Kapso Data Processing Addendum
Last updated: August 25, 2026
Effective date: September 1, 2026
This Data Processing Addendum, including its schedules (the “DPA”), forms part of the agreement between Kapso, Inc. (“Kapso”) and the customer that uses the Services (“Customer”) and governs Kapso’s Processing of Personal Data on Customer’s behalf.
This DPA applies automatically when Customer accepts the Kapso Terms of Service, signs an order form or other agreement that incorporates it, or uses Services involving the Processing of Personal Data. It does not require a separate signature. If the parties separately sign this DPA, it takes effect on the last signature date.
1. Definitions
Affiliate means an entity that controls, is controlled by, or is under common control with a party.
Applicable Data Protection Law means privacy, data-protection, and data-security law applicable to Kapso’s Processing of Personal Data under the Agreement, including, where applicable, the GDPR and U.S. State Privacy Laws.
Controller, Data Subject, Personal Data, Personal Data Breach, Process, Processing, and Processor have the meanings given in Applicable Data Protection Law. “Controller” includes a “business,” and “Processor” includes a “service provider” or “contractor,” where those terms are used by U.S. State Privacy Laws.
Customer Data means information submitted to or processed through the Services by or for Customer. Personal Data under this DPA means Customer Data that is regulated personal data or personal information. It excludes personal information Kapso processes independently as a controller, such as Customer business-contact, account, billing, and relationship information.
GDPR means the EU General Data Protection Regulation 2016/679, the UK GDPR, and applicable implementing or supplemental law, in each case where applicable.
Restricted Transfer means a transfer of Personal Data that requires a recognized transfer mechanism under the GDPR or Swiss data-protection law.
SCCs means the European Commission standard contractual clauses adopted by Implementing Decision (EU) 2021/914.
Services means the services covered by the Agreement.
State Privacy Laws means comprehensive U.S. state privacy laws applicable to the Processing.
Subprocessor means an Affiliate or third party engaged by Kapso to Process Personal Data on Customer’s behalf.
Capitalized terms not defined in this DPA have the meaning given in the agreement that incorporates this DPA (the “Agreement”).
2. Scope, roles, and duration
Customer is a Controller or Processor, as applicable. Kapso is a Processor or Subprocessor acting on Customer’s behalf. Each party will comply with the obligations applicable to its role under Applicable Data Protection Law.
This DPA applies for as long as Kapso Processes Personal Data on Customer’s behalf, including any post-termination period during which Kapso retains Personal Data under the Agreement or applicable law.
The subject matter, nature, purpose, categories of Personal Data, categories of Data Subjects, and duration of Processing are described in Schedule 1.
3. Customer instructions and responsibilities
Kapso will Process Personal Data only:
- to provide, secure, support, and maintain the Services;
- as configured or initiated by Customer and its authorized users;
- as described in the Agreement, this DPA, applicable order forms, and Customer’s other documented instructions;
- for product and model improvement as described in Section 11, unless Customer opts out; and
- as required by law, in which case Kapso will notify Customer before Processing unless law prohibits notice.
Kapso will promptly inform Customer if, in Kapso’s reasonable opinion, an instruction violates Applicable Data Protection Law. Kapso may suspend the affected Processing until the parties resolve the issue.
Customer is responsible for:
- the lawfulness, accuracy, and quality of Personal Data and its instructions;
- providing required notices and obtaining required consents, permissions, and lawful bases;
- responding to Data Subjects and regulators as Controller;
- configuring the Services and permissions appropriately;
- securing Customer-controlled systems, devices, credentials, API keys, and integrations; and
- ensuring that Customer’s use of the Services complies with law and the Agreement.
Customer will not submit Restricted Data prohibited by the Agreement without Kapso’s prior written approval and any required additional agreement.
4. Confidentiality and personnel
Kapso will ensure that personnel authorized to Process Personal Data are subject to confidentiality obligations and receive access only as reasonably necessary for their responsibilities. Kapso will take reasonable steps to ensure personnel understand applicable privacy and security duties.
5. Security
Kapso will maintain technical and organizational measures designed to protect Personal Data against accidental or unlawful destruction, loss, alteration, unauthorized disclosure, or access. The current measures are described in Schedule 2.
Kapso may update those measures to reflect changes in technology, risk, law, and the Services, provided that the updates do not materially reduce the overall level of protection during an applicable paid subscription term.
Customer acknowledges that security is a shared responsibility and that the Services cannot eliminate every risk. Customer has reviewed the Services and the measures made available by Kapso and is responsible for determining whether they are appropriate for Customer’s Processing.
6. Personal Data Breaches
Kapso will notify Customer without undue delay after becoming aware of a Personal Data Breach affecting Personal Data. The notice will include information reasonably available to Kapso about the nature of the incident, likely consequences, affected data, and remediation. Kapso may provide information in phases as its investigation progresses.
Kapso will take commercially reasonable steps to contain, investigate, mitigate, and remediate a Personal Data Breach and will reasonably cooperate with Customer’s legally required response. Notice is not an admission of fault or liability.
Customer is responsible for determining whether to notify Data Subjects, authorities, or others. Where legally permitted, Customer will consult Kapso before issuing a notice that identifies Kapso and will consider reasonable corrections relating to Kapso’s role.
Unsuccessful attempts or events that do not compromise Personal Data—such as scans, pings, unsuccessful logins, and blocked attacks—are not Personal Data Breaches under this DPA.
7. Data Subject requests and compliance assistance
Taking into account the nature of Processing, Kapso will provide tools and reasonable assistance technically available through the Services to help Customer respond to Data Subject requests. Customer can access, export, correct, and delete much of Customer Data through APIs, endpoints, and dashboard controls.
If Kapso receives a request relating to Personal Data controlled by Customer, Kapso will, where appropriate, direct the requester to Customer and notify Customer unless prohibited by law. Kapso will not independently respond on Customer’s behalf unless required by law or authorized by Customer.
Taking into account the nature of Processing and information available to Kapso, Kapso will provide reasonable assistance with Customer’s legally required data-protection impact assessments, prior consultations, security obligations, and breach obligations. Kapso may charge reasonable fees for assistance that requires material work outside the ordinary Services, after providing advance notice and, on request, a good-faith estimate.
8. Subprocessors
Customer authorizes Kapso to engage the Affiliates and third-party Subprocessors listed on the Kapso Subprocessor List and gives general authorization for Kapso to add or replace Subprocessors under this Section.
Kapso will:
- enter into a written agreement requiring each Subprocessor to protect Personal Data in a manner appropriate to the services it performs;
- remain responsible for the Subprocessor’s performance of the data-protection obligations Kapso delegates to it; and
- provide at least 15 days’ prior notice of a new Subprocessor that will materially Process Personal Data, including by email, in-product notice, or an update-notification mechanism associated with the Subprocessor List.
Customer may object within 15 days after notice on reasonable, documented data-protection grounds. The parties will work in good faith to address the objection. If they cannot reach a reasonable solution, Customer may stop using the affected feature or terminate the affected Services as its sole remedy for the objection. Customer remains responsible for fees and usage incurred before termination.
Kapso may use a Subprocessor without advance notice where urgently necessary to maintain security or availability, but will provide notice as soon as reasonably practicable.
9. International transfers
Customer authorizes Kapso and its Subprocessors to Process Personal Data in the United States, Chile, and other countries where they operate, subject to the safeguards in this DPA.
For a Restricted Transfer from the EEA, the SCCs are incorporated by reference as follows:
- Module Two applies where Customer is a Controller and Kapso is a Processor.
- Module Three applies where Customer is a Processor and Kapso is a Subprocessor.
- The optional docking clause in Clause 7 applies.
- Option 2 in Clause 9 applies, with the notice period in Section 8 of this DPA.
- The optional language in Clause 11 does not apply.
- The supervisory authority is determined under Clause 13 based on the relevant data exporter and Data Subjects.
- The governing law for Clause 17 is the law of Ireland.
- The courts for Clause 18 are the courts of Ireland.
- Schedules 1 through 3 of this DPA complete the relevant annexes to the SCCs.
For a Restricted Transfer subject to the UK GDPR, the SCCs as completed above apply as modified by the then-current mandatory UK International Data Transfer Addendum issued by the UK Information Commissioner. The parties are deemed to have completed the tables using the information in this DPA, with Customer as exporter and Kapso as importer, and select the option allowing the importer to end the addendum if an approved change creates a substantial disproportionate increase in direct cost and the parties cannot reach an alternative arrangement.
For a Restricted Transfer subject to Swiss law, the SCCs apply with references to the GDPR understood to include the Swiss Federal Act on Data Protection where necessary; the competent authority is the Swiss Federal Data Protection and Information Commissioner; and Swiss Data Subjects may bring proceedings in Switzerland where required by law.
If a valid replacement transfer mechanism becomes available, Kapso may update this Section on notice, provided the replacement does not materially reduce required protection.
10. Return, deletion, and retention
During the term, Customer may access or export Customer Data using available Service functionality. Customer should complete exports before terminating the account.
Upon Customer’s valid request or termination of the affected Services, Kapso will delete or anonymize Personal Data within a commercially reasonable period, subject to:
- Customer’s instructions and available product controls;
- normal backup rotation and technical limitations;
- retention required or permitted by law;
- security, fraud-prevention, dispute, financial, and audit requirements; and
- data that has been aggregated or de-identified so that it no longer constitutes Personal Data.
Kapso will protect retained Personal Data and Process it only for the applicable retention purpose. Further detail appears in the Privacy Policy and applicable Service documentation.
11. AI and service improvement
Customer instructs Kapso to Process Personal Data as needed to provide AI, transcription, speech, automation, and related features selected by Customer, including transmission to providers identified in the Subprocessor List.
Unless Customer opts out through an available account control or by written notice to legal@kap.so, Customer also instructs Kapso to use Customer Data to develop, test, train, and improve Kapso features and models where permitted by Applicable Data Protection Law. An opt-out withdraws this instruction prospectively for model-training and generalized improvement uses. It does not prevent Processing required to provide the Services, fulfill another Customer instruction, maintain security, investigate abuse, comply with law, or create aggregated or de-identified analytics.
Kapso will not authorize an AI Subprocessor to use Personal Data to train that Subprocessor’s general models except where disclosed to Customer, required by a feature or provider selected by Customer, or separately authorized by Customer. Kapso will use commercially reasonable provider settings and contractual options intended to limit provider training where available.
Kapso does not use automated decision-making on Customer’s behalf that produces legal or similarly significant effects unless the relevant Service documentation or order form identifies that functionality. Customer is responsible for human review and for determining whether an automated use is lawful and appropriate.
12. Audits and information
On reasonable written request, Kapso will provide information reasonably necessary to demonstrate compliance with this DPA. Kapso may satisfy requests through then-current third-party audit reports, certifications, security documentation, questionnaires, penetration-test summaries, or similar materials, subject to confidentiality restrictions.
Customer may audit Kapso’s compliance no more than once in any 12-month period, unless additional audits are required by law, a competent authority, or a confirmed Personal Data Breach. Before an audit, Customer must:
- give at least 30 days’ written notice where practicable;
- provide a proposed scope and plan limited to Processing relevant to Customer;
- use an independent, qualified auditor that is not a Kapso competitor;
- sign reasonable confidentiality terms; and
- avoid unreasonable interference with Kapso’s operations or the security and confidentiality of other customers.
Audits will ordinarily be remote and document-based. On-site access is available only where legally required and where the information cannot reasonably be provided another way. Customer bears its audit costs and will reimburse Kapso for reasonable costs of assistance beyond ordinary compliance materials, unless the audit identifies a material breach by Kapso.
13. U.S. State Privacy Laws
Where State Privacy Laws apply, Kapso acts as Customer’s service provider or contractor for Personal Data. Kapso will not:
- sell or share Personal Data for cross-context behavioral advertising;
- retain, use, or disclose Personal Data outside the direct business relationship with Customer or for a commercial purpose other than the specific purposes described in the Agreement and this DPA, except as permitted by State Privacy Laws;
- combine Personal Data received from Customer with personal information received from another person or from Kapso’s own interactions with a consumer, except as permitted by State Privacy Laws; or
- attempt to re-identify de-identified data except to test whether de-identification processes comply with law.
Kapso certifies that it understands and will comply with the restrictions in this Section. Customer may take reasonable and appropriate steps to help ensure Kapso uses Personal Data consistently with Customer’s obligations, including the audit rights in Section 12.
14. Government requests
Unless prohibited by law, Kapso will notify Customer of a legally binding government request for Personal Data and will direct the authority to Customer where appropriate. Kapso will review requests for legal validity, disclose only information legally required, and challenge requests where there are reasonable grounds to do so.
15. Liability and order of precedence
Each party’s liability under this DPA is subject to the exclusions and limitations in the Agreement, except to the extent Applicable Data Protection Law or the SCCs prohibit that limitation.
If there is a conflict concerning Processing of Personal Data, the following order applies: the applicable SCCs or mandatory transfer terms; this DPA; the Agreement; and other incorporated documents. The remainder of the Agreement continues in effect.
16. Changes and termination
Kapso may update this DPA where reasonably necessary to comply with law, update transfer mechanisms, or reflect changes to the Services, provided the update does not materially reduce protection of Personal Data. Kapso will give reasonable notice of material changes.
The governing law and dispute provisions of the Agreement apply to this DPA, except where mandatory transfer terms require otherwise.
Schedule 1 — Processing Details
Parties
Data importer / Provider
Kapso, Inc.
251 Little Falls Drive
Wilmington, Delaware 19808, United States
Privacy contact: legal@kap.so
Role: Processor or Subprocessor
Data exporter / Customer
The customer identified in the Agreement.
Role: Controller or Processor, as applicable.
Contact: the account owner, administrator, or other contact Customer designates.
Subject matter and purpose
Processing Customer Data to provide, secure, support, maintain, and improve the Services as described in the Agreement, including messaging, WhatsApp connectivity, APIs, integrations, automation, AI, transcription, voice, telephony, analytics, billing support, and related functions initiated by Customer.
Duration and frequency
Ongoing for the duration of the Agreement and any limited post-termination retention period. Transfers occur continuously or as initiated by Customer and its users.
Categories of Data Subjects
- Customer’s users, personnel, contractors, representatives, and business contacts;
- Customer’s customers, prospective customers, and end users;
- WhatsApp users, message senders and recipients, contacts, and conversation participants;
- individuals whose information is included in Customer Content; and
- other Data Subjects whose Personal Data Customer directs Kapso to Process.
Categories of Personal Data
- names, usernames, identifiers, contact details, and profile information;
- WhatsApp, Meta Business Portfolio, WABA, phone-number, template, message, contact, and conversation identifiers;
- message content, media, documents, recordings, transcripts, and related metadata;
- prompts, model inputs and outputs, agent instructions, tool inputs/results, and files;
- IP addresses, device, browser, authentication, API, webhook, usage, event, log, diagnostic, and security information;
- organization, role, permission, integration, and configuration data;
- support communications; and
- usage, subscription, billing-event, balance, and transaction metadata, excluding full payment-card data processed directly by Stripe.
Sensitive or Restricted Data
None intentionally. Customer must not submit Restricted Data identified in the Agreement without Kapso’s prior written approval and any required additional agreement.
Processing operations
Collection, receipt, access, organization, structuring, hosting, storage, retrieval, consultation, use, transmission, disclosure to authorized Subprocessors and integrations, analysis, generation, modification, combination, restriction, export, deletion, and anonymization as necessary to provide the Services.
Subprocessors
The current Kapso Subprocessor List, as updated under Section 8.
Schedule 2 — Technical and Organizational Measures
Kapso maintains a risk-based security program appropriate to the size and nature of the Services. Measures include, as applicable:
Access and identity
- unique workforce accounts and role-based access;
- least-privilege access to production and customer systems;
- multi-factor authentication for critical systems where supported;
- documented onboarding, role-change, and offboarding procedures; and
- periodic review of access to critical systems.
Data and infrastructure protection
- encryption in transit using industry-standard protocols where supported;
- encryption at rest through infrastructure-provider controls for primary storage and managed services where supported;
- managed secret storage and restrictions on disclosure of credentials;
- tenant and project authorization controls; and
- separation of production access from ordinary end-user access.
Application and change security
- version control and review of production changes;
- automated tests and security checks appropriate to the change;
- dependency and vulnerability monitoring;
- controls for API authentication, authorization, input handling, webhooks, and rate limiting; and
- proportionate review of high-risk AI, sandbox, and infrastructure changes.
Logging, monitoring, and incident response
- operational and security logging with access and retention controls;
- monitoring and alerting for material availability and security events;
- an incident-response process covering triage, containment, investigation, recovery, communication, and follow-up; and
- preservation of relevant evidence during material incidents.
Availability and recovery
- managed infrastructure and database backup capabilities appropriate to critical services;
- documented business-continuity and disaster-recovery responsibilities;
- restoration and incident exercises conducted on a risk-based schedule; and
- provider-status and production-health monitoring.
Personnel and vendors
- confidentiality obligations and security/privacy training for authorized personnel;
- vendor inventory and risk-based review of critical providers;
- written data-protection terms with Subprocessors; and
- processes to update public and contractual Subprocessor disclosures.
Data lifecycle
- product and API functionality supporting access, export, project deletion, and selected erasure requests;
- retention periods based on operational, security, legal, and customer requirements;
- deletion or anonymization from active systems following valid requests or termination, subject to backup rotation and lawful retention; and
- efforts to minimize sensitive information in logs and telemetry.
Schedule 3 — SCC Annex Information
For Annex I.A of the SCCs, the parties and roles are identified in Schedule 1. By entering into the Agreement, each party is deemed to sign the SCCs as of the effective date of this DPA.
For Annex I.B, the transfer and Processing details are described in Schedule 1.
For Annex I.C, the competent supervisory authority is determined under Clause 13 of the SCCs and Section 9 of this DPA.
For Annex II, the technical and organizational measures are described in Schedule 2.
For Annex III, the authorized Subprocessors are listed in the Kapso Subprocessor List.