Data processing agreement (DPA)

This page describes the framework for Kloner's data processing agreement. The agreement is a legally binding addendum to the service agreement and is entered into automatically when you start using Kaduno. It governs Kloner's processing of personal data on your behalf as the controller. This is a draft.

DRAFT — under legal review. Not yet a binding document.

Roles and responsibilities

Under GDPR Articles 4(7) and 4(8) the following roles apply:

- **The customer** is the controller of personal data relating to their end users, customers, and employees processed via Kaduno. - **Kloner AS** is the processor and acts solely on the customer's instructions, unless otherwise required by law.

Kloner may engage sub-processors to carry out parts of the processing, as listed in the categories on our sub-processors page.

Purposes and nature of processing

Kloner processes personal data on behalf of the customer for the sole purpose of delivering, operating, and supporting the Kaduno platform.

The types of data processed depend on which modules the customer uses and what data the customer enters. Examples include customer and contact information (Kaduno CRM), order data (Kaduno Commerce), communications (Kaduno Reach), and timesheets or payroll (Kaduno Finance/HR integrations).

Processing continues for the duration of the agreement.

Security measures — summary

Kloner implements appropriate technical and organisational security measures, including:

- Tenant isolation at the data layer (see the security page for details). - Role-based access control for Kloner staff and customer users. - TLS encryption of data in transit. - Audit logging of access and changes. - Access management for Kloner staff based on the principle of least privilege.

A full technical description is available on our security page and can be elaborated in an individual service agreement.

Assistance with data subject rights

Kloner assists the customer in fulfilling data subject rights (access, rectification, erasure, portability, etc.) to the extent technically feasible via the platform's features.

The customer is responsible for receiving and assessing requests from data subjects, and for making decisions on fulfilment. Kloner implements the technical measures on the customer's instruction.

Deletion on termination

After the agreement ends, and following the agreed transition period for data export, Kloner will delete the customer's personal data from production systems.

Kloner may retain data in anonymised or aggregated form, and in backup storage until the normal deletion rotation, in accordance with the platform's data retention policy.

On request, Kloner will issue a confirmation that deletion has been carried out.

Audits and documentation

Kloner maintains the documentation required by GDPR Article 30 for processing on behalf of customers.

The customer may request a written summary of relevant security measures. If the customer requires a formal audit review, this is arranged individually. Such audits are conducted without disrupting other customers' operations and at the customer's cost where they entail significant additional work for Kloner.