Kaia AI, Inc. — Legal
Data Processing Addendum
Last updated: July 2026
This page summarizes the data-processing terms that apply when Kaia AI, Inc. (“Kaia”) processes personal data contained in a customer’s workspace content, and is the addendum accepted at signup alongside the Terms of Service and Privacy Policy. Customers that require a countersigned agreement — including audit, transfer-mechanism, or industry-specific annexes — execute the full DPA with Kaia directly (Section 10).
1. Roles of the parties
For personal data contained in customer workspace content, the customer organization is the controller (or, under US state privacy laws, the business) and Kaia is the processor (or service provider), acting on the customer’s documented instructions. For account, workspace-profile, and inquiry data, Kaia is an independent controller as described in the Privacy Policy.
2. Scope, nature, and purpose of processing
Kaia processes customer content solely to provide the contracted service: operating regulated business-process workflows over the content the customer uploads to its tenant workspace — classification, evidence preparation, routing, correction handling, and audit-trail capture — for the duration of the agreement. The types of personal data and the data subjects concerned are determined by what the customer chooses to upload. The customer’s data-sharing consent setting (private-only by default) instructs whether anything derived from its content participates in cross-tenant learning, as described in the Privacy Policy.
3. Confidentiality of processing
Persons Kaia authorizes to process customer content are bound by confidentiality obligations, and access is limited to what operating and supporting the service requires.
4. Security measures
- Tenant isolation. Customer workspaces are isolated by PostgreSQL row-level security enforced at the database layer; every authenticated request is scoped to the requesting organization and role.
- Append-only audit trail. A database trigger blocks updates and deletes to audit records, so the record of who did what, when, cannot be altered after the fact.
- Access control. Role-gated procedures on every authenticated call; separation of duties on compliance sign-offs; credentials stored as bcrypt hashes, never in plaintext.
- Encryption. Connections to the platform are encrypted in transit (TLS). Dedicated encrypted database infrastructure is provisioned for customer production data.
- Consent-gated learning. No cross-tenant learning from customer content without explicit opt-in; shared structural patterns are anonymized and require at least five independent contributing organizations (k-anonymity) before sharing.
- Verifiable control state. Kaia’s control inventory is disclosed in-product: each platform control cites live, verifiable evidence or is shown as an open control, and a generated evidence package excludes — and lists, with reasons — any claim the platform cannot back. Kaia does not hold a SOC 2 attestation and no Kaia surface presents one as held.
5. Subprocessors
Kaia uses the following subprocessors to provide the service:
- Vercel Inc. (United States) — website and application hosting.
- Amazon Web Services, Inc. (United States) — cloud infrastructure: managed database, document storage, email delivery, and model inference via Amazon Bedrock.
- Anthropic, PBC — the Claude models used for AI processing, accessed through Amazon Bedrock on AWS infrastructure.
- Inngest, Inc. — background job orchestration.
Kaia maintains this list on this page and, under an executed DPA, provides notice of subprocessor changes with an opportunity to object. Kaia remains responsible for its subprocessors’ performance of data-protection obligations.
6. Data subject requests
Requests from individuals concerning personal data in customer content are routed to the customer as controller. Taking into account the nature of the processing, Kaia assists the customer in responding — including through the workspace’s own export and audit-trail capabilities.
7. Breach notification
Kaia will notify the affected customer without undue delay after becoming aware of a personal data breach affecting that customer’s content, and will provide information about the nature of the breach, the affected data, and the measures taken, as it becomes available.
8. Return and deletion
On termination of the agreement, Kaia will return or delete customer content at the customer’s choice, except where law requires retention — append-only audit records carry retention classes aligned to the regulatory regimes the service supports and are retained accordingly.
9. Audits and transfers
Kaia supports customer audit rights through the in-product evidence package — generated deterministically from recorded platform state — together with reasonable cooperation as agreed in the executed DPA. Processing takes place in the United States; where a lawful transfer mechanism (such as standard contractual clauses) is required, it is incorporated through the executed DPA.
10. Executing the full DPA
To execute the countersigned Data Processing Addendum — including subprocessor-notice terms, transfer mechanisms, and any industry-specific annex your regime requires (for example, a business associate agreement for protected health information) — contact Kaia through the contact form or at support@kaiaai.ai. Kaia AI, Inc. is a Delaware corporation.