This Data Processing Agreement (the "DPA") forms part of, and is incorporated by reference into, the Terms of Service between Kisnip ("Kisnip", "we", "us", "our") and the customer ("Customer", "you") who has accepted those Terms (together, the "Agreement"). It governs the processing of personal data that Kisnip carries out on your behalf when you use our website, dashboard, and embeddable voice and chat assistant (the "Service"). Where there is a conflict between this DPA and the rest of the Agreement on the subject of data protection, this DPA prevails.
This DPA reflects the requirements of Article 28 of the EU General Data Protection Regulation ("GDPR") and the equivalent provisions of the Swiss Federal Act on Data Protection ("FADP").
1. Definitions
Terms such as "personal data", "processing", "controller", "processor", "sub-processor", "data subject", and "personal data breach" have the meanings given to them in the GDPR. "Applicable Data Protection Law" means the GDPR, the Swiss FADP, and any other data protection or privacy law that applies to the processing of personal data under the Agreement. "Customer Personal Data" means personal data that Kisnip processes on your behalf under the Agreement.
2. Roles of the parties
For the Customer Personal Data processed through the Service (for example, the content of conversations between your website visitors and the assistant, and the contact details visitors provide), you act as the controller and Kisnip acts as the processor. Where you are yourself a processor acting on behalf of a third-party controller, you warrant that you have the authority to instruct Kisnip as a sub-processor and that our processing is consistent with that controller's instructions.
Kisnip acts as an independent controller for the limited data it processes to run its business, for example your account and billing details, and account-level security and fraud prevention. That processing is described in our Privacy Policy and is not governed by this DPA.
3. Scope and details of processing
Kisnip processes Customer Personal Data only to provide, secure, and support the Service in accordance with your documented instructions, as set out in this DPA, the rest of the Agreement, and your use of the Service's features and settings. The subject matter, duration, nature and purpose of the processing, the types of personal data, and the categories of data subjects are described in Annex A. Kisnip will inform you if, in its opinion, an instruction infringes Applicable Data Protection Law.
4. Kisnip's obligations
Kisnip will:
- process Customer Personal Data only on your documented instructions, including with regard to international transfers, unless required to do otherwise by law (in which case, where permitted, we will inform you first);
- ensure that persons authorised to process Customer Personal Data are bound by appropriate confidentiality obligations;
- implement and maintain the technical and organisational security measures described in Annex C;
- respect the conditions in this DPA for engaging sub-processors;
- assist you, taking into account the nature of the processing, in responding to data subject requests and in meeting your obligations regarding security, breach notification, data protection impact assessments, and prior consultation; and
- make available the information necessary to demonstrate compliance with Article 28 of the GDPR.
5. Confidentiality
Kisnip treats all Customer Personal Data as confidential. Access is limited to personnel who need it to provide, support, or secure the Service, and those personnel are subject to written confidentiality commitments. These obligations survive the end of their engagement with Kisnip.
6. Security
Kisnip implements appropriate technical and organisational measures to ensure a level of security appropriate to the risk, taking into account the state of the art, the costs of implementation, and the nature, scope, context and purposes of processing. A summary of those measures is set out in Annex C. Kisnip may update its security measures from time to time provided that the updated measures do not materially reduce the overall level of protection.
7. Sub-processors
You give Kisnip general authorisation to engage the sub-processors listed in Annex B to process Customer Personal Data. Kisnip enters into a written agreement with each sub-processor imposing data protection obligations no less protective than those in this DPA, and remains responsible for each sub-processor's performance.
If Kisnip intends to add or replace a sub-processor, it will update the list in Annex B and, where you have asked to be notified, give you reasonable notice. If you have a legitimate, data-protection-related objection to a new sub-processor, you may raise it with us by contacting us; we will work with you in good faith to address it, and if we cannot, you may terminate the affected part of the Service.
8. Data subject rights
Taking into account the nature of the processing, Kisnip will assist you by appropriate technical and organisational measures, insofar as possible, in fulfilling your obligation to respond to requests from data subjects exercising their rights of access, rectification, erasure, restriction, portability, and objection. The Service also provides self-service tools that let you view, export where available, and delete conversation data and your account. If Kisnip receives a request directly from a data subject relating to Customer Personal Data, it will, where legally permitted, direct that person to you rather than responding itself.
9. Personal data breaches
Kisnip will notify you without undue delay after becoming aware of a personal data breach affecting Customer Personal Data, and will provide the information reasonably available to help you meet your own notification obligations under Applicable Data Protection Law. Kisnip will take reasonable steps to mitigate the effects of, and to minimise any damage resulting from, the breach.
10. Data protection impact assessments
Taking into account the nature of the processing and the information available to Kisnip, Kisnip will provide reasonable assistance to help you carry out data protection impact assessments and, where required, prior consultations with a supervisory authority.
11. International transfers
Kisnip and its sub-processors may process Customer Personal Data in the European Union and in other regions where our infrastructure providers operate. Where Customer Personal Data is transferred to a country that does not provide an adequate level of protection, Kisnip relies on an appropriate transfer mechanism recognised under Applicable Data Protection Law, such as the European Commission's Standard Contractual Clauses (and, for transfers subject to the Swiss FADP, the versions recognised by the Swiss Federal Data Protection and Information Commissioner), together with any supplementary measures that may be required.
12. Return and deletion of data
On termination of the Agreement, and at your choice, Kisnip will delete or return Customer Personal Data and delete existing copies, unless retention is required by law. When you delete conversations or your account through the Service, associated Customer Personal Data is deleted or anonymised within 30 days, except where we are required to retain certain records to comply with legal obligations (for example, accounting records).
13. Audits
Kisnip will make available to you the information reasonably necessary to demonstrate compliance with its obligations under this DPA, and will allow for and contribute to audits, including inspections, conducted by you or an auditor you mandate. To respect the confidentiality and security of other customers, audits are carried out on reasonable prior notice, no more than once per year (unless required by a supervisory authority or following a breach), during business hours, and in a manner that does not disrupt the Service. Kisnip may satisfy audit requests by providing relevant third-party certifications or reports where available.
14. Liability
Each party's liability arising out of or related to this DPA is subject to the limitations and exclusions of liability set out in the Agreement.
15. Term, termination, and precedence
This DPA takes effect when you accept the Agreement and remains in force for as long as Kisnip processes Customer Personal Data on your behalf. This DPA supersedes any prior data processing terms between the parties for the Service. All other terms of the Agreement remain in full force and effect.
16. Governing law
This DPA is governed by the same law and subject to the same jurisdiction as set out in the Agreement, except where Applicable Data Protection Law requires otherwise.
17. How this DPA is agreed
This DPA is incorporated into our Terms of Service. When you create an account and accept the Terms, you enter into this DPA with Kisnip in electronic form; no separate signature is required, as permitted under Article 28(9) GDPR. If your organisation needs a counter-signed copy for its records, contact us and we will arrange one.
18. Contact
Questions about this DPA or our data protection practices? Contact us or email [email protected]. You may also find our plain-language GDPR & data protection overview helpful.
19. Annex A: Details of processing
Subject matter. The provision of the Kisnip Service to the Customer.
Duration. For the term of the Agreement, plus any period during which Customer Personal Data is retained in accordance with this DPA.
Nature and purpose. Hosting, storing, transmitting, and processing Customer Personal Data to operate the embeddable voice and chat assistant, generate AI replies, produce conversation summaries and leads, and provide the dashboard, support, and security of the Service.
Types of personal data. Depending on how visitors interact with the assistant, this may include: the content of chat and voice conversations (processed as text; audio is not retained after a conversation ends), any contact details a visitor provides (such as name, email address, or phone number), the page URL where a conversation took place, language and locale, and related technical metadata.
Categories of data subjects. The Customer's website visitors and end users who interact with the assistant, and the Customer's own authorised users of the dashboard.
20. Annex B: Sub-processors
Kisnip uses the following sub-processors to provide the Service. Each is engaged under a data processing agreement with obligations no less protective than those in this DPA.
- Google (Firebase), Google Ireland Limited / Google LLC: hosting, database, authentication, storage, and serverless functions. Processed in the EU and other regions where Google operates.
- Google (Gemini / Vertex AI), Google LLC: generation of AI conversation replies.
- Stripe, Stripe Payments Europe, Ltd.: payment and subscription processing (billing data only).
- Hostpoint AG, Switzerland: delivery of transactional and summary emails.
We keep this list current. To be notified of changes, contact us.
21. Annex C: Technical and organisational measures
Kisnip maintains security measures appropriate to the risk, including:
- Encryption. Personal data is encrypted in transit (TLS) and at rest on our infrastructure providers.
- Access control. Access to Customer Personal Data is restricted to authorised personnel on a need-to-know basis, protected by authentication and role-based permissions.
- Infrastructure security. The Service runs on established cloud infrastructure (Google Firebase) with the physical, network, and operational safeguards those providers maintain.
- Data minimisation. Voice input is processed in real time and audio recordings are not retained after a conversation ends, only text transcripts.
- Resilience. Managed, redundant infrastructure supports the availability and integrity of the Service.
- Confidentiality. Personnel are bound by confidentiality obligations and receive guidance on handling personal data.
- Incident response. Processes are in place to detect, assess, and respond to personal data breaches and to notify affected customers without undue delay.