Data Processing Addendum
The text of this page constitutes the data processing terms Klair Technology Solutions Private Limited (Klair Labs) offers to every DSAR Desk customer. It supplements our Terms of Service and applies whenever we process personal data on your behalf. If your organisation needs a countersigned copy for its records, email hello@klairtech.com with the subject line "DPA — <your workspace email>" and you'll receive a countersigned PDF copy of these terms.
1. Parties and roles
You (the business operating a DSAR Desk workspace) are the controller of the personal data your requesters submit through your intake link. Klair Labs is the processor, handling that data only to provide the service, on your instructions. This division is also explained in plainer language in section 2 of our Privacy Policy.
2. Subject matter and duration
The subject matter is the personal data processed in your DSAR Desk workspace. Processing lasts as long as your account exists, plus any retention window you have configured — and ends when you delete your workspace, which you can do yourself at any time from Settings.
3. Nature and purpose of processing
Storing, organising, and displaying data-subject requests; calculating response deadlines; sending the transactional emails the product describes (sign-in links, requester acknowledgements, deadline reminders); delivering webhook events to endpoints you configure; and producing exports you request. Nothing else — we do not use this data for our own purposes, analytics on its content, marketing, or training anything.
4. Categories of data subjects and personal data
- Data subjects: people who submit requests through your intake link (your customers or users), and the team members you add to your workspace.
- Personal data: requester email addresses; request type and selected law; any free-text details a requester types; values of custom intake fields you define; internal notes your team adds; timestamps and status history; team members' email addresses.
You control what your intake form asks for. Don't use custom fields to collect data the product doesn't need — we store what your form submits.
5. Our obligations as processor
- Process personal data only to provide the service, as configured by you in the product — your use of the product's controls constitutes your documented instructions.
- Keep it confidential. Klair Labs is a one-person company; the one person with access is bound by these terms, and access is described plainly on the security page.
- Apply the security measures described on the security page, which forms part of this addendum: encryption in transit and at rest, isolated per-product infrastructure, an append-only audit trail, and continuous backups.
- Assist you in meeting your own data-subject-rights obligations, to the extent the product's export, correction, and deletion functions allow — and manually by email where they don't.
- Notify you without undue delay after becoming aware of a personal data breach affecting your workspace's data.
- Delete or return personal data at the end of the engagement, per section 9.
6. Sub-processors
You give general authorisation for the sub-processors listed at dsar.klairlabs.com/subprocessors.html, which names each one, what it does, and where it runs. We update that page at least 14 days before adding a new sub-processor, and you can ask to be notified by email — the page explains how. If you object to an addition, your remedy is to export your data and delete your workspace before the change takes effect; we don't pretend a solo product can run a per-customer opt-out of its own infrastructure.
7. International transfers
Personal data is stored in AWS's Asia Pacific (Mumbai) region, ap-south-1, and we do not move it between regions. Amazon CloudFront's edge network caches and serves the site's pages near the visitor; it does not store the personal data described in section 4. If your own legal analysis requires a specific transfer mechanism for data moving from your jurisdiction to India — for example, EU standard contractual clauses — note that this addendum does not yet incorporate them; email hello@klairtech.com and we will address it with you directly rather than claim coverage this page doesn't provide.
8. Audit rights
You may ask us to demonstrate compliance with this addendum. We'll answer reasonable written questions and share relevant documentation first; where that genuinely isn't enough, you may conduct or commission an audit at your own cost, at most once per year, on reasonable notice and without access to other customers' data.
9. Deletion and return on termination
Workspace deletion is self-serve: Settings → delete workspace removes your account, every request record, and any branding, immediately. Export your request data (CSV, available on all plans) before deleting — deletion is not reversible from the product. We retain only what payment and tax law requires us to keep about the commercial relationship, as described in the Privacy Policy.
10. Liability and precedence
Liability under this addendum is governed by the limitation in section 8 of the Terms of Service. For data-protection matters, if this addendum and the Terms conflict, this addendum prevails.
11. Getting a signed copy
Email hello@klairtech.com, subject "DPA — <your workspace email>". You'll receive a countersigned PDF of this addendum for your compliance records. Changes to this addendum are recorded in the legal changelog.