Data Processing Agreement

When you are the controller.

If you use KleioBase to research on behalf of clients or an organisation, you are the controller of that personal data and we are your processor. This agreement sets out what we do with it, what we will not do with it, and what you can require of us. It applies automatically, with no signature needed.

Last updated
August 10, 2026
Effective date
August 5, 2026

Section 1

Applicability and scope

This Data Processing Agreement (the “DPA”) forms part of, and is incorporated into, the Terms of Service between you (“Customer”) and Itamar Denkberg, a sole proprietor based in Israel trading as KleioBase (“KleioBase,” “we,” “us”). Capitalised terms that are not defined here have the meaning given to them in the Terms.

This DPA applies where and to the extent that Customer, when using the Service, is acting as a controllerof personal data that is subject to Data Protection Law, and KleioBase processes that personal data on Customer’s behalf. It is written for the professional case: a genealogist researching on behalf of a client, a firm or archive researching on behalf of its own users, or any other Customer who determines the purposes and means of the processing for someone else.

If your use of the Service is purely personal or household activity, this DPA does not apply to you. Researching your own family history for yourself falls within the household exemption in Article 2(2)(c) GDPR (and its equivalents), so there is no controller-to-processor relationship to govern. In that case our Privacy Policy governs our handling of your data, and nothing in this DPA gives you rights or imposes obligations.

No signature is required. This DPA is in force automatically, from the effective date above, for every Customer within its scope, whether or not anyone signs it. If your own compliance process needs a countersigned copy for your records, you can request one here. A countersigned copy records these same terms; it does not change them, and it is not what brings them into force. The Service is operated by a single individual, so we do not negotiate, execute, or maintain bespoke data processing terms: this DPA applies on identical terms to every Customer within its scope, which is what keeps it accurate and keeps the sub-processor register in Annex III honest.

Where KleioBase acts as an independent controllerrather than as Customer’s processor (see Section 3 (Roles of the parties)), this DPA does not apply and our Privacy Policy governs instead.

Section 2

Definitions

The following terms track the definitions in Article 4 GDPR and are to be read consistently with the equivalent provisions of any other applicable Data Protection Law.

  • Data Protection Lawmeans Regulation (EU) 2016/679 (the “GDPR”), the UK GDPR and the Data Protection Act 2018, and any other data protection or privacy law applicable to Customer’s processing of Customer Personal Data.
  • Personal Data means any information relating to an identified or identifiable natural person.
  • Customer Personal Data means Personal Data contained in Customer Content, meaning the documents Customer uploads, the data the Service extracts from them, and everything Customer builds from that data in the Service, as itemised in the processor rows of Section 3 (Roles of the parties) and described in Annex I. It does not include Personal Data for which KleioBase is an independent controller.
  • Processing means any operation performed on Personal Data, whether or not by automated means, including collection, storage, organisation, alteration, retrieval, use, disclosure, restriction, erasure, and destruction.
  • Controller means the party that determines the purposes and means of the Processing of Personal Data. For Customer Personal Data, that is Customer.
  • Processor means the party that Processes Personal Data on behalf of the Controller. For Customer Personal Data, that is KleioBase.
  • Data Subject means the identified or identifiable natural person to whom Personal Data relates.
  • Personal Data Breach means a breach of security leading to the accidental or unlawful destruction, loss, alteration, unauthorised disclosure of, or access to, Personal Data transmitted, stored, or otherwise Processed.
  • Sub-processormeans any third party engaged by KleioBase to Process Customer Personal Data on Customer’s behalf. Providers that only handle data for which KleioBase is an independent controller are not Sub-processors under this DPA.
  • Service means the KleioBase platform as defined in the Terms of Service.

Section 3

Roles of the parties

KleioBase has two distinct roles, and which one applies depends on the data, not on the customer. For the content you put into the Service we act as your processor. For the data we need in order to run a business (who your account belongs to, whether you have paid, whether someone is attacking the Service) we act as an independent controller, because we determine those purposes ourselves.

DataOur roleGoverned by
Uploaded documents and record imagesProcessorThis DPA
AI transcriptions, translations, and extracted genealogical dataProcessorThis DPA
Person profiles, families, places, notes, and tagsProcessorThis DPA
Research Companion conversations and files attached to themProcessorThis DPA
Person profile picturesProcessorThis DPA
Exports you generate (GEDCOM, data export archives, PDF reports)Processor, except for the account information that a full data export archive also containsThis DPA; Privacy Policy for that account information
Account identifiers and authentication dataIndependent controllerPrivacy Policy
Billing and subscription recordsIndependent controllerPrivacy Policy
Device and technical data (IP address, user agent, device type)Independent controllerPrivacy Policy
Product usage and analytics dataIndependent controllerPrivacy Policy
Marketing identifiers and advertising eventsIndependent controllerPrivacy Policy
Security, rate limiting, and abuse detection logsIndependent controllerPrivacy Policy
Support and other correspondence with usIndependent controllerPrivacy Policy

Where the table says Independent controller, this DPA does not apply to that data. We are not processing it on your instructions, you cannot instruct us to stop, and our handling of it is governed by our Privacy Policy and by our own obligations as a controller under Data Protection Law. This is the ordinary position for a hosted service and it is stated plainly here so that the boundary of this DPA is not ambiguous.

Customer is responsible, as controller, for establishing a lawful basis for the Processing of Customer Personal Data, for meeting any Article 9 condition where genealogical records reveal special categories of personal data, and for the notices given to Data Subjects. KleioBase does not assess the lawfulness of Customer’s underlying research.

Section 4

Processing on documented instructions

KleioBase Processes Customer Personal Data only on Customer’s documented instructions, including with regard to transfers to a third country, unless required to do so by a law to which KleioBase is subject.

Customer’s documented instructions comprise, in full:

  • this DPA, including Annex I;
  • the Terms of Service; and
  • Customer’s configuration and use of the Service, meaning the features Customer enables, the documents Customer uploads, the processing Customer initiates, and the actions Customer confirms.

Additional instructions outside this scope require our written agreement, and we may decline them or charge for them where they are not supported by the Service as built.

If we form the view that an instruction infringes Data Protection Law, we will inform Customer immediately and may suspend the affected Processing until the instruction is withdrawn, amended, or confirmed. We are not obliged to carry out a legal review of Customer’s instructions and this obligation is triggered only where the infringement is apparent to us.

Where a law to which KleioBase is subject requires Processing beyond Customer’s instructions, we will inform Customer of that legal requirement before Processing, unless the law prohibits that notice on important grounds of public interest.

Section 5

Confidentiality

KleioBase ensures that persons authorised to Process Customer Personal Data are bound by an obligation of confidentiality.

We state the position honestly rather than describing a programme that does not exist: the Service is operated by a sole proprietor. Itamar Denkberg is the only person with administrative access to production systems, and is bound by the confidentiality obligation in this Section directly. There is no wider workforce, and therefore no staff training curriculum, no background-check policy, and no internal access committee, and we do not claim to have any of those.

If KleioBase ever engages an employee or contractor who requires access to Customer Personal Data, that person will be bound by a written confidentiality obligation no less protective than this Section before access is granted, and access will be limited to what their task requires.

Section 6

Security of processing

Taking into account the state of the art, the costs of implementation, and the nature, scope, context, and purposes of the Processing, as well as the risk to the rights and freedoms of natural persons, KleioBase implements appropriate technical and organisational measures to ensure a level of security appropriate to the risk, as required by Article 32 GDPR.

The measures in force are set out in Annex II. Annex II describes only measures that are actually implemented today. We do not hold a SOC 2 report, an ISO 27001 certification, or any equivalent third-party security attestation, and we do not represent that we do.

We may update the measures in Annex II over time, provided the updated measures do not materially reduce the overall level of security of the Service.

Security is shared. Customer is responsible for the security of its own account credentials, for who it grants access to, for the accuracy and lawfulness of what it uploads, and for keeping its own copies of anything it cannot afford to lose (see Section 6.4 of the Terms).

Section 7

Sub-processors

Customer gives KleioBase general written authorisation to engage Sub-processors to Process Customer Personal Data. The Sub-processors authorised as at the effective date of this DPA are listed in Annex III. The current authoritative list is maintained at the sub-processors page.

7.1 Notice of new Sub-processors

We will give Customer at least 30 days’ notice before a new Sub-processor begins Processing Customer Personal Data. Notice is given by updating the sub-processors page and by email to everyone who has subscribed to change notifications on that page. Subscribing to those notifications is how Customer receives notice; we recommend that Customer does so.

7.2 Objection

Customer may object to a new Sub-processor on reasonable data protection grounds by writing to [email protected] within the notice period. We will work with Customer in good faith to resolve the objection, for example by explaining the safeguards in place or, where it is technically possible, by describing how Customer can avoid the affected feature.

If the objection cannot be resolved before the Sub-processor begins Processing, Customer may terminate the affected part of the Service by written notice, and we will refund any prepaid fees covering the remainder of the then-current subscription period on a pro rata basis for the terminated part. This is Customer’s sole remedy for an unresolved objection.

7.3 Terms and liability

KleioBase imposes on each Sub-processor, by written contract, data protection obligations that are no less protective than those in this DPA, to the extent applicable to the nature of the service the Sub-processor provides. KleioBase remains fully liable to Customer for the performance of each Sub-processor’s obligations.

This is why Annex III is shorter than the vendor table in our Privacy Policy: a provider is only listed as a Sub-processor here if it Processes Customer Personal Data and a written data processing agreement is in force with it.

Section 8

Data subject rights

Taking into account the nature of the Processing, KleioBase assists Customer by appropriate technical and organisational measures, insofar as this is possible, in fulfilling Customer’s obligation to respond to requests to exercise Data Subject rights under Chapter III GDPR.

That assistance is delivered primarily through the Service itself, which is what makes it achievable rather than aspirational. Customer can, at any time and without contacting us:

  • Access and portability: export a full archive of the data held in the account, and export family tree data in GEDCOM format, from Settings.
  • Rectification: edit or correct any extracted record, person profile, family relationship, place, or note directly in the knowledge base.
  • Erasure and restriction: delete individual records and profiles, empty the knowledge base, or delete the account outright, from Settings.

Where Customer needs assistance that the Service does not provide, Customer may write to [email protected] and we will provide reasonable assistance, taking into account the nature of the Processing and the information available to us. We may charge a reasonable fee for assistance that requires substantial manual work.

Requests received directly from a Data Subject. If we receive a request from a Data Subject that relates to Customer Personal Data, we will not respond to it substantively. We will forward it to Customer without undue delay and, where we can identify the requester, tell them that we have done so and that Customer is the controller responsible for answering. Customer is responsible for responding within the time limits set by Data Protection Law.

Section 9

Personal data breach

KleioBase notifies Customer of a Personal Data Breach affecting Customer Personal Data without undue delay and in any event within 48 hours of becoming aware of it. Notice is given by email to the address on the Customer account, so Customer should keep that address current and monitored.

We become “aware” when we have a reasonable degree of certainty that a security incident has compromised Personal Data. The notification will describe, to the extent known at the time:

  • the nature of the breach, including how it occurred;
  • the categories and approximate number of Data Subjects affected, and the categories and approximate number of records affected, including whether uploaded documents or extracted genealogical data are involved;
  • the likely consequences of the breach;
  • the measures taken or proposed to address the breach and to mitigate its possible adverse effects; and
  • a contact point for further information.

An initial notice may be incomplete. Where we do not yet hold all of the information above, we will send what we have within the 48-hour deadline, mark it as preliminary, and supplement it in phases as the investigation progresses rather than delaying the first notice.

Notification is not an acknowledgement of fault or liability. Customer, as controller, remains responsible for assessing whether the breach is notifiable to a supervisory authority or to Data Subjects and for making any such notification. KleioBase provides reasonable assistance with that assessment, taking into account the nature of the Processing and the information available to us.

Section 10

Impact assessments and prior consultation

Taking into account the nature of the Processing and the information available to us, KleioBase provides Customer with reasonable assistance with any data protection impact assessment under Article 35 GDPR and any prior consultation with a supervisory authority under Article 36 GDPR, where these relate to Customer’s use of the Service.

In practice, that assistance is documentary. This DPA, our Privacy Policy, Annex I (a description of the Processing), Annex II (the security measures), and the sub-processors page are designed to supply most of what an assessment needs, and they are published so that Customer can use them without asking.

We also maintain internal data protection records for the Service, including an impact assessment covering the AI processing described in Annex I. On written request to [email protected], we will make relevant extracts of those records available to Customer for the purpose of Customer’s own assessment. We may withhold information whose disclosure would compromise the security of the Service or the confidentiality of another customer’s data, and we may require that extracts be treated as confidential.

Section 11

Deletion and return of Customer Personal Data

11.1 Export

The Service’s export tools are available on every plan, including the free tier, throughout the term and are the mechanism by which Customer retrieves Customer Personal Data. Ending a paid subscription does not delete anything: the account reverts to the free tier and the data remains in place and exportable.

Where we end the relationship, Customer has at least 30 days from the date we close the account or give notice of termination, whichever is later, to export Customer Personal Data before we delete it, except where we are entitled to terminate access immediately for a reason set out in the Account termination section of the Terms.

That 30-day window does not apply where Customer deletes its own data. Deleting an account, or clearing the knowledge base, is an instruction from Customer to erase, and we act on it immediately and irreversibly as described in 11.2 below. There is no grace period and no recovery window on that path, by design, so Customer should export anything it needs to keep before deleting.

11.2 Deletion

At Customer’s choice, KleioBase deletes Customer Personal Data at the end of the provision of the Services. Customer exercises that choice directly in the Service: deleting individual records or profiles, clearing the knowledge base, or deleting the account. Account deletion and knowledge-base clearing are processed immediately, with no recovery grace period, across our database, file storage, and the third-party services that hold related data.

Where Customer does not exercise that choice, Customer Personal Data is retained and deleted in line with our published retention schedule, which is summarised in Section 9 of our Privacy Policy. In outline: account-scoped data is kept for the life of the account because it is the Service; trashed records and profiles are hard-deleted after 30 days; generated export archives are deleted after 7 days; and free accounts with no sign-in activity for 24 months may be deleted after written notice and a reasonable grace period. Deletion is enforced automatically, by scheduled purge jobs or by deletion cascade, not by manual effort.

KleioBase may retain Customer Personal Data to the extent required by a law to which it is subject, and will inform Customer of that requirement unless the law prohibits it. Payment and tax records held by our Merchant of Record are retained for their statutory period and are outside the scope of this Section.

11.3 Backups

We do not surgically edit backups, and we will not promise that we do. Deleting data removes it from the live Service immediately, but a copy may remain in routine encrypted infrastructure backups until those backups expire on their normal rotation. Our database provider currently retains daily backups on a rolling 7-day window, after which they are overwritten. Backups are encrypted at rest, are not accessible from the running Service, and are used only for disaster recovery. If a backup is ever restored, we undertake to re-apply any deletion that the restore reversed.

Section 12

Audit and information rights

KleioBase makes available to Customer the information necessary to demonstrate compliance with the obligations in Article 28 GDPR and allows for and contributes to audits, including inspections, conducted by Customer or another auditor mandated by Customer, on the terms below.

12.1 Information first

Customer’s audit right is satisfied in the first instance by written information: this DPA, our Privacy Policy, Annex II, the sub-processor register, and our responses to a reasonable security questionnaire, which Customer may send once per year to [email protected]. We will respond within 30 days.

12.2 On-site and third-party audits

An on-site inspection or an audit by a third-party auditor may be conducted only where a supervisory authority requires it or where Data Protection Law otherwise mandates it, and then only:

  • on at least 30 days’ prior written notice;
  • no more than once in any 12-month period;
  • during normal business hours and without disrupting the Service;
  • at Customer’s cost, including our reasonable time;
  • subject to a confidentiality agreement, and where the auditor is not a competitor of KleioBase; and
  • without access to any other customer’s data, to systems or premises controlled by a Sub-processor, or to information whose disclosure would compromise the security of the Service.

These limits are deliberate. The Service is operated by one person on infrastructure we do not physically control, so an unbounded on-site audit right would be a promise we could not keep.

Section 13

International transfers

KleioBase is established in Israel. Israel benefits from a European Commission adequacy decision and from the corresponding United Kingdom adequacy regulations. Transfers of Customer Personal Data from the EEA or the United Kingdom to KleioBase therefore require no additional transfer safeguard.

Onward transfers to Sub-processors, most of which are established in the United States, are covered by the transfer mechanism recorded against each Sub-processor in Annex III. That mechanism is either the EU-US Data Privacy Framework, where the Sub-processor is certified under it, or the European Commission Standard Contractual Clauses, together with the UK International Data Transfer Addendum where UK transfers are in scope and the Sub-processor’s terms provide for it. Customer authorises KleioBase to enter into those clauses with each Sub-processor on Customer’s behalf, in Customer’s capacity as controller.

We keep a transfer impact assessment covering these destinations and review it when a Sub-processor, a processing location, or a transfer mechanism changes. Where a transfer mechanism is invalidated or a Sub-processor ceases to be certified, we will adopt an alternative lawful mechanism or cease the affected transfer.

Section 14

Limitation of liability

Each party’s liability arising out of or related to this DPA, whether in contract, tort, or under any other theory of liability, is subject to the exclusions and to the aggregate limitation of liability set out in the Limitation of liability section of the Terms of Service. Any claims under this DPA and under the Terms count together toward that single aggregate cap, and do not create a separate or additional cap.

For clarity, this Section does not limit any liability that cannot be limited or excluded under applicable law, and it does not affect the rights of a Data Subject to compensation under Article 82 GDPR or to lodge a complaint with a supervisory authority.

Section 15

Term, precedence, and governing law

15.1 Term

This DPA takes effect on the effective date stated above and remains in force for as long as the Terms of Service are in force between the parties and KleioBase Processes Customer Personal Data. Sections that by their nature should survive, including Section 5 (Confidentiality), Section 11 (Deletion and return), and Section 14 (Limitation of liability), survive its termination.

15.2 Precedence

In the event of a conflict between this DPA and the Terms of Service, this DPA prevails with respect to the subject matter of the Processing of Customer Personal Data. In all other respects the Terms prevail. Where this DPA conflicts with a mandatory requirement of Data Protection Law, that requirement prevails.

15.3 Governing law and forum

This DPA is governed by the laws of the State of Israel, and any dispute arising out of it is subject to the exclusive jurisdiction of the competent courts in Tel Aviv-Jaffa, Israel, in each case as set out in the Dispute resolution section of the Terms of Service. This choice of law and forum does not deprive a Data Subject of any protection or remedy available to them under Data Protection Law.

15.4 Changes to this DPA

We may update this DPA. Material changes are announced by the same mechanism as changes to the Terms of Service: we update the “Last updated” date, notify Customer by email or through a prominent notice on the website, and give at least 30 days’ notice before the change takes effect. Changes to Annex III follow the Sub-processor notice procedure in Section 7 (Sub-processors) instead.

Annex

Annex I - Description of the processing

A. Subject matter and duration

Subject matter: the provision of the KleioBase genealogy research platform, being the storage of historical documents uploaded by Customer, the AI-assisted extraction of structured genealogical data from them, and the organisation of that data into a knowledge base.

Duration: for the term of the Terms of Service, and thereafter until Customer Personal Data is deleted in accordance with Section 11 (Deletion and return).

Frequency: continuous, for as long as Customer uses the Service.

B. Nature and purpose of the processing

The purpose is to provide the Service to Customer. The operations carried out are:

  • Storage and hosting of uploaded document images, imported family tree files, profile pictures, and the resulting knowledge base.
  • AI transcription, translation, and structured extraction: uploaded documents are transmitted to Google’s Gemini API, which returns a transcription in the original language, an English translation, and structured genealogical fields.
  • Profile matching and duplicate detection:comparison of person profiles within Customer’s own knowledge base to suggest that two profiles may describe the same individual. Suggestions are presented for review and are never applied automatically.
  • Connection discovery (Archivist and Professional plans): a periodic batched analysis of data Customer has already uploaded, which surfaces possible relationships between people named across separate records. Suggestions only; never applied automatically.
  • Duplicate fact detection(Researcher plan and above): when one of Customer’s person profiles records the same repeatable fact under several wordings, a deliberately context-free query - two recorded values and the kind of fact, with no name or profile identifier - is sent to Google’s Gemini API to assess whether they denote the same thing. A confirmed answer is stored in a dictionary shared across all KleioBase customers, keyed only on the two values and the fact type, never on Customer or any Data Subject. Nothing is changed on a profile automatically; Customer chooses which wording to keep, and the rest are retained as alternates.
  • Research Companion conversational assistance:an AI assistant that reads Customer’s knowledge base to answer questions about it, can read files Customer attaches to the conversation, and, where Customer invokes it, can search the public web and fetch public web pages. Where the assistant proposes a change to the knowledge base, the change is applied only after Customer confirms it.
  • Place geocoding: place names extracted from records are sent to a geocoding provider to obtain coordinates for the places map.
  • Historical context matching:dates and facts in Customer’s own data are matched against a curated, non-personal reference dataset of historical events to add context to timelines and anniversaries. Some events in that reference dataset are scoped to a religion, nationality, or caste, and where a person in Customer’s data has none of their own recorded, one may be derived for this purpose from that person’s nearest recorded ancestor or, failing that, a spouse; a person’s own recorded value always takes priority over a value derived this way, and nothing is derived from a name, a place, or any source outside Customer’s own data. Customer may instruct KleioBase not to perform that derivation by turning off the Infer historical context from relatives setting in account settings, in which case matching uses only what each person has recorded of their own.
  • Export generation:production of GEDCOM files, data export archives, and PDF research reports on Customer’s request.

KleioBase does not use Customer Personal Data to train AI models, and our AI provider is contractually barred from using data submitted through the paid API to train or improve its models.

C. Categories of data subjects

  • Individuals named or depicted in the historical records Customer uploads. These are predominantly deceased persons, who are not data subjects under Recital 27 GDPR, but they may include living individuals, such as recent relatives, witnesses, and informants named in more recent records.
  • Individuals whose personal data Customer enters directly, for example in notes, tags, or an imported family tree file.
  • Customer’s own clients or end users, to the extent Customer places their personal data in the Service.

D. Categories of personal data

  • Names, including maiden and alternate names, and titles.
  • Dates and places of birth, baptism, marriage, divorce, death, burial, residence, immigration, and other recorded life events.
  • An optional marker of whether a named individual is living or deceased, together with a qualifying date, which Customer may set directly or which may be derived from an imported family tree file.
  • Family relationships, including parentage, marriage, and sibling links.
  • Occupations, employers, ages, and civil status.
  • Images of source documents, which may contain any personal data recorded in the original, including signatures.
  • Photographs attached to person profiles or to a Companion conversation.
  • Free text Customer writes: notes, tags, corrections, and Research Companion conversation content.

E. Special categories of personal data

Historical genealogical records routinely reveal special categories of personal data within the meaning of Article 9 GDPR, in particular data revealing racial or ethnic origin and religious belief, and occasionally health data recorded as a cause of death. KleioBase does not ask for this data and does not seek it out; it is present because it is in the records Customer uploads, and it is extracted and stored as part of the record.

Customer, as controller, is responsible for identifying an Article 9 condition for this Processing. The restrictions applied by KleioBase are the measures in Annex II, which apply to all Customer Personal Data without distinction.

F. Retention

As set out in Section 11 (Deletion and return) and summarised in Section 9 of our Privacy Policy.

Annex

Annex II - Technical and organisational measures

These are the measures in force as at the effective date of this DPA. They are described at the level of detail that can be disclosed without weakening them, and every measure listed is implemented today rather than planned.

A. Access control and tenant isolation

  • Row-level securityis enforced in the database on customer-scoped tables, so a request carrying one account’s credentials cannot read or write another account’s rows even if the application layer is bypassed.
  • Per-account storage isolation: uploaded documents, imported files, profile pictures, and Companion attachments are stored under an account-scoped path in storage buckets governed by owner-scoped access policies.
  • Least-privilege service access: the privileged service-role credential is confined to server-side operations that genuinely require it, and is never exposed to the browser.
  • Signed, expiring URLs are used to serve document images rather than public links.

B. Authentication

  • Email and password authentication with hashed password storage, or single sign-on through Google or GitHub.
  • Session handling and token refresh managed by our authentication provider.
  • Bot protection on account authentication and on public form submissions.

C. Encryption

  • In transit: TLS for all connections to the Service and between the Service and its Sub-processors.
  • At rest: database and object storage encryption provided by our infrastructure providers, including for backups.

D. Availability and resilience

  • Managed database and object storage infrastructure, with routine automated backups taken and retained by our database provider on its standard rolling schedule.
  • Uptime and error monitoring with alerting, so that a failure surfaces without waiting for a customer report.
  • In-product export tools on every plan, so Customer can maintain its own independent copy of its data at any time.

We do not operate a formal business continuity or disaster recovery programme with tested recovery time and recovery point objectives, and we do not claim one. The Service is provided without an uptime commitment, as stated in Section 4.2 of the Terms.

E. Abuse prevention and monitoring

  • Per-tier API rate limiting across endpoints, with concurrency limits on AI processing.
  • Automated abuse detection for upload bursts, prompt injection attempts against the AI assistant, account sharing, and sustained maximum-budget usage, with flags raised for review.
  • Error monitoring configured not to send personal data by default, with redaction of sensitive values in alerts.
  • Short-lived, automatically pruned security and rate-limit logs.

F. Data minimisation and deletion

  • A documented retention schedule covering every category of stored data, enforced automatically by scheduled purge jobs or by deletion cascade rather than by manual cleanup.
  • Self-service account deletion and knowledge-base clearing, processed immediately, including propagation to the third-party services that hold related data.
  • Payment card data is never received or stored by KleioBase; it is handled entirely by our Merchant of Record.

G. Organisational measures

  • A documented breach response plan covering detection sources, severity classification, a risk-of-harm assessment, regulatory notification clocks, and notification templates. That plan is written around our own notification duties as a controller. The 48-hour commitment to Customer in Section 9 (Personal data breach) is a separate contractual obligation that stands on its own terms and is owed whatever that internal plan does or does not say.
  • Maintained internal records of processing activities, lawful bases, transfer risk, and per-vendor data processing agreements.
  • A written data protection review before shipping a change that touches a data flow, a retention rule, or a Sub-processor.
  • Confidentiality obligations on every person with access, as set out in Section 5 (Confidentiality).

H. What we do not have

Stated explicitly, so that Customer’s own assessment is not built on an assumption we have not made: KleioBase does not hold a SOC 2 report or an ISO 27001 certification, does not commission third-party penetration testing, does not operate a formal business continuity or disaster recovery programme, does not carry cyber liability insurance, and does not employ dedicated security personnel. Customer should take this into account when deciding what categories of personal data to place in the Service.

Annex

Annex III - Authorised sub-processors

This annex lists the Sub-processors that Process Customer Personal Data on Customer’s behalf, and only those. The test is functional, not a matter of vendor category: a provider appears here where it Processes Customer Personal Data for us, and does not appear here where it only handles data for which KleioBase is an independent controller. A provider can do both, for different data, and the providers listed below are listed because of the Customer Personal Data they touch, not because of everything else they also do for us.

The providers KleioBase uses purely as an independent controller are therefore absent from this table: payment processing and billing, product analytics, advertising measurement, customer support, issue tracking and incident response, bot protection and inbound email routing, and the third-party identity providers behind single sign-on. Those providers are disclosed in our Privacy Policy and on the sub-processors page, but they are not Sub-processors under this DPA, which is why this table is shorter than the one you will find there.

ProviderPurposeData sharedLocationTransfer safeguard
SupabaseDatabase hosting, authentication, file storageAll user data, uploaded documents, AI-extracted dataUSAStandard Contractual Clauses (SCCs) and DPA
Google (Gemini API)AI document transcription and data extraction; Research Companion conversations, including files you attach directly to a conversationUploaded documents and processing context; images/PDFs attached to a Research Companion conversationUSAEU-US Data Privacy Framework (certified)
Brave Search (Brave Software, Inc.)Primary web-search provider for the AI Research Companion in production. Our self-hosted search service is used for overflow once the monthly Brave request budget is nearly exhausted, and as a fallback if Brave errors.Search query text derived from your Research Companion request. No account details or uploaded documents are sent.USAData Processing Addendum incorporating EU Standard Contractual Clauses
MapboxGeocoding of locations extracted from recordsPlace names and addressesUSAEU-US Data Privacy Framework (certified)
ResendTransactional and marketing email delivery; receives inbound mail to role addresses (privacy@, contact@, support@, abuse@, security@, legal@, marketing@) and forwards it to our application via webhookEmail addresses, email content (outbound and inbound)USAEU-US Data Privacy Framework (certified) and SCCs
RailwayApplication hosting and deploymentIP address, request data (server logs)USADPA and SCCs
SentryError monitoring, performance tracking, and masked session replay (only after you consent to analytics)Error reports, which may include IP address, browser info, and application state at the time of an error; and, only if you consent to analytics, masked session replays (a reconstruction of page interactions - clicks, navigation, and DOM changes - with all text and form inputs masked) recorded for a sample of sessions and on errors, buffered in your browser's sessionStorageUSAEU-US Data Privacy Framework (certified) and SCCs

The sub-processors page is the authoritative, current list and marks which providers process Customer Content. Where that page and this annex differ, that page is current and this annex is a snapshot as at the last updated date above. Changes are notified in accordance with Section 7 (Sub-processors).

Questions about this DPA, or a request under it, go to [email protected]. This DPA is written in English; any translation is provided for convenience only, and if there is any inconsistency the English version controls. It should be read together with the Terms of Service and the Privacy Policy.

We use cookies and similar technologies. Essential cookies keep the site working. We only load analytics (PostHog) and marketing (Meta Pixel) with your consent. See our Privacy Policy.