KaydPOS
Legal Sign in

On this page

  1. Parties and roles
  2. Subject matter and duration
  3. Nature and purpose of processing
  4. Data types and data subjects
  5. Processing on the Customer's instructions
  6. Confidentiality
  7. Technical and organisational measures
  8. Subprocessors
  9. International transfers
  10. Personal data breach notification
  11. Assistance with data-subject requests
  12. Return and deletion of data
  13. Audit and information rights
  14. Liability
  15. Annex A — Processing activities
  16. Annex B — Technical and organisational measures
  17. Annex C — Subprocessors

Data Processing Agreement

KaydPOS Version 1.0 Effective 2026-07-18 Last updated 2026-07-18 Operating from Somalia

This Data Processing Agreement (DPA) applies when a subscribing business (the "Customer") uploads personal data into KaydPOS. It forms part of the Terms of Service.

Operator identity note KaydPOS is currently operated and offered under the trading name "KaydPOS" from Somalia. The formal registered legal entity name and registration details have not yet been confirmed for publication and are not stated here to avoid publishing inaccurate information.

1. Parties and roles

This Data Processing Agreement ("DPA") is between the subscribing business ("Customer", Controller) and KaydPOS ("Processor"), and applies whenever the Customer's personal data is processed through the KaydPOS platform. It forms part of, and is incorporated into, the Terms of Service.

2. Subject matter and duration

KaydPOS processes personal data on the Customer's behalf for the purpose of providing the cloud point-of-sale platform described in the Terms of Service, for as long as the Customer's subscription is active, plus the data export and deletion period described in Section 12.

3. Nature and purpose of processing

KaydPOS stores, retrieves, and makes available the data the Customer enters into the platform (or causes to be entered by its staff), so that the Customer can run its sales, inventory, staff and reporting operations. KaydPOS does not process this data for any purpose of its own.

4. Data types and data subjects

Data subjectsTypical personal data
Customer's staff (business owner, cashiers, managers)Name, username, contact details, role/permissions, activity logs
Customer's own customersName, contact details, purchase history, credit/balance information, as entered by the Customer

5. Processing on the Customer's instructions

KaydPOS will process personal data only on the Customer's documented instructions — which includes the Customer's own configuration and use of the platform's normal features — unless required to do otherwise by law, in which case KaydPOS will inform the Customer beforehand unless legally prohibited from doing so.

6. Confidentiality

KaydPOS ensures that any personnel authorised to process personal data are subject to an appropriate confidentiality obligation.

7. Technical and organisational measures

The following measures are actually implemented in the platform as of this document's last update:

  • Tenant isolation — each business's data is scoped to that business at the application and database-query level, so one business cannot query or view another's records.
  • Access controls — role- and permission-based access within a business account, so staff only see what their role permits.
  • Transport encryption — HTTPS is enforced site-wide with HTTP Strict Transport Security (HSTS).
  • Password hashing — passwords are stored using one-way cryptographic hashing (bcrypt), never in plain text.
  • Login rate limiting — repeated failed login attempts are throttled.
  • Production hardening — debug mode and detailed error/stack traces are disabled in production; error pages do not expose internal details.
  • Logging — application error logs are kept for operational troubleshooting and security review.
  • Backups — periodic backups of the application database are taken and stored outside the publicly accessible web directory.

See Annex B for the itemised list. No certification (ISO, SOC 2, PCI DSS or otherwise) is claimed, because none currently exists for KaydPOS.

8. Subprocessors

The Customer authorises KaydPOS to engage the subprocessors listed in Annex C, which is kept up to date at /subprocessors. KaydPOS will provide notice of any intended addition or replacement of a subprocessor with a material change in the nature of processing, giving the Customer an opportunity to object on reasonable data-protection grounds.

9. International transfers

The infrastructure hosting the KaydPOS platform is located in Frankfurt, Germany (EU) — verified directly by network geolocation of the production server. Processing the Customer's data therefore involves transferring it to and storing it in Germany/the EU. No specific formal transfer mechanism (such as Standard Contractual Clauses) beyond the hosting provider's own published policies has been independently confirmed. A Customer that needs more detail for its own compliance purposes should contact KaydPOS at privacy@kaydpos.com.

10. Personal data breach notification

KaydPOS will notify the Customer without undue delay after becoming aware of a personal data breach affecting the Customer's data, and will provide the information reasonably available at the time to help the Customer meet its own notification obligations.

11. Assistance with data-subject requests

Where a data subject exercises a right (access, correction, deletion, restriction, objection, or portability) directly with KaydPOS regarding data the Customer controls, KaydPOS will forward the request to the Customer promptly and provide reasonable technical assistance to help the Customer respond, including for data protection impact assessments where genuinely applicable given the nature of processing.

12. Return and deletion of data

Following termination of the Customer's subscription, KaydPOS will make the Customer's data available for export for a limited period, and will delete or anonymise it thereafter, except to the extent retention is required by law. The specific export window and deletion timeline are set out on the Billing, Cancellation and Refunds page.

13. Audit and information rights

KaydPOS will make available to the Customer the information reasonably necessary to demonstrate compliance with this DPA, and will allow for and contribute to audits conducted by the Customer or an auditor mandated by the Customer, subject to reasonable notice, scope, and confidentiality protections, and without requiring disclosure of other customers' data or KaydPOS's internal security architecture.

14. Liability

Liability under this DPA is subject to the limitation of liability set out in the Terms of Service.

Annex A — Processing activities

ActivityDescription
StoragePersonal data entered by the Customer is stored in the platform's database.
Retrieval and displayData is retrieved and displayed to the Customer's authorised staff through the application.
ReportingSales, stock and staff data is aggregated into reports for the Customer's own use.
BackupPeriodic database backups for disaster recovery.

Annex B — Technical and organisational measures

  • Tenant/business-level data isolation
  • Role-based access control within each business account
  • HTTPS with HSTS enforced site-wide
  • Password hashing (bcrypt)
  • Login rate limiting
  • Production debug mode disabled; generic error pages
  • Application error logging
  • Periodic database backups stored outside the public web directory

Annex C — Subprocessors

See the live, maintained list at https://kaydpos.com/subprocessors, which is incorporated into this Annex by reference and kept current.

← Back to homepage