Legal

Data Processing Agreement

Last updated: September 26, 2026. Attached to Enterprise order forms and offered on request to GDPR-eligible Pro / Scale customers.5 min readKranth AI, Inc.

This DPA is incorporated by reference into the Kranth Master Service Agreement / Order Form between Kranth AI, Inc. ("Processor") and the Customer named in the Order Form ("Controller").

#1. Definitions

Terms used here have the meanings given in the EU General Data Protection Regulation (GDPR), as supplemented or replaced.

  • "Personal Data": any data relating to an identified or identifiable natural person.
  • "Processing": any operation performed on Personal Data.
  • "Subprocessor": a third party engaged by Processor to process Personal Data on behalf of Controller.

#2. Subject + duration

  • Subject: Kranth processes Personal Data on Controller's behalf solely to provide the Service described in the Order Form.
  • Duration: From the Order Form effective date until termination of the Order Form, plus a 30-day data-export grace period.

#3. Categories of data + data subjects

  • Categories of data: account identifiers (name, email, Nexus user_id, Google/GitHub OAuth ids, avatar), authentication data (password hash, and MFA secrets encrypted at the column level), simulation + debate submissions (idea_text, debate topics, transcripts; voice-debate audio is publicly addressable when Controller shares a debate), interview submissions (the decision under review and its context, and the Data Subject's own answers as transcribed text, together with per-answer evasion scores and the readiness assessment derived from them; in a voice interview the microphone audio is streamed to the transcription subprocessor in real time and is not recorded or stored by Processor), content from connected integrations (GitHub App PR titles/bodies, Linear issue + comment text), integration identifiers (Telegram chat id, Slack workspace id/name, Discord webhook URLs, Linear API key), API key metadata (prefix, last_used_at, never the full key after creation), billing metadata (Stripe customer ID, never raw card details), operational telemetry (hashed IP, request IDs, audit log entries).
  • Categories of data subjects: Controller's employees, contractors, customers, or other end users to the extent Controller submits Personal Data about them.

#4. Processor obligations

Processor will:

  1. Process Personal Data only on documented instructions from Controller, including with regard to cross-border transfers.
  2. Ensure persons authorized to process the data are bound by confidentiality.
  3. Implement appropriate technical and organizational measures (see Annex 2).
  4. Engage Subprocessors only with prior consent (see Annex 1) and bind them to terms no less protective than this DPA.
  5. Assist Controller in responding to Data Subject Requests within the timelines required by law.
  6. Notify Controller of any Personal Data Breach without undue delay (target: within 48 hours of detection).
  7. Delete or return all Personal Data at end of services per Controller's choice, subject to retention obligations under law.
  8. Make available all information necessary to demonstrate compliance with this DPA and allow audits per Section 8.

#5. Controller obligations

Controller represents that:

  1. It has the legal basis to share the Personal Data with Processor (consent, contract, legitimate interest, etc.).
  2. Its instructions to Processor are lawful.
  3. It will inform Processor of any change of legal basis.

#6. Subprocessors

  • Authorized subprocessors are listed at kranth.ai/subprocessors (canonical) and Annex 1.
  • Processor will give Controller 30 days' notice via email to the billing contact before adding a new subprocessor that processes Personal Data.
  • Controller may object in writing within the notice window; if Processor cannot accommodate the objection, Controller may terminate the affected portion of the services with a pro-rata refund.

#7. International transfers

Where Personal Data is transferred outside the EU/EEA, Processor uses the EU Standard Contractual Clauses (SCCs) incorporated by reference, with the appropriate modules per the transfer scenario (typically Module 2 controller-to-processor, Module 3 processor-to-processor for subprocessors). UK transfers use the IDTA / UK Addendum. Swiss transfers use the Swiss addendum where required.

The primary data store (Postgres) is hosted in the EU (Germany). Object storage (Cloudflare R2) uses Cloudflare's automatic region placement. Regional pinning beyond this is not yet offered.

#8. Audits

  • Processor conducts regular internal reviews of its operational controls. No independent third-party attestation (for example, SOC 2) exists yet.
  • Controller may, at most once per 12 months, request an audit summary; Processor will provide a written summary of current security controls within 30 days of request.
  • For Enterprise customers requiring on-site audits, contact [email protected]. Fees apply if the audit goes beyond reasonable scope.

#9. Data Subject Requests

  • Processor will assist Controller in responding to Data Subject Requests (access, rectification, erasure, portability, restriction, objection) within the GDPR's mandated timelines.
  • Controller is the primary respondent to Data Subjects. Processor's role is enabling.
  • API affordances: GET /v1/sims/{id}/export for portability, account deletion in /app/settings for erasure, [email protected] for the rest.

#10. Breach notification

  • Processor will notify Controller of a Personal Data Breach without undue delay after becoming aware.
  • Target: within 48 hours of detection.
  • Notification includes: nature of breach, categories of data + records affected, likely consequences, measures taken, contact point.

#11. Liability

Processor's liability under this DPA is subject to the limitations of liability in the MSA (typically: capped at trailing-12-month fees, no consequential damages, exceptions for breach of confidentiality + IP indemnity).

#12. Termination

Either party may terminate this DPA upon termination of the MSA. On termination, Processor will, per Controller's choice, delete or return all Personal Data within 30 days, unless law requires longer retention.


#Annex 1: Approved Subprocessors

As of the effective date: see kranth.ai/subprocessors.

#Annex 2: Technical and Organizational Measures (TOMs)

  • TLS 1.2+ for all transit
  • Provider-side encryption at rest for R2 object storage
  • AES-256-GCM column-level encryption for MFA secrets
  • Argon2id-hashed API keys (shown once at creation, never stored raw)
  • HMAC-SHA256 signatures on all outbound webhooks; inbound GitHub webhooks verified with constant-time compare and a 5-minute replay window
  • Application-level append-only audit log
  • Append-only credit ledger
  • Workspace isolation enforced at the SQL layer (org_id-scoped queries with cross-org 404)
  • Per-org rate limiting (Redis sliding-window)
  • Worker recovery sweeper (auto-failover for stuck sims)
  • Daily logical database backups to R2 (7-day rotation) + periodic restore drills
  • Structured logging to journalctl; alert pattern kranth.alert.*
  • Vulnerability disclosure program at [email protected]
  • Quarterly security review

#Annex 3: Contacts


Signed by Kranth officer + Customer signatory on attachment to the Order Form. To request a signed DPA, email [email protected].

You read the whole thing. Most people don't. Thank you.

Questions about this document? [email protected] · Back to the top