Data Processing Agreement (DPA)
between the Creator (hereinafter “Controller”) and Kullisa Labs, Alexander Leypold, Schmittstrasse 15/10, 8720 Knittelfeld, Austria (hereinafter “Processor”) the following Data Processing Agreement is concluded:
1. Subject Matter and Duration
- The Processor processes personal data of end customers on behalf of the Controller in dedicated end customer databases.
- The term of this DPA corresponds to the term of the Creator TOS. Upon termination of the Creator TOS, this DPA also ends automatically.
2. Nature, Purpose, and Scope of Processing
| Activity | Purpose | Data Categories | Data Subjects |
|---|---|---|---|
| End customer registration (Google OAuth) | Account creation | Email, name, profile picture URL | Controller’s end customers |
| Subscription management | Plan management, access control | Subscription plan, status, Stripe customer ID | Subscription end customers |
| Credit management | Wallet, metering, ledger | Balance (USD), transaction history | Credit end customers |
| Stripe webhook processing | Payment processing, sync | Payment status, subscription events | Controller’s end customers |
| Gateway authorisation | Access control for extensions | JWT with plan level | Controller’s end customers |
3. Binding Instructions
- The Processor processes personal data exclusively on the documented instructions of the Controller (Art. 28(3)(a) GDPR).
- Documented instructions arise from this DPA, the Creator TOS, and the platform architecture.
- The Processor shall inform the Controller without delay if an instruction violates the GDPR (Art. 28(3)(h) GDPR).
4. Technical and Organisational Measures (TOMs)
The Processor implements the following TOMs pursuant to Art. 32 GDPR:
| Measure | Category | Description |
|---|---|---|
| AES-256 encryption | Art. 32(1)(a) | Creator API keys for AI providers encrypted in database |
| Database isolation | Art. 32(1)(b) | Strict database separation with access controls limiting write operations |
| HTTPS/TLS | Art. 32(1)(b) | All data transmission encrypted |
| JWT signatures | Art. 32(1)(b) | Cryptographic authentication for gateways |
| Access control | Art. 32(1)(b) | Restricted administrative access |
| Automated testing | Art. 32(1)(c) | Test suite including security tests |
| Database backups | Art. 32(1)(c) | Regular database backups |
| Least privilege | Art. 32(1)(b) | Access controls enforce the principle of least privilege |
5. Sub-Processors
- The Processor engages the following sub-processors:
Sub-Processor Service Data Processed Safeguard Stripe Inc. Payment processing Email, name, amounts DPF-certified Microsoft Azure Hosting Anonymised IP EU data centres Google Ireland Ltd. OAuth Email address EU-based - The Processor undertakes to notify the Controller in advance of any intended engagement of further sub-processors. The Controller has a right to object.
- Sub-processors are contractually bound to the same data protection standards.
6. Assistance to the Controller
- The Processor supports the Controller in fulfilling data subject rights (Arts. 15–21 GDPR) through account deletion endpoints and data export APIs.
- The Processor supports the Controller in complying with notification obligations under Arts. 33 and 34 GDPR.
7. Deletion and Return
- Upon termination of the contract, the Processor shall delete all personal data of end customers within 30 days.
- Exception: Transaction data retained in anonymised form for 7 years (§132 BAO / §212 UGB).
8. Audit Rights
The Controller has the right to have an independent, confidentiality-bound auditor verify compliance. The audit must be announced at least four weeks in advance and may be conducted during business hours without disrupting operations.
9. Severability
Should individual provisions of this DPA be or become invalid, this shall not affect the validity of the remaining provisions.