Contents7 sections
Scope and application
This document concerns personal-data processing by Kortyx S.L. for customers of hosted Kortyx Cloud. A separately executed agreement, with completed processing instructions and schedules, is required before customer personal-data processing is authorized. Do not submit real customer personal data before that process is complete. Independently operated OSS SDK applications and self-hosted Studio deployments have their own operator responsibilities.
Parties, roles and processing schedule
For approved customer application personal data, the customer’s controller/processor role and Kortyx’s processor/subprocessor role must be specified in the signed agreement. Subject matter, duration, nature and purposes, categories of data subjects and personal data, and the customer’s documented instructions must be completed for the actual service. Account administration for Kortyx’s own purposes is addressed separately in the Cloud Privacy Notice.
Instructions and confidentiality
The final agreement must bind processing to documented lawful instructions, including transfers, and address personnel confidentiality, authorized access, and requests that exceed or conflict with those instructions. No completed instruction schedule is established by viewing this page.
Security and assistance
The final agreement must specify technical and organizational measures supported by operational evidence and assistance with data-subject rights, security incidents, breach obligations and impact assessments. Measures, responsibilities, notification procedures and timings remain to be agreed. This document does not claim certifications or unverified security commitments.
Subprocessors and international transfers
The final agreement must establish authorization for subprocessors, a verified schedule, notice of changes and an objection process, and applicable flow-down obligations. Locations and any required international-transfer mechanisms and assessments must be verified. The subprocessor schedule is at https://kortyx.io/cloud/subprocessors. Customer-selected providers must be classified by their actual role.
Return, deletion, information and audits
The final agreement must specify return/deletion on termination, legally required retention, backup handling, information demonstrating compliance, and audit/inspection rights with practical procedures. Data retention, deletion verification and assistance commitments must match the approved service and evidence.
Completion and execution
Business/contact address, applicable registration/tax details, a private legal/privacy channel, processing and security annexes, retention schedule, transfer safeguards and legal review remain outstanding. Terms acceptance alone does not execute this DPA. Publication and execution of a final DPA require a separate authorized process.