Data

Data Processing Addendum

Last updated: June 22, 2026

This page summarizes how KayMind handles personal data on behalf of clients. A full Data Processing Addendum (DPA) is available to sign as part of any enterprise engagement, and forms part of the project agreement.

Roles

When we build and operate a system for you, you are the data controller and KayMind (operated by New Bay Corporation) acts as the data processor. We process personal data only on your documented instructions.

Scope of processing

The DPA defines the subject matter, duration, nature, and purpose of processing; the categories of data and data subjects; and the obligations of both parties, consistent with GDPR Article 28.

Security measures

We apply technical and organizational measures appropriate to the risk, including encryption in transit and at rest, access controls, environment isolation, and logging, consistent with GDPR Article 32.

Sub-processors

We use a limited set of infrastructure and service providers, such as hosting and email. The DPA includes the current sub-processor list and a commitment to notify you of changes so you can object.

Data subject rights

We assist you in responding to access, correction, deletion, and portability requests, including removing personal data from the systems we operate on your behalf, such as databases and retrieval indexes, where technically feasible.

Breach notification

In the event of a personal data breach affecting your data, we notify you without undue delay and within 72 hours of becoming aware, consistent with GDPR Article 33.

International transfers and residency

Where required, we support EU or other regional data residency for the systems we operate, and rely on Standard Contractual Clauses for any cross-border transfer. Residency options are scoped per project.

Use of data

We do not reuse your business data for any purpose outside your project, and we do not use it to train models beyond the scope of your own engagement.