Legal Center

Legal Center

Data Processing Addendum

Last updated 2026-08-07Version 2026-08-07.1

DRAFT SKELETON — this is not yet a signable DPA. It needs full legal drafting before being offered to customers who require one.

Roles

Legal review needed

Where a Kaptly account holder collects personal data from respondents through a published form, the account holder is generally the data controller and Kaptly acts as a data processor on their behalf. [CONFIRM — legal review: this characterization, and any exceptions (e.g. account-holder data itself, where Kaptly is the controller).]

If the controller enables workspace collaboration, its invited workspace members are authorized users acting under that controller's responsibility. They receive full access to workspace respondent data and can configure available exports and delivery integrations; the controller is responsible for their instructions, access, and timely removal.

Processing instructions

Legal review needed

[CONFIRM: standard DPA clause — processor processes personal data only on documented instructions from the controller, including regarding international transfers.]

Subprocessors

Owner confirmation neededLegal review needed

Current subprocessors are listed on the Subprocessors page. [CONFIRM: notice period for adding a new subprocessor, and the controller's right to object.]

Security measures

Security review needed

See the Security and Responsible Disclosure page for the current, verified state of security measures. [CONFIRM: this section should list only measures that have actually been implemented and reviewed, once that review happens — not aspirational measures.]

Assistance with data subject requests

Owner confirmation neededLegal review needed

[CONFIRM: process and SLA for Kaptly assisting a controller in responding to access/erasure requests from their respondents, beyond the self-serve per-response delete that already exists.]

Breach notification

Owner confirmation neededSecurity review neededLegal review needed

[CONFIRM: breach notification timeline and process — currently undefined.]

Deletion on termination

When a controller closes their Kaptly account (self-serve, from Settings → Danger zone), their account, forms, responses — including any respondent personal data — and uploaded files are deleted immediately and permanently, with no grace period. See the Privacy Policy's data retention section for the narrow set of exceptions Kaptly may still retain (anonymized/aggregated usage data, security/fraud/abuse logs, records needed for an active dispute, anything legally required).

Audits

Owner confirmation neededLegal review needed

[CONFIRM: whether/how a controller can audit Kaptly's processing — likely limited given the current beta/pre-audit state.]