DATA PROCESSING ADDENDUM
How Kyntra processes personal data for you.
This Addendum applies automatically, as part of the Terms of Service, wherever your use of Kyntra involves personal data of your own customers, contacts and users. You are the controller; ATL4S.AI INC. is your processor.
VERSION dpa-2026-09-01 · LAST REVISED · 1 SEPTEMBER 2026
1. Roles and scope
For personal data in your business data, your contact and recipient lists, your published projects and communications sent on your behalf (“Customer Personal Data”), you are the controller and we process only for you. For account, billing, security and product-usage data about you, we are the controller under the Privacy Notice. For personal data appearing in public sources our research features collect, the Privacy Notice's Section 6 path applies and we handle correction and deletion requests directly.
2. What processing happens (processing map)
- Research at onboarding — public business information, which can include names in public reviews, registries and news; data subjects: your staff and third-party authors; purpose: building your business's facts graph at your request.
- Content generation — business facts and brand assets; purpose: producing your site, funnel, brand and email content.
- Communications sending — your contact lists (name, address for the channel, consent records); data subjects: your customers; purpose: sending on your behalf, on your documented instructions, with your consent records controlling.
- Hosting and operations — project data and account activity; purpose: operating, securing and supporting the service.
3. Instructions
We process Customer Personal Data only on your documented instructions, including transfers, unless law requires otherwise (in which case we tell you before processing, where the law allows). The product's approval, publish and per-channel authorization controls are documented instructions, and they are logged as such. Revoking a channel or deleting data in the product is an instruction we execute.
4. Confidentiality and security
- People we authorize to process Customer Personal Data are bound by confidentiality.
- Technical and organizational measures include: encryption in transit; encryption at rest on our infrastructure providers' platforms; least-privilege access controls and tenant isolation; recorded consent checked before every send; fail-closed publish gates; versioned artifacts enabling rollback; and logging appropriate to detect and investigate incidents.
- The Security page states what is verified and what remains gated — we do not claim certifications we do not hold.
5. Subprocessors
You authorize the subprocessors below, engaged under written terms no less protective than this Addendum. We announce additions or replacements at least 14 days before they process Customer Personal Data — by updating this page and notifying accounts by email or in the product — and you may object on reasonable data-protection grounds, in which case we work out an alternative or you may cancel affected services.
- Fly.io, Inc. (US) — application and compute hosting.
- Vercel Inc. (US) — web hosting and delivery for Kyntra surfaces.
- Supabase, Inc. (US) — managed database platform.
- Stripe, Inc. (US) — payment processing and invoicing.
- Resend, Inc. (US) — transactional and campaign email delivery.
- Together Computer, Inc. (US) — AI model inference.
- OpenRouter, Inc. (US) — AI model routing (fallback inference).
- Google LLC (US) — sign-in (OAuth), where you choose it.
- GitHub, Inc. (US) — sign-in and repository connections, where you choose them.
6. AI providers and training
Model providers receive content solely to return the requested output and are engaged under terms that do not permit training on your content. Customer Personal Data and Customer Content are not used to train models absent your separate, explicit, revocable opt-in recorded in the product; the model plane never receives your credentials or secrets.
7. International transfers
We are a US company and processing occurs primarily in the United States. Where GDPR/UK GDPR-scoped transfers occur, we rely on each provider's recognised mechanism — EU–US Data Privacy Framework certification or Standard Contractual Clauses — as recorded in our internal register; completing formal transfer documentation per provider is part of the pending counsel review flagged above.
8. Assistance, incidents, requests
- We assist you, considering the nature of processing, with data-subject requests, security, breach notification, and impact assessments (Art. 28(3)(e)–(f)).
- Data-subject requests we receive that belong to you as controller are passed to you without undue delay; opt-outs from recipients are also executed immediately in the consent system itself.
- We notify you without undue delay after becoming aware of a personal-data breach affecting Customer Personal Data, with the information Art. 33(3) requires as it becomes available.
9. Deletion, return and audit
- During the term you can delete projects and data in the product; deleting your account removes Customer Personal Data from live systems, with operational copies clearing on a rolling basis, except what law requires us to retain.
- On written request at termination we assist with export of your data before deletion, to the extent the product or a reasonable manual path supports it.
- We answer reasonable audit questionnaires and make available information necessary to demonstrate Art. 28 compliance; on-site audits are for cause, on notice, at your cost, and must not endanger other customers' data.
10. Liability and order of precedence
Liability under this Addendum is subject to the Terms' limitation of liability. If this Addendum conflicts with the Terms on personal-data processing, this Addendum controls. If a legally required data-processing form (for example a signed controller-processor agreement with SCCs) is needed for your compliance file, ask at hello@atl4s.ai.