Data Processing Agreement (DPA)

between the Creator (hereinafter “Controller”) and Kullisa Labs, Alexander Leypold, Schmittstrasse 15/10, 8720 Knittelfeld, Austria (hereinafter “Processor”) the following Data Processing Agreement is concluded:

1. Subject Matter and Duration

  1. The Processor processes personal data of end customers on behalf of the Controller in dedicated end customer databases.
  2. The term of this DPA corresponds to the term of the Creator TOS. Upon termination of the Creator TOS, this DPA also ends automatically.

2. Nature, Purpose, and Scope of Processing

ActivityPurposeData CategoriesData Subjects
End customer registration (Google OAuth)Account creationEmail, name, profile picture URLController’s end customers
Subscription managementPlan management, access controlSubscription plan, status, Stripe customer IDSubscription end customers
Credit managementWallet, metering, ledgerBalance (USD), transaction historyCredit end customers
Stripe webhook processingPayment processing, syncPayment status, subscription eventsController’s end customers
Gateway authorisationAccess control for extensionsJWT with plan levelController’s end customers

3. Binding Instructions

  1. The Processor processes personal data exclusively on the documented instructions of the Controller (Art. 28(3)(a) GDPR).
  2. Documented instructions arise from this DPA, the Creator TOS, and the platform architecture.
  3. The Processor shall inform the Controller without delay if an instruction violates the GDPR (Art. 28(3)(h) GDPR).

4. Technical and Organisational Measures (TOMs)

The Processor implements the following TOMs pursuant to Art. 32 GDPR:

MeasureCategoryDescription
AES-256 encryptionArt. 32(1)(a)Creator API keys for AI providers encrypted in database
Database isolationArt. 32(1)(b)Strict database separation with access controls limiting write operations
HTTPS/TLSArt. 32(1)(b)All data transmission encrypted
JWT signaturesArt. 32(1)(b)Cryptographic authentication for gateways
Access controlArt. 32(1)(b)Restricted administrative access
Automated testingArt. 32(1)(c)Test suite including security tests
Database backupsArt. 32(1)(c)Regular database backups
Least privilegeArt. 32(1)(b)Access controls enforce the principle of least privilege

5. Sub-Processors

  1. The Processor engages the following sub-processors:
    Sub-ProcessorServiceData ProcessedSafeguard
    Stripe Inc.Payment processingEmail, name, amountsDPF-certified
    Microsoft AzureHostingAnonymised IPEU data centres
    Google Ireland Ltd.OAuthEmail addressEU-based
  2. The Processor undertakes to notify the Controller in advance of any intended engagement of further sub-processors. The Controller has a right to object.
  3. Sub-processors are contractually bound to the same data protection standards.

6. Assistance to the Controller

  1. The Processor supports the Controller in fulfilling data subject rights (Arts. 15–21 GDPR) through account deletion endpoints and data export APIs.
  2. The Processor supports the Controller in complying with notification obligations under Arts. 33 and 34 GDPR.

7. Deletion and Return

  1. Upon termination of the contract, the Processor shall delete all personal data of end customers within 30 days.
  2. Exception: Transaction data retained in anonymised form for 7 years (§132 BAO / §212 UGB).

8. Audit Rights

The Controller has the right to have an independent, confidentiality-bound auditor verify compliance. The audit must be announced at least four weeks in advance and may be conducted during business hours without disrupting operations.

9. Severability

Should individual provisions of this DPA be or become invalid, this shall not affect the validity of the remaining provisions.

Imprint·Privacy·Terms·Report Abuse

© 2026 Kullisa Labs