Last updated: July 18, 2026 · Version 1.0
This Data Processing Agreement (“DPA”) forms part of the agreement between Kadropic Labs, Inc. (“Processor”, “we”) and the customer (“Controller”, “you”) for the use of LEO Soul (the “Service”), and governs our processing of personal data on your behalf under the EU General Data Protection Regulation (2016/679) (“GDPR”), the UK GDPR and Data Protection Act 2018, the Swiss FADP, and the California CCPA/CPRA, as applicable.
soul_state.
Where you self-host, no Customer Personal Data reaches us at all. So the “data we process on your behalf” is
minimal by design - this DPA still sets out the full Article 28 commitments in case any personal data is
processed.To request a countersigned copy, or the Standard Contractual Clauses as a standalone document, contact support@kadropiclabs.com. For Enterprise engagements this DPA can be executed alongside the Master Services Agreement.
“Customer Personal Data” means personal data we process on your behalf under the Service. “Data Subject”, “processing”, “controller”, “processor”, and “personal data breach” have the meanings given in the GDPR. “SCCs” means the Standard Contractual Clauses approved by the European Commission (Decision 2021/914), including the UK International Data Transfer Addendum where relevant. Capitalised terms not defined here have the meaning in the Terms of Service.
You are the controller (or a processor acting for a third-party controller) of Customer Personal Data, and we are your processor (or sub-processor). This DPA applies to our processing of Customer Personal Data in the course of providing the Hosted Service. Where you self-host, we generally do not process Customer Personal Data and act only in support of the software. The subject matter, duration, nature, purpose, data types, and categories of Data Subjects are described in Annex A.
We will process Customer Personal Data only on your documented instructions - which include this DPA, the Terms, your configuration of the Service, and your use of its features - and to comply with law. If we are required by law to process beyond your instructions, we will inform you first unless the law prohibits it. We will notify you if, in our opinion, an instruction infringes data-protection law. We do not sell Customer Personal Data and do not use it for our own purposes.
We ensure that personnel authorised to process Customer Personal Data are bound by appropriate confidentiality obligations and process it only as needed to provide the Service.
We implement appropriate technical and organisational measures to protect Customer Personal Data against accidental or unlawful destruction, loss, alteration, unauthorised disclosure, or access, taking into account the state of the art and the risks. Our measures are described in Annex B and on the Security page. The most significant control is architectural: for product turns there is no retained content to compromise.
You give general authorisation for us to engage subprocessors to provide the Service. We impose data-protection obligations on each subprocessor no less protective than this DPA and remain responsible for their performance. Our current subprocessors are listed in Annex C and the Privacy Policy. We will give you reasonable prior notice of any intended addition or replacement of a subprocessor and a chance to object on reasonable data-protection grounds; if we cannot resolve the objection, you may terminate the affected part of the Service.
Taking into account the nature of the processing, we will assist you by appropriate technical and organisational measures, insofar as possible, to respond to requests from Data Subjects to exercise their rights (access, rectification, erasure, restriction, portability, objection). Because we hold no message content and only limited account data, such assistance is typically straightforward. If a Data Subject contacts us directly about Customer Personal Data, we will refer them to you.
We will notify you without undue delay after becoming aware of a personal data breach affecting Customer Personal Data, and will provide the information you reasonably need to meet your own notification obligations, including the nature of the breach, likely consequences, and measures taken or proposed. Our notice is not an acknowledgement of fault.
We will provide reasonable assistance with your data-protection impact assessments and prior consultations with supervisory authorities, taking into account the information available to us. We will make available the information necessary to demonstrate compliance with Article 28 and allow for and contribute to audits, including inspections, conducted by you or an auditor you mandate - reasonably, on notice, no more than once a year (unless required by a regulator or following a breach), subject to confidentiality, and satisfiable in the first instance by our documentation, security page, and questionnaire responses.
Where our processing of Customer Personal Data involves a transfer from the EEA, UK, or Switzerland to a country without an adequacy decision, the SCCs are incorporated into this DPA by reference and apply, with you as data exporter and us as data importer: Module Two (controller-to-processor) or Module Three (processor-to-processor) as applicable, the UK Addendum for UK transfers, and the Swiss adaptations for Swiss transfers. Where the SCCs offer options, the governing law and forum follow the SCCs’ default for the exporter’s jurisdiction, the optional docking clause applies, and the annexes are populated by Annexes A-C of this DPA. We will also apply supplementary measures where needed.
On termination of the Service, we will delete or return Customer Personal Data as you choose, and delete
existing copies, except to the extent retention is required by law. Because message content and
soul_state are not retained, deletion primarily concerns account and billing data, which is handled
per the Privacy Policy.
Where we process personal information governed by the CCPA/CPRA on your behalf, we act as a service provider. We will not sell or share that information, retain, use, or disclose it for any purpose other than performing the Service (or as permitted by the CCPA), or combine it with other data except as permitted. We certify that we understand and will comply with these restrictions.
This DPA takes effect when you accept the Terms or the Service, and remains in force while we process Customer Personal Data. Each party’s liability under this DPA is subject to the limitations of liability in the Terms or a signed MSA. If there is a conflict, this DPA controls for data-protection matters; the SCCs control over this DPA for transfers they govern.
| Subject matter | Provision of the LEO Soul metacognitive Service. |
|---|---|
| Duration | The term of the Service plus any legally required retention. |
| Nature & purpose | Transient processing of turns; account, authentication, metering, billing, security, and support. |
| Categories of Data Subjects | Your authorised users/administrators; and any individuals whose data you choose to include in content you send (not retained by us). |
| Types of personal data | Account identifiers (name, email), authentication and security logs, billing identifiers; and, only transiently, any personal data present in your submitted content. |
| Special categories | Not requested or required; you should not submit special-category data without your own safeguards. |
| Frequency | Continuous, as you use the Service. |
soul_state; only aggregate counts metered.As listed in the Privacy Policy: Stripe (payments), cloud hosting/database providers (running the app), an email-delivery provider (transactional email), and OpenAI (the in-product LEO Assistant only). A current list is available to Enterprise customers on request.