Skip to content
Kanesh

Legal

Data processing agreement

For the conversations between your brand and your customers, you are the controller and Number Studios SL processes the data on your behalf. This agreement governs that processing under article 28 of the GDPR.

Last updated:

This English text is a courtesy translation. In case of discrepancy the Spanish version prevails.

1.Parties and acceptance

Controller: the company that contracts Kanesh (the “Customer”).

Processor: Number Studios SL (the “Processor”):

  • Company: Number Studios SL, trading as Nexau.
  • Tax ID (NIF): B-14938864.
  • Registered office: C/ Doce de Octubre 1, 2º 2, 14001 Córdoba, España.
  • Contact email: [email protected].

This agreement is part of the terms of service and is accepted with them, by signing or accepting the Order. On data protection matters it prevails over the terms. If you need a signed copy, ask at [email protected].

Terms used here (“personal data”, “processing”, “personal data breach”, etc.) have the meaning given to them by Regulation (EU) 2016/679 (GDPR).

2.Subject matter, nature and purpose

The Processor processes personal data on the Customer's behalf for the sole purpose of providing the Kanesh service, in particular to:

  • receive, store and display in the inbox the conversations from the channels the Customer connects, and send its team's replies;
  • draft and send AI replies from the Customer's knowledge, rules and store data, when the Customer enables it;
  • send the campaigns, flows and follow-ups the Customer configures;
  • handle calls, when the Customer enables voice;
  • produce the service's analytics and provide technical support.

Processing operations are collection, recording, storage, consultation, structuring, automated analysis, disclosure to the recipients the Customer chooses, and erasure.

3.Duration

This agreement lasts as long as the service contract and, afterwards, for the time needed to return or delete the data as described under “End of service”.

4.Types of data and categories of data subjects

Types of personal data, depending on the channels and features the Customer enables:

  • end customers' contact details and identifiers: name, phone number, email, social media handle or ID;
  • conversation content, including files, images and voice notes;
  • order and customer data read from the connected store (for example Shopify): products, amounts, shipping status and delivery details;
  • consent evidence: the text accepted, how it was given and when;
  • call recordings and transcripts, where voice is enabled;
  • the Customer's Users' data: name, work email, role and activity in the platform.

The service is not designed to process special categories of data. If the Customer decides to process them, it is responsible for assessing their lawfulness and putting the necessary safeguards in place.

Data subjects: the Customer's customers and prospective customers who write to it or whom it writes to, and the Customer's Users.

5.Customer instructions

The Processor processes the data only on the Customer's documented instructions, which are this agreement, the terms of service, the Order and the configuration the Customer sets in the platform, including the international transfers described below.

It will not use the data for its own purposes. If an instruction appears to infringe the GDPR or other data protection law, it will tell the Customer immediately. If the law requires it to process data for another reason, it will inform the Customer first, unless the law prohibits it.

6.Confidentiality

The Processor ensures that people authorised to process the data have committed to confidentiality or are under a statutory duty of confidentiality, and access it only as needed to provide the service or support.

7.Security measures

The Processor applies technical and organisational measures appropriate to the risk, under article 32 of the GDPR. These include:

  • each workspace's data is isolated at the database level;
  • credentials for connected channels are stored encrypted;
  • data is encrypted in transit (HTTPS);
  • API keys are scoped and revocable.

Measures are reviewed and updated over time, without lowering the level of protection. They are also described on Security & privacy.

The Customer is responsible for security on its side: managing who in its team has access, protecting its credentials and configuring the service appropriately for its data.

8.Sub-processors

Under GDPR article 28.2, the Customer gives general written authorisation for the Processor to use the sub-processors listed on the sub-processors page, which shows each one's purpose, data, location, transfer safeguard and status, with a change log.

  • Prior notice: the Processor will notify the Customer, by email to its administrator and by publishing it on that page, at least 30 days before a new or replacement sub-processor processes its data. Anyone can subscribe to those notices as described on that page.
  • Objection: within that period, the Customer may object in writing on reasonable data protection grounds. The parties will look for a solution in good faith.
  • Termination: if none is found, the Customer may terminate the contract for the affected service without penalty, and the Processor will refund the pro-rata part of the fees prepaid for the unused period.
  • Urgency: if a sub-processor has to be replaced urgently for security or service-continuity reasons, the Processor will give notice as soon as possible, explain why, and the right to object applies in the same way from that notice.

The Processor will impose on each sub-processor, by contract, data protection obligations equivalent to those in this agreement, and remains liable to the Customer for their performance.

Services the Customer connects and authorises itself, such as its Shopify store, its Klaviyo account or its mailbox, are not sub-processors: the Customer deals with them directly, under their terms.

9.International transfers

The Customer instructs the Processor to make the international transfers needed to provide the service with the authorised sub-processors. Several of them are based in the United States or have a US parent; the sub-processors page shows which. Even when data is stored in the EU, those cases are treated as transfers, because the provider may access the data from outside.

  • Sub-processors certified under the EU-US Data Privacy Framework: the transfer relies on the Commission's adequacy decision, Implementing Decision (EU) 2023/1795 of 10 July 2023 (GDPR article 45).
  • Sub-processors that aren't certified: the transfer relies on the standard contractual clauses of Implementing Decision (EU) 2021/914 of 4 June 2021 (GDPR article 46), in the relevant module (normally processor to processor), incorporated in the Processor's contract with that sub-processor.
  • If a sub-processor's certification lapses, the standard contractual clauses apply or the transfer stops.

For transfers based on standard contractual clauses, the Processor documents a transfer impact assessment, taking into account the laws of the destination country and the applicable technical and organisational measures, and adopts supplementary measures where needed. On request, it will give the Customer a summary of that assessment and a copy of the applicable safeguards.

10.Assistance to the Customer

Taking into account the nature of the processing, the Processor helps the Customer:

  • respond to data subjects' requests to exercise their rights (access, rectification, erasure, objection, restriction and portability). If a data subject contacts the Processor, it will forward the request to the Customer without delay and will not answer it itself unless the Customer instructs it to;
  • meet its obligations on security, breach notification, data protection impact assessments and prior consultation with the supervisory authority (GDPR articles 32 to 36), by providing the information available to it.

11.Personal data breaches

The Processor will notify the Customer without undue delay after becoming aware of any personal data breach affecting the Customer's data. The notice will go to the Customer administrator's email and include, as far as known, the information in GDPR article 33.3: the nature of the breach, the categories and approximate number of data subjects and records concerned, likely consequences, measures taken or proposed, and a contact point ([email protected]). If not all the information is available at once, it will be provided in phases.

The Processor will take reasonable steps to contain the breach and mitigate its effects, and will cooperate with the Customer. As controller, the Customer is responsible for notifying the supervisory authority and data subjects where required.

12.End of service: return and deletion

Before the contract ends, the Customer may ask for a copy of its data in a structured, commonly used format. After cancellation, the Processor deletes the Customer's data, including copies, within 90 days.

The Processor will keep only the data the law requires it to retain, blocked, and for the legal period.

13.Information and audits

The Processor will make available to the Customer the information needed to demonstrate compliance with this agreement and GDPR article 28. Requests will first be handled with documentation and written answers.

If that information is not enough, or if a supervisory authority requires it, the Customer may carry out an audit, itself or through an independent auditor bound by confidentiality, with at least 30 days' notice, during business hours, without access to other customers' data, and at most once a year except after a personal data breach. Each party bears its own costs.

14.Liability for data protection

This agreement has its own liability regime, which prevails over that of the terms of service:

  • Each party is liable for the damage it causes by breaching this agreement or its data protection obligations, under GDPR article 82.
  • Administrative fines and claims by data subjects or third parties arising from one party's breach are borne by that party, to the extent it is responsible for them. If both are responsible for the same damage, each bears its share according to its responsibility.
  • Between the parties, the Processor's total liability for breaching this agreement is limited to twice the general cap in the terms of service (that is, twice what the Customer paid in the twelve months before the event), unless the Order sets another amount. This special cap replaces the general one for these breaches, and the exclusion of indirect damages in the terms does not prevent a party from claiming what it had to pay data subjects or authorities because of the other party's breach.
  • None of these limits applies in cases of wilful misconduct or gross negligence.
  • Nothing above limits either party's liability towards data subjects, or any liability that cannot be limited by law.

15.Other obligations

  • The Processor will keep a record of the processing activities it carries out on the Customer's behalf (GDPR article 30.2).
  • The Customer warrants that it has a legal basis for the processing it entrusts and has informed the data subjects.
  • Governing law and jurisdiction are those of the terms of service.