Kintsugi Data Processing Agreement
Last updated: Aug 26, 2026
This Data Processing Agreement (this “DPA”) is incorporated by reference into the agreement between Kintsugi AI, Inc. (“Kintsugi”) and the customer that has entered into that agreement (“Customer”) for Customer’s use of Kintsugi’s services (the “Agreement”). This DPA applies whenever Kintsugi processes Personal Information on Customer’s behalf in providing the Services. Capitalized terms not defined here have the meanings given in the Agreement. Kintsugi may update this DPA in accordance with the modification provisions of the Agreement, provided no update will materially reduce the protections afforded to Personal Information.
1. DEFINITIONS
“CCPA” means the California Consumer Privacy Act of 2018, as amended by the California Privacy Rights Act, and its implementing regulations.
“Data Protection Laws” means all U.S. federal and state privacy and data protection laws applicable to Kintsugi’s processing of Personal Information under the Agreement, including the CCPA and comparable state privacy statutes.
“Personal Information” means Customer Data that identifies, relates to, describes, or could reasonably be linked with a particular individual or household, or that is otherwise “personal information” or “personal data” under Data Protection Laws.
“Process” (and its variants) means any operation performed on Personal Information, including collection, use, storage, retrieval, disclosure, and deletion. “Business,” “Service Provider,” “Consumer,” “Sell,” and “Share” have the meanings given in the CCPA.
“Security Incident” means a breach of security leading to the accidental or unlawful destruction, loss, alteration, or unauthorized disclosure of or access to Personal Information Processed by Kintsugi under this DPA. Security Incidents do not include unsuccessful attempts or activities that do not compromise Personal Information, such as blocked intrusion attempts, port scans, or failed log-in attempts.
“Sub-processor” means a third party engaged by Kintsugi to Process Personal Information on Customer’s behalf in connection with the Services.
2. ROLES AND SCOPE
2.1 Roles. As between the Parties, Customer is the Business and Kintsugi is a Service Provider with respect to Personal Information Processed under the Agreement. Annex B describes the categories of Personal Information, the categories of individuals, and the nature and purpose of the Processing.
2.2 Customer’s Responsibilities. Customer is responsible for the accuracy and lawfulness of the Personal Information it provides, for providing any notices to and obtaining any consents from individuals that Data Protection Laws require, and for its own compliance with Data Protection Laws as a Business.
2.3 Instructions. Kintsugi will Process Personal Information only to perform the Services and on Customer’s documented instructions, unless required to do otherwise by law, in which case Kintsugi will inform Customer of that requirement before Processing unless the law prohibits it. The Agreement, this DPA, and Customer’s configuration and use of the Services constitute Customer’s complete documented instructions. Kintsugi will promptly inform Customer if, in Kintsugi’s reasonable opinion, an instruction violates Data Protection Laws.
3. SERVICE PROVIDER COMMITMENTS
3.1 Kintsugi certifies that it will: (a) not Sell or Share Personal Information; (b) not retain, use, or disclose Personal Information for any purpose other than performing the Services specified in the Agreement, or as otherwise permitted by the CCPA; (c) not retain, use, or disclose Personal Information outside the direct business relationship between Kintsugi and Customer; (d) not combine Personal Information with personal information Kintsugi receives from or on behalf of another party, except as permitted by the CCPA; and (e) notify Customer promptly if Kintsugi determines it can no longer meet its obligations under Data Protection Laws. Customer may take reasonable and appropriate steps permitted by the CCPA to confirm that Kintsugi uses Personal Information consistently with Customer’s obligations, and to stop and remediate any unauthorized use.
3.2 Kintsugi will ensure that personnel it authorizes to Process Personal Information are bound by written or statutory confidentiality obligations and receive appropriate training on protecting Personal Information.
4. SECURITY
4.1 Kintsugi will implement and maintain reasonable technical, administrative, and physical safeguards designed to protect Personal Information against Security Incidents, appropriate to the nature of the Personal Information, including the measures described in Annex. Kintsugi may update those measures from time to time, provided the updates do not materially reduce the overall level of protection.
5. SUB-PROCESSOR
5.1 Changes. Kintsugi will give at least 30 days’ notice before adding or replacing a Sub-processor that Processes Personal Information. Customer may object in writing on reasonable data protection grounds within that period, and the Parties will work in good faith to resolve the objection. If they cannot, Customer may terminate the affected Service and receive a pro rata refund of prepaid fees for the unused remainder of the applicable Subscription Term.
5.2 Flow-Down. Kintsugi will impose data protection obligations on each Sub-processor that are no less protective than those in this DPA as applicable to the services the Sub-processor provides, and remains responsible for each Sub-processor’s performance.
6. INDIVIDUAL RIGHTS REQUESTS
6.1 Kintsugi will promptly notify Customer if it receives a request from an individual to exercise rights under Data Protection Laws with respect to Personal Information Processed under this DPA, and will not respond except to direct the individual to Customer, unless the law requires otherwise. Taking into account the nature of the Processing, Kintsugi will provide reasonable assistance, through the functionality of the Services or otherwise, to help Customer respond to such requests.
7. SECURITY INCIDENT NOTIFICATION
7.1 Kintsugi will notify Customer without undue delay, and in any event within 72 hours, after becoming aware of a Security Incident. The notice will include the information reasonably available to Kintsugi about the nature of the incident, the categories and approximate number of individuals and records affected, the likely consequences, and the measures taken or proposed. Kintsugi will take reasonable steps to contain and remediate the incident and will provide updates as further information becomes available. Kintsugi’s notification is not an acknowledgment of fault or liability.
8. AUDITS AND ASSESSMENTS
8.1 Reports. Upon Customer’s reasonable written request and subject to confidentiality obligations, Kintsugi will make available its then-current third-party audit report or security certification SOC 2 Type II, which the Parties agree will ordinarily satisfy Customer’s audit rights under this DPA and Data Protection Laws.
8.2 Further Assessment. If Customer reasonably determines the reports in Section 8.1 are insufficient to demonstrate compliance as required by Data Protection Laws, Customer (or an independent auditor on its behalf that is not a competitor of Kintsugi) may assess Kintsugi’s compliance with this DPA no more than once per twelve (12) months, on at least 30 days’ notice, during business hours, in a manner that does not disrupt Kintsugi’s operations, and subject to confidentiality obligations and Kintsugi’s security policies. Customer bears the cost. Nothing in this Section requires Kintsugi to disclose information about other customers or information that would compromise its security.
9. DELETION AND RETURN
9.1 On termination or expiration of the Agreement, Kintsugi will delete or return Personal Information in accordance with the data return and deletion provisions of the Agreement. Kintsugi may retain Personal Information contained in automatic backups or archives, or as required by law (including tax record retention requirements applicable to filings Kintsugi prepared), in which case this DPA continues to apply to the retained Personal Information until it is deleted.
10. INTERNATIONAL DATA
10.1 The Services are provided from and Personal Information is Processed in the United States. If Kintsugi Processes personal data subject to the EU or UK General Data Protection Regulation or Swiss data protection law on Customer’s behalf, the Parties will execute an addendum to this DPA incorporating the applicable transfer mechanism, including the European Commission’s Standard Contractual Clauses and the UK International Data Transfer Addendum as applicable. Until such an addendum is executed, Customer shall not submit personal data subject to those laws to the Services.
11. GENERAL
11.1 Each Party’s liability arising out of this DPA is subject to the exclusions and limitations of liability set forth in the Agreement, and liability under this DPA and the Agreement is aggregated for that purpose, in each case to the maximum extent permitted by Data Protection Laws. If this DPA conflicts with the Agreement regarding the Processing of Personal Information, this DPA controls. This DPA terminates automatically when Kintsugi ceases all Processing of Personal Information under the Agreement, except for provisions that by their nature survive.
ANNEX — DESCRIPTION OF PROCESSING
A. Categories of individuals: Customer’s customers and end purchasers; Customer’s employees, contractors, and agents who are Authorized Users; other individuals whose information appears in Customer Data.
B. Categories of Personal Information: names; email addresses; billing and shipping addresses; transaction data (items purchased, amounts, dates); tax registration and exemption certificate information; business contact information; IP addresses and technical identifiers.
C. Sensitive information: none intended or required. Customer shall not submit sensitive personal information except as expressly agreed in an Order Form.
D. Nature and purpose of Processing: providing Kintsugi’s tax compliance services, including tax calculation, nexus monitoring, registration, exemption certificate management, return preparation, filing, remittance, and voluntary disclosure agreement services; customer support; and compliance with applicable law.
E. Duration and frequency: continuous, for the term of the Agreement plus the retention periods described in the Agreement and Section 9 of this DPA.
F. Kintsugi contact for privacy matters: legal@trykintsugi.com