Customer-facing DPA template, for review. Not yet executed.
This Data Processing Agreement ("DPA") forms part of the agreement between the customer ("Controller") and Keld Inc ("Processor", "Keld") for use of the Keld service (the "Agreement"). It applies where Keld processes personal data on the Controller's behalf, principally the contents of inference jobs that flow through the Keld marketplace to a provider.
"GDPR" means Regulation (EU) 2016/679 and, as applicable, the UK GDPR. "Personal data", "processing", "controller", "processor", "sub-processor" and "data subject" have the meanings in the GDPR. "Customer Personal Data" means personal data within inference payloads and related data Keld processes for the Controller.
The Controller is the controller of Customer Personal Data; Keld is the processor. Where the Controller is itself a processor for a third party, Keld is a sub-processor. Keld processes Customer Personal Data only to provide the service and only on the Controller's documented instructions, including those in the Agreement and this DPA. Details of the processing are in Annex I.
The Controller is responsible for the lawfulness of the data it submits and its instructions, including having a valid legal basis and any required notices or consents for the personal data it sends through Keld.
The Controller gives general authorization for Keld to engage sub-processors, including the cloud infrastructure and the inference providers that execute jobs. The current list is at keld.co/subprocessors. Keld will impose data-protection obligations on each sub-processor that are no less protective than this DPA (flow-down), and remains responsible for their performance. Keld will give at least 30 days' notice of intended changes (additions or replacements) and allow the Controller to object on reasonable data-protection grounds within that period.
Where Keld transfers Customer Personal Data outside the EEA or the UK, the parties rely on the European Commission's Standard Contractual Clauses (Module Two, controller-to-processor), and the UK International Data Transfer Addendum for UK data, which are incorporated into this DPA by reference and completed in Annex III. Keld applies supplementary measures, including encryption in transit and Zero Data Retention, and conducts transfer risk assessments where required. The completed SCCs are attached to the signed DPA (see Annex III).
Keld maintains technical and organizational measures appropriate to the risk, including: encryption of data in transit (TLS); Zero Data Retention for inference payloads; least-privilege, role-based access with logging; control-plane / data-plane separation; and an information-security program aligned with our SOC 2 control set.
Keld will make available information needed to demonstrate compliance and, on reasonable notice and confidentiality terms, allow audits by the Controller or its mandated auditor, including making available third-party reports (such as SOC 2) where they reasonably satisfy the request. Audits take place no more than once in any 12-month period (unless required by a supervisory authority or following a breach), on reasonable prior notice and during business hours.
Keld will notify the Controller without undue delay after becoming aware of a personal data breach affecting Customer Personal Data, with the information reasonably available to help the Controller meet its own notification duties.
This DPA is subject to the liability provisions of the Agreement. It runs for as long as Keld processes Customer Personal Data. If there's a conflict between this DPA and the Agreement on data protection, this DPA controls; on transfers, the SCCs control.
As described in Section 7; the full schedule of technical and organizational measures is provided to customers as part of the signed DPA package.
EU SCCs (Module Two, controller-to-processor) and the UK International Data Transfer Addendum, completed and executed as part of the signed DPA.