Data Processing Addendum
For customers subject to GDPR, CCPA, and similar data protection regulations. This DPA supplements the Kayaan customer agreement.
1. Parties and roles
The customer is the data controller. Kayaan, Inc. is the data processor acting on the customer's documented instructions.
2. Scope of processing
Kayaan processes personal data to provide the platform — including load covering, carrier communication, check call automation, tracking, and paperwork — for the duration of the customer agreement.
3. Sub-processors
A current list of Kayaan sub-processors (cloud infrastructure, telephony, email, carrier identity APIs) is available on request. Customers are notified before new sub-processors are added.
4. Security measures
Technical and organizational measures include encryption in transit (TLS 1.2+) and at rest, role-based access control, audit logging, least-privilege engineering access, and regular security review.
5. Data transfers
For transfers outside the EU/UK, Kayaan relies on Standard Contractual Clauses or equivalent transfer mechanisms.
6. Data subject rights
Kayaan assists the customer in responding to data subject access, correction, deletion, and portability requests within legally required timeframes.
7. Breach notification
Kayaan notifies the customer without undue delay upon becoming aware of a personal data breach affecting customer data.
8. Contact
DPA requests or questions: support@kayaan.ai.
