Data Processing Agreement

Version 2.0 · Effective August 28, 2026

Data Processing Agreement

KAV Labs LLC

838 Walker Road, Suite 21-2

Dover, DE 19904

Version:

2.0

Owner:

KAV Labs Leadership Team

Effective Date:

August 28, 2026

Last Reviewed:

August 28, 2026

This Data Processing Agreement ("DPA") forms part of the agreement between KAV Labs LLC ("KAV Labs," "Processor") and the customer entity using the KAV Labs services ("Customer," "Controller"). It governs the processing of Personal Data that Customer transmits through the KAV Labs integration services (the "Services").

1. Roles of the Parties

Customer is the Controller of Personal Data processed through the Services. KAV Labs acts as Processor and processes Personal Data only on Customer's documented instructions, which include the configuration Customer selects when enabling an integration.

Where Customer is itself a processor for a third party, KAV Labs acts as a subprocessor and the same obligations apply.

2. Scope & Nature of Processing

  • Subject matter: provision of prebuilt integrations that transfer records between Customer's source systems and Customer's Klaviyo account.
  • Duration: the term of the agreement, plus the deletion period described in Section 9.
  • Nature and purpose: retrieval, transformation, transmission, and storage of records solely to operate the Services.
  • Categories of data subjects: Customer's end customers, contacts, guests, and patients as applicable to the integration.
  • Categories of Personal Data: identifiers such as name, email address, phone number, postal address; transaction, booking, and event records; marketing consent status; and integration identifiers.
  • Special categories: KAV Labs does not require special categories of Personal Data. Customer must not configure the Services to transmit them unless expressly agreed in writing.

3. Customer Data Ownership

  • Customer retains all right, title, and interest in and to Customer Data. KAV Labs acquires no ownership rights in it.
  • KAV Labs processes Customer Data solely to provide, secure, and support the Services.
  • KAV Labs does not sell, rent, license, or otherwise disclose Customer Data for its own commercial purposes.
  • KAV Labs does not use Customer Data to train, fine-tune, or evaluate artificial intelligence or machine learning models.
  • KAV Labs does not combine Customer Data with data from other customers to create derived products or benchmarks.
  • Aggregated, fully anonymized operational metrics (for example, volume of API calls processed) that cannot identify Customer or any data subject may be used to monitor and improve the Services.

4. Processor Obligations

  • Process Personal Data only on documented instructions from Customer.
  • Ensure personnel authorized to process Personal Data are bound by confidentiality obligations.
  • Implement the technical and organizational measures described in Section 5.
  • Assist Customer, taking into account the nature of processing, in responding to data subject requests and in meeting its obligations regarding security, breach notification, and data protection impact assessments.
  • Notify Customer without undue delay if, in KAV Labs' opinion, an instruction infringes applicable data protection law.

5. Security Measures

KAV Labs implements and maintains appropriate technical and organizational measures, including:

  • Encryption of data in transit using TLS 1.2 or higher.
  • Encryption of data at rest using AES-256.
  • Encrypted storage of third-party API credentials and access tokens, which are never written to application logs.
  • Role-based, least-privilege access control with multi-factor authentication required for all personnel accounts, and periodic access reviews.
  • Separation of production and non-production environments.
  • Logging and monitoring of access to production systems.
  • Regular patching and severity-based vulnerability remediation.
  • Encrypted backups with periodic restoration testing.
  • Confidentiality obligations and security expectations applied to personnel and vendors.

Full detail is published in the KAV Labs Information Security Policy, which is incorporated into this DPA by reference and may be updated from time to time provided the protections are not materially reduced.

6. Data Retention

KAV Labs retains Personal Data only for as long as needed to provide the Services:

Data categoryRetention period
Raw inbound webhook payloads7 days from receipt, then automatically purged
Application and diagnostic logs30 days from creation, then automatically purged
Integration configuration and stored credentialsDuration of the agreement; deleted within 30 days of termination
Sync state and identifier mappings (e.g. external record ID mapped to Klaviyo profile ID)Retained for the duration of the agreement so that records are updated rather than duplicated; deleted within 30 days of termination
Encrypted backupsRolling backup window, then automatically overwritten
Billing and account recordsAs required by law; contains Customer billing contacts only, no end-customer Personal Data

7. Subprocessors

Customer provides general authorization for KAV Labs to engage subprocessors. Each subprocessor is bound by written terms offering protections no less protective than this DPA, and KAV Labs remains fully liable for their performance.

Subprocessors that process end-customer Personal Data

SubprocessorPurposeData accessedLocation
Google Cloud PlatformApplication hosting, database, storageCustomer Data processed through the ServicesUnited States

Subprocessors that handle KAV Labs business records only

These providers do not receive or process end-customer Personal Data transmitted through the Services.

SubprocessorPurposeData accessedLocation
StripePayment processingCustomer billing contacts only — no end-customer dataUnited States
Google WorkspaceBusiness email, file storage, support correspondenceSupport correspondence onlyUnited States
Google Analyticskavlabs.co website analyticsWebsite visitors only — no Customer DataUnited States

KAV Labs will give Customer at least thirty (30) days' notice before engaging a new subprocessor that will process Personal Data, during which Customer may object on reasonable data protection grounds. The current list is maintained at kavlabs.co/subprocessors.

8. Personal Data Breach Notification

KAV Labs will notify Customer without undue delay and in any event within seventy-two (72) hours of confirming a Personal Data Breach affecting Customer Data. Notification will be sent to the account and security contacts Customer has provided.

Notification will include:

  • The nature of the breach and, where known, the categories and approximate volume of records and data subjects affected.
  • The likely consequences of the breach.
  • The measures taken or proposed to address it and mitigate adverse effects.
  • A contact point for further information.

Where full detail is not available within 72 hours, KAV Labs will provide information in phases as it becomes available, and will reasonably cooperate with Customer in any regulatory or data subject notifications Customer must make.

9. Return & Deletion of Data

  • On termination or expiry of the agreement, KAV Labs will delete Customer Data from active production systems within thirty (30) days.
  • Copies held in encrypted backups are purged within the rolling backup window and remain protected by this DPA until purged.
  • Customer may request an export of its configuration and sync state before deletion, provided the request is made before the deletion period ends.
  • KAV Labs will provide written certification of deletion on Customer's request.
  • KAV Labs may retain data where required by law, in which case it remains subject to the confidentiality and security obligations of this DPA.

Deleting data from KAV Labs does not delete data already delivered into Customer's Klaviyo account, which Customer controls directly.

10. California Consumer Privacy Act (Service Provider)

To the extent the California Consumer Privacy Act, as amended by the CPRA, applies to Personal Information processed under this DPA, KAV Labs acts as a Service Provider and certifies that it will:

  • Not sell or share Personal Information as those terms are defined by the CCPA/CPRA.
  • Not retain, use, or disclose Personal Information for any purpose other than performing the Services specified in the agreement, or as otherwise permitted by the CCPA.
  • Not retain, use, or disclose Personal Information outside the direct business relationship between KAV Labs and Customer.
  • Not combine Personal Information received from Customer with Personal Information received from other sources, except as permitted by the CCPA.
  • Comply with applicable CCPA obligations and provide the same level of privacy protection required of a business.
  • Notify Customer if it determines it can no longer meet these obligations, and cooperate with reasonable steps to stop and remediate unauthorized use.
  • Assist Customer in responding to verifiable consumer requests to know, delete, correct, or opt out.

11. International Data Transfers

KAV Labs processes and stores Personal Data in the United States. Where Personal Data is transferred from the European Economic Area, the United Kingdom, or Switzerland to a country without an adequacy decision, the following mechanisms apply and are incorporated into this DPA by reference:

  • EEA transfers: the Standard Contractual Clauses approved by European Commission Implementing Decision (EU) 2021/914, Module Two (Controller to Processor). Clause 7 (docking) is incorporated; for Clause 9, Option 2 (general written authorization) applies with a thirty (30) day notice period; for Clause 11, the optional independent dispute resolution body is not selected; for Clause 17, the clauses are governed by the law of Ireland; and for Clause 18(b), disputes are resolved in the courts of Ireland.
  • UK transfers: the UK International Data Transfer Addendum to the EU SCCs (Version B1.0) issued by the Information Commissioner, with the Addendum's Tables completed by reference to this DPA and Section 2 above.
  • Swiss transfers: the EU SCCs, with references to the GDPR interpreted as references to the Swiss FADP and the Swiss Federal Data Protection and Information Commissioner as the supervisory authority.

The details required by the Annexes to the SCCs are set out in Section 2 (description of processing), Section 5 (technical and organizational measures), and Section 7 (subprocessors) of this DPA.

12. Audits & Information Rights

KAV Labs will make available to Customer the information reasonably necessary to demonstrate compliance with this DPA and will respond to reasonable security questionnaires. Customer may request an audit no more than once per twelve (12) month period, on at least thirty (30) days' written notice, during business hours, subject to confidentiality and without unreasonably disrupting KAV Labs' operations. Additional audits may be conducted following a confirmed Personal Data Breach affecting Customer Data or where required by a supervisory authority.

13. Liability

Each party's liability under this DPA is subject to the limitations and exclusions of liability set out in the agreement between the parties, except where applicable data protection law does not permit such limitation.

14. Execution

This DPA is incorporated into and forms part of the agreement between KAV Labs and Customer. By accepting that agreement or using the Services, Customer accepts this DPA on behalf of the entity it represents, and no separate signature is required for it to take effect.

KAV Labs LLC

838 Walker Road, Suite 21-2

Dover, DE 19904

Email: teamkav@kavlabs.co

We will provide notice of material changes to this document via email to account contacts and by posting an updated version here.