Data Processing Addendum

Last updated 26 August 2026
Last reviewed: 26 August 2026
How this works

The text of this page constitutes the data processing terms Klair Technology Solutions Private Limited (Klair Labs) offers to every DSAR Desk customer. It supplements our Terms of Service and applies whenever we process personal data on your behalf. If your organisation needs a countersigned copy for its records, email hello@klairtech.com with the subject line "DPA — <your workspace email>" and you'll receive a countersigned PDF copy of these terms.

1. Parties and roles

You (the business operating a DSAR Desk workspace) are the controller of the personal data your requesters submit through your intake link. Klair Labs is the processor, handling that data only to provide the service, on your instructions. This division is also explained in plainer language in section 2 of our Privacy Policy.

2. Subject matter and duration

The subject matter is the personal data processed in your DSAR Desk workspace. Processing lasts as long as your account exists, plus any retention window you have configured — and ends when you delete your workspace, which you can do yourself at any time from Settings.

3. Nature and purpose of processing

Storing, organising, and displaying data-subject requests; calculating response deadlines; sending the transactional emails the product describes (sign-in links, requester acknowledgements, deadline reminders); delivering webhook events to endpoints you configure; and producing exports you request. Nothing else — we do not use this data for our own purposes, analytics on its content, marketing, or training anything.

4. Categories of data subjects and personal data

You control what your intake form asks for. Don't use custom fields to collect data the product doesn't need — we store what your form submits.

5. Our obligations as processor

6. Sub-processors

You give general authorisation for the sub-processors listed at dsar.klairlabs.com/subprocessors.html, which names each one, what it does, and where it runs. We update that page at least 14 days before adding a new sub-processor, and you can ask to be notified by email — the page explains how. If you object to an addition, your remedy is to export your data and delete your workspace before the change takes effect; we don't pretend a solo product can run a per-customer opt-out of its own infrastructure.

7. International transfers

Personal data is stored in AWS's Asia Pacific (Mumbai) region, ap-south-1, and we do not move it between regions. Amazon CloudFront's edge network caches and serves the site's pages near the visitor; it does not store the personal data described in section 4. If your own legal analysis requires a specific transfer mechanism for data moving from your jurisdiction to India — for example, EU standard contractual clauses — note that this addendum does not yet incorporate them; email hello@klairtech.com and we will address it with you directly rather than claim coverage this page doesn't provide.

8. Audit rights

You may ask us to demonstrate compliance with this addendum. We'll answer reasonable written questions and share relevant documentation first; where that genuinely isn't enough, you may conduct or commission an audit at your own cost, at most once per year, on reasonable notice and without access to other customers' data.

9. Deletion and return on termination

Workspace deletion is self-serve: Settings → delete workspace removes your account, every request record, and any branding, immediately. Export your request data (CSV, available on all plans) before deleting — deletion is not reversible from the product. We retain only what payment and tax law requires us to keep about the commercial relationship, as described in the Privacy Policy.

10. Liability and precedence

Liability under this addendum is governed by the limitation in section 8 of the Terms of Service. For data-protection matters, if this addendum and the Terms conflict, this addendum prevails.

11. Getting a signed copy

Email hello@klairtech.com, subject "DPA — <your workspace email>". You'll receive a countersigned PDF of this addendum for your compliance records. Changes to this addendum are recorded in the legal changelog.