Data Processing Addendum

This Data Processing Addendum ("DPA") forms part of the Terms of Service between Catalytics Group, LLC ("Klaaro," "we," "us") and the customer agreeing to those Terms ("Customer," "you"), and governs our processing of personal data on your behalf. This DPA is incorporated into the Terms of Service by reference and applies automatically. No signature is required. If you require a countersigned copy, email contact@klaaro.co.

1. Definitions

Terms such as controller, processor, data subject, personal data, processing, and supervisory authority have the meanings given in the GDPR. Business, service provider, sell, and share have the meanings given in the CCPA.

"Customer Personal Data" means personal data contained in Customer Content or otherwise processed by us on your behalf in providing the Service.

"Data Protection Law" means all privacy and data protection laws applicable to the processing, including the EU GDPR, UK GDPR, Swiss FADP, the CCPA as amended, and other US state privacy laws.

"Standard Contractual Clauses" or "SCCs" means the clauses approved by the European Commission in Decision 2021/914.

"Subprocessor" means a third party engaged by us to process Customer Personal Data.

2. Roles

You are the controller (or, where you act on behalf of another controller, the processor) of Customer Personal Data. We are the processor (or subprocessor). Under the CCPA, you are the business and we are a service provider.

Where we process personal data about you as our customer — your account details, billing information, and your use of the Service — we act as a controller, and that processing is governed by our Privacy Policy rather than this DPA.

3. Our obligations

3.1 Processing on instructions

We process Customer Personal Data only on your documented instructions. Your instructions consist of the Terms of Service, this DPA, and your use of the Service's features. We will tell you if we believe an instruction violates Data Protection Law, unless legally prohibited from doing so. If we are required by law to process outside your instructions, we will notify you first unless that law prohibits notice.

3.2 Purpose limitation

We will not:

  • sell or share Customer Personal Data as those terms are defined in the CCPA;

  • retain, use, or disclose Customer Personal Data for any purpose other than providing the Service, or outside our direct business relationship with you;

  • combine Customer Personal Data with data from other sources, except as permitted for a service provider under the CCPA;

  • use Customer Personal Data or Customer Content to train artificial intelligence or machine learning models.

We certify that we understand and will comply with these restrictions.

3.3 Confidentiality

Personnel authorised to process Customer Personal Data are bound by written confidentiality obligations and are provisioned on a least-privilege basis.

3.4 Security

We implement and maintain the technical and organisational measures described in Annex II.

3.5 Assistance

Taking into account the nature of the processing, we will provide reasonable assistance with:

  • responding to data subject requests you cannot fulfil through the Service's own functionality;

  • data protection impact assessments and prior consultations;

  • security, breach notification, and related obligations.

3.6 Data subject requests

If we receive a request from a data subject relating to Customer Personal Data, we will not respond directly except to confirm the request relates to you, and will forward it to you without undue delay.

3.7 Breach notification

We will notify you without undue delay after becoming aware of a personal data breach affecting Customer Personal Data, and will provide the information reasonably available to us to support your own notification obligations. Notice of a breach is not an acknowledgement of fault.

3.8 Deletion and return

On termination, Customer Personal Data is handled as described in our Privacy Policy. You may request deletion at any time by emailing contact@klaaro.co, and we will delete Customer Personal Data from active systems and instruct our subprocessors to do the same, subject to the backup windows described in Annex I and to any legal retention obligation.

Before termination, you can export Customer Content through the Service.

3.9 Audit

We will make available the information reasonably necessary to demonstrate compliance with this DPA. Where a third-party audit report is available, providing it satisfies this obligation. Otherwise you may request an audit no more than once per year, on thirty (30) days' notice, at your expense, during business hours, subject to confidentiality, and conducted so as not to disrupt our operations. A supervisory authority may audit as required by law.

4. Your obligations

You represent and warrant that:

  • you have provided all required notices and obtained all consents, permissions, and releases necessary for us to process Customer Personal Data as described, including from individuals appearing or speaking in uploaded media;

  • your instructions comply with Data Protection Law;

  • you are responsible for the accuracy and lawfulness of Customer Personal Data and for your configuration of the Service, including who you grant access to and what you share through share links;

  • you will not upload protected health information, payment card data, government identification numbers, biometric identifiers, or other data subject to specialised regulatory regimes. The Service is not designed or certified for such data, and we have no obligations under HIPAA, PCI DSS, or comparable regimes.

5. Subprocessors

5.1 General authorisation

You give general authorisation for us to engage subprocessors. Our current subprocessors are listed in Section 7.1 of our Privacy Policy (klaaro.co/privacy#subprocessors).

5.2 Notice and objection

We will notify you at least thirty (30) days before a new subprocessor begins processing Customer Personal Data. You may object on reasonable data protection grounds within that period. If we cannot offer a reasonable alternative, you may terminate the affected part of the Service and receive a pro-rata refund of prepaid unused fees.

5.3 Our responsibility

We impose data protection obligations on each subprocessor no less protective than those in this DPA, and we remain liable for their performance.

6. International transfers

We process Customer Personal Data in the United States.

Annex III (Standard Contractual Clauses) applies only where you are established in the European Economic Area, the United Kingdom, or Switzerland, or where your transfer of Customer Personal Data to us is otherwise subject to Chapter V of the GDPR or its UK or Swiss equivalent. Where it applies, the SCCs are incorporated into this DPA and take effect automatically, with the elections set out in Annex III.

Where Annex III does not apply, no transfer mechanism is asserted and this Section 6 has no effect beyond the statement of processing location above.

7. Liability

Each party's liability under this DPA is subject to the limitations and exclusions in the Terms of Service. Where the SCCs apply and their liability provisions conflict with this section, the SCCs prevail as required by law.

8. General

This DPA supersedes any conflicting data protection terms in the Terms of Service. In the event of conflict, the order of precedence is: (1) the SCCs where applicable, (2) this DPA, (3) the Terms of Service. Governing law and venue follow the Terms of Service, except where the SCCs require otherwise.

We may update this DPA on thirty (30) days' notice, provided no update materially reduces the protections it provides.

Annex I — Details of Processing

Data exporter: the Customer, acting as controller of Customer Personal Data.

Data importer: Catalytics Group, LLC, 1000 Brickell Avenue, Suite #715 PMB 734, Miami, FL 33131, United States. Contact: contact@klaaro.co. Acting as processor in providing the Klaaro platform.

Subject matter: provision of the Klaaro agency management platform, including media storage, timecoded review and approval, client portals, project and task management, and optional transcription and AI-assisted text generation.

Duration: the term of the Terms of Service, plus the retention periods described below.

Nature and purpose: storage, hosting, transcoding, transmission, display, organisation, retrieval, and deletion of Customer Content and account data, as directed by the Customer through the Service; automated speech-to-text transcription and text generation where requested by the Customer.

Categories of data subjects:

  • the Customer's personnel and authorised users

  • the Customer's own clients and their personnel

  • individuals appearing, speaking, or otherwise identifiable in uploaded media

  • individuals accessing content through share links

Categories of personal data:

  • identity and contact data: name, email address, phone number

  • account data: role, organisation membership, activity records

  • content data: video, audio, images, documents, comments, transcripts, and any personal data the Customer chooses to include

  • share-link access records: self-entered display name, one-way salted hash of IP address, one-way salted hash of user agent, timestamps and actions

  • billing contact and subscription data

Special category data: none is requested or required. The Customer must not upload data subject to specialised regulatory regimes. Uploaded media may incidentally contain material from which special categories could be inferred; the Customer is responsible for what it uploads.

Frequency: continuous, for the duration of the Service.

Retention:

  • files sent to trash: 30 days, then permanently deleted

  • deleted object versions in storage: purged within 30 days

  • database backups: rolling 7 days

  • unconverted trial accounts: permanently deleted 14 days after trial expiry

  • share-link access records: retained for the life of the account

  • account and Customer Content after cancellation: retained until deletion is requested

  • billing records: as required by tax and accounting law

Subprocessors: as listed in Section 7.1 of our Privacy Policy (klaaro.co/privacy#subprocessors), with processing purposes, locations, and duration as stated there.

Annex II — Technical and Organisational Measures

Encryption. TLS in transit. Encryption at rest for database and object storage.

Access control. Role-based access control enforced through a dedicated authorisation service. Least-privilege provisioning. Authentication managed by a dedicated identity provider; passwords are not stored in plain form. Access to production systems restricted to personnel who require it.

Upload and delivery architecture. Uploads go directly from the browser to object storage using short-lived signed URLs; files do not transit our application servers. Playback is served through short-lived signed URLs.

Pseudonymisation. IP addresses and user agents associated with share-link access are stored only as one-way salted hashes. Raw IP addresses are not persisted.

Logging and monitoring. Application error monitoring configured to exclude user identity, cookies, query parameters, and request bodies, with automatic redaction of credentials and signed URLs before transmission. Access to shared content is logged.

Availability. Managed database with automated daily backups and point-in-time restore over a rolling seven-day window. Redundant object storage.

Abuse prevention. Rate limiting on public and share endpoints. Signed callbacks between internal services.

Environment separation. Production, staging, and development environments are separated with distinct credentials.

Personnel. Written confidentiality and data protection obligations for all employees and contractors. Access revoked on role change or departure.

Subprocessor management. Data protection terms imposed on all subprocessors. Published subprocessor list with 30 days' notice of change.

Incident response. Documented process for identifying, escalating, and notifying personal data breaches without undue delay.

Annex III — Standard Contractual Clauses

This Annex applies only where Section 6 states that it does.

EEA transfers

The SCCs (Commission Implementing Decision (EU) 2021/914) are incorporated by reference, with:

  • Module Two (controller to processor) applying where the Customer is a controller, and Module Three (processor to processor) applying where the Customer is a processor acting for another controller;

  • Clause 7 (docking clause): applies;

  • Clause 9 (subprocessors): Option 2, general written authorisation, with a notice period of thirty (30) days;

  • Clause 11 (redress): the optional independent dispute resolution language does not apply;

  • Clause 17 (governing law): the law of Ireland;

  • Clause 18 (forum): the courts of Ireland;

  • Annex I to the SCCs: as set out in Annex I above. Competent supervisory authority: determined under Clause 13, being the authority of the member state in which the data exporter is established;

  • Annex II to the SCCs: as set out in Annex II above;

  • Annex III to the SCCs: the subprocessor list published in Section 7.1 of our Privacy Policy (klaaro.co/privacy#subprocessors).

UK transfers

The UK International Data Transfer Addendum (Version B1.0) is incorporated, with the SCCs above as the Approved EU SCCs. Tables 1 to 3 are populated from Annexes I and II above and the subprocessor list in our Privacy Policy. In Table 4, neither party may terminate on changes to the Approved Addendum.

Swiss transfers

The SCCs apply with these amendments: references to the GDPR are read as references to the Swiss FADP; the competent authority is the Federal Data Protection and Information Commissioner; and "member state" is not interpreted to exclude data subjects in Switzerland from bringing proceedings in their place of habitual residence.

Contact

contact@klaaro.co

Catalytics Group, LLC 1000 Brickell Avenue Suite #715 PMB 734 Miami, FL 33131