Legal

Data Processing Addendum

Effective 2 September 2026Last updated 2 September 2026

This addendum forms part of the Terms of Service between the customer (“Controller”) and KINDLE HOLDINGS PTE. LTD., a company incorporated in Singapore (UEN TBC: UEN), with its registered office at TBC: registered office address (“Processor”) and applies whenever we process personal data on the Controller's behalf. Where it conflicts with the Terms, this addendum wins.

01Roles and scope

The Controller determines the purposes and means of processing personal data contained in its workspace. The Processor processes that data only to provide the service. Each side complies with the data protection law that applies to it, including the EU and UK GDPR, the Singapore Personal Data Protection Act 2012 and, where applicable, the CCPA as amended.

The subject matter, duration, nature, purpose, categories of data and categories of data subject are set out in Annex 1.

02Processing instructions

The Processor processes personal data only on the Controller's documented instructions, which the Terms and normal use of the service constitute. If the Processor is legally required to process data otherwise, it will tell the Controller first unless the law forbids that notice. The Processor will notify the Controller if, in its opinion, an instruction breaches data protection law.

03Personnel and confidentiality

Access is limited to personnel who need it to deliver or support the service. All such personnel are bound by written confidentiality obligations that survive the end of their engagement, and receive data protection training.

04Security measures

The Processor implements the technical and organisational measures in Annex 2, appropriate to the risk, and will not materially reduce them during the term.

05Sub-processors

The Controller gives general authorisation for the Processor to engage sub-processors, on terms no less protective than this addendum. The Processor stays liable for their performance.

Sub-processorServiceLocation
TBC: cloud hostHosting, storage, backupsTBC: region
TBC: payment processorBillingTBC: region
TBC: email providerTransactional emailTBC: region
TBC: support deskSupport ticketingTBC: region

We give at least 30 days' notice before adding or replacing a sub-processor. The Controller may object on reasonable data protection grounds within that period; if we cannot offer an alternative, the Controller may terminate the affected service and receive a pro-rata refund.

06Data subject requests

Taking account of the nature of the processing, the Processor assists the Controller in responding to requests to access, correct, erase, restrict, port or object. The service's own export, edit and delete functions are the primary means. If a data subject contacts the Processor directly, it will forward the request to the Controller and not respond substantively itself.

07Personal data breach

The Processor notifies the Controller without undue delay and in any event within 48 hours of becoming aware of a personal data breach affecting the Controller's data, and provides the information the Controller reasonably needs to meet its own notification duties.

08Impact assessments

The Processor provides reasonable assistance with data protection impact assessments and prior consultations with supervisory authorities, to the extent the necessary information is not otherwise available to the Controller.

09Audits

The Processor makes available the information necessary to demonstrate compliance and allows for audits. Audit rights are satisfied in the first instance by the Processor's current third-party report or security documentation. Where that is insufficient, the Controller may audit once in any 12-month period, on 30 days' notice, during business hours, at its own cost, under confidentiality, and without disrupting the Processor's operations or other customers.

10International transfers

Where processing involves a transfer of personal data out of the EEA, the UK or Switzerland to a country without an adequacy decision, the parties enter into the Standard Contractual Clauses (Module Two, controller to processor), incorporated here by reference, with the UK International Data Transfer Addendum where the UK GDPR applies. Docking clause: optional. Governing law and forum under Clause 17/18: Ireland, unless the UK Addendum applies. For transfers out of Singapore the Processor complies with the PDPA transfer limitation obligation.

11Return and deletion

On termination the Controller may export its data through the service for 30 days. After that the Processor deletes personal data within a further 30 days, including from backups as they expire, except where law requires retention — in which case the data remains subject to this addendum.

12Liability and term

Each party's liability under this addendum is subject to the limitations in the Terms. This addendum takes effect when the Terms do and continues until the Processor stops processing personal data on the Controller's behalf.

13Annex 1 — Details of processing

Subject matterProvision of a hosted issue, sprint and bug tracking service
DurationThe term of the Terms, plus the deletion window above
Nature and purposeHosting, storage, transmission, display, backup, support
Categories of dataName, work email, avatar, role, authentication identifiers, IP address, activity logs, and any personal data the Controller places in issues, comments or attachments
Data subjectsThe Controller's employees, contractors, and any individuals it chooses to reference in workspace content
Special categoriesNot requested and not required. The Controller should not place special category data in the service.

14Annex 2 — Technical and organisational measures

  • TLS 1.2 or higher for all data in transit; AES-256 for data at rest.
  • Role-based access control, least privilege, and mandatory multi-factor authentication for staff.
  • Segregation of production from development and test environments; no production personal data in test.
  • Centralised, tamper-evident logging of administrative and access events.
  • Encrypted, tested backups with a documented restore procedure.
  • Secure development lifecycle with peer review, dependency scanning and pre-release security review.
  • Documented incident response plan, reviewed at least annually.
  • Vendor due diligence before onboarding any sub-processor.

Current detail is published on the Security page.