Data Processing Agreement
- Purpose
- Roles
- Instructions
- Confidentiality
- Security
- Subprocessors
- International Transfers
- Data Subject Rights
- Security Incidents
- Audit
- Deletion and Return
- Annex A Processing Details
- Annex B Security Measures
- Annex C Subprocessors
1. Purpose
This Data Processing Agreement (“DPA”) forms part of the agreement between Kraylo Ltd and the Customer and applies where Kraylo processes personal data on behalf of the Customer in connection with the Services.
2. Roles of the Parties
The Customer is the controller of Customer Personal Data. Kraylo is the processor. Each party will comply with applicable data protection laws, including the UK GDPR and Data Protection Act 2018.
3. Processing on Documented Instructions
Kraylo will process Customer Personal Data only on the Customer's documented instructions, including through the Agreement, this DPA, product configuration, user actions and support requests, unless required otherwise by applicable law.
4. Confidentiality
Kraylo will ensure that personnel authorised to process Customer Personal Data are subject to appropriate confidentiality obligations and access Customer Personal Data only where required for authorised purposes.
5. Security Measures
Kraylo will implement appropriate technical and organisational measures designed to protect Customer Personal Data against unauthorised or unlawful processing and accidental loss, destruction or damage. Measures include access controls, encryption in transit, role-based permissions, tenant separation, audit logging, monitoring and secure infrastructure practices.
6. Subprocessors
Customer authorises Kraylo to use subprocessors necessary to provide the Services. Kraylo will impose data protection obligations on subprocessors that are materially equivalent to those in this DPA. Kraylo will maintain a subprocessor list and provide notice of material changes where required.
7. International Transfers
Kraylo will not transfer Customer Personal Data internationally unless appropriate safeguards are in place, such as adequacy regulations, standard contractual clauses, UK international data transfer agreements or other lawful transfer mechanisms.
8. Assistance with Data Subject Rights
Taking into account the nature of processing, Kraylo will provide reasonable assistance to the Customer for responding to data subject rights requests. Where Kraylo receives a request directly relating to Customer Personal Data, Kraylo may refer the requester to the Customer unless legally required to respond.
9. Security Incidents
Kraylo will notify the Customer without undue delay after becoming aware of a personal data breach affecting Customer Personal Data. Notification will include available information reasonably required for the Customer to meet its legal obligations, subject to investigation status and confidentiality considerations.
10. Audit and Information
Kraylo will make available information reasonably necessary to demonstrate compliance with this DPA. Audits must be reasonable, proportionate, subject to confidentiality, and must not compromise the security or confidentiality of other customers or systems.
11. Return or Deletion
At the end of the Services, Kraylo will delete or return Customer Personal Data in accordance with the Agreement, product functionality and legal requirements, unless retention is required by law or necessary for legitimate security, audit or dispute purposes.
12. Annex A — Processing Details
| Subject matter | Provision of Kraylo business management software. |
|---|---|
| Duration | For the term of the Agreement and applicable retention periods. |
| Nature and purpose | Hosting, storage, transmission, retrieval, support, synchronisation, reporting, security and maintenance. |
| Data subjects | Customer users, administrators, managers, drivers, sales staff, customer contacts, delivery recipients and support contacts. |
| Data categories | Account data, customer contact data, order data, inventory records, banking evidence, operational notes, audit logs, images and technical metadata. |
| Special categories | Not intentionally collected or required by Kraylo. |
13. Annex B — Technical and Organisational Measures
- Encrypted connections using HTTPS/TLS.
- Authentication and session controls.
- Role-based access control.
- Company-level tenant data separation.
- Audit logging for significant actions.
- Least-privilege administrative access.
- Secure software development practices.
- Backup and recovery practices where configured.
- Monitoring and incident response procedures.
- Confidentiality obligations for authorised personnel.
14. Annex C — Subprocessors
Kraylo may use cloud hosting, authentication, database, email, support and monitoring providers required to operate the Services. A live subprocessor list should be maintained at /legal/subprocessors before enterprise launch.