Effective: September 26, 2025

Data Processing Addendum (DPA)

Entity: Kakr Labs, Inc. (Wyoming C-Corp)

This Data Processing Addendum ("DPA") forms part of the agreement between Kakr Labs Inc. ("Processor") and the customer ("Controller") for the provision of services. This DPA reflects the parties' agreement regarding the processing of Personal Data in accordance with applicable data protection laws.

Effective Date: September 26, 2025


1. Definitions

  • "Personal Data" means any information relating to an identified or identifiable natural person
  • "Processing" means any operation performed on Personal Data
  • "Controller" means the entity that determines the purposes and means of Processing Personal Data
  • "Processor" means Kakr Labs Inc., which Processes Personal Data on behalf of the Controller
  • "Sub-processor" means any third party engaged by the Processor to Process Personal Data

2. Scope and Purpose of Processing

Kakr Labs processes Personal Data only as necessary to provide the following services:

  • PTERI Wallet: Decentralized authentication and wallet management
  • PTERI Playground: Development and testing environment
  • PTERI Intelligence: AI-powered analytics and insights
  • PTERI Data: Blockchain data management and audit trails

We do NOT process sensitive personal data (e.g., health data, biometric data) unless explicitly agreed in writing.

3. Categories of Data and Data Subjects

We process the following categories of Personal Data:

A. Account Information

  • Email addresses
  • Public wallet addresses (BIP-39 compatible)
  • Account preferences and settings

B. Support and Communication Data

  • Name and contact information (when provided)
  • Support ticket content
  • Communication history

C. Usage Data (Anonymized)

  • API call logs and metrics
  • Performance and error data
  • Feature usage statistics

We do NOT collect or process: SSN, financial account details, biometric data, location tracking, or private keys/seed phrases.

4. Processor Obligations

Kakr Labs commits to:

  • Process Personal Data only on documented instructions from the Controller
  • Ensure confidentiality of personnel with access to Personal Data
  • Implement appropriate technical and organizational security measures
  • Assist the Controller in responding to data subject requests
  • Notify the Controller of any Personal Data breaches without undue delay
  • Delete or return Personal Data upon termination of services

If we believe an instruction violates applicable law, we will inform the Controller immediately.

5. Controller Obligations

The Controller commits to:

  • Ensure it has a lawful basis for Processing Personal Data
  • Provide clear instructions for data Processing
  • Comply with applicable data protection laws
  • Inform Kakr Labs of any restrictions on Processing

The Controller is responsible for obtaining necessary consents from data subjects.

6. Security Measures

Kakr Labs implements the following security measures:

A. Infrastructure Security

  • Hosted on Azure & IBM with SOC 2 and ISO 27001 compliance
  • Data encrypted at rest (AES-256) and in transit (TLS 1.3)
  • Multi-region redundancy and disaster recovery

B. System Security

  • Role-based access controls (RBAC)
  • Multi-factor authentication for administrative access
  • Regular security audits and penetration testing

C. Application Security

  • Decentralized 2FA via PTERI Wallet (2000% stronger than traditional 2FA)
  • Customer-controlled payment credentials
  • Immutable audit logs via blockchain

D. Privacy by Design

  • Data minimization: We collect only what's necessary
  • No private keys or seed phrases stored
  • Anonymized analytics and usage data

7. Data Subject Requests

Kakr Labs will assist the Controller in responding to data subject requests, including:

  • Access requests: Providing copies of Personal Data
  • Rectification requests: Correcting inaccurate data
  • Erasure requests: Deleting Personal Data
  • Portability requests: Exporting data in a structured format
  • Objection requests: Ceasing certain Processing activities

8. Audits and Compliance

Kakr Labs commits to:

  • Annual SOC 2 Type II audits
  • ISO 27001 certification maintenance
  • Providing audit reports upon request (subject to confidentiality)
  • Cooperating with regulatory inspections

9. Sub-processors

Kakr Labs engages the following Sub-processors:

A. Infrastructure Sub-processors

  • Microsoft Azure: Cloud hosting and infrastructure
  • IBM Cloud: Hybrid cloud and blockchain services
  • Google Cloud Platform: Performance monitoring and analytics

B. AI Sub-processors

  • OpenAI: AI-powered features in PTERI Intelligence (no wallet data shared)

We will notify the Controller of any changes to Sub-processors with at least 30 days' notice.

10. International Data Transfers

Personal Data may be transferred to:

  • United States (Kakr Labs headquarters)
  • European Union (Azure data centers)
  • Other regions where Azure/IBM operate

All transfers comply with GDPR Standard Contractual Clauses (SCCs) and other applicable safeguards.

11. Data Retention and Deletion

We retain Personal Data only as long as necessary for the purposes outlined in this DPA or as required by law.

Upon termination of services, we will:

  • Delete all Personal Data within 30 days, or
  • Return Personal Data to the Controller upon request

12. Liability and Indemnification

Liability for data protection violations is governed by:

  • The main service agreement between Kakr Labs and the Controller
  • Applicable data protection laws (e.g., GDPR Article 82)
  • Each party is liable for its own breaches of this DPA

13. Term and Termination

This DPA remains in effect for the duration of the service agreement. Upon termination, the data deletion provisions in Section 11 apply.

14. Contact Information

For questions about this DPA or data processing practices, contact:

  • Email: privacy@kakr.org
  • Website: https://kakr.org/contact

Kakr Labs Inc.

Decentralized by Design. Private by Default.