kAIxU SuperIDE

Data Processing Agreement

Skyes Over London LC  ·  Version 1.0  ·  Effective: March 1, 2026

This Data Processing Agreement ("DPA") forms part of the agreement between Skyes Over London LC ("Processor") and the customer entity that has agreed to the kAIxU Terms of Service ("Controller"). This DPA incorporates the EU Standard Contractual Clauses (Module 2: Controller to Processor) by reference. Enterprise customers requiring a countersigned DPA should contact legal@kaixu.app.

1. Definitions

Terms used but not defined here have the meanings given in the GDPR (Regulation (EU) 2016/679) and the UK GDPR as applicable.

2. Subject Matter and Duration

Processor agrees to process Personal Data on behalf of Controller solely for the purpose of providing the Services, for the duration of the subscription and for 30 days thereafter (during which Controller may export data prior to deletion).

3. Nature and Purpose of Processing

CategoryExamplesPurpose
Identity dataEmail address, hashed passwordAccount management, authentication
Workspace contentCode, text filesStorage and retrieval, AI-assisted editing (with users' consent)
Usage and telemetryAI call counts, session metadataQuota enforcement, billing, debugging
Security eventsLogin IPs, MFA eventsAccount security, audit logging

Data subjects include: Controller's employees, contractors, and end users who access the Services.

4. Processor Obligations

Processor shall:

5. Controller Obligations

Controller represents and warrants that it has the legal authority to provide Personal Data to Processor, that Personal Data has been collected lawfully, and that it has provided required notices to data subjects regarding the use of the Services.

6. Technical and Organisational Measures (TOMs)

DomainMeasure
Encryption in transitTLS 1.2 minimum on all connections; HSTS enforced
Encryption at restAES-256 at infrastructure level (Neon PostgreSQL)
Access controlRole-based access (owner / admin / editor / viewer); principle of least privilege
Authenticationbcrypt (cost 12) password hashing; TOTP MFA available
Audit loggingAll auth events, data access, and admin actions logged with IP and timestamp
Vulnerability managementnpm audit on every CI run; dependency updates reviewed monthly
Incident responseSecurity Incident response plan with 72-hour notification SLA
Personnel securityPrinciple of least privilege for internal system access; confidentiality agreements required

7. Sub-processors

Controller grants general written authorisation to engage the Sub-processors listed at /subprocessors. Processor shall notify Controller of any intended changes to Sub-processors with at least 15 days notice. Controller may object in writing within 15 days; if no resolution is reached, Controller may terminate the Services with a pro-rated refund.

8. International Transfers

Where Personal Data is transferred outside the EEA or UK to Sub-processors in the USA, such transfers are made under the EU Standard Contractual Clauses (Controller to Processor, Module 2) and, where applicable, the UK International Data Transfer Addendum. Copies of applicable SCCs are available upon written request to legal@kaixu.app.

9. Audit Rights

Controller (or its appointed auditor under confidentiality) may audit Processor's compliance with this DPA once per calendar year, with 30 days written notice, during business hours. Processor may satisfy audit requests by providing a current SOC 2 Type II report or equivalent third-party assessment in lieu of on-site audit.

10. Liability

Each party's liability under this DPA is subject to the limitations set out in the Terms of Service. This DPA does not expand those limits. Nothing in this DPA limits either party's liability to data subjects or supervisory authorities under applicable data protection law.

11. Governing Law

This DPA is governed by the same law as the Terms of Service, except where the GDPR or UK GDPR mandates otherwise. For EU / UK data transfers, the governing law for the SCCs is the law of the relevant EU member state or England and Wales respectively.

12. Contact

Data Protection enquiries: privacy@kaixu.app
Legal: legal@kaixu.app

13. Signatures

By accepting the Terms of Service (including the incorporated DPA), Controller agrees to be bound by this DPA as of the date of acceptance. Enterprise customers requiring a separately countersigned DPA should contact legal@kaixu.app.

Processor

Signature
Name & Title
Date

Skyes Over London LC

Controller (Customer)

Signature
Name & Title
Date