Data Processing Addendum
Last updated: June 2026
This Data Processing Addendum (“DPA”) forms part of the agreement between HeyKiko (the “Processor”) and the customer (the “Controller”) and governs the processing of personal data carried out on the Controller's behalf. It is designed to support compliance with the PDPA and comparable data-protection laws.
1. Roles
The Controller determines the purposes and means of processing. HeyKiko acts as Processor and processes personal data only on documented instructions from the Controller.
2. Scope of processing
- Subject matter — provision of the HeyKiko AI agent platform.
- Data types — content uploaded by the Controller and end-user conversation data.
- Data subjects — the Controller's staff and end users.
3. Confidentiality
Personnel authorised to process personal data are bound by appropriate confidentiality obligations.
4. Security measures
We implement technical and organisational measures appropriate to the risk, including encryption in transit and at rest, access controls, immutable audit logging, and regular security review.
5. Sub-processors
The Controller authorises the use of vetted sub-processors (such as cloud hosting and AI model providers) under terms no less protective than this DPA. We maintain a current list and will notify of material changes.
6. Data subject requests
We will assist the Controller, as far as reasonably possible, in responding to requests from data subjects to exercise their rights under applicable law.
7. Breach notification
We will notify the Controller without undue delay after becoming aware of a personal-data breach affecting the Controller's data.
8. Deletion and return
On termination, we will delete or return personal data in accordance with the Controller's instructions and applicable retention requirements.
Questions about this policy? Email support@hannsville.com.