KIVEX Data Processing Agreement (DPA)
For a new Customer, this DPA applies from the moment it is demonstrably accepted. For an existing Customer, it applies from the date notified in accordance with the Terms of Service; until then, the previously accepted version remains in effect.
This data processing agreement (the “DPA”) supplements the Contract between the Customer and Jakub Macura, Company ID (IČO) 24359939, Drahanovice 143, 783 44, Czech Republic (“KIVEX”). The DPA is entered into under Article 28 of Regulation (EU) 2016/679 (the “GDPR”) and forms part of the Contract where KIVEX processes personal data on behalf of the Customer.
This is an English translation provided for convenience. In the event of any discrepancy between the Czech and English versions, the Czech version prevails.
Contents
- 1. Interpretation and roles of the parties
- 2. Documented instructions
- 3. Customer obligations
- 4. Confidentiality and authorised persons
- 5. Security of processing
- 6. Sub-processors
- 7. International transfers
- 8. Data subject rights
- 9. Cooperation, DPIA and supervisory authority
- 10. Personal data breach
- 11. Audit and demonstration of compliance
- 12. Return, erasure and backups
- 13. Term and precedence of the DPA
- Annex A — Details of processing
- Annex B — Technical and organisational measures
- Annex C — Sub-processors
1. Interpretation and roles of the parties
1.1. The terms controller, processor, sub-processor, personal data, processing, data subject, personal data breach and supervisory authority have the meaning given to them in the GDPR.
1.2. The Customer is the controller of the entrusted personal data or a processor acting on behalf of another controller. KIVEX is a processor or sub-processor in relation to the Customer.
1.3. Where the Customer is a processor, it confirms that the relevant controller has authorised the engagement of KIVEX and of sub-processors under the terms of this DPA. The Customer will pass on to the controller the notices and information it receives from KIVEX under this DPA.
1.4. Processing for which KIVEX itself determines the purposes and means, in particular management of its own accounts, invoicing, KIVEX security, legal obligations and its own business communications, is governed by the Privacy Policy and is not entrusted processing under this DPA.
2. Documented instructions
2.1. KIVEX processes the entrusted personal data only on the Customer's documented instructions, which consist of the Contract, this DPA, the Order, the Service settings and the Customer's verified written instructions.
2.2. The instructions also cover transfers of data to sub-processors and outside the European Economic Area (the “EEA”) to the extent described in this DPA and in the current Sub-processor Register made available to Customers. The Register contains the identity of the relevant sub-processors and other information needed to assess their engagement, and is available in the Hub or on request at [email protected].
2.3. Where processing is required by Union or Member State law, KIVEX will inform the Customer in advance, unless that law prohibits such information on important grounds of public interest.
2.4. If KIVEX considers that an instruction infringes the GDPR or other data protection law, it will inform the Customer without undue delay and may suspend the execution of the instruction concerned until it is clarified or changed.
2.5. An instruction that requires a material change to the standard Service may be the subject of a separate agreement on scope, timing and reasonable costs. KIVEX may not make the fulfilment of an obligation it already has under the GDPR or the Contract conditional on such an agreement.
3. Customer obligations
3.1. The Customer is responsible, in particular, for:
- the lawfulness of the purpose, scope and legal basis of the processing;
- fulfilling the duty to inform End Users;
- obtaining and recording consents for persistent identifiers, optional analytics and other non-essential technologies;
- the accuracy and minimisation of data, and the configuration of retention and access permissions;
- the lawfulness of knowledge sources, lead capture and the transfer of data to integrations;
- handling data subject rights and assessing the need for a DPIA;
- not using the Service for prohibited high-risk processing or high-risk processing not discussed in advance.
3.2. In standard mode, the Customer must not purposely collect special categories of personal data under Article 9 GDPR or personal data relating to criminal convictions and offences under Article 10 GDPR, unless it has agreed an appropriate arrangement with KIVEX in writing in advance.
4. Confidentiality and authorised persons
4.1. KIVEX will make the entrusted personal data available only to persons who need it to perform the Contract and will limit their permissions according to their job role.
4.2. All authorised persons are bound by contractual or statutory confidentiality and receive appropriate instructions on data protection.
4.3. KIVEX regularly reviews access and revokes it as soon as it is no longer needed.
5. Security of processing
5.1. Taking into account the state of the art, the costs of implementation, the nature, scope, context and purposes of processing and the risks to individuals, KIVEX will implement appropriate technical and organisational measures under Article 32 GDPR.
5.2. The basic measures are described in Annex B to this DPA. KIVEX may change the measures from time to time, provided that the overall level of protection is not reduced.
5.3. KIVEX does not guarantee absolute security. However, it undertakes to manage risks, restrict access, protect data in transit, monitor relevant events and maintain procedures for incidents, recovery and erasure.
6. Sub-processors
6.1. The Customer gives KIVEX general written authorisation to engage the sub-processors listed in the current Sub-processor Register, always only to the extent of the features that are active. KIVEX makes the Register available to Customers in the Hub or on request at [email protected]; it need not be publicly accessible.
6.2. KIVEX will impose on each sub-processor, in writing, data protection obligations corresponding to the applicable part of this DPA and remains liable to the Customer for the performance of the sub-processor's obligations to the extent required by the GDPR.
6.3. KIVEX will give notice of any intended addition or replacement of a sub-processor at least 30 days before its engagement, usually by e-mail to the administrator and by updating the Sub-processor Register.
6.4. During this period, the Customer may raise a specific and reasoned objection relating to the protection of personal data. The parties will try to find a reasonable solution, such as disabling a feature or using an alternative supplier. If no solution is reasonably possible, the Customer may, before the supplier is engaged, terminate the feature concerned or the Contract without penalty and obtain a pro rata refund for the unused part.
7. International transfers
7.1. KIVEX will transfer entrusted personal data outside the EEA only in accordance with Chapter V GDPR.
7.2. The applicable mechanism may be an adequacy decision of the European Commission, standard contractual clauses, binding corporate rules or another valid mechanism.
7.3. Where necessary in view of the country, the supplier and the nature of the data, KIVEX will assess the risks of the transfer and implement supplementary contractual, technical or organisational measures.
7.4. KIVEX will provide information about the specific mechanism on request, to the extent that this does not compromise security or the confidential information of others.
8. Data subject rights
8.1. Taking into account the nature of the processing, KIVEX will reasonably assist the Customer by technical and organisational measures in fulfilling requests under Chapter III GDPR.
8.2. If KIVEX receives a request concerning data controlled by the Customer, it will forward it to the Customer without undue delay and will not respond to it on the merits unless the Customer authorises it to do so or the law requires it.
8.3. The Customer will first use the features available in the Hub. If a request requires non-standard manual intervention, the parties may agree on reasonable costs, unless such assistance is an obligation of KIVEX for which no charge may be made.
9. Cooperation, DPIA and supervisory authority
9.1. KIVEX will provide the Customer with information reasonably necessary to assess security, notification obligations, a DPIA and prior consultation under Articles 32 to 36 GDPR, taking into account the nature of the processing and the information available to KIVEX.
9.2. KIVEX will not determine the Customer's legal basis, carry out its DPIA or provide a legal opinion on its behalf, unless this is separately agreed.
10. Personal data breach
10.1. If KIVEX becomes aware of a breach of security of the entrusted personal data, it will notify the Customer without undue delay after becoming aware of it.
10.2. Based on the information available, the notification will contain:
- the nature of the incident and the categories of data and individuals concerned;
- the approximate scope, if known;
- the likely consequences;
- the measures taken or proposed;
- a contact point for further information.
10.3. Where it is not possible to provide the information at the same time, KIVEX will provide it in phases without further undue delay.
10.4. A notification is not an admission of liability. The Customer is responsible for assessing and fulfilling its notification obligations towards the authority and data subjects; KIVEX will provide it with the necessary cooperation.
11. Audit and demonstration of compliance
11.1. KIVEX will provide the information necessary to demonstrate compliance with Article 28 GDPR, in particular this DPA, a description of the measures, the list of sub-processors and available independent reports or certifications, if any.
11.2. If these materials are not sufficient, the Customer may request a reasonable audit no more than once every 12 months. The frequency limit does not apply after a serious incident or on the instruction of a supervisory authority.
11.3. An audit must be notified at least 30 days in advance, take place during business hours, not unreasonably disrupt operations and not compromise other customers' data, trade secrets or security. The auditor must be independent and bound by confidentiality.
11.4. The Customer bears its own costs and KIVEX's reasonable costs of a non-standard audit, unless the audit reveals a material breach of KIVEX's obligations.
11.5. KIVEX will promptly inform the Customer if, in its opinion, an audit instruction infringes the GDPR.
12. Return, erasure and backups
12.1. During the term of the Contract, the Customer may request export or erasure at [email protected] and use any self-service features actually made available in the Hub. KIVEX will provide the export by a secure procedure, in a scope and format corresponding to the categories of data it actually processes for the Customer. After termination, Data Portability and Switching Providers also applies.
12.2. After termination and expiry of the contractual retrieval period, KIVEX will, at the Customer's choice, return the entrusted personal data or delete it from active systems, unless further retention is required by law.
12.3. Backup copies, if made, are intended for recovery after an incident, are not used for new purposes and access to them must be restricted to authorised persons. If restoring a backup could make available again data that should already have been erased under a documented instruction or whose retention period has expired, KIVEX must not reuse such data for the ordinary provision of the Service and will take reasonable measures to reapply the applicable erasure and retention requirements.
12.4. This DPA does not promise a fixed rotation interval or a maximum retention period for backups. If the Customer needs such a commitment, it must be expressly set out in the Order. KIVEX maintains internal procedures corresponding to the backup and recovery method currently in use; this DPA does not create an obligation to make backups if they are not used for the service concerned.
13. Term and precedence of the DPA
13.1. The DPA takes effect at the same time as the Contract and remains in force for as long as KIVEX processes entrusted personal data.
13.2. In matters of entrusted processing, the DPA prevails over any conflicting provision of the other contractual documents.
13.3. Changes to this DPA are governed by Article 17 of the Terms of Service. A change must not reduce protection below the level required by the GDPR.
Annex A — Details of processing
| Area | Description |
|---|---|
| Subject matter | Operation of the website AI assistant, voice features, the Hub, knowledge sources, navigation, lead capture, hand-off to staff, analytics and agreed integrations |
| Duration | Standard maximum retention of conversations, text transcripts, leads, topics and summaries by plan: Free 7 days, One 30 days, Pro 90 days, Advanced 365 days, Scale 730 days and Custom individually under the Order; thereafter only for the time needed for export, erasure, recovery or mandatory retention |
| Nature of operations | Receipt, transmission, recording, temporary or configured storage, indexing, search, generation of responses, classification, summaries, speech transcription and synthesis, analysis, making available to authorised persons, export and erasure |
| Purposes | Answering visitors, website navigation, operation of voice features, lead collection, hand-off to staff, security, basic and optional analytics and other features enabled by the Customer |
| Data subjects | Website visitors, prospects, the Customer's customers, its staff, contact persons and persons named in authorised sources |
| Categories of data | Messages, voluntarily provided contact details, voice input, transcripts, conversation identifiers and, following the visitor's consent, IP and network metadata, URL and page context, topics, summaries, leads, hand-off requests and usage events |
| Special categories | The standard Service is not intended for their targeted collection; any intended processing requires a prior assessment and a written agreement |
Annex B — Technical and organisational measures
Depending on the risk, KIVEX maintains, in particular:
- access management by organisation, role and permission;
- logical separation of Workspaces and control of access to Agents;
- authentication of user accounts in line with the current security configuration;
- appropriate protection of passwords, tokens, keys and other access secrets;
- HTTPS for public interfaces and transfers between supported components;
- verification of permitted widget domains, request origins and sessions;
- limits on request size, rate and concurrency;
- security logging, monitoring and incident response procedures;
- security updates, vulnerability management and review of permissions proportionate to the risk;
- retention and erasure procedures in line with the configuration and documented instructions;
- documented backup and recovery procedures, where backups are made, including checks of applicable erasures and retention before data is returned to production;
- contractual management of suppliers and sub-processors;
- protection of stored data according to its nature, the risk and the current production configuration;
- pseudonymisation of selected network or visitor data where appropriate;
- where visitor analytics is enabled, minimisation of cookieless events without a stable ID and separation of optional analytics that requires consent.
Annex C — Sub-processors
The current Sub-processor Register forms part of this DPA. KIVEX makes it available to Customers in the Hub or on request at [email protected]. The version in effect when the Contract is concluded is recorded together with the acceptance of the DPA. The public privacy policy may list only categories of providers; this does not affect KIVEX's obligation to disclose to the Customer the identity of its relevant sub-processors.
Operator: Jakub Macura, Company ID (IČO) 24359939, Drahanovice 143, 783 44, Czech Republic. Contact: [email protected].
All documents are listed in the legal documents overview.

