DATA PROCESSING AGREEMENT
This Data Processing Agreement (the “DPA”) forms part of, and is incorporated by reference into, the Commercial Terms of Service (the “Agreement”) between Kinset Limited (“Kinset”) and the customer that is party to that Agreement (“Customer”).
Kinset Limited is a private company limited by shares incorporated in Ireland under company number 745880, with registered office at 15 Sandymount Road, Dublin 4, D04 X9K4, Ireland.
In the event of any conflict, this DPA shall prevail solely with respect to the Processing of Personal Data.
1. DEFINITIONS AND INTERPRETATION
1.1 In this DPA:
“Applicable Data Protection Law” means Regulation (EU) 2016/679 (the General Data Protection Regulation, or “GDPR”), the Irish Data Protection Act 2018, the UK GDPR and the UK Data Protection Act 2018, the e-Privacy Regulations 2011, and any other data protection or privacy legislation in force in the EEA or UK, in each case as amended or replaced from time to time.
“Customer Personal Data” means Personal Data Processed by Kinset on behalf of Customer in connection with the Services.
“SCCs” means the standard contractual clauses for the transfer of personal data to third countries adopted by the European Commission under Implementing Decision (EU) 2021/914, as amended or replaced from time to time.
“Subprocessor” means any third party engaged by Kinset to Process Customer Personal Data on behalf of Customer.
“UK Addendum” means the International Data Transfer Addendum to the EU SCCs issued by the UK Information Commissioner under section 119A of the UK Data Protection Act 2018, as amended or replaced from time to time.
1.2 The terms “Controller”, “Processor”, “Data Subject”, “Personal Data”, “Personal Data Breach”, “Processing”, “Special Categories of Personal Data” and “Supervisory Authority” have the meanings given in the GDPR.
1.3 References to articles are to articles of the GDPR unless stated otherwise.
2. ROLES OF THE PARTIES
2.1 The parties acknowledge that, with respect to Customer Personal Data:
(a) Customer is the Controller (or a Processor acting on behalf of a third-party Controller); and
(b) Kinset is the Processor.
2.2 In respect of certain Personal Data Processed for account administration, billing, service-related communications, compliance and platform security, each party may act as an independent Controller, and such Processing is governed by Kinset’s Privacy Policy.
2.3 Nothing in this DPA creates a joint controller relationship under Article 26 GDPR.
2.4 Where Customer is itself a Processor acting on behalf of a third-party Controller, Customer warrants that it has all necessary authority from that Controller to engage Kinset as a Subprocessor on the terms of this DPA, and that the instructions and authorisations given to Kinset under this DPA accurately reflect those of the underlying Controller.
3. DETAILS OF PROCESSING
The subject matter, duration, nature and purpose of the Processing, the categories of Data Subjects and the categories of Personal Data are set out in Annex I, which forms part of this DPA in accordance with Article 28(3) GDPR.
4. KINSET’S OBLIGATIONS AS PROCESSOR
Kinset shall:
4.1 Process Customer Personal Data only on documented instructions from Customer, including as set out in the Agreement, this DPA and Customer’s use of the Services. If Kinset is required by EU or Member State law to Process Customer Personal Data otherwise, it shall inform Customer of that legal requirement before Processing, unless that law prohibits such information on important grounds of public interest.
4.2 Ensure that persons authorised to Process Customer Personal Data are subject to a duty of confidentiality (whether contractual or statutory).
4.3 Implement and maintain appropriate technical and organisational measures in accordance with Article 32 GDPR and Annex II.
4.4 Not sell, rent or use Customer Personal Data for its own independent commercial purposes, including profiling, behavioural advertising or training of artificial intelligence or machine learning models, except as permitted in respect of aggregated and anonymised data under the Agreement.
4.5 Inform Customer without undue delay if, in Kinset’s reasonable opinion, an instruction infringes Applicable Data Protection Law.
4.6 Taking into account the nature of the Processing and the information available to Kinset, assist Customer in ensuring compliance with Customer’s obligations under Articles 32 to 36 GDPR (security, breach notification, data protection impact assessments and prior consultations).
5. SUBPROCESSORS
5.1 Customer hereby provides general written authorisation to Kinset to engage Subprocessors. A current list of Subprocessors is published at https://kinset.com/legal/subprocessors (the “Subprocessor List”).
5.2 Kinset shall:
(a) ensure that each Subprocessor is bound by a written contract imposing data protection obligations no less protective than those set out in this DPA, and in particular providing sufficient guarantees of appropriate technical and organisational measures;
(b) remain fully liable to Customer for the performance of each Subprocessor’s obligations under such contract; and
(c) carry out appropriate due diligence on each Subprocessor before engagement.
5.3 Kinset shall provide Customer with reasonable prior notice (which may be by email or by updating the Subprocessor List) of the addition or replacement of any Subprocessor.
5.4 Customer may object to the appointment of a new Subprocessor on reasonable data protection grounds within thirty (30) days of such notice. The parties shall discuss in good faith to address Customer’s objection. If the parties are unable to reach a resolution within a further thirty (30) days, Customer may, as its sole and exclusive remedy, terminate the Services affected by the appointment of the relevant Subprocessor by written notice, in which case Kinset shall refund any prepaid Fees covering the unused portion of the Subscription Term in respect of the affected Services.
6. INTERNATIONAL DATA TRANSFERS
6.1 Kinset shall not transfer Customer Personal Data to a country outside the EEA or the UK unless an appropriate transfer mechanism is in place under Applicable Data Protection Law.
6.2 Where required, transfers shall be based on:
(a) an adequacy decision adopted by the European Commission or the UK government;
(b) the SCCs (Module 2 for Controller-to-Processor transfers, Module 3 for Processor-to-Processor transfers, as applicable), supplemented by the UK Addendum where the transfer is subject to the UK GDPR; or
(c) another lawful transfer mechanism.
6.3 The parties agree that, where the SCCs are required, they are deemed incorporated into this DPA by reference, with the following options applied:
(a) Clause 7 (docking clause): incorporated;
(b) Clause 9 (subprocessing): Option 2 (general written authorisation), with at least thirty (30) days’ notice;
(c) Clause 11 (redress): the optional independent dispute resolution mechanism is not adopted;
(d) Clause 17 (governing law): Irish law;
(e) Clause 18 (jurisdiction): the courts of Ireland;
(f) Annex I.A (parties): Customer is the data exporter; Kinset is the data importer;
(g) Annex I.B (description of transfer): as set out in Annex I to this DPA;
(h) Annex I.C (competent supervisory authority): the Irish Data Protection Commission; and
(i) Annex II (technical and organisational measures): as set out in Annex II to this DPA.
6.4 Where the UK Addendum applies, Table 4 thereof is completed such that either party may end the Addendum in accordance with section 19 thereof.
7. DATA SUBJECT RIGHTS
7.1 Taking into account the nature of the Processing, Kinset shall provide reasonable assistance to Customer, by appropriate technical and organisational measures, insofar as practicable, to enable Customer to respond to requests from Data Subjects exercising their rights under Articles 15 to 22 GDPR.
7.2 If Kinset receives a request directly from a Data Subject in respect of Customer Personal Data, Kinset shall, where practicable, redirect the request to Customer and shall not respond to the Data Subject without Customer’s prior written instructions, except as required by applicable law.
7.3 To the extent that such assistance requires substantial effort beyond standard functionality of the Services, Customer shall reimburse Kinset for reasonable documented costs.
8. PERSONAL DATA BREACH
8.1 Kinset shall notify Customer without undue delay, and in any event within seventy-two (72) hours, after becoming aware of a Personal Data Breach affecting Customer Personal Data.
8.2 Such notification shall include, to the extent then known and as it becomes known:
(a) the nature of the Personal Data Breach, including, where possible, the categories and approximate number of Data Subjects and Personal Data records concerned;
(b) the likely consequences of the Personal Data Breach;
(c) the measures taken or proposed to be taken to address the Personal Data Breach and mitigate its possible adverse effects; and
(d) the name and contact details of a contact point from whom further information can be obtained.
8.3 Kinset’s notification of, or response to, a Personal Data Breach under this Section 8 shall not be construed as an acknowledgement by Kinset of any fault or liability.
9. AUDIT AND COMPLIANCE
9.1 Kinset shall make available to Customer all information reasonably necessary to demonstrate compliance with this DPA and Article 28 GDPR, including by providing copies of independent third-party certifications (such as ISO/IEC 27001) and audit reports (such as SOC 2 Type II) on a confidential basis where available.
9.2 Where the information made available under Section 9.1 is not sufficient to demonstrate compliance, Customer may, no more than once per year (except where required by a Supervisory Authority or following a Personal Data Breach), conduct an audit of Kinset’s relevant Processing activities, subject to:
(a) at least thirty (30) days’ prior written notice;
(b) the audit being conducted during normal business hours and in a manner that minimises disruption to Kinset’s operations;
(c) the auditor (which shall not be a competitor of Kinset) being subject to written confidentiality obligations no less protective than those in the Agreement; and
(d) Customer reimbursing Kinset’s reasonable documented costs of the audit.
9.3 The scope of any audit shall be limited to verifying compliance with this DPA and Applicable Data Protection Law, and shall exclude any information of other Kinset customers, commercially sensitive information unrelated to data protection, and any information the disclosure of which would breach Kinset’s legal or regulatory obligations.
10. RETURN AND DELETION
Upon termination or expiration of the Agreement, Kinset shall delete or return Customer Personal Data in accordance with Section 13.6 of the Agreement, except to the extent that storage of Customer Personal Data is required by EU or Member State law, in which case Kinset shall continue to protect such Personal Data in accordance with this DPA until securely deleted.
11. LIABILITY
The liability of the parties arising out of or in connection with this DPA shall be subject to the limitations and exclusions of liability set out in the Agreement. Nothing in this DPA shall expand or increase a party’s liability beyond that provided in the Agreement, save where prohibited by Applicable Data Protection Law.
12. GENERAL
12.1 This DPA shall terminate automatically upon termination or expiration of the Agreement, save in respect of obligations that by their nature survive termination.
12.2 This DPA is governed by, and shall be construed in accordance with, the laws of Ireland, and the courts of Ireland shall have exclusive jurisdiction in respect of any dispute, save as expressly provided otherwise in the SCCs.
12.3 In the event of any conflict between this DPA and the SCCs, the SCCs shall prevail to the extent required by Applicable Data Protection Law.
13. CHANGES TO THIS DPA
Kinset may update this DPA from time to time to reflect changes in law, regulation or guidance from Supervisory Authorities, or to reflect changes in the Services. Material changes will be notified to Customer in accordance with the Agreement. The most recent version will always be available on Kinset’s website with an updated “Last Updated” date.
Last Updated: May 2026
L
ANNEX I — DETAILS OF PROCESSING
A. List of Parties
Data Exporter: Customer (as identified in the Agreement).
Role: Controller (or Processor acting on behalf of a third-party Controller).
Data Importer: Kinset Limited.
Address: 15 Sandymount Road, Dublin 4, D04 X9K4, Ireland.
Contact: privacy@kinset.com.
Role: Processor.
B. Description of the Transfer / Processing
1. Subject matter: provision of the Services (the Kinset connected product platform, including digital link, digital product passport, life cycle assessment, impact reporting, supply chain traceability and supplier portal modules).
2. Duration: for the duration of the Agreement and any applicable retention period set out in the Agreement.
3. Nature and purpose: hosting, storage, organisation, structuring, retrieval, transmission, display and deletion of Customer Personal Data in connection with connected product, transparency, traceability, lifecycle and digital product passport functionality.
4. Categories of Data Subjects: depending on Customer’s use of the Services, Data Subjects may include:
(a) employees, officers, contractors and Authorised Users of Customer;
(b) employees and representatives of Customer’s suppliers, supply chain partners and service providers;
(c) business contacts of Customer; and
(d) individuals whose details are included within product, lifecycle, traceability or sustainability documentation submitted by or on behalf of Customer.
5. Categories of Personal Data: depending on Customer’s use of the Services, the categories of Personal Data Processed may include:
(a) names and business contact details (including business email, telephone and address);
(b) job titles, organisational roles and employer information;
(c) user account credentials and identifiers (in hashed form where applicable);
(d) technical identifiers such as IP address, device information and log data; and
(e) any additional Personal Data uploaded by or on behalf of Customer in connection with the Services.
6. Special Categories of Personal Data: Kinset does not intentionally Process Special Categories of Personal Data. Customer agrees not to upload such data unless expressly agreed in writing in advance.
7. Frequency of transfer: continuous, for the duration of the Agreement.
8. Retention period: as set out in the Agreement and Section 11 of the Privacy Policy.
9. Subprocessors: as set out in the Subprocessor List, including the subject matter, nature and duration of their Processing.
C. Competent Supervisory Authority
The Irish Data Protection Commission, 21 Fitzwilliam Square South, Dublin 2, D02 RD28, Ireland.
ANNEX II — TECHNICAL AND ORGANISATIONAL MEASURES
Kinset implements appropriate technical and organisational measures designed to ensure a level of security appropriate to the risk associated with the Processing of Customer Personal Data, including, without limitation:
1. Security Governance
Information security policies and standards, security awareness training for all personnel, designated personnel responsible for information security, and regular review of security controls.
2. Access Controls
Role-based access controls, least-privilege principles, multi-factor authentication for administrative access, periodic access reviews, and prompt revocation of access on role change or termination.
3. Encryption
Encryption of Customer Personal Data in transit using industry-standard protocols (TLS 1.2 or higher), and encryption of Customer Personal Data at rest using industry-standard algorithms.
4. Network and Infrastructure Security
Logical separation of customer environments, network segmentation, firewalls and intrusion detection, secure cloud hosting infrastructure, and hardening of operating systems and middleware.
5. Application Security
Secure software development lifecycle, code review, dependency scanning, vulnerability scanning, periodic penetration testing by qualified third parties, and prompt remediation of identified vulnerabilities.
6. Logging and Monitoring
Security monitoring, centralised logging of access and security events, detection of anomalous activity, and retention of logs for a period appropriate to the risk.
7. Personnel Security
Background checks (where lawful), confidentiality undertakings, and onboarding and termination procedures.
8. Vendor Management
Due diligence on Subprocessors prior to engagement, contractual data protection obligations no less protective than those in this DPA, and ongoing monitoring.
9. Backup and Resilience
Regular backups of Customer Personal Data, tested restoration procedures, and business continuity and disaster recovery planning appropriate to the nature of the Services.
10. Incident Management
Documented incident response procedures, defined roles and responsibilities, and procedures for the timely notification of Personal Data Breaches in accordance with Section 8 of this DPA.
11. Data Minimisation and Retention
Configuration of the Services to support data minimisation and retention controls, and processes for the secure deletion of Customer Personal Data in accordance with the Agreement.
Kinset reviews and updates these measures on an ongoing basis, taking into account technological developments, evolving threats and the cost of implementation, provided that any update does not materially reduce the overall level of protection.
