Data Processing Agreement
This Data Processing Agreement ("DPA") forms part of the Master Subscription Agreement ("Agreement") between Kozo Pulse Inc. ("Processor") and Customer ("Controller"). This DPA applies when Kozo Pulse processes Personal Data on behalf of Customer in providing the Services.
1. Definitions
Controller: The entity that determines the purposes and means of processing Personal Data.
Processor: The entity that processes Personal Data on behalf of the Controller.
Personal Data: Any information relating to an identified or identifiable natural person processed by Kozo Pulse on behalf of Customer, including contact information, professional information, and usage data tied to identifiable individuals.
Data Protection Laws: All applicable data protection laws including GDPR, UK GDPR, CCPA/CPRA, and similar legislation.
Sub-processor: Any Processor engaged by Kozo Pulse to process Personal Data on behalf of Customer.
Standard Contractual Clauses (SCCs): Standard contractual clauses approved by the European Commission (Decision 2021/914) or UK ICO.
2. Scope and Roles
Customer is the Controller that determines the purposes and means of processing Personal Data.
Kozo Pulse is the Processor that processes Personal Data on behalf of Customer in accordance with Customer's documented instructions.
Details of processing are set forth in Annex 1 below.
3. Processing Instructions and Compliance
Kozo Pulse will process Personal Data only in accordance with Customer's documented instructions, as necessary to provide the Services, and as required by applicable law.
If Kozo Pulse believes an instruction violates Data Protection Laws, Kozo Pulse will inform Customer and may suspend performance until the instruction is confirmed or modified.
Customer warrants that its instructions comply with all applicable Data Protection Laws and that necessary consents have been obtained.
4. Security Measures
Kozo Pulse has implemented appropriate technical and organizational measures to protect Personal Data (detailed in Annex 2), including:
Technical Measures
- Encryption in transit (TLS 1.2+) and at rest
- Access controls and authentication
- Network security and firewalls
- Regular security assessments and penetration testing
- Automated vulnerability scanning
- Secure backup and disaster recovery
Organizational Measures
- Security policies and procedures
- Employee training and background checks
- Confidentiality agreements
- Incident response procedures
- Regular security audits
Customer is responsible for using strong authentication, properly configuring security settings, protecting Login Credentials, and securing their own systems.
5. Sub-processors
Customer authorizes Kozo Pulse to engage Sub-processors. Current Sub-processors are listed below:
| Sub-processor | Service | Location |
|---|---|---|
| Google Cloud Platform | Infrastructure hosting | EU |
| Anthropic (Claude) | AI monitoring | US |
| OpenAI (ChatGPT) | AI monitoring | US |
| Google AI (Gemini) | AI monitoring | US |
| Stripe | Payment processing | US |
| Resend | Email services | US |
| Google Analytics | Website analytics | US |
| Sentry | Error tracking | EU |
Kozo Pulse will provide 30 days' advance notice of new Sub-processors and allow Customer to object on reasonable data protection grounds.
6. International Data Transfers
Personal Data is primarily processed in the EU (Google Cloud Platform - europe-west2 region, London).
For transfers from the EEA or UK to countries without adequate protection, Kozo Pulse relies on Standard Contractual Clauses and implements supplementary measures.
7. Personal Data Breaches
Kozo Pulse will notify Customer without undue delay (and within 72 hours where feasible) after becoming aware of any Personal Data breach affecting Customer Data.
Notification will include:
- The nature of the breach
- Affected categories and approximate numbers of Data Subjects
- Contact point for information
- Likely consequences
- Measures taken or proposed
Customer is responsible for notifying supervisory authorities and Data Subjects as required by Data Protection Laws.
8. Data Subject Rights
Kozo Pulse will, to the extent legally permitted, promptly notify Customer if it receives a Data Subject request relating to Customer's Personal Data.
Kozo Pulse will provide reasonable assistance to enable Customer to respond to Data Subject requests, including access, rectification, erasure, data portability, restriction of processing, and objection to processing.
9. Data Retention and Deletion
Kozo Pulse will process Personal Data for the duration of the Agreement unless otherwise instructed by Customer.
Upon termination or expiration:
- Customer has 30 days to export Personal Data
- After 30 days, Kozo Pulse will delete or anonymize all Personal Data
- Backup copies will be deleted within 90 days
- Kozo Pulse may retain data as required by law
10. Audit Rights
Customer may audit Kozo Pulse's compliance with this DPA once per year upon reasonable notice. Kozo Pulse will provide:
- Relevant documentation and records
- Responses to audit questionnaires
- Copies of third-party audit reports (SOC 2, ISO 27001)
- Access to facilities for on-site audits (subject to confidentiality and reasonable limitations)
Audits must not unreasonably interfere with Kozo Pulse's business operations.
11. Liability
Each Party's liability under this DPA is subject to the limitation of liability provisions in the Agreement.
Kozo Pulse's total liability for all claims under this DPA will not exceed the liability cap in the Agreement.
12. Term and Termination
This DPA takes effect on the Effective Date of the Agreement and continues until the Agreement expires or terminates.
Obligations regarding data deletion and confidentiality survive termination.
13. Standard Contractual Clauses
To the extent required by Data Protection Laws, the Standard Contractual Clauses are incorporated into this DPA by reference. The parties agree to execute the SCCs upon Customer's request.
Annex 1: Details of Processing
| Subject Matter | Provision of brand intelligence and monitoring services |
| Duration | Term of the Agreement |
| Nature and Purpose |
|
| Types of Personal Data |
|
| Categories of Data Subjects |
|
| Sensitive Data | Kozo Pulse does not intentionally process special categories of personal data (racial/ethnic origin, political opinions, religious beliefs, health data, biometric data, etc.). Customer must not submit such data to the Services. |
Contact Information
For DPA questions:
Email: contact@kozopulse.com
Subject: Data Processing Agreement
For data breaches:
Email: contact@kozopulse.com
Last updated: January 4, 2026
DPA Version: 1.0
Questions?
If you have any questions about this document, please contact us at: