Data Processing Agreement
Last updated: 26 August 2026
Version 1.1
Template version
This is KAIRO’s standard DPA, suitable for the majority of B2B customers. If your organisation requires bespoke terms, an executed paper copy, or your own DPA template signed back, email admin@kairoengine.com and we’ll route it to legal review (allow 5 working days).
On this page
- 011. Parties & Scope
- 022. Definitions
- 033. Subject Matter & Duration
- 044. Operator’s Instructions
- 055. Confidentiality
- 066. Security (TOMs)
- 077. Sub-processors
- 088. International Transfers
- 099. Retention & Deletion
- 1010. Data Subject Rights
- 1111. Personal Data Breach Notification
- 1212. Audits
- 1313. Liability
- 1414. Governing Law
1. Parties & Scope
This Agreement (“DPA”) supplements the Terms of Service between Kairo Engine Ltd (company number 17127596) (“KAIRO”, the Processor) and the Customer (“Operator”, the Controller) and governs all processing of Personal Data carried out by KAIRO on the Operator’s behalf in connection with the KAIRO platform.
In the event of conflict between this DPA and the Terms of Service, this DPA prevails for all matters relating to processing of Personal Data.
2. Definitions
“Personal Data”, “Controller”, “Processor”, “Data Subject”, “Process(ing)” and “Sub-processor” have the meanings given to them in the UK GDPR. “UK GDPR” means the UK General Data Protection Regulation as defined in section 3(10) of the Data Protection Act 2018, supplemented by section 205(4) of the Data Protection Act 2018.
3. Subject Matter & Duration
Subject matter: Provision of a multi-tenant SaaS platform for chauffeur dispatch and fleet operations.
Duration: For as long as the Operator maintains an active KAIRO subscription, plus the retention windows in Section 9.
Nature and purpose: Hosting, organising, transmitting, presenting and analysing data the Operator (or its agents) submits to the platform; sending transactional notifications; producing AI-assisted suggestions for dispatch and admin tasks.
Categories of Data Subject: Operator’s end customers (passengers / bookers), corporate account contacts, drivers, partner operators’ staff, Operator’s own staff users.
Categories of Personal Data: Names, contact details (email, phone, address), employer / role, vehicle registration plates, driver licence + DBS document metadata (documents themselves stored in object storage), passenger preferences, journey history, payment receipts (tokenised via Stripe; KAIRO never stores raw card numbers).
4. Operator’s Instructions
KAIRO will only Process Personal Data on documented instructions from the Operator, including with regard to international transfers, except where required by UK or EU law (in which case KAIRO will inform the Operator unless the law prohibits it). Configuring and using the platform constitutes the Operator’s ongoing instructions.
5. Confidentiality
KAIRO will ensure that any person authorised to Process Personal Data is bound by confidentiality obligations equivalent to those in this DPA.
6. Security (TOMs)
KAIRO has implemented and will maintain appropriate technical and organisational measures (TOMs) to protect Personal Data against accidental or unlawful destruction, loss, alteration, unauthorised disclosure or access. The list below describes what KAIRO runs today. Where KAIRO does not yet run a measure, the list says so rather than leaving the Operator to assume it.
- KAIRO serves every request over TLS 1.2 or later. Supabase Postgres and object storage encrypt stored data with AES-256.
- Postgres row-level security policies scope tenant data at the database layer. KAIRO restricts service-role access to server-side code paths that set an explicit tenant scope.
- KAIRO wraps TrueLayer banking tokens and the Dext API key in a second layer of AES-256-GCM encryption before writing them to the database. Gmail and Xero tokens do not carry that second layer and rely on the database encryption above. One KAIRO-held key performs the wrapping, so the keys are not split per tenant.
- Operators sign in with an email address and a password of at least 12 characters drawn from 3 character classes, on sessions Supabase issues and expires. KAIRO does not offer multi-factor authentication.
- KAIRO stamps each change to a booking record with the person who made it and the time, and shows that history on the job itself. KAIRO does not keep a separate audit log of sign-ins, role changes or settings changes.
- Supabase takes daily automated backups of the Postgres database. KAIRO does not run point-in-time recovery, so the earliest state KAIRO can restore is the most recent daily backup.
- KAIRO does not copy production data onto developer workstations.
KAIRO is working towards Cyber Essentials certification and does not claim SOC 2 or ISO 27001. The security page carries the same control list in shorter form and is kept in step with this section. Customers can request the current TOMs schedule by emailing admin@kairoengine.com.
7. Sub-processors
KAIRO may engage sub-processors to assist in providing the platform. The current list is published at /legal/sub-processors and will be updated with at least 30 days’ written notice before any addition or replacement.
KAIRO will impose written contractual terms on each sub-processor that are no less protective than those set out in this DPA.
8. International Transfers
Where Personal Data is transferred outside the UK or EEA, KAIRO will rely on the UK International Data Transfer Addendum to the EU Standard Contractual Clauses, the EU SCCs, or another transfer mechanism approved under Article 46 UK GDPR. The list of transfer destinations is in the Sub-processors page (Section 7).
9. Retention & Deletion
Personal Data will be retained for the active subscription period plus the periods set out below:
- Operational records (jobs, clients, drivers, fleet): deleted within 30 days of subscription termination, unless Operator requests export first.
- Invoices & financial records: retained 6 years from invoice date as required by HMRC (UK Companies Act / VAT regulations).
- Driver compliance documents (licences, DBS, MOT): retained for the regulatory minimum (typically 5 years from last engagement).
- Authentication logs: Supabase records sign-in events and retains them for the period its platform provides on KAIRO’s current plan. KAIRO does not keep its own copy, and cannot commit to a longer window than Supabase gives it.
- Backups: Supabase holds daily automated backups of the database under KAIRO’s current Supabase plan. KAIRO does not run point-in-time recovery, and will confirm the current backup retention window in writing on request.
On Operator request KAIRO will, within 30 days, return or delete all Personal Data, save where retention is required by law.
10. Data Subject Rights
KAIRO will, taking into account the nature of the processing, assist the Operator by appropriate technical and organisational measures, insofar as possible, to fulfil the Operator’s obligations to respond to Data Subject requests under UK GDPR Articles 15 to 22.
Access (Article 15). An Operator can export everything KAIRO holds about one data subject, covering the client record and their jobs, quotes, invoices and messages, from Settings → Account & data in the web app. The export is a single JSON file the Operator can hand to the individual.
Erasure (Article 17). KAIRO runs erasure on request rather than from a button in the product. Email admin@kairoengine.com from the Operator’s account and KAIRO will strip the identifying fields from that data subject’s client, job and quote records, delete their message history, and confirm both what it removed and what Section 9 required KAIRO to keep.
11. Personal Data Breach Notification
KAIRO will notify the Operator without undue delay after becoming aware of a Personal Data Breach affecting the Operator’s data. That is the standard UK GDPR Article 33(2) sets for a processor, and KAIRO accepts it as written. KAIRO will send that first notification as soon as it has something the Operator can act on, even while the investigation is still open, and will follow it with the information the Operator reasonably requires to meet its own obligations to the ICO and to Data Subjects under Articles 33 and 34.
The 72-hour deadline in Article 33(1) belongs to the Operator as Controller, and it starts when the Operator becomes aware of the breach. KAIRO deliberately does not restate 72 hours as its own deadline: a processor that used the full 72 hours would leave the Operator no time at all to report to the ICO.
12. Audits
The Operator may, no more than once per 12-month period and on at least 30 days’ notice, request information necessary to demonstrate compliance with this DPA. Where reasonable, this will be satisfied by providing relevant third-party audit reports (e.g. SOC 2 reports of sub-processors). Direct on-site audits require mutual agreement on scope, fees and confidentiality.
13. Liability
Liability under this DPA is subject to the limitations set out in the Terms of Service. Nothing in this DPA limits either party’s liability for breach of UK GDPR where such limitation is prohibited by law.
14. Governing Law
This DPA is governed by the laws of England and Wales. Disputes are subject to the exclusive jurisdiction of the courts of England and Wales.
Acceptance: by maintaining an active KAIRO subscription, the Operator accepts this DPA. A countersigned PDF copy is available on request to admin@kairoengine.com.