Data Processing Addendum
Governs our processing of personal information on your behalf when you act as the controller of client and vendor data.
1. Roles
This Data Processing Addendum (“DPA”) is incorporated into and forms part of the Terms of Service between Kavvim LLC (“Kavvim,” “Service Provider”) and Customer. It governs Kavvim’s processing of personal information that Customer submits to the Service.
Customer is the business, controller, and decision-maker. Customer determines what personal information enters the Service, whose information it is, and for what purpose. This includes information about Customer’s own clients.
Kavvim is the service provider and processor. Kavvim processes personal information only on Customer’s documented instructions, which consist of these Terms, this DPA, and Customer’s use of the Service’s features.
Kavvim will notify Customer if it believes an instruction violates applicable law.
2. Scope of processing
Subject matter: provision of the Service. Duration: the term of the subscription, plus the retention periods in Section 8. Nature and purpose: hosting, storage, transmission, display, backup, and processing of Customer Data to deliver the features Customer uses.
Categories of data subjects: Customer’s personnel and contractors; Customer’s clients and their household members or representatives; contacts at Customer’s vendors and suppliers.
Categories of personal information: identifiers (name, email, phone, postal address); commercial information (projects, invoices, payment records, purchase history); professional information (job title, rates, hours worked); visual information (photographs of persons, properties, and interiors); communications content (messages, comments, notes); internet activity limited to authentication and audit records; and payment card metadata excluding full card numbers.
Sensitive information. The Service is not designed for and should not be used to process government identifiers, financial account numbers, health information, biometric data, precise geolocation, or information revealing race, religion, sexual orientation, or union membership. Free-text fields are not validated; Customer is responsible for not entering such information into them.
3. Kavvim’s obligations
Kavvim will:
- (a) Process personal information only for the purposes of providing the Service and only on Customer’s instructions.
- (b) Not sell or share personal information as those terms are defined under the California Consumer Privacy Act, and not retain, use, or disclose it for any purpose other than performing the Service, including not for its own commercial purposes and not outside the direct business relationship with Customer.
- (c) Not train any artificial intelligence model on Customer Data, and not permit any subprocessor to do so. Kavvim will engage AI providers only where training on submitted content is prohibited by the provider’s commercial terms or disabled by an account-level control that Kavvim enables and maintains, and will record which applies for each provider.
- (d) Not combine Customer’s personal information with information received from another source, except as permitted by applicable law for security and fraud prevention.
- (e) Ensure that personnel with access are bound by confidentiality obligations and receive access only on a need-to-know basis.
- (f) Implement and maintain the technical and organizational measures described in Schedule A.
- (g) Comply with its obligations under applicable US state privacy laws and provide the same level of protection those laws require.
Kavvim certifies that it understands and will comply with these restrictions.
4. Subprocessors
Customer generally authorizes Kavvim to engage subprocessors. The current list is published on our Subprocessors page.
Kavvim will impose on each subprocessor written obligations no less protective than those in this DPA, and remains responsible for their performance.
Change notice. Kavvim will give 30 days’ notice before adding or replacing a subprocessor, by email to the account owner and by updating the published list with an effective date. Customer may object on reasonable data-protection grounds within 15 days. If the parties cannot resolve the objection, Customer may terminate the affected portion of the Service and receive a prorated refund of prepaid fees. Objection does not entitle Customer to veto the change.
Emergency replacement. Where a subprocessor terminates service, suffers a security incident, or becomes unavailable, Kavvim may substitute immediately and will notify Customer promptly afterward.
5. Data subject requests
Kavvim will not respond directly to a request from Customer’s client or personnel, except to direct them to Customer. Kavvim will promptly forward any such request it receives.
Kavvim will provide Customer with the tools and reasonable assistance necessary to respond, including access, correction, export, and deletion capability within the Service. Where the Service does not provide a capability directly, Kavvim will assist on request at no additional charge for reasonable volumes.
6. Security incidents
Kavvim will notify Customer without undue delay and within 72 hours of confirming a security incident affecting Customer’s personal information. The notice will describe the nature of the incident, the categories and approximate volume of information involved, the likely consequences, and the measures taken or proposed.
Kavvim will cooperate reasonably with Customer’s investigation and with any notification Customer must make. Notification is not an admission of fault or liability.
7. Audit and documentation
On written request, no more than once per twelve months, Kavvim will provide documentation reasonably necessary to demonstrate compliance with this DPA, and will complete a standard security questionnaire.
Customer may conduct or commission an audit of Kavvim’s controls where (a) a supervisory authority requires it, or (b) a confirmed security incident has affected Customer’s personal information. Such an audit is at Customer’s expense, on 30 days’ written notice, during business hours, under an appropriate confidentiality agreement, scoped by mutual agreement, and conducted so as not to disrupt Kavvim’s operations or compromise other customers’ confidentiality.
8. Retention and deletion
On termination, Kavvim will retain and delete Customer’s personal information according to the schedules in Terms of Service Section 10. Where Customer requests deletion, a 30-day export window applies, followed by 90 days of retention, with permanent deletion at day 120. Where the subscription simply ends without a deletion request, a 365-day export window applies, with permanent deletion at day 365.
A written deletion instruction from Customer always triggers the shorter timeline, whatever the billing state of the account. Customer may issue that instruction at any time, and Kavvim will confirm in writing when deletion is complete.
Kavvim may retain personal information where required by law, and will continue to protect it under this DPA for as long as it is retained.
9. International transfers
Kavvim processes personal information exclusively in the United States. This DPA does not currently address transfers subject to the GDPR or UK GDPR. If Customer requires such terms, contact legal@kavvim.com.
10. General
This DPA is subject to the limitation of liability in the Terms of Service. Where this DPA conflicts with the Terms of Service on the subject of personal information, this DPA controls. This DPA terminates when the Terms of Service terminate and all Customer personal information has been deleted or returned.
Schedule A - Technical and organizational measures
Access control. Role-based permissions across a fixed privilege catalog; row-level tenant isolation on every scoped table with server-side enforcement; uniform 404 responses preventing cross-tenant resource enumeration; least-privilege service principals; internal service tokens that fail closed.
Authentication. BCrypt password hashing at strength 10 with a server-enforced complexity policy; RSA-signed JWT access tokens with a 15-minute lifetime verified against a JWKS endpoint; opaque refresh tokens stored only as SHA-256 hashes, rotating on use, with a 30-day lifetime; optional TOTP and email multi-factor authentication with hashed single-use backup codes; rate limiting of 5 failed attempts per 5 minutes on authentication endpoints.
Encryption in transit. TLS 1.2 or better on all external connections, with HTTP redirected to HTTPS and a strict-transport-security header. Session cookies are marked Secure and SameSite=Strict, with one deliberate exception: the short-lived cookie that carries an in-flight single sign-on request is SameSite=None; Secure, because the identity provider’s callback is a cross-site navigation. It carries no session.
Encryption at rest. AES-256-GCM application-level encryption of payment card metadata, multi-factor authentication secrets, and third-party integration tokens, with master keys wrapped by AWS Key Management Service envelope encryption. Server-side encryption applied as a default rule on object storage.
Zero-knowledge credential vault. Vendor portal credentials are encrypted in the browser using RSA-OAEP 2048 key exchange and AES-GCM 256 content encryption, with keys derived by PBKDF2-HMAC-SHA256 at 600,000 iterations. Kavvim stores only ciphertext and cannot decrypt it.
Payment data. Full card numbers and security codes never reach Kavvim systems; card entry is handled by the payment processor’s hosted elements in the browser.
Network and application security. Redis-backed rate limiting at the gateway; narrow CORS policy; HMAC signature verification on payment webhooks and constant-time shared-secret verification on tracking webhooks; signed, time-limited URLs for private file access; validation of customer-supplied URLs against private, loopback, and link-local address ranges before fetching them; secrets held in environment configuration, never in source control.
Logging and monitoring. Audit logging of all mutations with actor attribution, partitioned monthly and retained 18 months live plus 7 years archived; explicit attribution of any administrative impersonation.
Development practices. Static analysis in the build pipeline: format enforcement, style checking, copy-paste detection, and coverage measurement.
Personnel. Access to production data limited to named platform administrators. Administrative access to customer accounts is recorded in the audit log with the operator identified.
Business continuity. Automated database backups with point-in-time recovery, taken on a schedule and additionally before every deploy. Backups are stored encrypted in the United States, and a restore has been tested end to end rather than only taken.
Kavvim does not currently hold a SOC 2 or ISO 27001 certification. This schedule describes measures actually implemented; it does not reference any third-party attestation.