Kinetry Data Processing Addendum
Effective: July 20, 2026
This Data Processing Addendum ("DPA") supplements and forms part of the Kinetry Terms of Service or other written agreement (the "Agreement") between Kalgren Consulting LLC, doing business as Kinetry ("Kinetry," "Company," "we," or "us"), and the customer that accepted the Agreement ("Customer," "you"). It governs the processing of personal information that Kinetry performs on Customer's behalf in providing the Kinetry service (the "Services"). If there is a conflict between this DPA and the Agreement on the subject of data protection, this DPA controls. Capitalized terms not defined here have the meanings given in the Agreement.
This DPA reflects Kinetry's current posture as a multi-tenant B2B service offered to customers in the United States only. It does not grant capabilities Kinetry does not have and does not claim any certification.
1. Definitions
- "Applicable Data Protection Law" — the privacy and data-protection laws of the United States that apply to the processing under this DPA, including the California Consumer Privacy Act as amended by the California Privacy Rights Act ("CCPA/CPRA"), the Colorado Privacy Act ("CPA"), and comparable state laws, in each case as applicable to the parties.
- "Participant Workspace Data" — personal information within Customer Data that relates to participants and other individuals in Customer's workspace, including roster information, assessment responses, observation notes, computed behavior scores, and AI-generated coaching content, that Kinetry processes on Customer's behalf.
- "Account and Site Data" — sign-in email addresses, Terms-acceptance records, support communications, billing identifiers, and service logs (timestamps, IP address, device or browser type) that Kinetry determines the purposes and means of processing.
- "Personal Information" — information that identifies, relates to, or could reasonably be linked with an identified or identifiable individual, as defined under Applicable Data Protection Law; references to "personal data" have the equivalent meaning.
- "Processing" and "process" — any operation performed on Personal Information, whether automated or not.
- "Subprocessor" — a third party engaged by Kinetry to process Participant Workspace Data in connection with the Services.
- "Data Subject Request" — a request from or on behalf of an individual to exercise rights under Applicable Data Protection Law, such as access, deletion, correction, or portability.
- "Business," "Service Provider," "Controller," "Processor," and "Sale" — have the meanings given under Applicable Data Protection Law.
2. Scope and Roles of the Parties
- Participant Workspace Data. With respect to Participant Workspace Data, Customer is the Business and Controller, and Kinetry is the Service Provider and Processor. Customer decides whether to offer the Services, which individuals participate, what assessments are collected, and why. Kinetry processes Participant Workspace Data solely on Customer's behalf and under Customer's documented instructions to provide the Services.
- Account and Site Data. With respect to Account and Site Data, Kinetry is the Business and Controller and is directly responsible for that data. Kinetry's handling of Account and Site Data is governed by the Kinetry Privacy Policy, not by this DPA's processor obligations.
- Assessment modes. The Services operate in one of two modes for a given workspace: multi-rater (360) mode, in which results are computed from the combined ratings of multiple raters; and advisor (single-assessor) mode, in which a Customer-designated advisor authors the assessments for individuals who do not log in. Customer's role as Controller and Business is the same in both modes.
- Customer responsibilities. Customer is responsible for the lawfulness of its instructions and of the Participant Workspace Data it submits, and for providing any notices to, and obtaining any consents or authorizations from, participants that Applicable Data Protection Law or Customer's own policies require. Customer's obligations under the Agreement, including §4 (Customer Responsibilities; Lawful Basis) and §7 (No Employment Decisions), continue to apply.
3. Processing on Documented Instructions
- Kinetry will process Participant Workspace Data only on Customer's documented instructions, including with respect to transfers, unless required to do otherwise by applicable law; in that case, Kinetry will inform Customer of the legal requirement before processing, unless the law prohibits such notice on important grounds of public interest.
- Customer's documented instructions are set out in the Agreement, this DPA, and Customer's configuration and use of the Services, and may be supplemented by further written instructions the parties agree upon. The Services' standard functionality — collecting assessments, computing scores, generating coaching content, delivering reports and analytics, and providing support — constitutes documented and agreed instructions.
- Kinetry will not process Participant Workspace Data for any purpose other than providing the Services and performing under the Agreement. Kinetry will not sell Participant Workspace Data, will not share it for cross-context behavioral advertising, and will not retain, use, or disclose it outside the direct business relationship with Customer or for any purpose other than the business purposes specified in this DPA and the Agreement.
- If Kinetry believes an instruction infringes Applicable Data Protection Law, it will inform Customer without undue delay; Kinetry is not obligated to review the legality of Customer's instructions generally.
- The subject matter, duration, nature and purpose of the processing, the types of Personal Information, and the categories of data subjects are described in Section 15 (Details of Processing).
4. Aggregated and De-identified Data
- As permitted by the Agreement, Kinetry may create aggregated, de-identified data derived from Customer Data and Results that does not identify, and cannot reasonably be used to identify, any individual, Customer, or Customer's organization. Such data is not Participant Workspace Data and is not subject to the processor obligations of this DPA.
- Where Kinetry de-identifies Personal Information, Kinetry will maintain and use it in de-identified form, will not attempt to re-identify it except to test the effectiveness of de-identification, and will obligate recipients to the same, consistent with Applicable Data Protection Law.
5. Confidentiality of Personnel
- Kinetry will ensure that personnel authorized to process Participant Workspace Data are bound by appropriate obligations of confidentiality and are made aware of the confidential nature of the data.
- Kinetry limits access to Participant Workspace Data to personnel who need it to operate, support, secure, or improve the Services, and — where Customer has engaged Kinetry for advisory services — to deliver those services, in each case on a least-privilege basis. Customer acknowledges, consistent with §8 of the Agreement, that authorized Kinetry personnel, including Kinetry's principal consultant, retain platform-level administrative access for these purposes, subject to the confidentiality obligations of the Agreement.
6. Security Measures
- Kinetry will implement and maintain reasonable technical and organizational measures designed to protect Participant Workspace Data against unauthorized or unlawful processing and against accidental loss, destruction, damage, alteration, or disclosure, appropriate to the nature of the data and the risks involved. These measures are described further in the Kinetry Security Overview, as updated from time to time.
- Kinetry's current security posture includes:
- encryption of data in transit using TLS;
- passwordless authentication using single-use, expiring, rate-limited sign-in links, with no stored passwords and no password database to compromise; session state is carried in an HMAC-signed, httpOnly cookie with a baked-in expiry;
- a bot-protection challenge (Cloudflare Turnstile) on the signup page;
- role- and tenant-scoped access controls enforced on every data path, so that a workspace's data is accessible only to that workspace's authorized users and roles;
- scoring internals, weights, and formulas kept server-side and not exposed to clients;
- least-privilege staff access limited to personnel who need it;
- error monitoring via Sentry configured without session replay and without default collection of personal information;
- statistical suppression in multi-rater mode that hides results computed from fewer than the minimum number of raters, reducing the ability to infer an individual rater's responses.
- Kinetry is not certified under SOC 2, ISO 27001, or any comparable standard, and makes no such representation. Kinetry may modify specific measures over time provided it does not materially reduce the overall level of protection for Participant Workspace Data.
- Customer is responsible for its own security decisions within the Services, including administrator role assignments, org-structure and visibility settings, and safeguarding of sign-in links, as described in the Agreement.
7. Subprocessors
- Customer authorizes Kinetry to engage Subprocessors to process Participant Workspace Data in connection with the Services. Kinetry will impose data-protection and confidentiality obligations on each Subprocessor that are substantially consistent with those in this DPA, and Kinetry remains responsible for each Subprocessor's performance of its obligations.
- The Subprocessors Kinetry currently uses, and their purposes, are:
- Neon — database hosting (storage of workspace and account data)
- Vercel — application hosting (running the Services)
- Stripe — payment processing via hosted checkout and billing portal (card data never touches Kinetry systems; Kinetry stores only Stripe customer and subscription identifiers)
- Resend — transactional email delivery (sign-in links, cycle and results notifications, service messages)
- OpenAI API — generation of AI coaching summaries and reports from Customer Data (OpenAI does not train models on data submitted through the API)
- Sentry — error tracking and diagnostics (configured without session replay and without default personal information)
- Cloudflare — Turnstile bot-challenge on the signup page
- Plausible — optional cookieless page analytics; currently disabled in production
- Right to object. Kinetry will provide Customer a mechanism to be notified of any intended addition or replacement of a Subprocessor that processes Participant Workspace Data, giving Customer a reasonable opportunity to object on reasonable data-protection grounds before the new Subprocessor begins such processing. If Customer objects and the parties cannot resolve the objection, Customer may, as its exclusive remedy, terminate the affected Services and receive the data-export assistance described in this DPA.
8. Assistance with Data Subject Requests
- Taking into account the nature of the processing, Kinetry will provide reasonable assistance to enable Customer to respond to Data Subject Requests relating to Participant Workspace Data. Because Customer is the Controller and Business for that data, individuals are directed to raise such requests with Customer, and Kinetry will not respond directly to a participant's Data Subject Request except to route it to Customer or as required by law.
- The Services include self-service tooling that satisfies most assistance obligations without additional engineering effort:
- Workspace export. A workspace administrator can download the workspace's complete data and results at any time (Admin → Company settings → Export workspace data).
- Per-person export. A workspace administrator can export the data for any individual (Admin → People → Export data). Exports respect rater confidentiality — in multi-rater mode they never include assessment responses authored by other raters, and a person's own raw self-assessment entries are included only when that person downloads the export themselves.
- Person erasure. A workspace administrator can permanently erase a removed person and everything recorded about them (Admin → People → Erase permanently). Erasure is immediate in production systems and cannot be undone. To protect rater confidentiality, past cycles in which the erased person assessed others are frozen and their already-published results stand as-is rather than being re-scored from the remaining responses.
- Workspace deletion. Customer may request deletion of the entire workspace by contacting privacy@kinetry.ai; Kinetry performs it after any active subscription is cancelled.
- Where a request cannot be fulfilled through this tooling, Kinetry will provide reasonable additional assistance at Customer's request, and may charge for assistance that is unreasonable, repetitive, or manifestly unfounded.
9. Personal Data Breach Notification
- Kinetry will notify Customer without undue delay after becoming aware of a confirmed breach of security leading to the accidental or unlawful destruction, loss, alteration, or unauthorized disclosure of or access to Participant Workspace Data ("Personal Data Breach").
- The notification will describe, to the extent then known and as it becomes available, the nature of the Personal Data Breach, the categories and approximate number of individuals and records affected, the likely consequences, and the measures taken or proposed to address it and mitigate its effects.
- Kinetry will take reasonable steps to investigate, mitigate, and remediate the Personal Data Breach, and will reasonably cooperate with Customer's own breach-response and notification obligations. Kinetry's notification is not an acknowledgment of fault or liability.
- Customer is responsible for determining whether the Personal Data Breach requires notice to individuals, regulators, or others under Applicable Data Protection Law, and for making any such notifications, except where Kinetry is separately required by law to notify.
10. Deletion and Return on Termination
- On expiration or termination of the Services, and at Customer's choice, Kinetry will delete or return Participant Workspace Data. Customer may export its Customer Data and Results in the formats the Services provide, using the export tooling described above, at any time during the term and for the export window described in the Agreement (currently 30 days after termination).
- After the export window, Kinetry may delete Participant Workspace Data from production systems within a commercially reasonable period, except to the extent retention is required by law.
- Residual copies may persist briefly after deletion: encrypted database backups age out within approximately 30 days, and error-tracking records age out within up to 90 days. A minimal record that an erasure or deletion occurred — for example, who was erased, when, and the associated Terms-acceptance evidence — may be retained for legal purposes. Aggregated, de-identified data is not subject to these deletion obligations.
11. Audit and Information Rights
- Kinetry will make available to Customer information reasonably necessary to demonstrate Kinetry's compliance with this DPA, including the Kinetry Security Overview and responses to reasonable written security and privacy questionnaires.
- If Customer reasonably requires further information to satisfy an audit obligation under Applicable Data Protection Law, the parties will accommodate the audit through a records-based review: Customer may submit a written request, no more than once per twelve-month period absent a Personal Data Breach or regulator requirement, and Kinetry will respond with relevant documentation. Any audit will be conducted during business hours, with reasonable advance notice, subject to confidentiality obligations, and in a manner that does not disrupt Kinetry's operations or compromise the security or confidentiality of other customers' data. On-site or hands-on inspection of production systems is not provided, given the multi-tenant, shared-infrastructure nature of the Services.
12. International Transfers
- Kinetry stores and processes Participant Workspace Data in the United States and offers the Services to customers in the United States only. Kinetry does not currently make cross-border transfers of Participant Workspace Data outside the United States as part of providing the Services.
- If Kinetry later processes Participant Workspace Data in, or transfers it to, another jurisdiction, it will do so only in accordance with Applicable Data Protection Law and will implement any transfer mechanism and safeguards then required, and will update this DPA or provide notice as appropriate.
13. No Use of Data to Train General AI Models
- Kinetry does not use individual participant responses, notes, or other identifiable Participant Workspace Data, or other Customer confidential information, to train large language models or general-purpose AI models. The AI coaching content generated through the Services is produced by Kinetry's Subprocessor OpenAI via its API, which does not train models on data submitted through the API.
- AI-generated output is decision-support only. It is grounded in cited evidence, requires human review, is not professional advice, and is never an automated employment decision, consistent with §7 and §10 of the Agreement.
- Kinetry may update the underlying AI model over time; Kinetry will notify Customer of material changes as provided in the Agreement.
14. CCPA/CPRA and Colorado Service-Provider and Processor Terms
This Section applies to Participant Workspace Data that constitutes Personal Information subject to CCPA/CPRA or the CPA. For that data, Kinetry acts as a Service Provider (under CCPA/CPRA) and Processor (under the CPA), and:
- Kinetry processes Participant Workspace Data only to perform the business purposes specified in the Agreement and this DPA, and does not retain, use, or disclose it for any other purpose or outside the direct business relationship with Customer, except as permitted by Applicable Data Protection Law.
- Kinetry does not Sell Participant Workspace Data and does not share it for cross-context behavioral advertising, and no monetary or other valuable consideration is exchanged for the disclosure of Participant Workspace Data to Kinetry.
- Kinetry does not combine Participant Workspace Data with personal information it receives from, or on behalf of, other persons, or collects from its own interactions with individuals, except as permitted by Applicable Data Protection Law to perform a business purpose.
- Kinetry will comply with the applicable obligations of CCPA/CPRA and the CPA and provide the same level of privacy protection as required of a Service Provider or Processor.
- Kinetry will notify Customer if it determines it can no longer meet its obligations under Applicable Data Protection Law, and Customer may, on notice, take reasonable and appropriate steps to stop and remediate unauthorized use of Participant Workspace Data.
- Customer grants Kinetry the rights above solely to perform the Services and enable Kinetry to comply with its obligations. Customer, as Business and Controller, is responsible for providing required notices to participants, establishing a lawful basis, and honoring individuals' rights, with Kinetry's assistance as described in Section 8.
- The parties acknowledge that engaging a Subprocessor as permitted by Section 7 is not a Sale or Share of Personal Information.
15. Details of Processing
- Subject matter. Kinetry's provision of the Services to Customer under the Agreement.
- Duration. The term of the Agreement, plus the post-termination export and deletion periods described in Section 10.
- Nature and purpose. Collecting workplace behavioral assessments; computing behavior scores and analytics; generating AI-written coaching summaries and reports; delivering results, analytics, and reports; and providing support, security, and related operation of the Services.
- Categories of data subjects. Customer's participants, employees, contractors, advisors, and other Authorized Users whose behaviors are assessed or who use the Services.
- Types of Personal Information. Roster and profile information (name, work email, role, manager, department or team); assessment responses and observation notes; computed behavior scores and AI-generated coaching content; and sign-in and usage records (timestamps, IP address, device or browser type). Participants are instructed not to submit special or sensitive categories of information — including financial, religious, political, union, health, genetic, biometric, or sexual-orientation data — and Customer must not upload protected health information or other regulated medical records unless the parties separately agree in writing.
16. General
- Term. This DPA takes effect on the effective date of the Agreement, or on Customer's acceptance of this DPA if later, and remains in effect for as long as Kinetry processes Participant Workspace Data on Customer's behalf.
- Order of precedence. This DPA is incorporated into and forms part of the Agreement. In the event of a conflict regarding the processing of Participant Workspace Data, this DPA controls over the body of the Agreement; the Agreement otherwise governs.
- Liability. Each party's liability under this DPA is subject to the limitations and exclusions of liability set out in the Agreement.
- Changes. Kinetry may update this DPA to reflect changes in the Services, Subprocessors, or Applicable Data Protection Law, consistent with the change process in the Agreement, provided that no update will materially reduce the protections for Participant Workspace Data.
- Governing law. This DPA is governed by the law and venue provisions of the Agreement.
Contact: legal@kinetry.ai (legal and terms) · privacy@kinetry.ai (privacy and data) · Kalgren Consulting LLC (d/b/a Kinetry), Minnesota, USA