Purpose
This Data Processing Agreement ("DPA") forms part of the agreement between Keloa B.V. ("Processor") and you ("Controller") and governs Keloa's processing of personal data on your behalf in connection with the Keloa platform.
Subject matter and duration
Keloa processes personal data submitted to the platform by you or your end users, for the purpose of providing AI-powered customer service and sales conversations. Processing continues for the duration of your subscription.
Categories of data
We process: customer contact details (name, email), conversation content, page metadata, and any data you upload to the knowledge base. Special categories of data should not be uploaded without prior written agreement.
Sub-processors
Keloa engages sub-processors as listed on our Sub-processors page. We notify you of any changes at least 30 days in advance and you have the right to object.
Security measures
Encryption at rest (AES-256) and in transit (TLS 1.3). Access controls with SSO and MFA for our staff. Annual penetration testing. Backup retention 30 days. Incident response within 24 hours of detection.
International transfers
Personal data is hosted in the EU. Where any sub-processor is located outside the EEA, transfers are governed by the Standard Contractual Clauses (Module 3, processor-to-processor).
Data subject requests
Keloa assists you in fulfilling data subject access, rectification, and deletion requests through self-service tools in the admin panel and via our support team.
Termination
On termination of the main agreement, Keloa returns or deletes all Customer Data within 90 days. Backups are purged on the standard 30-day cycle.
The countersigned DPA is available on request from your account manager or by emailing legal@keloa.ai.
Questions about this document? Email legal@keloa.ai. For data subject requests, see our Privacy Policy.