Legal

Data Processing Addendum

Version 2.0  ·  Effective date: 23 August 2026

In short: this Data Processing Addendum (“DPA”) forms part of the Agreement between the Customer and Kyra.bot Ltd (“KYRA”) where KYRA processes personal data on behalf of the Customer. It incorporates Schedule 1 (Processing details) and the Security Measures Schedule. It forms part of, and is governed by, the Business Terms of Service; where the Terms and this DPA conflict on the processing of personal data, this DPA prevails.

1 Definitions

Terms including controller, processor, data subject, personal data, personal data breach, processing and supervisory authority have the meanings in applicable Data Protection Law.

Data Protection Law means the UK GDPR, the Data Protection Act 2018 and related law as amended (including relevant changes made by the Data (Use and Access) Act 2025), the EU GDPR where applicable, and other data-protection law expressly applicable to the processing.

Customer Personal Data means personal data processed by KYRA on behalf of the Customer or its End Customer under the Agreement. Restricted Transfer means a transfer of personal data requiring a lawful transfer mechanism under applicable Data Protection Law. Subprocessor means another processor appointed by KYRA to process Customer Personal Data.

2 Roles

2.1 The Customer is controller of Customer Personal Data or is a processor authorised by the relevant End Customer or controller. KYRA is the Customer’s processor or subprocessor accordingly.

2.2 The Customer warrants that it and each instructing controller have complied with Data Protection Law, have a lawful basis and have given required notices for the processing instructed through the Service.

2.3 KYRA is an independent controller for its own account, billing, fraud prevention, security administration, legal-compliance and direct business-relationship data, as described in the Privacy Notice. This DPA does not apply to that controller processing.

3 Documented instructions

3.1 KYRA will process Customer Personal Data only on documented instructions, including the Agreement, Order Form, Customer configurations and support instructions, unless UK or other applicable law requires processing. Where legally permitted, KYRA will inform the Customer before processing required by law.

3.2 KYRA will promptly inform the Customer if, in its reasonable opinion, an instruction infringes Data Protection Law, and may suspend the affected instruction while the parties resolve it.

3.3 The Customer will not instruct KYRA to process data in a manner outside the Service’s documented scope without a written amendment.

4 Processing details

The subject matter, duration, nature, purpose, data subjects and data categories are described in Schedule 1.

5 Confidentiality and personnel

KYRA will ensure that personnel authorised to process Customer Personal Data are bound by confidentiality, receive appropriate security and privacy instruction, and access data only as necessary for their duties.

6 Security

6.1 KYRA will implement and maintain appropriate technical and organisational measures under Article 32, taking account of the state of the art, implementation cost, the nature, scope, context and purposes of processing, and the risks to individuals.

6.2 The current measures are described in the Security Measures Schedule below. KYRA may update them where overall protection is not materially reduced.

6.3 The Customer is responsible for configuring available controls appropriately, including roles, customer scopes, approvers, retention overrides, channel permissions and integration access.

7 Subprocessors

7.1 The Customer gives general written authorisation for KYRA to appoint the Subprocessors in the current Subprocessor Notice.

7.2 KYRA will impose written data-protection obligations on each Subprocessor that provide an equivalent level of protection appropriate to its processing. KYRA remains responsible for the Subprocessor’s performance of those obligations to the extent required by Data Protection Law.

7.3 KYRA will give at least 30 days’ prior notice of a new or replacement Subprocessor that will process Customer Personal Data, unless an urgent replacement is reasonably required to maintain security or service continuity. In an urgent case, notice will be given as soon as reasonably practicable.

7.4 The Customer may object during the notice period on reasonable, documented data-protection grounds. The parties will work in good faith on a reasonable alternative. If no reasonable alternative is available, either party may terminate the affected feature; if the feature is material, the Customer may terminate the affected Service and receive a pro-rata refund of prepaid unused fees.

8 International transfers

8.1 KYRA will not make a Restricted Transfer without a valid mechanism and required supplementary assessment or measures.

8.2 Depending on the transfer, mechanisms may include UK adequacy regulations, the UK International Data Transfer Agreement, the UK Addendum to EU Standard Contractual Clauses, EU adequacy decisions or the applicable EU Standard Contractual Clauses.

8.3 Where the EU SCCs or UK Addendum/IDTA are required between the Customer and KYRA, the applicable approved clauses are incorporated by reference or executed as an annex, with module, party details, governing option and competent authority completed in the Order Form or DPA evidence record.

8.4 KYRA will make reasonable transfer-mechanism information available on request, subject to confidentiality and provider restrictions.

9 Data-subject rights

9.1 Taking account of the nature of processing, KYRA will provide reasonable technical and organisational assistance for the Customer to respond to access, rectification, erasure, restriction, portability, objection and other applicable rights requests.

9.2 If KYRA receives a request relating to Customer Personal Data, it will refer the requester to the Customer where practicable and notify the Customer, unless prohibited by law. KYRA will not independently fulfil it except on instruction or legal obligation.

9.3 Assistance beyond standard product functionality may be chargeable at reasonable professional-service rates where the request is unusually burdensome and the charge is permitted by law. KYRA will agree the scope before charging.

10 Assistance and compliance

Taking account of the nature of processing and the information available, KYRA will reasonably assist the Customer with:

The Customer remains responsible for its own legal determinations and controller obligations. See also our DPIA support pack.

11 Personal data breaches

11.1 KYRA will notify the Customer without undue delay after becoming aware of a confirmed Personal Data Breach affecting Customer Personal Data.

11.2 The initial notice will contain information reasonably available at the time, which may be supplied in phases, including the nature of the incident, affected data and data subjects where known, likely consequences, containment and remediation, and a contact point.

11.3 KYRA will take reasonable steps to contain, investigate and mitigate the breach and will preserve relevant evidence.

11.4 Notification is not an admission of fault or liability. The Customer is responsible for notifying regulators and individuals in its controller role; KYRA is responsible for any notification required for its independent-controller processing.

12 Audits and information

12.1 KYRA will make information reasonably necessary to demonstrate compliance with Article 28 available to the Customer.

12.2 Audits will ordinarily begin with current independent reports, security documentation and a reasonable questionnaire. If these are insufficient, the Customer may conduct, or appoint an independent auditor to conduct, an audit on at least 30 days’ notice, not more than once per 12 months, during business hours and subject to confidentiality, safety and non-disruption requirements.

12.3 Frequency and notice limits do not apply following a material Personal Data Breach, credible evidence of material non-compliance or a binding regulatory requirement.

12.4 The Customer bears its audit costs. If an audit identifies material KYRA non-compliance, KYRA will bear its remediation costs and reasonable directly related re-verification costs.

12.5 Audits may not expose other customers’ information, compromise security or require disclosure of legally privileged material.

13 Return and deletion

13.1 On termination or the Customer’s written instruction, KYRA will, at the Customer’s choice and subject to product capability, return or export Customer Personal Data and delete remaining copies, unless law requires retention.

13.2 Unless otherwise agreed, the export window is 30 days after termination. Operational copies will be deleted or irreversibly anonymised within 30 days after the end of that window or earlier valid instruction.

13.3 Backups will be placed beyond ordinary use and expire through the documented backup cycle, targeted not to exceed 90 days, unless law or a documented legal hold requires longer. If restored, deletion restrictions will be reapplied before restored data is returned to ordinary use.

13.4 Financial and controller records are not Customer Personal Data processed solely on behalf of the Customer and may be retained under the Privacy Notice.

14 Government requests

Where legally permitted, KYRA will notify the Customer of a binding government request for Customer Personal Data, challenge an unlawful or disproportionate request where reasonable, and disclose only the data legally required.

15 Liability and precedence

Liability under this DPA is subject to the liability provisions of the Agreement. If this DPA conflicts with the Terms on the processing of Customer Personal Data, this DPA prevails.

16 Law

This DPA is governed by the law and jurisdiction stated in the Terms, without overriding mandatory rights or the governing provisions of incorporated transfer clauses.

Schedule 1 — Processing details

Subject matter and purpose

Providing a multi-tenant AI-assisted IT-support service, including channel communications, knowledge retrieval, answer generation, ticket creation and enrichment, analytics, quality review, customer administration, Microsoft 365 read operations and approved write operations.

Duration

The Agreement term plus the limited export, deletion and protected-backup periods described above.

Nature of processing

Collection, receipt, recording, organisation, storage, retrieval, consultation, analysis, embedding, generation, transmission, disclosure to authorised recipients and Subprocessors, ticket and action execution, restriction, export and deletion.

Data subjects

Personal-data categories

Customer instructions and rights

The Customer determines enabled tenants, channels, knowledge sources, integrations, action modes, approvers, retention overrides and users, and may access, export and delete data through product functionality or documented requests, subject to law and the Agreement.

Security Measures Schedule

Version 1.0  ·  Effective 23 August 2026  ·  forms part of this DPA

KYRA maintains measures designed to protect Customer Personal Data proportionate to the Service’s risk. These measures are contractual controls, not a claim of certification. A plain-English trust-center summary is also published at our Security & Trust Center.

1. Governance and risk

2. Identity and access

3. Tenant isolation

4. Encryption and secrets

5. Application and integration security

6. Logging, detection and incident response

Audit records are protected and monitored but are not described as technically immutable unless exported to an appropriately controlled immutable store.

7. Availability, backup and recovery

8. Personnel and suppliers

9. Customer controls

The Service provides controls for roles, customer scope, knowledge sources, integrations, AI-provider selection, action capability and approval, retention options and support access. The exact available controls depend on Plan and channel.

10. Testing and change management

Contact

Kyra.bot Ltd — company number 17408470 (registered in England & Wales)

66 Paul Street, London, EC2A 4NA, United Kingdom

Data-protection contact: [email protected]