Data Processing Agreement
The terms under which we process personal data on your behalf as your processor. This is the document your procurement or legal team asks for by name.
1 Definitions
- Controller
- The Client — the legal entity that has entered into a service agreement with K.I.N.D and who determines the purposes and means of processing personal data.
- Processor
- K.I.N.D Technologies Ltd (a company registered in England and Wales, company number 17260532, registered office: 33 Townsend Road, Stratford-upon-Avon, CV37 7DE), trading as K.I.N.D — who processes personal data on behalf of the Controller in accordance with this DPA and the applicable service agreement.
- Data Subject
- The individual whose personal data is processed — in the context of K.I.N.D's services, the lead or prospect identified for B2B outreach on behalf of the Client.
- Personal Data
- Any information relating to an identified or identifiable natural person, as defined in section 1 of the Protection of Personal Information Act 4 of 2013 (POPIA) and Article 4 of the GDPR.
2 Scope of Processing
K.I.N.D processes personal data solely for the purpose of B2B lead generation and outreach services performed on behalf of the Client. The categories of personal data processed include:
- Full name and job title
- Business email address
- Company name and industry
- Phone number (where available in source database)
- LinkedIn profile URL and publicly available professional information
- Email engagement data (replies, opt-outs)
K.I.N.D does not process special categories of personal data (as defined under POPIA and GDPR) and will not do so without explicit written consent from both the Client and the Data Subject.
Processing is carried out only on documented instructions from the Client, as set out in the Client's Ideal Customer Profile (ICP) configuration and campaign settings. K.I.N.D will inform the Client if it believes any instruction infringes applicable data protection law.
3 Data Location & Cross-Border Transfers
All personal data processed by K.I.N.D is stored in the European Union on Supabase's eu-west-1 region (Dublin, Ireland). Application servers run in the United States (Railway, US West). This includes lead records, campaign data, email logs, opt-out records, and client account data.
Where personal data is transferred outside the European Union or South Africa — including to our application servers in the United States — K.I.N.D applies appropriate safeguards as required by GDPR and POPIA section 72, including standard contractual clauses or equivalent protections.
Where sub-processors (see Section 5) are located outside the European Union, K.I.N.D has assessed the transfer basis and relies on appropriate safeguards including Standard Contractual Clauses (SCCs) and the sub-processor's own adequacy certifications.
4 Security Measures
K.I.N.D implements and maintains the following technical and organisational measures to protect personal data:
- Row-level security (RLS) on all database tables — client data is logically isolated and inaccessible to other tenants at the database layer
- Encryption at rest for all stored data using AES-256 via Supabase infrastructure
- Encryption in transit via TLS 1.2+ on all connections; HTTPS enforced on all K.I.N.D domains
- JWT-based access control with short-lived tokens scoped to minimum required permissions
- No passwords stored in plain text; authentication uses Supabase magic links and OAuth flows
- Regular internal security reviews of application logic and access controls
- Staff access to production data limited to personnel with a legitimate operational need
K.I.N.D will notify the Client without undue delay, and in any event within 72 hours of becoming aware, of a personal data breach that is likely to result in a risk to the rights and freedoms of Data Subjects.
5 Sub-processors
K.I.N.D engages the following sub-processors in the delivery of its services. Each sub-processor is subject to contractual obligations that provide equivalent data protection to this DPA.
| Sub-processor | Purpose | Location | Safeguards |
|---|---|---|---|
| Supabase | Database hosting, authentication, storage | Dublin, Ireland (eu-west-1) | EU-hosted; SOC 2 Type II |
| Resend | Transactional email delivery | United States | SOC 2 Type II; SCCs applied |
| Apollo.io | B2B contact database — the only source of prospect data | United States | DPA in place; SCCs applied |
| Anthropic | AI language model for email generation | United States | No data retained per API terms; SCCs applied |
| Stripe | Payment processing | United States | PCI DSS Level 1; SCCs applied |
| Railway | Application hosting (Portal, API, Admin) | United States | SOC 2-audited infrastructure; SCCs applied |
K.I.N.D will notify Clients of any intended changes to this list (additions or replacements of sub-processors) with reasonable prior notice, giving the Client the opportunity to object to such changes.
6 Data Retention
K.I.N.D retains personal data only for as long as necessary to deliver the services and meet legal obligations:
- Lead and prospect data is retained for the duration of the Client’s account and for 90 days after it closes, or until the Client requests deletion — whichever is earlier
- Email engagement logs (replies, opt-outs) are retained for the duration of the Client’s account and for 90 days after it closes
- Opt-out and suppression (blocklist) records are retained indefinitely to honour the Data Subject's right not to be contacted — deletion of these records would undermine the opt-out
- Client account data is retained for 90 days following account closure, then deleted (billing records are kept for 7 years where tax law requires)
Upon expiry of the applicable retention period, personal data is deleted or anonymised in a manner that renders re-identification impossible.
7 Client Rights
Clients may exercise the following rights in relation to personal data held by K.I.N.D on their behalf:
- Request a complete export of all personal data held for their account in a portable, machine-readable format
- Request deletion of all their account data and associated lead records at any time by emailing privacy@get-kind.com
- Request correction of inaccurate personal data
- Object to any specific processing activity
K.I.N.D will action deletion and export requests within 30 days of receipt. Where a request cannot be fulfilled in full (for example, where retention is required by law), K.I.N.D will explain the basis for retaining the data.
8 Data Subject Rights
K.I.N.D has implemented the following mechanisms for Data Subjects (leads and prospects) to exercise their rights:
- Opt-out: Any Data Subject may opt out by replying STOP, UNSUBSCRIBE, or any equivalent to any email. K.I.N.D immediately and permanently suppresses further contact with that individual across all campaigns and all clients on the platform
- Deletion requests: Data Subjects may request deletion of their personal data by emailing privacy@get-kind.com. K.I.N.D will action within 30 days, subject to the retention of suppression records as noted in Section 6
- Access requests: Data Subjects may request access to personal data held about them. K.I.N.D will respond within 30 days
- Objection: Data Subjects may object to processing at any time. K.I.N.D will cease processing unless a compelling legitimate basis can be demonstrated
Where K.I.N.D receives a Data Subject request that relates to data processed on behalf of a specific Client, K.I.N.D will promptly forward the request to the relevant Client and assist in fulfilling it.
9 Liability
K.I.N.D's total aggregate liability under this DPA — whether in contract, delict, or otherwise — is limited to the total fees paid by the Client to K.I.N.D in the three calendar months immediately preceding the event giving rise to the claim.
K.I.N.D is not liable for any indirect, consequential, incidental, or punitive damages arising from or related to this DPA, even if advised of the possibility of such damages.
Nothing in this clause limits liability for death or personal injury, fraud, or any liability that cannot be limited by applicable law.
10 Governing Law
This DPA and any dispute or claim arising out of or in connection with it (including non-contractual disputes or claims) is governed by and construed in accordance with the laws of England and Wales.
The parties submit to the exclusive jurisdiction of the courts of England and Wales to settle any dispute or claim arising out of or in connection with this DPA. For South African clients, K.I.N.D acknowledges the application of POPIA; for European clients, K.I.N.D acknowledges the primacy of applicable EU supervisory authority guidance in relation to GDPR obligations.
This DPA forms part of and is incorporated into K.I.N.D's Terms of Service. In the event of any conflict between this DPA and the Terms of Service on data protection matters, this DPA shall prevail.
11 CCPA / California Privacy Rights
For clients and data subjects located in California, USA, K.I.N.D complies with the California Consumer Privacy Act (CCPA) as amended by the California Privacy Rights Act (CPRA). The following rights apply to California residents:
- Right to know: You may request disclosure of the categories and specific pieces of personal information K.I.N.D has collected about you, the sources of collection, the business or commercial purpose, and any third parties with whom the information is shared. Requests will be fulfilled within 45 days.
- Right to delete: You may request deletion of personal information collected from you, subject to certain exceptions (e.g., where retention is required to complete a transaction, detect security incidents, or comply with legal obligations). Email privacy@get-kind.com to submit a deletion request.
- Right to opt out of sale or sharing: K.I.N.D does not sell personal information within the meaning of CCPA, nor does it share personal information for cross-context behavioural advertising. There is no opt-out mechanism required as this activity does not occur.
- Right to non-discrimination: K.I.N.D will not discriminate against you for exercising any CCPA rights — including by denying service, charging different prices, or providing a different level of service.
- Authorised agent requests: A California resident may designate an authorised agent to submit requests on their behalf. K.I.N.D will verify the agent's authorisation before processing the request.
K.I.N.D does not have actual knowledge that it sells or shares personal information of consumers under 16 years of age.
For all California privacy requests, contact: privacy@get-kind.com
Questions about this DPA?
Our team is based in South Africa and is happy to answer any questions about how we process your data or your clients' data.
Email privacy@get-kind.com