1. Introduction
This Data Processing Addendum (“DPA”) forms part of the Terms of Service between Sizmic Limited (“Sizmic”, “we”, “us”) and the customer (“Customer”, “you”) (together, the “Agreement”). It applies to the extent Sizmic processes Customer Personal Data on the Customer’s behalf in providing Kirak Studio (the “Service”).
For the Customer Personal Data covered by this DPA, the Customer is the controller (or a processor acting on behalf of a third-party controller) and Sizmic is the processor. This DPA does not apply to personal data for which Sizmic is a controller — for example, the Customer’s account and billing data — which is covered by the Privacy Policy.
A countersigned version of this DPA is available on request at legal@kirak.io. Whether or not it is signed, it is binding as part of the Agreement.
2. Definitions
Words defined in the Terms of Service have the same meaning here. In addition:
- “Data Protection Laws” — the UK GDPR, the Data Protection Act 2018, the Privacy and Electronic Communications Regulations 2003, and any other data protection or privacy law applicable to Sizmic’s processing under this DPA.
- “Customer Personal Data” — personal data that Sizmic processes on the Customer’s behalf in providing the Service, as described in Annex 1.
- “Controller”, “processor”, “data subject”, “personal data”, “processing”, “personal data breach”, and “supervisory authority” have the meanings in the UK GDPR.
- “Sub-processor” — any third party engaged by Sizmic to process Customer Personal Data.
- “UK Transfer Mechanism” — the UK International Data Transfer Agreement (IDTA), or the EU Standard Contractual Clauses (Module 2 or 3, as applicable) together with the UK Addendum, or another lawful transfer safeguard.
- “Restricted Transfer” — a transfer of Customer Personal Data to a country not covered by UK adequacy regulations.
3. Roles and scope of processing
3.1 Sizmic will process Customer Personal Data only as a processor, on the Customer’s behalf, and only for the purposes set out in Annex 1 and the Agreement.
3.2 Annex 1 sets out the subject matter, duration, nature and purpose of the processing, the types of personal data, and the categories of data subjects. The Customer is responsible for the accuracy and completeness of Annex 1 as it relates to the Customer’s configuration and use of the Service.
3.3 The Customer confirms that it has a lawful basis for the processing and that its instructions to Sizmic comply with Data Protection Laws.
4. Instructions
4.1 Sizmic will process Customer Personal Data only on the Customer’s documented instructions, which are: this DPA, the Agreement, the Customer’s configuration and use of the Service (including the region the Customer selects for its Instances and the modules it enables), and any further written instructions the Customer gives that the parties agree to.
4.2 Sizmic will inform the Customer if, in its opinion, an instruction infringes Data Protection Laws. Sizmic is not obliged to act on an instruction it reasonably believes is unlawful.
4.3 If Sizmic is required by law to process Customer Personal Data other than on the Customer’s instructions, it will inform the Customer of that legal requirement before processing, unless the law prohibits it.
5. Confidentiality
Sizmic will ensure that personnel authorised to process Customer Personal Data are bound by an appropriate obligation of confidentiality and receive appropriate data protection training.
6. Security
Taking into account the state of the art, the costs of implementation, and the nature, scope, context and purposes of processing, as well as the risk to data subjects, Sizmic will implement appropriate technical and organisational measures to protect Customer Personal Data, including the measures described in Annex 3. Sizmic may update these measures provided the level of protection is not reduced.
7. Sub-processing
7.1 The Customer gives Sizmic general authorisation to engage the Sub-processors listed at kirak.io/legal/subprocessors as at the effective date of this DPA.
7.2 Sizmic will give the Customer at least 30 days’ notice before adding or replacing a Sub-processor, by updating that page and notifying subscribers to its change-notification list. The Customer should subscribe to receive these notices.
7.3 The Customer may object to a new Sub-processor within the notice period on reasonable grounds relating to data protection. The parties will work in good faith to resolve the objection. If they cannot, the Customer may terminate the part of the Service that requires the objected-to Sub-processor, on written notice, and receive a pro-rata refund of prepaid, unused fees for that part.
7.4 Sizmic will impose data protection obligations on each Sub-processor by written contract that are no less protective than those in this DPA, and remains fully liable to the Customer for each Sub-processor’s performance.
8. Data subject rights
8.1 Taking into account the nature of the processing, Sizmic will assist the Customer, by appropriate technical and organisational measures and insofar as possible, to respond to requests from data subjects to exercise their rights under Data Protection Laws.
8.2 If Sizmic receives a request from a data subject relating to Customer Personal Data, it will not respond to that request except on the Customer’s instruction or as required by law, and will forward the request to the Customer without undue delay.
9. Assistance
Taking into account the nature of processing and the information available to Sizmic, Sizmic will provide reasonable assistance to the Customer with: data protection impact assessments; prior consultation with a supervisory authority; and the Customer’s obligations in relation to the security of processing and personal data breaches.
10. Personal data breach
10.1 Sizmic will notify the Customer without undue delay, and in any event within 72 hours of becoming aware of a personal data breach affecting Customer Personal Data.
10.2 The notification will include, to the extent known: the nature of the breach, the categories and approximate number of data subjects and records concerned, the likely consequences, and the measures taken or proposed. Sizmic will provide further information as it becomes available.
10.3 Sizmic will not notify supervisory authorities or data subjects of a breach on the Customer’s behalf unless the Customer instructs it to, or Sizmic is required to do so by law.
11. Return and deletion
11.1 On termination of the Agreement, or earlier on the Customer’s written request, Sizmic will, at the Customer’s choice, delete or return Customer Personal Data, and delete existing copies, except to the extent Sizmic is required by law to retain it.
11.2 In practice, and consistent with the Terms of Service: Customer Personal Data is deleted from Sizmic’s active systems when the Customer deletes the relevant project or after the 30-day post-termination export window; residual copies in encrypted backups are purged within a further 30 days.
11.3 On request, Sizmic will certify in writing that it has complied with this Section.
12. Audits
12.1 Sizmic will make available to the Customer the information reasonably necessary to demonstrate compliance with this DPA, including its security documentation and any third-party audit reports or completed security questionnaires it maintains.
12.2 Where that information is not sufficient, the Customer (or an independent auditor it appoints, who is not a competitor of Sizmic and is bound by confidentiality) may audit Sizmic’s processing, on at least 30 days’ written notice, no more than once in any 12-month period (unless required by a supervisory authority or following a personal data breach), during business hours, in a way that does not disrupt Sizmic’s operations or give access to any other customer’s data, and at the Customer’s cost.
13. International transfers
13.1 Sizmic’s own processing. Sizmic stores the data it holds as processor primarily in the UK and/or EEA. Where the Customer selects a non-UK/EEA region for its Instances, that is the Customer’s documented instruction, and the Customer is responsible, as controller, for ensuring it has a lawful basis and (where needed) a transfer mechanism for personal data processed in that region.
13.2 Onward transfers to Sub-processors. Where providing the Service involves a Restricted Transfer of Customer Personal Data to a Sub-processor (including AI model providers and infrastructure providers located in the United States), Sizmic will ensure the transfer is subject to a UK Transfer Mechanism and any additional safeguards required, or takes place to a country covered by UK adequacy regulations. The relevant clauses are incorporated into the Sub-processor agreements, with Sizmic acting as data exporter and the Sub-processor as data importer.
13.3 On request, Sizmic will provide a summary of the transfer mechanisms it relies on.
14. Liability
Each party’s liability arising out of or related to this DPA, whether in contract, tort, or under any other theory of liability, is subject to the exclusions and limitations of liability set out in the Terms of Service. Nothing in this DPA limits either party’s liability to a data subject or to a supervisory authority.
15. Term and conflict
15.1 This DPA takes effect when the Agreement does and continues for as long as Sizmic processes Customer Personal Data.
15.2 If there is a conflict between this DPA and the rest of the Agreement on a data protection matter, this DPA prevails. If there is a conflict between this DPA and a UK Transfer Mechanism, the UK Transfer Mechanism prevails as to the transfer it governs.
16. Governing law
This DPA is governed by the law of England and Wales, and the courts of England and Wales have exclusive jurisdiction, except as any UK Transfer Mechanism provides otherwise.
Annex 1 — Details of processing
| Subject matter | Sizmic’s provision of the Kirak Studio hosted service to the Customer. |
| Duration | The term of the Agreement, plus the deletion periods in Section 11. |
| Nature and purpose | Hosting, storing, transmitting, and otherwise processing data as directed by the Customer’s application configuration and use of the Service, including operating the runtime modules the Customer enables (such as authentication, payments, storage, notifications, scheduling, caching, and AI features), and providing the operating console, logs, traces, and backups. |
| Types of personal data | As determined and controlled by the Customer. May include: identifiers and account credentials; names and contact details; profile information; authentication and session data; payment and transaction metadata (card data is handled by the payment processor); files and content submitted by the Customer’s users; communications and notification data; and usage, device, and log data. The Customer must not store special category data unless it has configured the Service appropriately and has a lawful basis. |
| Categories of data subjects | As determined and controlled by the Customer. May include: the Customer’s registered users, end customers, employees, contractors, and contacts. |
| Frequency of processing | Continuous, for the duration of the Agreement. |
Annex 2 — Sub-processors
The current list of Sub-processors is maintained at kirak.io/legal/subprocessors. It covers, by category: cloud infrastructure and Instance hosting; payment processing; transactional and marketing email; AI model providers (Google, OpenAI, Anthropic); error and performance monitoring; and support tooling.
Annex 3 — Technical and organisational measures
- Encryption — TLS for data in transit; encryption at rest for databases, object storage, and backups.
- Access control — role-based, least-privilege access to production systems; multi-factor authentication for administrative access; access reviews; prompt revocation on role change or departure.
- Isolation — each Customer’s backend runs on a dedicated Instance, isolated at the network and compute level from other customers.
- Secrets — customer secrets held in an encrypted store, sealed per environment, not written to source control.
- Logging and monitoring — security and access logging; alerting on anomalous activity; retention as described in the Privacy Policy.
- Secure development — code review; dependency and vulnerability scanning; a documented vulnerability disclosure process (kirak.io/security).
- Resilience — regular encrypted backups; documented restore procedures.
- Incident response — a documented process for detecting, assessing, and notifying personal data breaches within the timelines in Section 10.
- Personnel — confidentiality obligations and data protection training for staff with access to Customer Personal Data.
- Sub-processor management — due diligence and written data protection terms with each Sub-processor.