KORPS.AI Sign in

Legal

Data Processing Addendum

Version 0.1 · Drafted August 28, 2026 · Draft for attorney review, not executed

Status of this document

This is an engineering draft published so that a prospective customer can see the shape of the terms and so counsel has something to mark up. It is not in force and binds nobody until it is executed in writing by both parties.

Open items marked like this include the contracting entity, the transfer mechanism, hosting region, audit terms and liability position.

1. Parties and precedence

This Addendum supplements the Terms of Service between the customer ("Controller") and [Korps contracting entity to be confirmed] ("Processor"). Where this Addendum conflicts with the Terms on the processing of personal data, this Addendum prevails.

Terms such as personal data, processing, controller, processor, data subject and supervisory authority have the meanings given in applicable data protection law, including UK GDPR and EU GDPR where relevant.

2. Roles

The Controller determines the purposes and means of processing Customer Personal Data. The Processor processes it only on the Controller's documented instructions, which are: the Terms, this Addendum, the configuration the Controller makes in the product, and the actions the Controller's agents take.

The Processor will tell the Controller if, in its opinion, an instruction infringes applicable data protection law.

3. Scope of processing

Details are set out in Annex 1.

4. Confidentiality

The Processor ensures that personnel authorised to process Customer Personal Data are bound by confidentiality obligations and are granted access on a need-to-know basis.

5. Security

The Processor implements appropriate technical and organisational measures, described in Annex 2. Those measures reflect the current state of the platform and may improve over time; they will not be materially reduced during the term.

6. Subprocessors

7. Data subject requests

Taking into account the nature of the processing, the Processor will assist the Controller with requests to exercise data subject rights, by providing the product functions needed to access, correct, export or delete records, and by passing on any request it receives directly rather than answering it itself.

8. Assistance

The Processor will provide reasonable assistance with data protection impact assessments, prior consultation with a supervisory authority, and security of processing, to the extent the information is within the Processor's control.

9. Personal data breach

The Processor will notify the Controller without undue delay, and intends to do so within 72 hours of becoming aware of a personal data breach affecting Customer Personal Data. The notice will describe the nature of the breach, the categories and approximate number of records affected so far as known, the likely consequences and the measures taken or proposed. The Processor will not delay an initial notice in order to complete its investigation.

10. Deletion and return

On termination, and at the Controller's choice, the Processor will delete or return Customer Personal Data, and delete existing copies, except where storage is required by law. Deletion of live records follows within a reasonable period; backup copies are deleted on the ordinary backup expiry cycle. Backup retention period to be confirmed.

11. Audit

The Processor will make available information reasonably necessary to demonstrate compliance with this Addendum. The Processor does not hold a SOC 2 report or ISO 27001 certificate, so third-party attestations cannot be offered in place of that information. Whether on-site audit rights are granted, and on what notice and frequency, is for counsel to settle.

12. International transfers

Where processing involves a transfer of personal data out of the UK or EEA, the parties intend to rely on the EU Standard Contractual Clauses and the UK International Data Transfer Addendum, incorporated by reference with Annex 1 and Annex 2 supplying the required details. The module selection, the docking clause position and the executed copies are to be confirmed by counsel.

13. Liability

Liability under this Addendum is to be aligned with the cap in the Terms of Service once counsel sets it.

14. Term

This Addendum applies for as long as the Processor processes Customer Personal Data under the Terms.

Annex 1: Details of processing

Required particulars of the processing.
Subject matterProvision of the Korps platform: accounts, workspaces and their membership, agents, teams, rooms and the messages committed in them, model connection records, runtime connections and usage metering.
DurationThe term of the Terms of Service, plus the deletion period in clause 10.
Nature and purposeHosting, storage, transmission, display and retrieval of customer records; routing content to the runtimes and model providers the Controller configures; metering usage; operating and securing the service.
Categories of data subjectThe Controller's users and workspace members; individuals referenced in content the Controller or its agents put into Korps.
Categories of personal data Account identifiers and email addresses; password hashes; session, refresh-token, recovery-code and runtime-token hashes; workspace, membership, team and agent records; the text of messages committed in rooms, with the identity of whoever wrote each one; model connection records naming a provider and where its credential is held, never the credential; avatar images; server hostnames and runtime metadata; usage token counts; operational logs including IP address; any personal data contained in customer content.
Special category dataNone. The Controller must not submit special category data; the platform is not configured for it.
FrequencyContinuous, for the duration of the service.
Processor contactprivacy@korps.ai · to be confirmed

Annex 2: Technical and organisational measures

These are the measures actually implemented as of the draft date. The Security page describes them in detail and states known gaps.

Signature

This draft is unsigned. To request an executed copy, contact legal@korps.ai · mailbox to be confirmed.