Legal · Data processing
Data Processing Agreement
This Data Processing Agreement ("DPA") governs how kolm.ai processes AI application audit data and redacted logs on behalf of enterprise customers. It is incorporated into your Master Services Agreement or order form with kolm.ai and is governed by its terms.
The short version
kolm.ai processes only the agent audit data and redacted log material you submit for review. We act as your processor; you remain the controller. All data is tenant-isolated. We notify you in writing within 72 hours of any confirmed breach. Sub-processors are listed in Section 6. We provide at least 30 days' written notice before adding any new sub-processor.
Controller and processor are GDPR roles. The controller decides why and how data is processed; the processor only acts on the controller's instructions. In plain terms:
1. Definitions
Controller, Processor, Data Subject, Personal Data, and Processing have the meanings given in Regulation (EU) 2016/679 ("GDPR").
Customer Data means all data, including Personal Data, that Customer submits to the kolm.ai audit and evidence services, including agent interaction logs, redacted prompts and completions, tool-call traces, and associated metadata.
Services means the kolm.ai agent audit, evidence-report generation, Ed25519-signed report issuance, offline verification, and related control-plane services made available at kolm.ai.
MSA means the Master Services Agreement or equivalent order form between the parties that incorporates this DPA.
2. Scope and roles
Customer acts as Controller of Customer Data. kolm.ai acts as Processor. kolm.ai will process Customer Data only on Customer's documented instructions, including with regard to transfers of Personal Data to third countries, unless required to do otherwise by applicable Union or Member State law. In such a case, kolm.ai will inform Customer of that legal requirement before processing, unless the law prohibits disclosure on important grounds of public interest.
3. Subject matter and duration
The subject matter of processing is the provision of agent security audit and evidence-report services as described in the MSA. Processing continues for the duration of the MSA plus a wind-down period not exceeding 30 days following termination or expiry, after which Customer Data will be deleted or returned in accordance with Section 11.
4. Nature and purpose of processing
kolm.ai processes Customer Data for the following purposes, and no others, unless Customer provides further documented instructions:
- Receiving, ingesting, and storing agent interaction logs and redacted materials submitted by Customer for audit.
- Running automated security checks (permission scope analysis, prompt-injection detection, egress-path enumeration, tool-call integrity review) against submitted logs and traces.
- Generating a cryptographically signed evidence report (Ed25519 over a SHA-256 manifest) summarising audit findings.
- Issuing the signed evidence report and making it available for offline verification by Customer or Customer's counterparties.
- Operating the evidence-report registry and providing verification receipts.
- Providing Customer with self-serve data-export and deletion capabilities.
5. Categories of data subjects and personal data
The categories of Personal Data processed and the data subjects to whom they relate are as follows:
| Category of data subject | Categories of personal data |
|---|---|
| Customer employees and administrators | Account email address, tenant identifiers, API credentials, audit configuration settings. |
| End users of Customer's agent-based product (only when Customer routes their data through the kolm.ai audit surface) | Redacted or pseudonymised prompts and completions, tool-call inputs and outputs, session identifiers, and any other fields present in the logs Customer submits. Customer is responsible for ensuring appropriate redaction before submission. |
kolm.ai does not require or request special categories of personal data (GDPR Art. 9) in order to provide the Services. Customer must not submit special-category data unless expressly agreed in writing.
6. Sub-processors
Customer hereby authorises kolm.ai to engage the sub-processors listed below. The current list, by role, is published at /subprocessors. kolm.ai will give Customer at least 30 days' written notice before engaging any new sub-processor or materially changing the role of an existing one. Customer may object on reasonable data-protection grounds within that notice period; if the parties cannot resolve the objection, Customer may terminate the relevant services without penalty on the grounds of the objection.
| Sub-processor role | Purpose | Processing region |
|---|---|---|
| Edge content delivery and frontend hosting | Serving the kolm.ai web application, documentation, and static assets. | United States; EU; global edge nodes. |
| Control-plane compute hosting | Running the kolm.ai API, audit pipeline, evidence-report engine, and registry. | United States (US-East). |
| Third-party model inference (conditional) | Where Customer's audit configuration routes specific log material to an external model provider for automated analysis, that provider acts as a sub-processor for those inputs only. This applies solely when Customer selects such a route; kolm.ai's default processing does not involve third-party model inference. | Per the applicable provider's published data-processing regions, as disclosed in the notice required above. |
| Payment processing | Processing subscription and invoice payments for paid plans. Billing data only; no Customer audit data is shared. | United States; EU. |
7. Processor obligations
kolm.ai agrees to the following obligations in its capacity as Processor:
- Instructions: Process Customer Data only on Customer's documented instructions. Where kolm.ai believes an instruction would infringe applicable data-protection law, it will promptly notify Customer.
- Confidentiality: Ensure that personnel authorised to process Customer Data are bound by an appropriate duty of confidentiality.
- Assistance: Provide reasonable assistance to Customer in fulfilling its obligations under GDPR Arts. 32-36 (security, breach notification, data-protection impact assessments, prior consultation).
- Records: Maintain records of processing activities carried out on Customer's behalf, as required by GDPR Art. 30(2), and make them available on request.
- Sub-processor flow-down: Impose data-protection obligations on any sub-processor that are no less protective than those in this DPA.
8. Security measures (GDPR Art. 32)
kolm.ai implements and maintains the following technical and organisational measures, taking into account current technical standards, the costs of implementation, and the nature, scope, context, and purposes of processing:
- Encryption in transit: TLS 1.3 is enforced for all connections to the kolm.ai API and web surfaces. Unencrypted HTTP is redirected.
- Encryption at rest: Customer Data, including captured audit logs and generated evidence reports, is encrypted at rest using AES-256.
- Tenant isolation: Every data record is fenced by a tenant_id enforced at every store boundary. Defense-in-depth filters prevent cross-tenant access at the application, query, and storage layers.
- Evidence-report integrity: Each signed evidence report is issued with an Ed25519 signature over a SHA-256 manifest, enabling offline verification without any trust in kolm.ai's servers.
- Access control: Least-privilege role-based access control (RBAC) is applied to all internal systems. Administrative access requires multi-factor authentication and is logged via the internal audit pipeline.
- Vulnerability management: Dependencies are tracked and patched on a risk-prioritised schedule, and the open-source verifier and signing core are published for independent review.
- Incident response: kolm.ai maintains a documented incident-response plan covering detection, containment, eradication, recovery, and notification obligations.
Customer may review the full security posture at /security and the threat model at /security/threat-model.
9. Data-subject rights
kolm.ai will provide reasonable assistance to Customer in responding to data-subject requests made under GDPR Chapter III (right of access, rectification, erasure, restriction of processing, data portability, and right to object). kolm.ai will forward to Customer, without undue delay, any data-subject request it receives that relates to Customer Data, and will not respond directly to the data subject without Customer's prior authorisation, unless required to do so by law.
Customer may request export or deletion of Customer Data (to respond to access and portability requests within the statutory timeframes) by contacting dev@kolm.ai. Authenticated account administrators can also export and delete data directly from the kolm dashboard.
10. Personal data breach notification
kolm.ai will notify Customer in writing without undue delay, and in any event within 72 hours of becoming aware of a confirmed Personal Data breach affecting Customer Data. The notification will include, to the extent then known: the nature of the breach, the categories and approximate number of data subjects and records affected, the likely consequences, and the measures taken or proposed to address the breach and mitigate its effects.
Breach reports and disclosures should be directed to dev@kolm.ai. kolm.ai will cooperate with Customer and relevant supervisory authorities as required.
11. Return and deletion of Customer Data
On termination or expiry of the MSA, or upon Customer's earlier written request, kolm.ai will, at Customer's election, either securely return or delete all Customer Data (including audit logs, evidence reports, and intermediate artefacts) within 30 days. Copies held in automated backup systems will be purged on the next scheduled backup-rotation cycle, which does not exceed 90 days. Deletion will be confirmed to Customer in writing upon completion.
Retention beyond this period is permitted only where required by applicable law; in such cases, kolm.ai will notify Customer, process the retained data for no other purpose, and delete it as soon as the legal obligation is satisfied.
12. Audit rights
Customer may audit kolm.ai's compliance with this DPA no more than once per calendar year, on at least 30 days' prior written notice. Audits will be conducted remotely during normal business hours and at Customer's expense, unless an audit reveals a material breach, in which case reasonable audit costs will be borne by kolm.ai.
kolm.ai does not currently hold a SOC 2 report. In lieu of a third-party certification, kolm.ai satisfies Customer's audit rights through its published security posture, this DPA, written responses to a security questionnaire, and the open, offline verifier that lets Customer independently check every evidence report. Customer may request supporting materials by writing to dev@kolm.ai.
13. International transfers
Where Processing of Customer Data involves a transfer of Personal Data to a country outside the European Economic Area ("EEA") that has not been granted an adequacy decision by the European Commission, kolm.ai will ensure that the transfer is subject to appropriate safeguards. The primary mechanism is the EU Standard Contractual Clauses (Commission Decision 2021/914), Module 2 (Controller-to-Processor), which are incorporated by reference into this DPA and govern in the event of any conflict with its other provisions.
For transfers to sub-processors in third countries, kolm.ai will enter into Module 3 SCCs (Processor-to-Processor) or rely on another lawful transfer mechanism, as applicable. Details of the transfer mechanisms in place for each sub-processor are available on written request to dev@kolm.ai.
14. Liability
The aggregate liability of each party in connection with this DPA is subject to the limitations and caps set out in the MSA. Nothing in this DPA limits either party's liability to the extent that it cannot be limited or excluded under applicable data-protection law, including liability to data subjects under GDPR Art. 82.
15. Governing law and jurisdiction
This DPA is governed by the law specified in the MSA. If the MSA does not specify a choice of law, this DPA is governed by the laws of the State of Delaware, USA, without prejudice to any mandatory data-protection law of the jurisdiction in which the relevant data subjects are habitually resident. The parties submit to the exclusive jurisdiction of the courts of Delaware for resolution of any dispute arising from this DPA, except where mandatory law requires a different forum.
16. Contact and counter-signature
Questions about this DPA, requests for a counter-signed PDF copy, or requests to negotiate amendments should be directed to dev@kolm.ai. Please include your entity name, registered address, and the nature of your request. kolm.ai will provide a fully-executable version of this DPA on request and is prepared to review reasonable amendments from regulated industries including healthcare, financial services, and EU public-sector organisations.
See also: Terms of Service · Privacy Policy · Sub-processors · SLA · Acceptable Use · Security Posture
Write to us before you sign.
We review reasonable amendments for regulated customers and can provide a counter-signed PDF on request.
Caveats: Scope is contractual. Permission posture, redaction and audit-trail integrity are assessed. Injection is tested and reported, not warranted.