Owner-approved version 1, approved 2026-10-01. Customer acceptance and live sales remain disabled until the controlled release checks pass.
1. Scope and roles
These terms apply where KXRA processes personal data in customer content on behalf of a business customer. The customer is controller and KXRA is processor for that data. KXRA remains controller for its own account, billing, security, legal and relationship records.
2. Processing instructions
KXRA will process customer personal data only on documented instructions contained in the service agreement, accepted project orders and authorised platform actions, unless law requires other processing. KXRA will inform the customer if an instruction appears to breach data-protection law unless prohibited from doing so.
3. Processing details
The subject matter is hosting and processing authorised business content to provide KXRA platform tools and separately ordered project services. Processing may include collection, organisation, storage, retrieval, analysis, generation, transmission to approved subprocessors, restriction and deletion.
Data subjects may include the customer's staff, contractors, clients, prospects and business contacts. Data may include work-contact details, project records, communications, files, brand material and other categories the customer is authorised to submit. Special-category and criminal-offence data are excluded unless expressly agreed in writing with additional controls.
4. Confidentiality and personnel
KXRA will ensure people authorised to process customer personal data are bound by confidentiality and receive access only where needed for their role.
5. Security
KXRA will maintain measures appropriate to risk, including tenant isolation, row-level database controls, least-privilege service roles, authentication, encryption in transit, controlled secrets, audit evidence, tested backup procedures and incident handling.
6. Subprocessors
The customer authorises the subprocessors identified in the current KXRA subprocessor register. KXRA will impose materially equivalent data-protection obligations and remains responsible for their processing under these terms.
KXRA will give reasonable prior notice of a new subprocessor that will process customer content. The customer may object on reasonable data-protection grounds before the change takes effect; the parties will work in good faith on an alternative, and either party may end the affected service if no reasonable alternative exists.
7. International transfers
KXRA will not transfer customer personal data outside the United Kingdom unless a lawful transfer basis applies. Where required, KXRA will use the UK International Data Transfer Agreement, UK Addendum or another valid safeguard and make relevant information available to the customer.
8. Assistance
Taking account of the nature of processing and information available, KXRA will reasonably assist the customer with data-subject requests, security obligations, impact assessments and regulator consultations. KXRA may charge reasonable costs for assistance outside the normal service where the need was not caused by KXRA's breach.
9. Personal-data incidents
KXRA will notify the customer without undue delay after becoming aware of a personal-data breach affecting customer content and will provide available information reasonably needed for the customer's assessment and notifications. KXRA's notice is not an admission of fault.
10. Return and deletion
At the customer's choice and subject to available product controls, KXRA will return or delete customer personal data after the service ends, unless law requires retention. Ordinary customer content is scheduled for deletion or irreversible anonymisation within 90 days after closure, and backup copies expire within a further 35 days unless a legal hold applies.
11. Audit information
KXRA will provide information reasonably necessary to demonstrate compliance. Audits must be proportionate, protect other customers and security, use existing independent reports where suitable, and normally occur no more than once a year unless a breach or regulator requires more.
12. Priority
If these data processing terms conflict with other customer terms on processor obligations, these terms take priority for that conflict.
Related documents: customer document index.