Agreement, including the EU General Data Protection Regulation 2016/679 (“GDPR”), the UK GDPR and Data Protection Act 2018, the Swiss Federal Act on Data Protection, and US state privacy laws such as the CCPA. “Controller,” “Processor,” “Data Subject,” “Personal Data,” “Personal Data Breach,” and “processing” have the meanings given in the GDPR. “Customer Content” means data Customer or its users submit to the Service. “SCCs” means the Standard Contractual Clauses annexed to European Commission Implementing Decision (EU) 2021/914. “Subprocessor” means a third party engaged by Kyroco to process Personal Data.
The parties acknowledge that, with respect to Customer Content, Customer is the Controller and Kyroco is the Processor; where Customer is itself a processor, Kyroco is a subprocessor. The subject-matter, duration, nature and purpose of the processing, the types of Personal Data, and the categories of Data Subjects are described in Annex I. Kyroco processes Personal Data only to provide and support the Service and as otherwise instructed by Customer in accordance with this DPA.
Kyroco will process Personal Data only on Customer’s documented instructions, including the Agreement, this DPA, and Customer’s configuration and use of the Service, unless required to process by law (in which case Kyroco will inform Customer of that legal requirement unless prohibited). Kyroco will inform Customer if, in its opinion, an instruction infringes Data Protection Laws. Customer is responsible for the lawfulness of Customer Content and for having a lawful basis (and, for any special-category data it chooses to submit, a valid Article 9 condition).
Kyroco ensures that persons authorized to process the Personal Data are bound by an appropriate duty of confidentiality and process the data only as instructed.
Kyroco implements and maintains the technical and organizational measures set out in Annex II, appropriate to the risk under Article 32 GDPR, taking into account the state of the art, costs, and the nature, scope, context, and purposes of processing. Customer has reviewed those measures and agrees they are appropriate for Customer Content, considering the risk. Kyroco may update the measures provided the overall level of protection is not reduced.
Customer grants Kyroco general authorization to engage Subprocessors to process Personal Data, subject to this Section. A current list of Subprocessors is published at kyroco.ai/legal/subprocessors. Kyroco will give Customer at least thirty (30) days’ advance notice (via the subprocessor page and/or email) before adding or replacing a Subprocessor, during which Customer may object on reasonable data-protection grounds; the parties will work in good faith to resolve the objection, and if they cannot, Customer may terminate the affected Service. Kyroco imposes on each Subprocessor, by written contract, data-protection obligations no less protective than those in this DPA, and remains fully liable to Customer for each Subprocessor’s performance.
Taking into account the nature of the processing, Kyroco will assist Customer by appropriate technical and organizational measures, insofar as possible, to respond to requests to exercise Data-Subject rights (access, rectification, erasure, restriction, portability, and objection), including through Service functionality that lets Customer access, export, correct, and delete Customer Content. If Kyroco receives a request directly from a Data Subject regarding Customer Content, it will not respond other than to direct the Data Subject to Customer, and will promptly inform Customer.
Kyroco will notify Customer without undue delay after becoming aware of a Personal Data Breach affecting Customer Content, and will provide information reasonably available to it to help Customer meet its own notification obligations under Articles 33 to 34 GDPR, together with the measures Kyroco takes to address the breach. Kyroco’s target is to notify Customer without undue delay and no later than 72 hours after it becomes aware. Kyroco’s notification is not an acknowledgment of fault.
Kyroco will provide reasonable assistance to Customer with data-protection impact assessments and any prior consultation with a supervisory authority under Articles 35 to 36 GDPR, taking into account the nature of processing and the information available to Kyroco.
On termination or expiry of the Service, and at Customer’s choice, Kyroco will delete or return all Customer Content and delete existing copies, unless retention is required by law. Deletion covers the source data and, on Kyroco’s standard cycle, derived artifacts (including embeddings and index entries) and routine backups. The Service’s post-termination retrieval period is described in the Agreement.
Kyroco will make available to Customer information reasonably necessary to demonstrate compliance with this DPA and will allow for and contribute to audits, including inspections, conducted by Customer or an auditor it mandates. To satisfy audit rights, Kyroco may first offer relevant third-party certifications, reports, or summaries (e.g. SOC 2, security whitepaper). Audits are on reasonable prior notice, no more than once per year absent a Personal Data Breach or regulator requirement, during business hours, and subject to confidentiality.
Kyroco is based in the United States and processes Customer Content there by default. Where Kyroco processes Personal Data subject to GDPR, UK, or Swiss law and transfers it to a country without an adequacy decision, the transfer is governed by the SCCs, which are incorporated into this DPA by reference and completed as follows:
Kyroco has assessed the risks of US transfers and applies supplementary measures, including strong encryption in transit and at rest and strict access controls, as described in Annex II.
Where the CCPA (as amended) or a comparable US state law applies, Kyroco acts as a service provider (or contractor / processor). Kyroco will not sell or share Personal Data, will not retain, use, or disclose it except to perform the Service (or as permitted by law), will not combine it with data from other sources except as permitted, and certifies that it understands and will comply with these restrictions. Customer may take reasonable steps to ensure Kyroco uses Personal Data consistently with Customer’s obligations.
Each party’s liability under this DPA is subject to the limitations and exclusions of liability in the Agreement. This DPA is governed by the law and jurisdiction stated in the Agreement, except where Data Protection Laws or the SCCs require otherwise. If any provision conflicts with the SCCs, the SCCs prevail for the relevant transfer. This DPA takes effect on the effective date of the Agreement and remains in force while Kyroco processes Personal Data on Customer’s behalf.
Data exporter: the Customer identified in the Agreement (controller, or processor acting for a third-party controller). Data importer: Kyroco, LLC, 5772 Bridgeboro Way, Peachtree Corners, GA 30092, provider of the Korium Service (processor). EU/UK representative for Kyroco under Article 27: to be designated (see our Privacy Policy for current status). Contact for data protection: reports@kyroco.ai.
The supervisory authority of the EU member state in which Kyroco’s EU representative is established, or of the customer’s lead establishment where applicable.
Kyroco maintains the following measures (subject to update without reducing the overall level of protection):
For US transfers, the encryption and access-control measures above serve as supplementary measures supporting the SCCs.
The authorized Subprocessors are those listed at kyroco.ai/legal/subprocessors, which is incorporated into this DPA by reference and maintained current. As of the effective date they include:
| Subprocessor | Purpose | Location |
|---|---|---|
| Amazon Web Services | Cloud infrastructure & hosting; managed LLM inference (Bedrock) | United States |
| Stripe | Payments & subscription billing | United States |
| Cloudflare | DNS, CDN, network security | United States / global |
| Google (Workspace) | Transactional & business email | United States |
Prepared 2026-07-21. This DPA should be reviewed by data-protection counsel before it is offered to customers or signed.