Kiwy

Legal · Effective

Data Processing Addendum

The DPA governing Kiwy's processing of buyer personal data on behalf of sellers: sub-processors, security measures, breach notification, and international transfers.

This Data Processing Addendum ("DPA") amends and forms part of the Kiwy Terms of Service ("Main Agreement") between Kiwy Technologies, LLC ("Kiwy", "Processor") and the creator, merchant, or organization accepting the Main Agreement ("Customer", "Seller", or "Controller").

1. Scope & Application

1.1 Purpose: This DPA applies to the processing of Personal Data by Kiwy on behalf of Customer in connection with the provision of the digital commerce platform, digital product distribution, license key generation, and customer portal services described in the Main Agreement.

1.2 Role Clarification:

  • Processor Role: For Personal Data processed by Kiwy strictly on Customer's documented instructions (e.g., hosting Customer support records, delivering digital assets to Buyers, or granting access entitlements), Customer is the Data Controller and Kiwy is the Data Processor.
  • Independent Controller Operations: Kiwy's independent processing of data for its own legal obligations as Merchant of Record — including tax calculation and remittance, payment card processing, anti-fraud evaluation, and acting on the trade sanctions screening performed by our payment and verification partners — is undertaken by Kiwy as an independent Data Controller and governed directly by the Kiwy Privacy Policy and Terms of Service.

2. Definitions

For the purposes of this DPA:

  • "Applicable Data Protection Law" means all privacy and data protection laws applicable to the processing of Personal Data under this DPA, including the EU General Data Protection Regulation (GDPR), UK GDPR, UK Data Protection Act 2018, and the California Consumer Privacy Act (CCPA/CPRA).
  • "Customer Personal Data" means Personal Data provided by or collected on behalf of Customer and processed by Kiwy as a Data Processor pursuant to the Main Agreement.
  • "Data Subject", "Controller", "Processor", "Personal Data", "Personal Data Breach", and "Processing" have the meanings given under Applicable Data Protection Law.
  • "Standard Contractual Clauses (SCCs)" means the Standard Contractual Clauses approved by the European Commission in Decision (EU) 2021/914.

3. Processing Instructions & Confidentiality

3.1 Documented Instructions: Kiwy shall process Customer Personal Data solely on behalf of and in accordance with Customer's documented instructions, as specified in the Main Agreement, this DPA, or as otherwise agreed in writing, unless required to do so by applicable law.

3.2 Confidentiality: Kiwy shall ensure that personnel authorized to process Customer Personal Data are bound by appropriate obligations of confidentiality.

4. Security Measures

4.1 Technical & Organizational Safeguards: Kiwy shall implement and maintain appropriate technical and organizational measures to protect Customer Personal Data against accidental or unlawful destruction, loss, alteration, unauthorized disclosure, or access, as detailed in Annex II.

4.2 Security Evaluation: Kiwy regularly evaluates the effectiveness of its technical and organizational security measures to ensure processing activities remain secure.

5. Sub-Processors

5.1 General Authorization: Customer grants Kiwy general authorization to engage third-party sub-processors (such as cloud infrastructure providers, database hosting services, content delivery networks, and transactional email providers) to assist in delivering the Service.

5.2 Sub-Processor Requirements: Kiwy shall enter into written agreements with each sub-processor imposing data protection obligations no less protective than those set forth in this DPA.

5.3 Sub-Processor Notice: Customers may request an up-to-date summary of sub-processors or subscribe to sub-processor change notifications by emailing legal@kiwy.ai.

6. Data Subject Rights & Assistance

6.1 Data Subject Requests: Taking into account the nature of the processing, Kiwy shall assist Customer by appropriate technical and organizational measures, insofar as possible, to enable Customer to fulfill its obligations to respond to Data Subject requests under Applicable Data Protection Law.

6.2 Forwarding Requests: If Kiwy receives a Data Subject request directly concerning Customer Personal Data processed on behalf of Customer, Kiwy shall promptly refer the request to Customer where feasible.

7. Personal Data Breach Notification

7.1 Notice to Customer: Kiwy shall notify Customer without undue delay (and in any event within 48 hours) upon becoming aware of a confirmed Personal Data Breach affecting Customer Personal Data.

7.2 Breach Response: The notification shall describe the nature of the breach, the categories of data affected, and the remedial actions taken or proposed. Kiwy shall take reasonable steps to mitigate the effects of the breach.

8. International Data Transfers

8.1 Transfer Mechanisms: To the extent that the processing of Customer Personal Data involves a transfer from the EEA, UK, or Switzerland to a country outside those regions that has not received an adequacy decision, the transfer shall be governed by:

  • The EU Standard Contractual Clauses (Module 2: Controller-to-Processor), incorporated herein by reference; and
  • The UK International Data Transfer Addendum, incorporated herein by reference for UK transfers; and
  • For transfers originating from Switzerland, the EU Standard Contractual Clauses as adapted under the Swiss Federal Act on Data Protection ("FADP"): references to the GDPR are read as references to the FADP, the competent supervisory authority is the Swiss Federal Data Protection and Information Commissioner ("FDPIC"), the term "Member State" does not operate to prevent data subjects in Switzerland from bringing proceedings in their place of habitual residence, and the clauses also protect the personal data of legal entities until such protection ceases under Swiss law.

9. Return and Deletion of Data

9.1 Deletion upon Termination: Upon termination of the Main Agreement or written request from Customer, Kiwy shall delete or return all Customer Personal Data in its possession, except to the extent that retention is required by applicable tax, accounting, financial compliance, or trade sanctions laws.

10. Miscellaneous

10.1 Precedence: In the event of any conflict between the terms of this DPA and the Main Agreement, the terms of this DPA shall prevail regarding the processing of Customer Personal Data.

10.2 Governing Law: This DPA shall be governed by the choice of law specified in the Main Agreement, except where Applicable Data Protection Law mandates local law.

Annex I: Details of Processing

  • Categories of Data Subjects: Buyers purchasing digital products or subscriptions from Customer through Kiwy.
  • Categories of Personal Data: Name, email address, billing address, purchase date, product identifier, license key/entitlement, and customer support correspondence.
  • Nature and Purpose of Processing: Digital product delivery, customer portal access, license key validation, subscription management, and customer support fulfillment on behalf of Customer.
  • Duration of Processing: The duration of the Main Agreement plus applicable statutory retention periods (e.g., 7 years for tax/financial records).

Annex II: Technical & Organizational Security Measures

  • Encryption in Transit: Transport Layer Security (TLS 1.2/1.3) for all web, API, and dashboard traffic.
  • Encryption at Rest: Industry-standard AES-256 encryption for database records, cloud storage files, and sensitive credentials.
  • Access Control: Strict role-based access control (RBAC), multi-factor authentication (MFA), and audit logging for system administrative access.
  • System Monitoring: Automated threat monitoring, application error logging, and routine infrastructure patching.

Contact Information

Kiwy Technologies, LLC
2810 North Church Street STE 88591
Wilmington, DE, 19802 US
Email: legal@kiwy.ai