Data Processing Agreement

Last updated: December 20, 2025

1. Introduction

This Data Processing Agreement ("DPA") forms part of the Terms of Service between Kelu ("Processor") and the Customer ("Controller") and governs the processing of personal data by Kelu on behalf of the Customer in connection with the Services.

2. Definitions

  • "Personal Data" means any information relating to an identified or identifiable natural person
  • "Processing" means any operation performed on personal data
  • "Data Subject" means the individual to whom personal data relates
  • "Sub-processor" means any third party engaged by Kelu to process personal data

3. Scope and Purpose

Kelu processes personal data solely for the purpose of providing the Services, which includes:

  • Crawling and indexing of customer-connected knowledge sources
  • Generating embeddings and AI answers with source citations
  • Storing conversations, feedback, and analytics
  • Account management and authentication
  • Customer support

4. Data Categories

Personal data processed may include:

  • Contact information (name, email)
  • Account credentials
  • Website content and URLs
  • Usage data and analytics
  • Communication records

5. Processor Obligations

Kelu agrees to:

  • Process personal data only on documented instructions from the Controller
  • Ensure personnel are bound by confidentiality obligations
  • Implement appropriate technical and organizational security measures
  • Assist the Controller with data subject requests
  • Delete or return personal data upon termination
  • Make available information necessary for compliance audits

6. Security Measures

Kelu implements the following security measures:

  • Encryption of data in transit (TLS 1.3) and at rest (AES-256)
  • Access controls and authentication
  • Regular security assessments and penetration testing
  • Incident response procedures
  • Employee security training
  • Physical security at data centers

7. Sub-processors

Kelu uses the following sub-processors:

ProviderPurposeLocation
AWSCloud infrastructureUS/EU
StripePayment processingUS
SendGridEmail deliveryUS
CloudflareHosting and CDNGlobal
OpenAI, Anthropic, GoogleLLM and embedding generationUS

We will notify customers of any changes to sub-processors with at least 30 days notice.

8. International Transfers

Where personal data is transferred outside the EEA, Kelu ensures appropriate safeguards are in place, including Standard Contractual Clauses (SCCs) approved by the European Commission.

9. Data Subject Rights

Kelu will assist the Controller in responding to data subject requests, including rights of access, rectification, erasure, portability, and objection to processing.

10. Data Breach Notification

Kelu will notify the Controller without undue delay (and in any event within 72 hours) upon becoming aware of a personal data breach that affects Controller data.

11. Term and Termination

This DPA remains in effect for the duration of the Services agreement. Upon termination, Kelu will delete or return all personal data within 30 days, unless retention is required by law.

12. Contact

For DPA inquiries or to request a signed copy:

Email: [email protected]
Data Protection Officer: [email protected]

Request a Signed DPA

Enterprise customers can request a countersigned DPA for their records.

Request DPA