Legal Center
Data Processing Addendum
DRAFT SKELETON — this is not yet a signable DPA. It needs full legal drafting before being offered to customers who require one.
Roles
Where a Kaptly account holder collects personal data from respondents through a published form, the account holder is generally the data controller and Kaptly acts as a data processor on their behalf. [CONFIRM — legal review: this characterization, and any exceptions (e.g. account-holder data itself, where Kaptly is the controller).]
If the controller enables workspace collaboration, its invited workspace members are authorized users acting under that controller's responsibility. They receive full access to workspace respondent data and can configure available exports and delivery integrations; the controller is responsible for their instructions, access, and timely removal.
Processing instructions
[CONFIRM: standard DPA clause — processor processes personal data only on documented instructions from the controller, including regarding international transfers.]
Subprocessors
Current subprocessors are listed on the Subprocessors page. [CONFIRM: notice period for adding a new subprocessor, and the controller's right to object.]
Security measures
See the Security and Responsible Disclosure page for the current, verified state of security measures. [CONFIRM: this section should list only measures that have actually been implemented and reviewed, once that review happens — not aspirational measures.]
Assistance with data subject requests
[CONFIRM: process and SLA for Kaptly assisting a controller in responding to access/erasure requests from their respondents, beyond the self-serve per-response delete that already exists.]
Breach notification
[CONFIRM: breach notification timeline and process — currently undefined.]
Deletion on termination
When a controller closes their Kaptly account (self-serve, from Settings → Danger zone), their account, forms, responses — including any respondent personal data — and uploaded files are deleted immediately and permanently, with no grace period. See the Privacy Policy's data retention section for the narrow set of exceptions Kaptly may still retain (anonymized/aggregated usage data, security/fraud/abuse logs, records needed for an active dispute, anything legally required).
Audits
[CONFIRM: whether/how a controller can audit Kaptly's processing — likely limited given the current beta/pre-audit state.]