Data Processing Addendum
This addendum forms part of the Terms of Service between the customer (“Controller”) and KINDLE HOLDINGS PTE. LTD., a company incorporated in Singapore (UEN TBC: UEN), with its registered office at TBC: registered office address (“Processor”) and applies whenever we process personal data on the Controller's behalf. Where it conflicts with the Terms, this addendum wins.
01Roles and scope
The Controller determines the purposes and means of processing personal data contained in its workspace. The Processor processes that data only to provide the service. Each side complies with the data protection law that applies to it, including the EU and UK GDPR, the Singapore Personal Data Protection Act 2012 and, where applicable, the CCPA as amended.
The subject matter, duration, nature, purpose, categories of data and categories of data subject are set out in Annex 1.
02Processing instructions
The Processor processes personal data only on the Controller's documented instructions, which the Terms and normal use of the service constitute. If the Processor is legally required to process data otherwise, it will tell the Controller first unless the law forbids that notice. The Processor will notify the Controller if, in its opinion, an instruction breaches data protection law.
03Personnel and confidentiality
Access is limited to personnel who need it to deliver or support the service. All such personnel are bound by written confidentiality obligations that survive the end of their engagement, and receive data protection training.
04Security measures
The Processor implements the technical and organisational measures in Annex 2, appropriate to the risk, and will not materially reduce them during the term.
05Sub-processors
The Controller gives general authorisation for the Processor to engage sub-processors, on terms no less protective than this addendum. The Processor stays liable for their performance.
| Sub-processor | Service | Location |
|---|---|---|
| TBC: cloud host | Hosting, storage, backups | TBC: region |
| TBC: payment processor | Billing | TBC: region |
| TBC: email provider | Transactional email | TBC: region |
| TBC: support desk | Support ticketing | TBC: region |
We give at least 30 days' notice before adding or replacing a sub-processor. The Controller may object on reasonable data protection grounds within that period; if we cannot offer an alternative, the Controller may terminate the affected service and receive a pro-rata refund.
06Data subject requests
Taking account of the nature of the processing, the Processor assists the Controller in responding to requests to access, correct, erase, restrict, port or object. The service's own export, edit and delete functions are the primary means. If a data subject contacts the Processor directly, it will forward the request to the Controller and not respond substantively itself.
07Personal data breach
The Processor notifies the Controller without undue delay and in any event within 48 hours of becoming aware of a personal data breach affecting the Controller's data, and provides the information the Controller reasonably needs to meet its own notification duties.
08Impact assessments
The Processor provides reasonable assistance with data protection impact assessments and prior consultations with supervisory authorities, to the extent the necessary information is not otherwise available to the Controller.
09Audits
The Processor makes available the information necessary to demonstrate compliance and allows for audits. Audit rights are satisfied in the first instance by the Processor's current third-party report or security documentation. Where that is insufficient, the Controller may audit once in any 12-month period, on 30 days' notice, during business hours, at its own cost, under confidentiality, and without disrupting the Processor's operations or other customers.
10International transfers
Where processing involves a transfer of personal data out of the EEA, the UK or Switzerland to a country without an adequacy decision, the parties enter into the Standard Contractual Clauses (Module Two, controller to processor), incorporated here by reference, with the UK International Data Transfer Addendum where the UK GDPR applies. Docking clause: optional. Governing law and forum under Clause 17/18: Ireland, unless the UK Addendum applies. For transfers out of Singapore the Processor complies with the PDPA transfer limitation obligation.
11Return and deletion
On termination the Controller may export its data through the service for 30 days. After that the Processor deletes personal data within a further 30 days, including from backups as they expire, except where law requires retention — in which case the data remains subject to this addendum.
12Liability and term
Each party's liability under this addendum is subject to the limitations in the Terms. This addendum takes effect when the Terms do and continues until the Processor stops processing personal data on the Controller's behalf.
13Annex 1 — Details of processing
| Subject matter | Provision of a hosted issue, sprint and bug tracking service |
| Duration | The term of the Terms, plus the deletion window above |
| Nature and purpose | Hosting, storage, transmission, display, backup, support |
| Categories of data | Name, work email, avatar, role, authentication identifiers, IP address, activity logs, and any personal data the Controller places in issues, comments or attachments |
| Data subjects | The Controller's employees, contractors, and any individuals it chooses to reference in workspace content |
| Special categories | Not requested and not required. The Controller should not place special category data in the service. |
14Annex 2 — Technical and organisational measures
- TLS 1.2 or higher for all data in transit; AES-256 for data at rest.
- Role-based access control, least privilege, and mandatory multi-factor authentication for staff.
- Segregation of production from development and test environments; no production personal data in test.
- Centralised, tamper-evident logging of administrative and access events.
- Encrypted, tested backups with a documented restore procedure.
- Secure development lifecycle with peer review, dependency scanning and pre-release security review.
- Documented incident response plan, reviewed at least annually.
- Vendor due diligence before onboarding any sub-processor.
Current detail is published on the Security page.