Scope and Application
Definitions
In this DPA:
“Account Data” means personal data relating to the Customer’s relationship with Kendis, including the names and contact details of users and administrators, billing and subscription information, and the content of support communications.
“Applicable Laws” means the data-protection and privacy laws applicable to the Processing of Customer Personal Data under this DPA, including, where applicable, EU Data Protection Laws and US state privacy laws.
“Contracted Processor” means Kendis or a Subprocessor.
“Customer Personal Data” means any personal data Processed by a Contracted Processor on behalf of the Customer in connection with the Cloud Services under the Principal Agreement, including personal data within Trial Data or Licensee Data (each as defined in the Principal Agreement, where used).
“EU Data Protection Laws” means the GDPR and any laws implementing or supplementing the GDPR, together with, where applicable, the equivalent laws of the United Kingdom and Switzerland.
“GDPR” means EU Regulation 2016/679.
“Hosting Region” means the geographic location in which Customer Personal Data (other than Account Data) is stored and Processed, being a Hosting Region identified in the Hosting and Subprocessor Schedule, as selected by the Customer or specified under the Principal Agreement.
“Hosting and Subprocessor Schedule” or “Schedule” means the Kendis Hosting and Subprocessor Schedule published at trust.kendis.io/subprocessors, identifying the Hosting Regions offered by Kendis, the infrastructure providers and Subprocessors engaged in each, and the transfer mechanisms relied upon, as updated in accordance with Section 6 (Subprocessing). The Schedule is incorporated into this DPA by reference.
“Restricted Transfer” means a transfer of Customer Personal Data to a Contracted Processor, or between Contracted Processors, that would be prohibited by EU Data Protection Laws in the absence of the Standard Contractual Clauses or another lawful transfer mechanism.
“Standard Contractual Clauses” or “SCCs” means the standard contractual clauses for international transfers approved by the European Commission, as set out or incorporated in Annex 3.
“Subprocessor” means any third party engaged by Kendis to Process Customer Personal Data in connection with the Cloud Services.
The terms “Controller”, “Data Subject”, “Personal Data”, “Personal Data Breach”, “Processing” and “Supervisory Authority” have the meanings given in the GDPR, and “Sell”, “Share”, “Service Provider” and “Business Purpose” have the meanings given under the CCPA (as defined in Section 13), in each case as the context requires. “Include” means include without limitation.
Processing of Customer Personal Data
Personnel
Kendis shall take reasonable steps to ensure the reliability of any personnel of a Contracted Processor with access to Customer Personal Data, ensure access is limited to those who need it to provide the Cloud Services, and ensure such personnel are bound by confidentiality obligations. Kendis shall use commercially reasonable efforts to screen personnel with access to Customer Personal Data against applicable sanctions and denied- or restricted-party lists, and shall not knowingly permit any individual who is identified on such a list to have access to Customer Personal Data.
Security
Taking into account the state of the art, costs of implementation, and the nature, scope, context and purposes of Processing, as well as the risks to Data Subjects, Kendis shall implement appropriate technical and organisational measures to ensure a level of security appropriate to the risk, including, as appropriate, the measures referred to in Article 32(1) GDPR. In assessing the appropriate level of security, Kendis shall take particular account of the risks presented by a Personal Data Breach.
Subprocessing
Data Subject Rights
Taking into account the nature of the Processing, Kendis shall assist the Customer by appropriate technical and organisational measures, insofar as possible, to respond to requests from Data Subjects. Kendis shall promptly notify the Customer if a Contracted Processor receives a request from a Data Subject relating to Customer Personal Data, and shall not respond to the request except on the Customer’s documented instructions or as required by applicable law.
Personal Data Breach
Kendis shall notify the Customer without undue delay, and in any event within seventy-two (72) hours, after becoming aware of a Personal Data Breach affecting Customer Personal Data, and shall provide sufficient information to enable the Customer to meet any obligation to report the breach or inform Data Subjects. Kendis shall cooperate with the Customer and take reasonable steps to assist in the investigation, mitigation and remediation of the breach. For the avoidance of doubt, unsuccessful or immaterial security events that do not result in unauthorised access to, or compromise of, Customer Personal Data do not constitute a Personal Data Breach for the purposes of this Section and are not individually notifiable, including pings and other broadcast attacks on firewalls or edge servers, port scans, unsuccessful log-on attempts, denial-of-service attacks that do not result in the relevant service being taken offline, and similar events that do not result in unauthorised access to or compromise of Customer Personal Data.
Data Protection Impact Assessment
Kendis shall provide reasonable assistance to the Customer with data-protection impact assessments and prior consultations with Supervisory Authorities that the Customer reasonably considers required under Article 35 or 36 GDPR, in each case solely in relation to the Processing of Customer Personal Data and taking into account the nature of the Processing and the information available to the Contracted Processors.
Deletion and Return
Audit and Compliance
Kendis shall demonstrate compliance with this DPA through documentary evidence. On reasonable written request (no more than once per calendar year, except following a confirmed Personal Data Breach affecting Customer Personal Data or where required by a competent Supervisory Authority), Kendis shall provide, within thirty (30) days: its current ISO/IEC 27001 certificate (or a substantially equivalent recognised certification); the most recent third-party security and compliance reports of its key Subprocessors as identified in the Schedule, as made available under those Subprocessors’ own compliance programmes; a summary of its most recent third-party penetration test; and a completed security questionnaire in a format reasonably required by the Customer. Information provided under this Section is Kendis’s Confidential Information. Customer Personal Data is hosted by the Subprocessors identified in the Schedule in their data centres; inspection of those facilities is governed by those Subprocessors’ own audit programmes and certifications, and on-site audits at Kendis’s premises are not available, as Customer Personal Data is not stored there. Where, after good-faith review of the documentary evidence, the Customer has a reasonable, specific and material concern that has not been adequately addressed, the Parties shall promptly meet and confer in good faith, including through written follow-up, additional documentation, or remote walk-through sessions as appropriate. Where required by a competent Supervisory Authority or by mandatory Applicable Laws, Kendis shall additionally provide such cooperation as is legally required.
Hosting Regions and Restricted Transfers
US State Privacy Laws
This Section applies where US state privacy or data-protection laws apply to the Processing of Customer Personal Data, including the California Consumer Privacy Act as amended by the California Privacy Rights Act and its regulations (“CCPA”) and comparable laws of other US states (including, as applicable, Virginia, Colorado, Connecticut, Utah and Texas) (together, “US Privacy Laws”). Where this Section applies: (a) Kendis acts as a “service provider” or “processor” and the Customer acts as the “business” or “controller”; (b) Kendis shall not Sell or Share Customer Personal Data, and shall not retain, use or disclose Customer Personal Data (i) for any purpose other than the specific Business Purpose of providing the Cloud Services, (ii) outside the direct business relationship between the Parties, or (iii) by combining it with personal information obtained from sources other than the Customer, except as permitted by US Privacy Laws; (c) Kendis certifies that it understands the restrictions in this Section and will comply with them, and will notify the Customer if it determines it can no longer meet its obligations under US Privacy Laws; (d) Kendis shall provide the same level of privacy protection as is required of businesses by US Privacy Laws, and shall reasonably assist the Customer in responding to verifiable consumer requests (such as access, deletion, correction and opt-out) relating to Customer Personal Data; and (e) Kendis shall enable the Customer to take reasonable and appropriate steps to help ensure that Kendis uses Customer Personal Data in a manner consistent with the Customer’s obligations under US Privacy Laws, and shall, on reasonable notice, allow the Customer to take reasonable steps to stop and remediate any unauthorized use of Customer Personal Data.
Liability, Precedence and General
Details of Processing
This Annex sets out the information regarding the Processing of Customer Personal Data required by Article 28(3) GDPR.
Subject matter and duration. As set out in the Principal Agreement and this DPA; for the duration of the Cloud Services and any retention period required by applicable law.
Nature and purpose. Processing to provide the Kendis Cloud Services in accordance with the Principal Agreement, including hosting and visualising work-management data extracted from the Customer’s connected ALM tools.
Categories of data subjects. End users of the Cloud Services, and individuals whose personal data is supplied by such end users.
Types of personal data. Direct identifiers (first name, last name, email); device and traffic data (e.g., IP and MAC addresses); and any personal data supplied by users of the Cloud Services.
Special categories of data. None. Kendis does not knowingly collect, and the Customer and its users shall not submit, special categories of data as defined under EU Data Protection Laws.
Location of Processing. As set out in the Hosting and Subprocessor Schedule for the applicable Hosting Region.
Subprocessors
The Subprocessors engaged by Kendis, the Hosting Regions in which they operate, and the transfer mechanisms relied upon are identified in the Hosting and Subprocessor Schedule published at trust.kendis.io/subprocessors. The Schedule is incorporated into this DPA by reference and is updated in accordance with Section 6 (Subprocessing). Kendis remains fully liable to the Customer for the performance of its Subprocessors’ obligations.
Standard Contractual Clauses
Version History
Customers with a signed agreement with a Kendis contracting entity, and customers with self-hosted deployments, are governed by the data-processing terms of their agreement rather than this DPA. For the data-processing terms applicable to your deployment, hosting arrangement or location, contact Kendis at security@kendis.io.

