This Data Processing Addendum (“DPA”) forms part of the Terms of Service, Order Form, Master Services Agreement, or other written or electronic agreement between the customer entity identified in the Agreement (“Customer”) and KIKLIKO, Inc. (“KLIPY”) under which KLIPY provides its APIs, plugins, dashboard, and related services (the “Services”).
This DPA applies where KLIPY processes Personal Data on behalf of Customer in connection with the Services. For such processing, Customer is the Controller and KLIPY is the Processor, unless otherwise stated in the Agreement.
If there is a conflict between this DPA and the Agreement regarding the processing of Personal Data, this DPA will control.
1. Definitions:
“Applicable Data Protection Laws” means all privacy and data protection laws applicable to the processing of Personal Data under the Agreement, including, where applicable, the EU GDPR, the UK GDPR, the Swiss FADP, and the California Consumer Privacy Act as amended.
“Controller,” “Processor,” “Data Subject,” “Personal Data,” “Personal Data Breach,” “processing,” and “Subprocessor” have the meanings given to them under Applicable Data Protection Laws.
“EU GDPR” means Regulation (EU) 2016/679.
“UK GDPR” means the EU GDPR as incorporated into UK law.
“SCCs” means the European Commission Standard Contractual Clauses for international transfers of personal data, as applicable.
2. Scope and Roles
Customer determines the purposes and means of processing Personal Data submitted to or processed through the Services. KLIPY processes Personal Data only as a Processor on behalf of Customer and only to provide, secure, support, maintain, and improve the Services in accordance with the Agreement, this DPA, and Customer’s documented instructions.
Customer’s documented instructions include the Agreement, this DPA, Customer’s configuration of the Services, and any written instructions mutually agreed by the parties.
KLIPY will promptly inform Customer if, in KLIPY’s opinion, an instruction infringes Applicable Data Protection Laws, unless prohibited by law.
3. Details of Processing
The subject matter, nature, purpose, duration, categories of Data Subjects, and categories of Personal Data are described in Schedule 1.
Customer will not submit Sensitive Personal Data, special category data, children’s data, government identifiers, payment card data, health data, or other regulated data to the Services unless expressly agreed in writing by KLIPY.
4. Customer Obligations
Customer is responsible for ensuring that it has a lawful basis for collecting and disclosing Personal Data to KLIPY and for providing all required notices and obtaining all required consents from Data Subjects.
Customer is responsible for the accuracy, quality, and legality of Personal Data submitted to the Services and for ensuring that its use of the Services complies with Applicable Data Protection Laws.
5. KLIPY Processor Obligations
KLIPY will:
a process Personal Data only on Customer’s documented instructions, including with respect to international transfers, unless required by applicable law;
b.ensure that persons authorized to process Personal Data are subject to confidentiality obligations;
c. implement and maintain appropriate technical and organizational measures designed to protect Personal Data against unauthorized or unlawful processing and against accidental loss, destruction, damage, alteration, or disclosure;
d. provide reasonable assistance to Customer, taking into account the nature of the processing and the information available to KLIPY, to help Customer comply with its obligations regarding security, Personal Data Breach notifications, data protection impact assessments, prior consultations, and Data Subject requests;
e. delete or return Personal Data after termination of the Services, at Customer’s choice, unless applicable law requires continued storage; and
f. make available information reasonably necessary to demonstrate compliance with this DPA and allow for and contribute to audits as described in Section 10.
6. Subprocessors
Customer grants KLIPY general authorization to engage Subprocessors to provide the Services.
KLIPY will maintain a current list of Subprocessors at [Subprocessor URL]. KLIPY will provide notice of any new or replacement Subprocessor by updating the Subprocessor list or by other reasonable means.
Customer may object to a new Subprocessor on reasonable data protection grounds within 15 days after notice. If Customer objects, KLIPY will use commercially reasonable efforts to resolve the objection. If the parties cannot resolve the objection, Customer may suspend or terminate the affected Services.
KLIPY will enter into a written agreement with each Subprocessor imposing data protection obligations that are substantially equivalent to those in this DPA. KLIPY remains liable to Customer for the performance of its Subprocessors’ data protection obligations.
7. Security
KLIPY will maintain appropriate technical and organizational measures designed to protect Personal Data, as further described in Schedule 2.
Customer acknowledges that security measures may evolve over time, provided that KLIPY does not materially decrease the overall security of the Services.
8. Personal Data Breach
KLIPY will notify Customer without undue delay after becoming aware of a Personal Data Breach affecting Customer Personal Data.
KLIPY’s notice will include available information reasonably necessary for Customer to meet its breach notification obligations, including the nature of the breach, categories of affected data, likely consequences, and measures taken or proposed to address the breach, to the extent such information is available.
KLIPY will take reasonable steps to mitigate the effects of the Personal Data Breach and prevent recurrence.
9. Data Subject Requests
If KLIPY receives a request from a Data Subject relating to Customer Personal Data, KLIPY will not respond directly except to direct the Data Subject to Customer, unless legally required to respond.
Taking into account the nature of the Services, KLIPY will provide reasonable assistance to Customer in responding to Data Subject requests.
10. Audits and Compliance Information
Upon Customer’s reasonable written request, KLIPY will make available information reasonably necessary to demonstrate compliance with this DPA.
Where such information is insufficient to demonstrate compliance, Customer may request an audit no more than once per year, unless required by a regulator or following a confirmed Personal Data Breach. Audits must be conducted during normal business hours, with reasonable prior notice, by Customer or an independent auditor subject to confidentiality obligations, and in a manner that does not unreasonably disrupt KLIPY’s business or compromise the security or confidentiality of other customers’ data.
KLIPY may satisfy audit requests by providing third-party audit reports, certifications, security summaries, penetration test summaries, or similar documentation, where available.
11. International Data Transfers
To the extent KLIPY processes Personal Data subject to the EU GDPR in a country that does not provide an adequate level of protection, the parties agree that the SCCs apply as follows:
a. Module 2 applies where Customer is a Controller and KLIPY is a Processor;
b. Customer is the data exporter and KLIPY is the data importer;
c. Schedule 1 forms Annex I to the SCCs;
d. Schedule 2 forms Annex II to the SCCs;
e. the Subprocessor list forms Annex III to the SCCs; and
f. the optional docking clause applies.
To the extent KLIPY processes Personal Data subject to the UK GDPR in a country that does not provide an adequate level of protection, the UK International Data Transfer Addendum to the EU SCCs applies.
If the SCCs, UK Addendum, or other applicable transfer mechanism is updated, replaced, or invalidated, the parties will cooperate in good faith to implement a valid transfer mechanism.
12. EU and UK Representatives
Where required under Article 27 of the EU GDPR or UK GDPR, KLIPY has appointed representatives for data protection matters.
EU Representative:
Rickert Rechtsanwaltsgesellschaft mbH
KIKLIKO, Inc.
Colmantstraße 15
53115 Bonn
Germany
Email:
[email protected]
UK Representative:
Rickert Services Ltd UK
KIKLIKO, Inc.
PO Box 1487
Peterborough
PE19XX
United Kingdom
Email:
[email protected]
13. Deletion and Return
Upon termination or expiration of the Agreement, KLIPY will delete or return Customer Personal Data, at Customer’s choice, unless applicable law requires continued retention.
KLIPY may retain Personal Data in backup, archival, or security systems for a limited period in accordance with its standard retention practices, provided that such data remains protected under this DPA and is deleted in the ordinary course.
14. Government and Law Enforcement Requests
If KLIPY receives a legally binding request from a public authority for access to Customer Personal Data, KLIPY will, unless legally prohibited, notify Customer and use reasonable efforts to redirect the requesting authority to Customer.
KLIPY will only disclose Customer Personal Data to the extent legally required.
Schedule 1: Details of Processing
A. Subject Matter
Provision of KLIPY’s APIs, plugins, dashboard, analytics, security, support, and related Services.
B. Nature and Purpose of Processing
KLIPY processes Personal Data to provide, operate, secure, monitor, support, maintain, troubleshoot, and improve the Services, including GIF, Sticker, Clip, Meme, and GenAI-related API integrations.
C. Duration of Processing
For the duration of the Agreement and as otherwise required to comply with legal, security, backup, and contractual obligations.
D. Categories of Data Subjects
Customer’s authorized users, developers, administrators, and end-users who interact with KLIPY-powered functionality within Customer’s application, website, keyboard, platform, or service.
E. Categories of Personal Data
Depending on Customer’s implementation, Personal Data may include:
• IP addresses;
• device identifiers;
• user agent and device metadata;
• search queries;
• usage logs;
• API request metadata;
• approximate location derived from IP address;
• account or business contact information for Customer administrators; and
• other data submitted by Customer or transmitted through the Services.
F. Sensitive Personal Data
The Services are not designed to process Sensitive Personal Data. Customer must not submit Sensitive Personal Data to the Services unless expressly agreed in writing by KLIPY.
G. Processing Operations
Collection, transmission, hosting, storage, retrieval, analysis, logging, organization, structuring, deletion, and other processing necessary to provide the Services.
Schedule 2: Technical and Organizational Measures
KLIPY maintains an information security program designed to protect Personal Data, including the following measures:
1. Access Control
• Role-based access control;
• least-privilege access principles;
• multi-factor authentication for administrative access;
• periodic access reviews;
• access revocation procedures for departing personnel.
2. Encryption
• Encryption in transit using HTTPS/TLS;
• encryption at rest using cloud provider or storage-layer encryption;
• secure management of production secrets and credentials.
3. Infrastructure and Network Security
• Use of reputable cloud, hosting, storage, CDN, and infrastructure providers;
• logical separation of environments;
• firewall, network, and access restrictions where appropriate;
• monitoring of production systems.
4. Vulnerability and Patch Management
• Vulnerability scanning or security review of production systems;
• timely remediation of critical vulnerabilities;
• dependency and infrastructure patching procedures.
5. Logging and Monitoring
• Centralized logging for key production systems;
• monitoring designed to detect security, reliability, and operational events;
• alerting and incident escalation procedures.
6. Backup and Resilience
• Backup and restoration procedures;
• resiliency measures appropriate to the Services;
• disaster recovery and business continuity planning.
7. Personnel Security
• Confidentiality obligations for personnel;
• security awareness practices;
• restricted access to production systems.
8. Incident Response
• Documented incident response procedures;
• internal escalation and investigation processes;
• breach notification process for affected customers.
Schedule 3: Subprocessors
KLIPY may update this list from time to time. KLIPY will provide notice of any new or replacement subprocessor in accordance with the DPA, and Customer may object as set out in the DPA.
| Entity Name |
Purpose of Processing |
Location of Processing / Hosting |
| Google Cloud (GCP) |
Cloud infrastructure, database hosting, and core application processing. |
US, Germany, Singapore |
| Cloudflare |
Content Delivery Network (CDN), web performance optimization, and DDoS security protection. |
Global
|
| Brevo |
Transactional email delivery and marketing automation. |
European Union (France, Germany, Belgium) |
| Atlassian (Jira) |
IT service management, bug tracking, and customer support issue resolution. |
United States |
| Intercom |
Customer support messaging, help desk, and direct client communications. |
United States |
| Hetzner |
Cloud infrastructure and dedicated server hosting. |
Germany and US |