Data processing terms
Written in plain English. Company details in square brackets are still being completed. These data processing terms cover the personal data we handle for your organisation in its Klusko workspace.
These data processing terms (“DPA”) are between [Company name] Ltd, registered in England and Wales, company number [number], registered office [address] (“Klusko”, “we”, “us”), and the organisation that holds a Klusko account (“you”, “the customer”).
They form part of our terms of service and apply automatically when you use Klusko. You don’t need to sign anything. Words such as “controller”, “processor”, “personal data”, “personal data breach” and “data subject” have the meanings given in the UK GDPR.
1. Roles
For the personal data in your workspace, you are the controller and we are your processor. We only process it to provide Klusko to you.
We are a separate controller for account, billing and contact data, website visitor data and support messages. Our privacy policy covers that data, and this DPA doesn’t.
2. Details of the processing
- Subject matter: providing the Klusko service (tasks, projects and team chat).
- Duration: for as long as your account is open, and until deletion under section 11.
- Nature of processing: storing, organising, displaying, transmitting, backing up and deleting data, as the service requires.
- Purpose: running Klusko for you under the terms of service.
- Types of personal data: names and email addresses of the people you invite, and any personal data in tasks, comments, chat messages, files and custom fields that your people add. You decide what goes in.
- Data subjects: your Admins, Members and Guests, and any other people mentioned in your content (for example your customers or suppliers).
- Special category data: Klusko isn’t designed for special category or criminal offence data. If you choose to put it in, you’re responsible for having a lawful basis and a condition for doing so.
3. Your instructions
We process workspace personal data only on your documented instructions. These terms, the terms of service, and what your Admins and users do in Klusko (creating, editing, sharing and deleting content) are your instructions. You can give further written instructions if they’re reasonable and consistent with how the service works.
The exception is where UK law requires us to process the data in some other way. If so, we’ll tell you before we do it, unless that law forbids telling you.
If we think an instruction breaks the UK GDPR or other data protection law, we’ll tell you promptly. We don’t have to follow that instruction until it’s resolved.
You’re responsible for having a lawful basis for the processing, for the content you put in and for giving your people any privacy information they need.
4. Confidentiality
Everyone we authorise to process workspace personal data is bound by a duty of confidentiality, either by contract or by law.
5. Security
We keep appropriate technical and organisational measures in place to protect workspace personal data, taking into account the nature of the data and the risks involved, as Article 32 of the UK GDPR requires. They include:
- encryption in transit (TLS) and at rest
- separation of each customer’s data by database row-level security
- hashed passwords
- regular backups
We may change these measures over time, but we won’t reduce the overall level of protection. Our security page has more detail.
6. Subprocessors
You give us general authorisation to use subprocessors. The current list is on our subprocessors page: Supabase Inc., Railway Corporation, Resend and GIPHY.
Before we add or replace a subprocessor, we’ll give at least 30 days’ notice by updating that page and emailing your Admins. The notice will say who the subprocessor is, what it will do and where it will process the data.
You can object on reasonable data protection grounds by emailing privacy@klusko.com within that 30 days. If you do, we’ll work with you in good faith to find a solution, such as a change to how your account uses the service. If we can’t resolve it, you can close your account before the change takes effect, and we’ll refund the unused part of any fees you’ve paid in advance.
We’ll put a written contract in place with each subprocessor that gives the same level of data protection as this DPA. We remain liable to you for our subprocessors’ performance of their obligations.
7. International transfers
Your workspace data is stored in the EU, in Frankfurt, Germany. The UK treats the EU and EEA as adequate, so that storage isn’t a restricted transfer that needs extra safeguards.
Some subprocessors are in the United States. For any restricted transfer of workspace personal data to them, we rely on:
- the UK Extension to the EU-US Data Privacy Framework, where the provider is certified under it, or
- otherwise, the EU Commission’s Standard Contractual Clauses together with the International Data Transfer Addendum issued by the ICO (the “UK Addendum”), or the ICO’s International Data Transfer Agreement (IDTA)
We’ll carry out the transfer risk assessment the law requires, and we’ll put in place any additional measures it shows are needed. We won’t make a restricted transfer on any other basis without telling you first. You can ask for a copy of the relevant safeguards at privacy@klusko.com. We may leave out commercial terms that don’t relate to data protection.
8. Help with data subject requests
If someone asks us to exercise their data protection rights over content in your workspace, we won’t answer the request ourselves (except to tell them to contact you). We’ll pass it to you without undue delay.
Admins can edit and delete content in projects and remove or disable people in Klusko, which covers most requests. Where that isn’t enough, we’ll give you reasonable help, taking into account what we know and how the service works, so you can respond within the time the law allows.
9. Personal data breaches
If we become aware of a personal data breach affecting workspace personal data, we’ll tell you without undue delay and in any case within 48 hours of becoming aware of it. We’ll email your Admins.
As far as we know it at the time, our notice will include:
- what happened, and when
- the categories and approximate number of people and records affected
- the likely consequences
- what we’ve done, or plan to do, to deal with it and reduce any harm
- a contact who can tell you more
If we don’t have all the details at first, we’ll send what we have and follow up as we learn more. We’ll give you the reasonable help you need to meet your own duty to notify the ICO within 72 hours and, where needed, the people affected.
Telling you about a breach isn’t an admission of fault.
10. Other help
Taking into account the nature of the processing and the information we have, we’ll give you reasonable help with:
- your security obligations under Article 32 of the UK GDPR
- data protection impact assessments, and any prior consultation with the ICO, under Articles 35 and 36
- any enquiry from the ICO about workspace data
If a request goes beyond what’s reasonable, or beyond what the service normally provides, we may charge a reasonable fee, and we’ll agree it with you first.
11. Deletion or return at the end
Before your account closes, you can ask us for a copy of your workspace data and we’ll help you export it. After the account is closed, we’ll delete your workspace content within 30 days. Copies in our backups are overwritten within 90 days.
We’ll only keep workspace personal data after that if UK law requires us to, and then only for as long as the law requires, protected under this DPA.
12. Audits and information
We’ll make available to you the information you reasonably need to show that we’re meeting our obligations under Article 28 of the UK GDPR. We’ll start by answering written questions and sharing any relevant reports or certifications from us or our subprocessors.
If that isn’t enough, or if a regulator requires it, you (or an independent auditor you appoint who is bound by confidentiality and isn’t our competitor) may audit us, including by inspection. For audits:
- give us at least 30 days’ written notice, unless there’s been a personal data breach or a regulator requires a shorter period
- no more than once in any 12 months, unless there’s been a personal data breach or a regulator requires it
- during UK working hours, without unreasonably disrupting our business
- at your cost
We’ll let you know promptly if an audit request would require us to break a confidentiality duty to another customer or subprocessor, and we’ll look for another way to give you the assurance you need.
13. Liability and precedence
Each party’s liability under this DPA is subject to the limits in the terms of service, except where the law doesn’t allow those limits.
If this DPA and the terms of service conflict on anything about workspace personal data, this DPA wins. If this DPA and the UK Addendum or IDTA conflict, the UK Addendum or IDTA wins.
14. Contact
For anything about this DPA, email privacy@klusko.com. To report a security issue, email security@klusko.com.
[Company name] Ltd, registered in England and Wales, company number [number], registered office [address]. ICO registration number [ZA000000].