Legal
Data Processing Addendum
Effective September 23, 2026 · Kratu AI LLC
1. Scope and roles
This Data Processing Addendum ("DPA") forms part of the Terms of Service between you ("Customer") and Kratu AI LLC ("Processor"). It applies when we process personal data on your behalf — chiefly the responses your research respondents submit through forms you publish ("Customer Personal Data").
You are the controller (GDPR, UK GDPR) and the "business" (CCPA/CPRA); we are your processor and "service provider". It takes effect when you accept the Terms; no signature is needed. If you need a countersigned copy, email [email protected].
2. Details of processing
- Subject matter and duration: providing the Service, for the term of the Terms plus the deletion period in Section 9.
- Nature and purpose: hosting forms; collecting, storing and displaying responses; analytics and AI-assisted analysis; adaptive follow-up questions (if you enable them); exports and integrations you configure; spam and bot prevention.
- Data subjects: your respondents, and anyone else whose data you put into the Service.
- Categories of data: whatever your forms ask; optional respondent name and email; truncated IP address (removed after 30 days), approximate location, device, browser, time zone.
- Special categories: none intended. You must not collect them unless permitted by law and the Acceptable Use Policy.
3. Processing on your instructions
We process Customer Personal Data only on your documented instructions — which are the Terms, this DPA and your use and configuration of the Service — unless the law requires otherwise, in which case we'll tell you first unless the law prohibits that. We'll tell you if we believe an instruction infringes data-protection law. We won't sell or share Customer Personal Data, retain, use or disclose it for any purpose other than providing the Service, or combine it with personal data from other sources except as the CCPA permits for service providers.
4. Confidentiality
Everyone we authorize to process Customer Personal Data is bound by confidentiality obligations, and access is limited to those who need it to operate, support or secure the Service.
5. Subprocessors
You authorize the subprocessors listed at hypothis.ai/subprocessors. We impose data-protection terms on each that are at least as protective as this DPA, and remain responsible for their performance. We'll give at least 30 days' notice of a new subprocessor by updating that page and emailing customers who request notices at [email protected]. You may object on reasonable data-protection grounds; if we can't reasonably accommodate the objection, you may terminate the affected Service and receive a pro-rated refund of prepaid fees.
6. Security
We maintain appropriate technical and organisational measures, including encryption in transit (TLS), encryption of stored credentials and tokens, tenant isolation, access controls and least privilege, logging, rate limiting and bot protection, encrypted off-site backups, and data minimisation (for example truncating respondent IP addresses).
7. Assistance with data-subject requests and compliance
Taking into account the nature of processing, we'll help you respond to data-subject requests (you can export and delete responses yourself in the Service), and with security, breach notification, data-protection impact assessments and prior consultations. If a respondent contacts us directly, we'll forward the request to you without undue delay and won't respond ourselves except to redirect them, unless the law requires.
8. Personal data breaches
We'll notify you without undue delay, and in any event within 72 hours, after becoming aware of a personal data breach affecting Customer Personal Data, with the information you reasonably need to meet your own notification obligations, and we'll take reasonable steps to contain and remediate it.
9. Return and deletion
You can export responses (CSV) and your whole account (ZIP) at any time. When you delete responses, forms or your account, we delete the Customer Personal Data (after the account-deletion grace period described in the Terms), and it rolls out of backups within 30 days, unless the law requires us to keep it.
10. Audits
On reasonable written request (no more than once a year, unless required by a regulator or after a breach), we'll provide information necessary to demonstrate compliance with this DPA, such as security documentation and written answers to your questionnaire. Any on-site audit requires reasonable notice, happens during business hours, is at your cost, and is subject to confidentiality.
11. International transfers
We process data in the United States. For transfers of personal data from the EU/EEA, the parties agree to the Standard Contractual Clauses adopted by Commission Implementing Decision (EU) 2021/914, Module Two (controller-to-processor) — and Module Three for onward transfers to subprocessors — which are incorporated by reference with: Clause 7 (docking) included; Clause 9 option 2 (general authorization, 30 days' notice); Clause 11 optional language omitted; Clauses 17 and 18: laws and courts of Ireland; Annexes completed from Sections 2 and 6 of this DPA. For the UK, the ICO's International Data Transfer Addendum applies; for Switzerland, the SCCs apply with the FADP as the relevant law. Where a transfer mechanism such as the EU–U.S. Data Privacy Framework applies, we may rely on it instead.
12. Liability and order of precedence
Each party's liability under this DPA is subject to the limitations in the Terms, except where the law does not allow it. If this DPA conflicts with the Terms, this DPA wins for data protection; if the SCCs conflict with anything else, the SCCs win.
13. Contact
Kratu AI LLC, 2114 Wasatch Blvd, Sandy, UT 84092 · [email protected]