Data Processing Agreement
Version 2.0 · Effective August 28, 2026
Data Processing Agreement
KAV Labs LLC
838 Walker Road, Suite 21-2
Dover, DE 19904
2.0
KAV Labs Leadership Team
August 28, 2026
August 28, 2026
This Data Processing Agreement ("DPA") forms part of the agreement between KAV Labs LLC ("KAV Labs," "Processor") and the customer entity using the KAV Labs services ("Customer," "Controller"). It governs the processing of Personal Data that Customer transmits through the KAV Labs integration services (the "Services").
1. Roles of the Parties
Customer is the Controller of Personal Data processed through the Services. KAV Labs acts as Processor and processes Personal Data only on Customer's documented instructions, which include the configuration Customer selects when enabling an integration.
Where Customer is itself a processor for a third party, KAV Labs acts as a subprocessor and the same obligations apply.
2. Scope & Nature of Processing
- Subject matter: provision of prebuilt integrations that transfer records between Customer's source systems and Customer's Klaviyo account.
- Duration: the term of the agreement, plus the deletion period described in Section 9.
- Nature and purpose: retrieval, transformation, transmission, and storage of records solely to operate the Services.
- Categories of data subjects: Customer's end customers, contacts, guests, and patients as applicable to the integration.
- Categories of Personal Data: identifiers such as name, email address, phone number, postal address; transaction, booking, and event records; marketing consent status; and integration identifiers.
- Special categories: KAV Labs does not require special categories of Personal Data. Customer must not configure the Services to transmit them unless expressly agreed in writing.
3. Customer Data Ownership
- Customer retains all right, title, and interest in and to Customer Data. KAV Labs acquires no ownership rights in it.
- KAV Labs processes Customer Data solely to provide, secure, and support the Services.
- KAV Labs does not sell, rent, license, or otherwise disclose Customer Data for its own commercial purposes.
- KAV Labs does not use Customer Data to train, fine-tune, or evaluate artificial intelligence or machine learning models.
- KAV Labs does not combine Customer Data with data from other customers to create derived products or benchmarks.
- Aggregated, fully anonymized operational metrics (for example, volume of API calls processed) that cannot identify Customer or any data subject may be used to monitor and improve the Services.
4. Processor Obligations
- Process Personal Data only on documented instructions from Customer.
- Ensure personnel authorized to process Personal Data are bound by confidentiality obligations.
- Implement the technical and organizational measures described in Section 5.
- Assist Customer, taking into account the nature of processing, in responding to data subject requests and in meeting its obligations regarding security, breach notification, and data protection impact assessments.
- Notify Customer without undue delay if, in KAV Labs' opinion, an instruction infringes applicable data protection law.
5. Security Measures
KAV Labs implements and maintains appropriate technical and organizational measures, including:
- Encryption of data in transit using TLS 1.2 or higher.
- Encryption of data at rest using AES-256.
- Encrypted storage of third-party API credentials and access tokens, which are never written to application logs.
- Role-based, least-privilege access control with multi-factor authentication required for all personnel accounts, and periodic access reviews.
- Separation of production and non-production environments.
- Logging and monitoring of access to production systems.
- Regular patching and severity-based vulnerability remediation.
- Encrypted backups with periodic restoration testing.
- Confidentiality obligations and security expectations applied to personnel and vendors.
Full detail is published in the KAV Labs Information Security Policy, which is incorporated into this DPA by reference and may be updated from time to time provided the protections are not materially reduced.
6. Data Retention
KAV Labs retains Personal Data only for as long as needed to provide the Services:
| Data category | Retention period |
|---|---|
| Raw inbound webhook payloads | 7 days from receipt, then automatically purged |
| Application and diagnostic logs | 30 days from creation, then automatically purged |
| Integration configuration and stored credentials | Duration of the agreement; deleted within 30 days of termination |
| Sync state and identifier mappings (e.g. external record ID mapped to Klaviyo profile ID) | Retained for the duration of the agreement so that records are updated rather than duplicated; deleted within 30 days of termination |
| Encrypted backups | Rolling backup window, then automatically overwritten |
| Billing and account records | As required by law; contains Customer billing contacts only, no end-customer Personal Data |
7. Subprocessors
Customer provides general authorization for KAV Labs to engage subprocessors. Each subprocessor is bound by written terms offering protections no less protective than this DPA, and KAV Labs remains fully liable for their performance.
Subprocessors that process end-customer Personal Data
| Subprocessor | Purpose | Data accessed | Location |
|---|---|---|---|
| Google Cloud Platform | Application hosting, database, storage | Customer Data processed through the Services | United States |
Subprocessors that handle KAV Labs business records only
These providers do not receive or process end-customer Personal Data transmitted through the Services.
| Subprocessor | Purpose | Data accessed | Location |
|---|---|---|---|
| Stripe | Payment processing | Customer billing contacts only — no end-customer data | United States |
| Google Workspace | Business email, file storage, support correspondence | Support correspondence only | United States |
| Google Analytics | kavlabs.co website analytics | Website visitors only — no Customer Data | United States |
KAV Labs will give Customer at least thirty (30) days' notice before engaging a new subprocessor that will process Personal Data, during which Customer may object on reasonable data protection grounds. The current list is maintained at kavlabs.co/subprocessors.
8. Personal Data Breach Notification
KAV Labs will notify Customer without undue delay and in any event within seventy-two (72) hours of confirming a Personal Data Breach affecting Customer Data. Notification will be sent to the account and security contacts Customer has provided.
Notification will include:
- The nature of the breach and, where known, the categories and approximate volume of records and data subjects affected.
- The likely consequences of the breach.
- The measures taken or proposed to address it and mitigate adverse effects.
- A contact point for further information.
Where full detail is not available within 72 hours, KAV Labs will provide information in phases as it becomes available, and will reasonably cooperate with Customer in any regulatory or data subject notifications Customer must make.
9. Return & Deletion of Data
- On termination or expiry of the agreement, KAV Labs will delete Customer Data from active production systems within thirty (30) days.
- Copies held in encrypted backups are purged within the rolling backup window and remain protected by this DPA until purged.
- Customer may request an export of its configuration and sync state before deletion, provided the request is made before the deletion period ends.
- KAV Labs will provide written certification of deletion on Customer's request.
- KAV Labs may retain data where required by law, in which case it remains subject to the confidentiality and security obligations of this DPA.
Deleting data from KAV Labs does not delete data already delivered into Customer's Klaviyo account, which Customer controls directly.
10. California Consumer Privacy Act (Service Provider)
To the extent the California Consumer Privacy Act, as amended by the CPRA, applies to Personal Information processed under this DPA, KAV Labs acts as a Service Provider and certifies that it will:
- Not sell or share Personal Information as those terms are defined by the CCPA/CPRA.
- Not retain, use, or disclose Personal Information for any purpose other than performing the Services specified in the agreement, or as otherwise permitted by the CCPA.
- Not retain, use, or disclose Personal Information outside the direct business relationship between KAV Labs and Customer.
- Not combine Personal Information received from Customer with Personal Information received from other sources, except as permitted by the CCPA.
- Comply with applicable CCPA obligations and provide the same level of privacy protection required of a business.
- Notify Customer if it determines it can no longer meet these obligations, and cooperate with reasonable steps to stop and remediate unauthorized use.
- Assist Customer in responding to verifiable consumer requests to know, delete, correct, or opt out.
11. International Data Transfers
KAV Labs processes and stores Personal Data in the United States. Where Personal Data is transferred from the European Economic Area, the United Kingdom, or Switzerland to a country without an adequacy decision, the following mechanisms apply and are incorporated into this DPA by reference:
- EEA transfers: the Standard Contractual Clauses approved by European Commission Implementing Decision (EU) 2021/914, Module Two (Controller to Processor). Clause 7 (docking) is incorporated; for Clause 9, Option 2 (general written authorization) applies with a thirty (30) day notice period; for Clause 11, the optional independent dispute resolution body is not selected; for Clause 17, the clauses are governed by the law of Ireland; and for Clause 18(b), disputes are resolved in the courts of Ireland.
- UK transfers: the UK International Data Transfer Addendum to the EU SCCs (Version B1.0) issued by the Information Commissioner, with the Addendum's Tables completed by reference to this DPA and Section 2 above.
- Swiss transfers: the EU SCCs, with references to the GDPR interpreted as references to the Swiss FADP and the Swiss Federal Data Protection and Information Commissioner as the supervisory authority.
The details required by the Annexes to the SCCs are set out in Section 2 (description of processing), Section 5 (technical and organizational measures), and Section 7 (subprocessors) of this DPA.
12. Audits & Information Rights
KAV Labs will make available to Customer the information reasonably necessary to demonstrate compliance with this DPA and will respond to reasonable security questionnaires. Customer may request an audit no more than once per twelve (12) month period, on at least thirty (30) days' written notice, during business hours, subject to confidentiality and without unreasonably disrupting KAV Labs' operations. Additional audits may be conducted following a confirmed Personal Data Breach affecting Customer Data or where required by a supervisory authority.
13. Liability
Each party's liability under this DPA is subject to the limitations and exclusions of liability set out in the agreement between the parties, except where applicable data protection law does not permit such limitation.
14. Execution
This DPA is incorporated into and forms part of the agreement between KAV Labs and Customer. By accepting that agreement or using the Services, Customer accepts this DPA on behalf of the entity it represents, and no separate signature is required for it to take effect.
We will provide notice of material changes to this document via email to account contacts and by posting an updated version here.