Kestrant

Data Processing Agreement

Last updated: August 2026

Draft — not yet reviewed by counsel. This document describes how Kestrant actually works today and is structured for a lawyer to review and finalize. It is not legal advice and should not be published as final terms before that review.

This agreement applies where Kestrant processes personal data on behalf of a customer. The customer is the controller; Kestrant is the processor.

Subject matter and duration

Kestrant processes personal data only to provide the service, for as long as the subscription is active, plus the 30-day export window described in the privacy policy.

Nature of the data

Categories of data subject: the customer's employees and authorized users. Categories of personal data: name, work email, role, and activity records (who did what and when). Financial figures about the business are commercial data, not personal data, but are treated with the same confidentiality.

No special categories of data are required by the service, and none should be uploaded.

Our obligations

We process personal data only on documented instructions from the controller; keep personnel with access bound by confidentiality; apply the technical and organizational measures described on the security page; assist the controller with data subject requests and with breach notification; and delete or return the data at the end of the engagement.

Sub-processors

The controller authorizes the sub-processors listed in the privacy policy (Supabase, Vercel, Resend, Stripe). We will give notice before adding a new sub-processor, giving the controller a reasonable opportunity to object. Each sub-processor is bound by obligations no less protective than these.

Security incidents

We notify the controller without undue delay, and in any case within 72 hours of becoming aware of a personal data breach affecting their data, with the information available at the time and updates as the picture becomes clearer.

International transfers

Where personal data is transferred outside its country of origin, the transfer relies on the applicable safeguards (Standard Contractual Clauses or an adequacy decision), to be confirmed by counsel on finalization.

Audit

On reasonable notice and no more than once a year (or after a breach), the controller may request the information necessary to demonstrate our compliance with this agreement.

Deletion and return

At the end of the engagement we delete the personal data within the period described in the privacy policy, except where retention is required by law. Audit records are retained as described there; they identify actions, not the content of financial statements.

Requests for a countersigned copy: legal@kestrant.com.