Data Processing Addendum
1 Definitions
Terms including controller, processor, data subject, personal data, personal data breach, processing and supervisory authority have the meanings in applicable Data Protection Law.
Data Protection Law means the UK GDPR, the Data Protection Act 2018 and related law as amended (including relevant changes made by the Data (Use and Access) Act 2025), the EU GDPR where applicable, and other data-protection law expressly applicable to the processing.
Customer Personal Data means personal data processed by KYRA on behalf of the Customer or its End Customer under the Agreement. Restricted Transfer means a transfer of personal data requiring a lawful transfer mechanism under applicable Data Protection Law. Subprocessor means another processor appointed by KYRA to process Customer Personal Data.
2 Roles
2.1 The Customer is controller of Customer Personal Data or is a processor authorised by the relevant End Customer or controller. KYRA is the Customer’s processor or subprocessor accordingly.
2.2 The Customer warrants that it and each instructing controller have complied with Data Protection Law, have a lawful basis and have given required notices for the processing instructed through the Service.
2.3 KYRA is an independent controller for its own account, billing, fraud prevention, security administration, legal-compliance and direct business-relationship data, as described in the Privacy Notice. This DPA does not apply to that controller processing.
3 Documented instructions
3.1 KYRA will process Customer Personal Data only on documented instructions, including the Agreement, Order Form, Customer configurations and support instructions, unless UK or other applicable law requires processing. Where legally permitted, KYRA will inform the Customer before processing required by law.
3.2 KYRA will promptly inform the Customer if, in its reasonable opinion, an instruction infringes Data Protection Law, and may suspend the affected instruction while the parties resolve it.
3.3 The Customer will not instruct KYRA to process data in a manner outside the Service’s documented scope without a written amendment.
4 Processing details
The subject matter, duration, nature, purpose, data subjects and data categories are described in Schedule 1.
5 Confidentiality and personnel
KYRA will ensure that personnel authorised to process Customer Personal Data are bound by confidentiality, receive appropriate security and privacy instruction, and access data only as necessary for their duties.
6 Security
6.1 KYRA will implement and maintain appropriate technical and organisational measures under Article 32, taking account of the state of the art, implementation cost, the nature, scope, context and purposes of processing, and the risks to individuals.
6.2 The current measures are described in the Security Measures Schedule below. KYRA may update them where overall protection is not materially reduced.
6.3 The Customer is responsible for configuring available controls appropriately, including roles, customer scopes, approvers, retention overrides, channel permissions and integration access.
7 Subprocessors
7.1 The Customer gives general written authorisation for KYRA to appoint the Subprocessors in the current Subprocessor Notice.
7.2 KYRA will impose written data-protection obligations on each Subprocessor that provide an equivalent level of protection appropriate to its processing. KYRA remains responsible for the Subprocessor’s performance of those obligations to the extent required by Data Protection Law.
7.3 KYRA will give at least 30 days’ prior notice of a new or replacement Subprocessor that will process Customer Personal Data, unless an urgent replacement is reasonably required to maintain security or service continuity. In an urgent case, notice will be given as soon as reasonably practicable.
7.4 The Customer may object during the notice period on reasonable, documented data-protection grounds. The parties will work in good faith on a reasonable alternative. If no reasonable alternative is available, either party may terminate the affected feature; if the feature is material, the Customer may terminate the affected Service and receive a pro-rata refund of prepaid unused fees.
8 International transfers
8.1 KYRA will not make a Restricted Transfer without a valid mechanism and required supplementary assessment or measures.
8.2 Depending on the transfer, mechanisms may include UK adequacy regulations, the UK International Data Transfer Agreement, the UK Addendum to EU Standard Contractual Clauses, EU adequacy decisions or the applicable EU Standard Contractual Clauses.
8.3 Where the EU SCCs or UK Addendum/IDTA are required between the Customer and KYRA, the applicable approved clauses are incorporated by reference or executed as an annex, with module, party details, governing option and competent authority completed in the Order Form or DPA evidence record.
8.4 KYRA will make reasonable transfer-mechanism information available on request, subject to confidentiality and provider restrictions.
9 Data-subject rights
9.1 Taking account of the nature of processing, KYRA will provide reasonable technical and organisational assistance for the Customer to respond to access, rectification, erasure, restriction, portability, objection and other applicable rights requests.
9.2 If KYRA receives a request relating to Customer Personal Data, it will refer the requester to the Customer where practicable and notify the Customer, unless prohibited by law. KYRA will not independently fulfil it except on instruction or legal obligation.
9.3 Assistance beyond standard product functionality may be chargeable at reasonable professional-service rates where the request is unusually burdensome and the charge is permitted by law. KYRA will agree the scope before charging.
10 Assistance and compliance
Taking account of the nature of processing and the information available, KYRA will reasonably assist the Customer with:
- security obligations;
- personal-data-breach assessment and notification;
- data-protection impact assessments;
- prior consultation with supervisory authorities;
- records and information needed to demonstrate compliance.
The Customer remains responsible for its own legal determinations and controller obligations. See also our DPIA support pack.
11 Personal data breaches
11.1 KYRA will notify the Customer without undue delay after becoming aware of a confirmed Personal Data Breach affecting Customer Personal Data.
11.2 The initial notice will contain information reasonably available at the time, which may be supplied in phases, including the nature of the incident, affected data and data subjects where known, likely consequences, containment and remediation, and a contact point.
11.3 KYRA will take reasonable steps to contain, investigate and mitigate the breach and will preserve relevant evidence.
11.4 Notification is not an admission of fault or liability. The Customer is responsible for notifying regulators and individuals in its controller role; KYRA is responsible for any notification required for its independent-controller processing.
12 Audits and information
12.1 KYRA will make information reasonably necessary to demonstrate compliance with Article 28 available to the Customer.
12.2 Audits will ordinarily begin with current independent reports, security documentation and a reasonable questionnaire. If these are insufficient, the Customer may conduct, or appoint an independent auditor to conduct, an audit on at least 30 days’ notice, not more than once per 12 months, during business hours and subject to confidentiality, safety and non-disruption requirements.
12.3 Frequency and notice limits do not apply following a material Personal Data Breach, credible evidence of material non-compliance or a binding regulatory requirement.
12.4 The Customer bears its audit costs. If an audit identifies material KYRA non-compliance, KYRA will bear its remediation costs and reasonable directly related re-verification costs.
12.5 Audits may not expose other customers’ information, compromise security or require disclosure of legally privileged material.
13 Return and deletion
13.1 On termination or the Customer’s written instruction, KYRA will, at the Customer’s choice and subject to product capability, return or export Customer Personal Data and delete remaining copies, unless law requires retention.
13.2 Unless otherwise agreed, the export window is 30 days after termination. Operational copies will be deleted or irreversibly anonymised within 30 days after the end of that window or earlier valid instruction.
13.3 Backups will be placed beyond ordinary use and expire through the documented backup cycle, targeted not to exceed 90 days, unless law or a documented legal hold requires longer. If restored, deletion restrictions will be reapplied before restored data is returned to ordinary use.
13.4 Financial and controller records are not Customer Personal Data processed solely on behalf of the Customer and may be retained under the Privacy Notice.
14 Government requests
Where legally permitted, KYRA will notify the Customer of a binding government request for Customer Personal Data, challenge an unlawful or disproportionate request where reasonable, and disclose only the data legally required.
15 Liability and precedence
Liability under this DPA is subject to the liability provisions of the Agreement. If this DPA conflicts with the Terms on the processing of Customer Personal Data, this DPA prevails.
16 Law
This DPA is governed by the law and jurisdiction stated in the Terms, without overriding mandatory rights or the governing provisions of incorporated transfer clauses.
Schedule 1 — Processing details
Subject matter and purpose
Providing a multi-tenant AI-assisted IT-support service, including channel communications, knowledge retrieval, answer generation, ticket creation and enrichment, analytics, quality review, customer administration, Microsoft 365 read operations and approved write operations.
Duration
The Agreement term plus the limited export, deletion and protected-backup periods described above.
Nature of processing
Collection, receipt, recording, organisation, storage, retrieval, consultation, analysis, embedding, generation, transmission, disclosure to authorised recipients and Subprocessors, ticket and action execution, restriction, export and deletion.
Data subjects
- Customer and End-Customer employees, contractors, administrators and Authorised Users.
- End Users requesting IT support.
- Microsoft 365 users and administrators whose records are accessed under Customer instruction.
- Approvers and support contacts.
- MSP and End-Customer technicians whose ticket work may be quality-reviewed.
- Other persons whose information is incidentally included in support content or documents.
Personal-data categories
- Name, work email, phone number, role, organisation and channel identifiers.
- Authentication and account metadata, login IP, session, security and anomaly telemetry.
- Teams, Slack, SMS, voice and widget message content and metadata.
- Call audio where processed, transcripts, call timing and direction, and recording state.
- Attachments, screenshots, extracted text and knowledge documents.
- Microsoft 365 directory, group, licence, device, mailbox, MFA and sign-in information.
- Requested and approved actions and their results.
- PSA and ticket content, classification, priority, status and technician information.
- Ticket QA scores, flags and coaching suggestions.
- Usage, audit, consent, approval and support-impersonation records.
- Customer configuration, knowledge provenance and integration identifiers.
- Special-category or other sensitive personal data only where incidentally submitted; the Service is not designed to require it as standard.
Customer instructions and rights
The Customer determines enabled tenants, channels, knowledge sources, integrations, action modes, approvers, retention overrides and users, and may access, export and delete data through product functionality or documented requests, subject to law and the Agreement.
Security Measures Schedule
KYRA maintains measures designed to protect Customer Personal Data proportionate to the Service’s risk. These measures are contractual controls, not a claim of certification. A plain-English trust-center summary is also published at our Security & Trust Center.
1. Governance and risk
- Assigned ownership for security, privacy, incident response and service operations.
- Periodic risk assessment and threat modelling for authentication, tenant isolation, integrations, AI actions, voice and billing.
- Security requirements and review in the software-development lifecycle.
- A maintained data, provider and system inventory.
- Regular review of privileged access and production configuration.
2. Identity and access
- Individual staff identities and least-privilege role assignment.
- Multi-factor authentication for production administrative access.
- Separate MSP and KYRA staff authentication boundaries.
- Role- and permission-based MSP access with customer scope.
- Time-limited, audited support impersonation and elevation subject to Customer controls.
- Session expiry, revocation and protection using Secure, HttpOnly cookies where applicable.
- Step-up authentication for particularly sensitive administrative actions where implemented and required by policy.
3. Tenant isolation
- MSP-scoped partitioning and server-derived tenant identity.
- Object-level ownership checks for customer-scoped operations.
- Separate knowledge-retrieval scope per customer tenant.
- Server-side authorisation independent of model-generated content.
- Regression tests and build-time route and permission checks.
4. Encryption and secrets
- TLS for data in transit over supported public endpoints.
- Azure platform encryption for Storage data at rest.
- Additional authenticated encryption for stored third-party credentials.
- Secrets held in Azure Key Vault or supported managed secret stores and not committed to source.
- Managed identities and RBAC preferred to static platform credentials.
- Documented rotation and revocation procedures.
5. Application and integration security
- Signature verification for supported provider webhooks using the exact request body.
- Replay controls and durable idempotency for externally retried operations.
- Input validation, output encoding and a progressively enforced browser Content Security Policy.
- SSRF protections for customer-configurable outbound destinations, including redirect and DNS-rebinding controls.
- Rate limiting, spam and abuse protection and size and time limits.
- AI tool proposals schema-validated and re-authorised in trusted code; privileged actions subject to configured capability and approval controls.
- Dependency scanning, a supported-version policy and timely security patching.
6. Logging, detection and incident response
- Audit logging for authentication, configuration, privilege, billing and material data and action events.
- Central operational telemetry with restricted access and documented retention.
- Alerts for authentication anomalies, application failures, queue backlog and poison, backup failure, provider and webhook failure, billing anomalies and privileged actions.
- Incident-response procedures covering containment, evidence, assessment, notification, recovery and review.
- Breach records maintained as required by law.
Audit records are protected and monitored but are not described as technically immutable unless exported to an appropriately controlled immutable store.
7. Availability, backup and recovery
- Production health monitoring and dependency-aware checks.
- Regular encrypted export and backup of required Table and Blob data to a separately permissioned recovery account.
- Appropriate storage redundancy, versioning and soft deletion, and deletion controls.
- Documented recovery objectives and restore procedures.
- Periodic restore and deployment-rollback testing.
- Backup access restricted and logged; backup copies expire under the retention schedule.
8. Personnel and suppliers
- Confidentiality obligations for personnel with access to Customer Personal Data.
- Security and privacy onboarding and periodic awareness.
- Access removal on role change or departure.
- Risk-appropriate due diligence and data-protection terms for Subprocessors.
- Review of Subprocessor security and transfer evidence.
9. Customer controls
The Service provides controls for roles, customer scope, knowledge sources, integrations, AI-provider selection, action capability and approval, retention options and support access. The exact available controls depend on Plan and channel.
10. Testing and change management
- Automated tests for security-critical logic and tenant isolation.
- Independent penetration testing proportionate to risk and before material launch where appropriate.
- Controlled, versioned deployment and rollback.
- Production changes reviewed, logged and monitored.
- Critical and high findings remediated, or affected features disabled, before release.
Contact
Kyra.bot Ltd — company number 17408470 (registered in England & Wales)
66 Paul Street, London, EC2A 4NA, United Kingdom
Data-protection contact: [email protected]