§ Legal · DPA

Data processing agreement.

The terms on which we process personal data on your behalf as your processor — including for Kaiva Bridge, our hosted MCP gateway. Incorporated into your Terms of Service and any Order Form.

Effective
Aug 10, 2026
Updated
Aug 10, 2026
Basis
GDPR Art. 28

The short version.

You are the controller of the personal data you route through Kaiva; we are your processor and only process it on your documented instructions. We keep it confidential and secure, don't use it to train foundation models, only use sub-processors under equivalent terms with notice to you, help you meet data-subject requests, notify you of any breach without undue delay, and return or delete the data when we're done. The full detail — including our security measures and sub-processors — is below.

01Parties & scope

This Data Processing Agreement (“DPA”) is entered into between you (the “Customer”, acting as controller) and SLATEAI LIMITED, a company registered in England & Wales (Company No. 16601902), registered office Suite RA01, 195-197 Wood Street, London, E17 3NU, trading as Kaiva (“Kaiva”, “we”, acting as processor).

This DPA forms part of, and is governed by, the agreement between the parties for the use of the Service (the “Agreement” — see our Terms of Service). It applies where, and to the extent that, we process Personal Data on your behalf in providing the Service, including the Kaiva Agent Platform and Kaiva Bridge. Where a negotiated DPA is executed between the parties, that document controls. In the event of conflict on the subject of data protection, this DPA prevails over the Terms.

§ Acceptance — no signature required. This DPA is incorporated into the Agreement by reference. By accepting the Agreement — including by first use of, or payment for, the Service — you enter into this DPA, and you and Kaiva are each deemed to have signed the Standard Contractual Clauses incorporated by reference (Section 13), as of the effective date of the Agreement. Enterprise customers may request a counter-signed copy at [email protected].

02Definitions

Data Protection Law” means all laws applicable to the processing of Personal Data under the Agreement, including the UK GDPR and the Data Protection Act 2018, the EU GDPR (Regulation (EU) 2016/679), and applicable US state privacy laws. “Personal Data”, “controller”, “processor”, “data subject”, “processing”, and “personal data breach” have the meanings given in Data Protection Law. “Customer Personal Data” means Personal Data contained within Customer Data that we process on your behalf. “Sub-processor” means any processor we engage to process Customer Personal Data. Capitalised terms not defined here have the meaning given in the Terms.

03Roles & instructions

As between the parties, you are the controller and we are the processor of Customer Personal Data. Where you are yourself a processor acting for a third-party controller, we act as sub-processor and you warrant you have the authority and instructions necessary to engage us.

We will process Customer Personal Data only on your documented instructions, including as set out in this DPA, the Terms, your Order Form, and your configuration and use of the Service (for example the servers, policies, and data-loss-prevention rules you set in Kaiva Bridge), unless required to do otherwise by law — in which case we will inform you first, unless the law prohibits it. We will inform you if, in our opinion, an instruction infringes Data Protection Law. We do not sell Customer Personal Data and do not use it to train foundation models.

04Details of processing

The subject matter, duration, nature and purpose of the processing, the types of Personal Data, and the categories of data subjects are described in Annex 1. You are responsible for the accuracy of, and for having a lawful basis and any necessary consents for, the Personal Data you route through the Service.

05Processor obligations

In accordance with Article 28(3) of the UK/EU GDPR, we will:

  • process Customer Personal Data only on your documented instructions;
  • ensure persons authorised to process it are under an appropriate duty of confidentiality;
  • implement the technical and organisational measures set out in Annex 2;
  • respect the conditions in Section 08 for engaging Sub-processors;
  • assist you, by appropriate measures, in responding to data-subject requests (Section 09);
  • assist you in ensuring compliance with your obligations under Articles 32–36 (security, breach notification, data-protection impact assessments, and prior consultation), taking into account the nature of processing and the information available to us;
  • at your choice, delete or return Customer Personal Data at the end of the provision of services (Section 11); and
  • make available the information necessary to demonstrate compliance and allow for and contribute to audits (Section 12).

06Confidentiality

We treat Customer Personal Data as confidential. Access is limited to personnel who need it to provide, secure, or support the Service, who are bound by written confidentiality obligations and trained in their data-protection responsibilities. Upstream credentials you provide to Kaiva Bridge are stored encrypted (sealed) and are never exposed to the calling agent or held in plain text.

07Security

Taking into account the state of the art, the costs of implementation, and the nature, scope, context and purposes of processing, as well as the risk to data subjects, we implement appropriate technical and organisational measures to ensure a level of security appropriate to the risk, as described in Annex 2. You are responsible for your own configuration of the Service, your access controls and credentials, and the security of systems you connect to it.

08Sub-processors

You provide general authorisation for us to engage Sub-processors to process Customer Personal Data, subject to this Section. Our current Sub-processors are listed in Annex 3. We impose data-protection obligations on each Sub-processor that are no less protective than those in this DPA, and we remain liable to you for their performance of those obligations.

We will give you reasonable prior notice of the addition or replacement of a Sub-processor (by updating Annex 3 and/or by email where you have subscribed to notifications). You may object on reasonable data-protection grounds within thirty (30) days; if we cannot reasonably accommodate the objection, you may terminate the affected part of the Service.

09Data-subject rights

Taking into account the nature of the processing, we will assist you by appropriate technical and organisational measures, insofar as possible, to fulfil your obligation to respond to requests to exercise data-subject rights (access, rectification, erasure, restriction, portability, and objection). If we receive such a request directly, we will promptly forward it to you and will not respond ourselves except on your instruction or as required by law.

10Personal-data breach

We will notify you without undue delay, and in any event within seventy-two (72) hours of becoming aware, of a personal data breach affecting Customer Personal Data. The notification will describe, to the extent known, the nature of the breach, the likely consequences, and the measures taken or proposed to address it, and we will provide further information as it becomes available. We will reasonably assist you with your own notification obligations to supervisory authorities and data subjects.

11Deletion & return

On termination or expiry of the Agreement, and at your choice, we will delete or return Customer Personal Data and delete existing copies, unless retention is required by law. Customer Data is available for export on reasonable request during the term and for a limited period thereafter, in accordance with the retention windows in our Privacy Policy. Backups are deleted on their ordinary rotation cycle.

12Audits

We will make available information reasonably necessary to demonstrate compliance with this DPA and will allow for and contribute to audits, including inspections, conducted by you or an auditor you mandate. To respect the confidentiality and security of our other customers, audits are conducted no more than once per year (save where required by a supervisory authority or following a breach), on reasonable prior written notice, during business hours, subject to confidentiality obligations, and — where sufficient — may be satisfied by our provision of then-current third-party reports, certifications, or a completed security questionnaire.

13International transfers

Our production infrastructure is located in the EU by default. Where processing of Customer Personal Data involves a transfer outside the UK or EEA to a country without an adequacy decision, that transfer is made under an appropriate safeguard, namely:

  • the EU Standard Contractual Clauses 2021/914 (the “SCCs”), which are incorporated into this DPA by reference and completed by the information in the Annexes, with the parties' roles as set out in Section 03; and
  • for transfers subject to UK law, the UK International Data Transfer Agreement (IDTA) or the UK Addendum to the SCCs;

together with any supplementary measures identified by a transfer impact assessment. Where a listed Sub-processor relies on its own transfer mechanism (for example the EU–US Data Privacy Framework or its own SCCs), that mechanism also applies to onward transfers to it.

14Liability & term

This DPA takes effect on the effective date of the Agreement and continues for as long as we process Customer Personal Data on your behalf. Each party's liability under or in connection with this DPA is subject to the limitations and exclusions of liability set out in the Terms, except where Data Protection Law does not permit such limitation. Nothing in this DPA relieves either party of its own direct obligations under Data Protection Law.

A1Annex 1 · Details of processing

Subject matterProvision of the Service (Kaiva Agent Platform and Kaiva Bridge) to the Customer.
DurationThe term of the Agreement, plus any period for return/deletion.
Nature & purposeHosting, routing, relaying, policy enforcement, DLP masking, logging, storage, and support necessary to deliver the Service and its audit records.
Types of Personal DataDetermined and controlled by the Customer. May include: account and contact details of Authorised Users; and any Personal Data contained in the content, tool calls, and upstream responses the Customer routes through the Service, together with audit metadata (caller identifier, tool, timestamp, decision, latency, and redacted argument/response summaries).
Special-category dataNot intended. The Customer should not route special-category data unless it has a lawful basis and has configured appropriate DLP/redaction.
Categories of data subjectsDetermined by the Customer. May include the Customer's Authorised Users, employees, customers, and end users whose data passes through the Service.
FrequencyContinuous, for the duration of the Agreement.

A2Annex 2 · Security measures

We maintain technical and organisational measures including:

  • Encryption of data in transit (TLS 1.3) and at rest (AES-256).
  • Encrypted (sealed) storage of upstream credentials and other secrets; client API keys stored only as a one-way hash.
  • Redaction and data-minimisation in audit logs; customer-configurable DLP masking of sensitive fields.
  • Server-side request-forgery (SSRF) and egress controls on outbound gateway requests.
  • Access controls on the principle of least privilege, with authentication, tenant isolation, and audit-logged changes.
  • Single-server scoping of gateway API keys and a per-workspace kill-switch.
  • Tamper-evident, append-only audit records for gateway activity.
  • Regular security reviews, backups, and a documented incident-response process.

§ Shared responsibility. These measures protect the Service. You remain responsible for how you configure it — your policies, DLP rules, key handling, and the security of the upstream systems and end-user systems you connect.

A3Annex 3 · Sub-processors

We currently engage the following Sub-processors to process Customer Personal Data:

Sub-processorPurposeLocation
RailwayApplication hosting, compute, and databases (incl. Kaiva Bridge and its audit logs)EU (default)
CloudflareDNS, CDN, TLS, and DDoS protection; edge deliveryGlobal edge
StripePayment and subscription processingEU / US
Model providers (e.g. OpenAI, Anthropic, Google, xAI)Generating model responses where you route requests to them; subject to no-training configurations where offeredPer provider

The current list is also available on request to [email protected]. We will give reasonable advance notice of material changes as set out in Section 08.

Sign a DPA

Counter-signature, enterprise red-lines, MSAs.

[email protected]

Sub-processor notices

Subscribe to advance notice of sub-processor changes.

[email protected]

Security & diligence

Security questionnaires, reports, vendor review.

[email protected]