Data Processing Agreement
This Data Processing Agreement (DPA) applies when a subscribing business (the "Customer") uploads personal data into KaydPOS. It forms part of the Terms of Service.
1. Parties and roles
This Data Processing Agreement ("DPA") is between the subscribing business ("Customer", Controller) and KaydPOS ("Processor"), and applies whenever the Customer's personal data is processed through the KaydPOS platform. It forms part of, and is incorporated into, the Terms of Service.
2. Subject matter and duration
KaydPOS processes personal data on the Customer's behalf for the purpose of providing the cloud point-of-sale platform described in the Terms of Service, for as long as the Customer's subscription is active, plus the data export and deletion period described in Section 12.
3. Nature and purpose of processing
KaydPOS stores, retrieves, and makes available the data the Customer enters into the platform (or causes to be entered by its staff), so that the Customer can run its sales, inventory, staff and reporting operations. KaydPOS does not process this data for any purpose of its own.
4. Data types and data subjects
| Data subjects | Typical personal data |
|---|---|
| Customer's staff (business owner, cashiers, managers) | Name, username, contact details, role/permissions, activity logs |
| Customer's own customers | Name, contact details, purchase history, credit/balance information, as entered by the Customer |
5. Processing on the Customer's instructions
KaydPOS will process personal data only on the Customer's documented instructions — which includes the Customer's own configuration and use of the platform's normal features — unless required to do otherwise by law, in which case KaydPOS will inform the Customer beforehand unless legally prohibited from doing so.
6. Confidentiality
KaydPOS ensures that any personnel authorised to process personal data are subject to an appropriate confidentiality obligation.
7. Technical and organisational measures
The following measures are actually implemented in the platform as of this document's last update:
- Tenant isolation — each business's data is scoped to that business at the application and database-query level, so one business cannot query or view another's records.
- Access controls — role- and permission-based access within a business account, so staff only see what their role permits.
- Transport encryption — HTTPS is enforced site-wide with HTTP Strict Transport Security (HSTS).
- Password hashing — passwords are stored using one-way cryptographic hashing (bcrypt), never in plain text.
- Login rate limiting — repeated failed login attempts are throttled.
- Production hardening — debug mode and detailed error/stack traces are disabled in production; error pages do not expose internal details.
- Logging — application error logs are kept for operational troubleshooting and security review.
- Backups — periodic backups of the application database are taken and stored outside the publicly accessible web directory.
See Annex B for the itemised list. No certification (ISO, SOC 2, PCI DSS or otherwise) is claimed, because none currently exists for KaydPOS.
8. Subprocessors
The Customer authorises KaydPOS to engage the subprocessors listed in Annex C, which is kept up to date at /subprocessors. KaydPOS will provide notice of any intended addition or replacement of a subprocessor with a material change in the nature of processing, giving the Customer an opportunity to object on reasonable data-protection grounds.
9. International transfers
The infrastructure hosting the KaydPOS platform is located in Frankfurt, Germany (EU) — verified directly by network geolocation of the production server. Processing the Customer's data therefore involves transferring it to and storing it in Germany/the EU. No specific formal transfer mechanism (such as Standard Contractual Clauses) beyond the hosting provider's own published policies has been independently confirmed. A Customer that needs more detail for its own compliance purposes should contact KaydPOS at privacy@kaydpos.com.
10. Personal data breach notification
KaydPOS will notify the Customer without undue delay after becoming aware of a personal data breach affecting the Customer's data, and will provide the information reasonably available at the time to help the Customer meet its own notification obligations.
11. Assistance with data-subject requests
Where a data subject exercises a right (access, correction, deletion, restriction, objection, or portability) directly with KaydPOS regarding data the Customer controls, KaydPOS will forward the request to the Customer promptly and provide reasonable technical assistance to help the Customer respond, including for data protection impact assessments where genuinely applicable given the nature of processing.
12. Return and deletion of data
Following termination of the Customer's subscription, KaydPOS will make the Customer's data available for export for a limited period, and will delete or anonymise it thereafter, except to the extent retention is required by law. The specific export window and deletion timeline are set out on the Billing, Cancellation and Refunds page.
13. Audit and information rights
KaydPOS will make available to the Customer the information reasonably necessary to demonstrate compliance with this DPA, and will allow for and contribute to audits conducted by the Customer or an auditor mandated by the Customer, subject to reasonable notice, scope, and confidentiality protections, and without requiring disclosure of other customers' data or KaydPOS's internal security architecture.
14. Liability
Liability under this DPA is subject to the limitation of liability set out in the Terms of Service.
Annex A — Processing activities
| Activity | Description |
|---|---|
| Storage | Personal data entered by the Customer is stored in the platform's database. |
| Retrieval and display | Data is retrieved and displayed to the Customer's authorised staff through the application. |
| Reporting | Sales, stock and staff data is aggregated into reports for the Customer's own use. |
| Backup | Periodic database backups for disaster recovery. |
Annex B — Technical and organisational measures
- Tenant/business-level data isolation
- Role-based access control within each business account
- HTTPS with HSTS enforced site-wide
- Password hashing (bcrypt)
- Login rate limiting
- Production debug mode disabled; generic error pages
- Application error logging
- Periodic database backups stored outside the public web directory
Annex C — Subprocessors
See the live, maintained list at https://kaydpos.com/subprocessors, which is incorporated into this Annex by reference and kept current.