This Data Processing Addendum ("DPA") forms part of the agreement between Kakr Labs Inc. ("Processor") and the customer ("Controller") for the provision of services. This DPA reflects the parties' agreement regarding the processing of Personal Data in accordance with applicable data protection laws.
Effective Date: September 26, 2025
1. Definitions
- "Personal Data" means any information relating to an identified or identifiable natural person
- "Processing" means any operation performed on Personal Data
- "Controller" means the entity that determines the purposes and means of Processing Personal Data
- "Processor" means Kakr Labs Inc., which Processes Personal Data on behalf of the Controller
- "Sub-processor" means any third party engaged by the Processor to Process Personal Data
2. Scope and Purpose of Processing
Kakr Labs processes Personal Data only as necessary to provide the following services:
- PTERI Wallet: Decentralized authentication and wallet management
- PTERI Playground: Development and testing environment
- PTERI Intelligence: AI-powered analytics and insights
- PTERI Data: Blockchain data management and audit trails
We do NOT process sensitive personal data (e.g., health data, biometric data) unless explicitly agreed in writing.
3. Categories of Data and Data Subjects
We process the following categories of Personal Data:
A. Account Information
- Email addresses
- Public wallet addresses (BIP-39 compatible)
- Account preferences and settings
B. Support and Communication Data
- Name and contact information (when provided)
- Support ticket content
- Communication history
C. Usage Data (Anonymized)
- API call logs and metrics
- Performance and error data
- Feature usage statistics
We do NOT collect or process: SSN, financial account details, biometric data, location tracking, or private keys/seed phrases.
4. Processor Obligations
Kakr Labs commits to:
- Process Personal Data only on documented instructions from the Controller
- Ensure confidentiality of personnel with access to Personal Data
- Implement appropriate technical and organizational security measures
- Assist the Controller in responding to data subject requests
- Notify the Controller of any Personal Data breaches without undue delay
- Delete or return Personal Data upon termination of services
If we believe an instruction violates applicable law, we will inform the Controller immediately.
5. Controller Obligations
The Controller commits to:
- Ensure it has a lawful basis for Processing Personal Data
- Provide clear instructions for data Processing
- Comply with applicable data protection laws
- Inform Kakr Labs of any restrictions on Processing
The Controller is responsible for obtaining necessary consents from data subjects.
6. Security Measures
Kakr Labs implements the following security measures:
A. Infrastructure Security
- Hosted on Azure & IBM with SOC 2 and ISO 27001 compliance
- Data encrypted at rest (AES-256) and in transit (TLS 1.3)
- Multi-region redundancy and disaster recovery
B. System Security
- Role-based access controls (RBAC)
- Multi-factor authentication for administrative access
- Regular security audits and penetration testing
C. Application Security
- Decentralized 2FA via PTERI Wallet (2000% stronger than traditional 2FA)
- Customer-controlled payment credentials
- Immutable audit logs via blockchain
D. Privacy by Design
- Data minimization: We collect only what's necessary
- No private keys or seed phrases stored
- Anonymized analytics and usage data
7. Data Subject Requests
Kakr Labs will assist the Controller in responding to data subject requests, including:
- Access requests: Providing copies of Personal Data
- Rectification requests: Correcting inaccurate data
- Erasure requests: Deleting Personal Data
- Portability requests: Exporting data in a structured format
- Objection requests: Ceasing certain Processing activities
8. Audits and Compliance
Kakr Labs commits to:
- Annual SOC 2 Type II audits
- ISO 27001 certification maintenance
- Providing audit reports upon request (subject to confidentiality)
- Cooperating with regulatory inspections
9. Sub-processors
Kakr Labs engages the following Sub-processors:
A. Infrastructure Sub-processors
- Microsoft Azure: Cloud hosting and infrastructure
- IBM Cloud: Hybrid cloud and blockchain services
- Google Cloud Platform: Performance monitoring and analytics
B. AI Sub-processors
- OpenAI: AI-powered features in PTERI Intelligence (no wallet data shared)
We will notify the Controller of any changes to Sub-processors with at least 30 days' notice.
10. International Data Transfers
Personal Data may be transferred to:
- United States (Kakr Labs headquarters)
- European Union (Azure data centers)
- Other regions where Azure/IBM operate
All transfers comply with GDPR Standard Contractual Clauses (SCCs) and other applicable safeguards.
11. Data Retention and Deletion
We retain Personal Data only as long as necessary for the purposes outlined in this DPA or as required by law.
Upon termination of services, we will:
- Delete all Personal Data within 30 days, or
- Return Personal Data to the Controller upon request
12. Liability and Indemnification
Liability for data protection violations is governed by:
- The main service agreement between Kakr Labs and the Controller
- Applicable data protection laws (e.g., GDPR Article 82)
- Each party is liable for its own breaches of this DPA
13. Term and Termination
This DPA remains in effect for the duration of the service agreement. Upon termination, the data deletion provisions in Section 11 apply.
14. Contact Information
For questions about this DPA or data processing practices, contact:
- Email: privacy@kakr.org
- Website: https://kakr.org/contact
Kakr Labs Inc.
Decentralized by Design. Private by Default.