Data Processing Addendum
Applies to Kliio Beta
Last updated: July 9, 2026
This Data Processing Addendum (“DPA”) supplements and forms part of the Kliio Terms of Service, or other written agreement, between Kliio, Inc., a Delaware corporation (“Kliio,” “Processor”), and the customer that has accepted those terms (“Creator,” “Controller,” “you”) (together, the “Agreement”). This DPA applies to Kliio’s Processing of Personal Data on your behalf in connection with the Service. If you have not agreed to the Agreement, this DPA has no effect.
In the event of a conflict, this DPA controls over the Agreement with respect to the Processing of Personal Data. Annexes A, B, and C are incorporated into this DPA.
1. Definitions
Capitalized terms not defined here have the meaning given in the Agreement. The following terms apply to this DPA:
Applicable Data Protection Law means all laws and regulations applicable to the Processing of Personal Data under the Agreement, including the EU General Data Protection Regulation 2016/679 (“EU GDPR”), the UK GDPR and Data Protection Act 2018 (“UK GDPR”), and U.S. state privacy laws including the California Consumer Privacy Act as amended by the California Privacy Rights Act (“CCPA”).
Controller, Processor, Data Subject, Personal Data, Personal Data Breach, and Processing have the meanings given under Applicable Data Protection Law. Under the CCPA, Controller corresponds to Business, Processor corresponds to Service Provider, and Data Subject corresponds to Consumer.
Creator Personal Data means Personal Data contained in Creator Data that Kliio Processes on your behalf under the Agreement, principally Personal Data of your Fans.
Sub-processor means any third party engaged by Kliio to Process Creator Personal Data.
Standard Contractual Clauses (SCCs) means the clauses approved by the European Commission for the transfer of Personal Data to third countries (Commission Implementing Decision (EU) 2021/914), and, for UK transfers, the UK International Data Transfer Addendum.
Restricted Transfer means a transfer of Creator Personal Data to a country that is not subject to an adequacy determination under Applicable Data Protection Law.
2. Roles and scope of processing
2.1 Roles.
As between the parties, you are the Controller (Business) and Kliio is the Processor (Service Provider) of Creator Personal Data. Each party will comply with its obligations under Applicable Data Protection Law. You are responsible for the lawfulness of your collection and use of Creator Personal Data, including establishing a lawful basis and providing all required notices to, and obtaining any required consents from, Data Subjects.
2.2 Documented instructions.
Kliio will Process Creator Personal Data only on your documented instructions, including as set out in the Agreement, this DPA, and your configuration and use of the Service, and as needed to provide, secure, and support the Service. Kliio will not Process Creator Personal Data for any other purpose. If Kliio is required by law to Process Creator Personal Data otherwise, it will inform you before Processing, unless legally prohibited.
2.3 Unlawful instructions.
Kliio will inform you if, in its reasonable opinion, an instruction infringes Applicable Data Protection Law, without obligation to provide legal advice.
2.4 Details of Processing.
The subject matter, duration, nature and purpose of the Processing, the types of Personal Data, and the categories of Data Subjects are described in Annex A.
3. Confidentiality
Kliio will ensure that personnel authorized to Process Creator Personal Data are bound by appropriate confidentiality obligations and have received appropriate training, and will limit access to those personnel who need it to provide the Service.
4. Security
4.1 Measures.
Kliio will implement and maintain appropriate technical and organizational measures designed to protect Creator Personal Data against accidental or unlawful destruction, loss, alteration, unauthorized disclosure, or access, taking into account the state of the art, the costs of implementation, and the nature, scope, and purposes of Processing. Kliio’s current measures are described in Annex B and may be updated provided protection is not materially reduced.
4.2 Your responsibility.
You are responsible for your own use and configuration of the Service, including access controls for your account, the data you choose to bring into the Service, and the security of any export you take under the Agreement.
5. Sub-processors
5.1 General authorization.
You provide general authorization for Kliio to engage Sub-processors to Process Creator Personal Data. Kliio’s current Sub-processors are listed in Annex C. Sub-processors typically include cloud-hosting, infrastructure, and, in Transaction Mode, the payment processor described in the Agreement.
5.2 Flow-down.
Kliio will impose data-protection obligations on each Sub-processor that are no less protective than those in this DPA, and remains liable for its Sub-processors’ performance of those obligations.
5.3 Changes and objection.
Kliio will give you notice (for example, by updating Annex C or by email or in-product notice) before adding or replacing a Sub-processor. You may object on reasonable data-protection grounds within fifteen (15) days. The parties will work in good faith to resolve the objection; if they cannot, you may terminate the affected part of the Service and export your Creator Data under the Agreement.
6. Assistance to the Controller
6.1 Data-subject requests.
Taking into account the nature of the Processing, Kliio will assist you by appropriate technical and organizational measures, insofar as possible, to respond to requests from Data Subjects to exercise their rights (access, correction, deletion, portability, restriction, objection, and CCPA consumer rights). If Kliio receives such a request directly, it will, where permitted, forward it to you and not respond except on your instruction. Kliio fulfills verified Data Subject access, deletion, and portability requests on the Controller's instruction within thirty (30) days. Kliio provides this assistance through its team; self-service tooling is in development and will supplement this process as it becomes available.
6.2 DPIAs and consultation.
Kliio will provide reasonable assistance with data-protection impact assessments and prior consultations with supervisory authorities, taking into account the nature of Processing and the information available to Kliio.
7. Personal Data Breach
Kliio will notify you without undue delay, and in any event in line with its obligations under Applicable Data Protection Law, after becoming aware of a Personal Data Breach affecting Creator Personal Data. The notice will describe, to the extent known, the nature of the breach, the likely consequences, the measures taken or proposed, and a point of contact, and Kliio will provide further information as it becomes available. Kliio will take reasonable steps to mitigate and remediate. Notice of a breach is not an acknowledgment of fault or liability.
8. International transfers
8.1 Transfer mechanism.
To the extent Kliio’s Processing involves a Restricted Transfer of Creator Personal Data, the parties agree the SCCs (and, for UK transfers, the UK International Data Transfer Addendum) are incorporated by reference and apply, with you as data exporter and Kliio as data importer. Module Two (Controller-to-Processor) applies as between you and Kliio; Module Three applies to onward transfers to Sub-processors as applicable.
8.2 SCC operative elements.
For purposes of the SCCs: the optional docking clause applies; the supervisory authority and governing law are as determined under the SCCs based on your establishment; Annex A provides the description of transfer; Annex B provides the technical and organizational measures; and Annex C lists Sub-processors. The audit and Sub-processor provisions of this DPA satisfy the corresponding SCC clauses.
8.3 Conflict.
In the event of a conflict between this DPA and the SCCs, the SCCs control with respect to Restricted Transfers.
9. CCPA-specific terms
To the extent Kliio Processes Personal Data of California Consumers as a Service Provider:
Kliio will Process such Personal Data only for the limited and specified business purpose of providing the Service under the Agreement, and not for any other purpose.
Kliio will not sell or share (as defined under the CCPA) such Personal Data, and will not retain, use, or disclose it outside the direct business relationship or for any purpose other than the business purposes specified.
Kliio will not combine such Personal Data with Personal Data received from, or on behalf of, other parties, except as permitted by the CCPA to perform a business purpose.
Kliio certifies that it understands and will comply with these restrictions.
Kliio will notify you if it determines it can no longer meet its obligations under the CCPA, and you may take reasonable steps to stop and remediate unauthorized use.
10. Deletion and return
Upon termination or expiry of the Agreement, and at your choice, Kliio will return or delete Creator Personal Data, except to the extent retention is required by law. Consistent with the Agreement’s anti-lock-in commitments, you may, throughout the term and during the wind-down period stated in the Agreement (at least ninety (90) days), export your Creator Data, including Creator Personal Data, through the Service’s one-click structured export in a non-proprietary, documented format, with consent records that travel with the data and at no export fee. After the wind-down period, Kliio may delete Creator Personal Data in the ordinary course, subject to legal retention requirements and routine backup cycles, with backups deleted on their normal schedule.
11. Audit
Kliio will make available information reasonably necessary to demonstrate compliance with this DPA and will allow for and contribute to audits, including inspections, conducted by you or an auditor you mandate. To minimize disruption, the parties agree Kliio may satisfy audit requests by providing relevant third-party certifications, reports, or a written response to a reasonable security questionnaire; on-site audits will be on reasonable prior notice, no more than once per year absent a Personal Data Breach or regulator requirement, during business hours, subject to confidentiality, and at your cost.
12. Liability
Each party’s liability arising out of or related to this DPA is subject to the limitations and exclusions of liability in the Agreement, and any reference to the liability of a party means the aggregate liability of that party under the Agreement and this DPA together. Nothing in this DPA limits liability that cannot be limited under Applicable Data Protection Law, including, where applicable, the liability provisions of the SCCs.
13. General
This DPA is governed by the law and subject to the venue stated in the Agreement, except where Applicable Data Protection Law or the SCCs require otherwise. If any provision of this DPA is held invalid, the remainder continues in effect. This DPA may be updated by Kliio as required to reflect changes in Applicable Data Protection Law or Sub-processors, on reasonable notice, provided no update materially reduces the protection of Creator Personal Data.
Annex A. Details of Processing
Controller
The Creator that accepts the Agreement. Contact: the Creator account contact.
Processor
Kliio, Inc., [registered address]. Contact: privacy@kliio.com.
Subject matter
Provision of the Kliio Service: ingesting, unifying, structuring, and making portable the Creator’s Fan relationships across connected Platforms, and, where enabled, supporting Transaction Mode.
Duration
For the term of the Agreement plus the wind-down period, then deletion per Section 10.
Nature and purpose
Collection, storage, organization, structuring, aggregation, retrieval, transmission, and deletion of Creator Personal Data to operate the Service on the Controller’s instructions.
Types of Personal Data
Fan identifiers (name, email, account or handle identifiers); subscription, tier, and entitlement data; transaction and billing-relationship metadata; behavioral and engagement data aggregated across connected Platforms. Excludes special-category data unless the Controller chooses to provide it, which is not requested by Kliio.
Categories of Data Subjects
The Creator’s Fans (paying members and free fans) and the Creator’s own authorized users.
Frequency
Continuous, for the duration of the Agreement.
Recipients
Kliio personnel and Sub-processors listed in Annex C.
Annex B. Technical and organizational measures
Kliio maintains the following technical and organizational measures to protect Creator Personal Data:
Access control: separated at the tenant level, with each creator's data scoped to their own account and enforced at the application layer; sessions are typed (creator or member) and validated on every request.
Encryption: encryption of Creator Personal Data in transit (TLS, with HSTS enforced). Stored third-party credentials are encrypted at the field level using AES-256-GCM envelope encryption. The database is hosted on a provider with encryption at rest.
Network and infrastructure: hosting with a reputable cloud provider, environment segregation, and firewalling and network controls.
Data minimization and segregation: logical separation of Creator data; collection limited to what the Service requires.
Logging and monitoring: logged at the hosting and database platform level, and the application uses error monitoring to detect operational failures.
Resilience: backups, and restoration procedures tested on a defined cadence.
Vulnerability management: dependency and patch management, and security review of changes prior to release.
Personnel: confidentiality obligations and security awareness for personnel with access.
Incident response: a documented process for detecting, escalating, and responding to Personal Data Breaches, including Controller notification.
Sub-processor management: diligence and contractual flow-down of protections to Sub-processors.
Annex C. Sub-processors
Vercel
Application hosting, serverless compute, and edge network. Location: United States.
Turso
Database and storage of Creator Data and the fan ledger. Location: United States.
Resend
Transactional and authenticated email sending. Location: United States.
Stripe (Transaction Mode only, when enabled)
Payment processing; Creator is merchant of record. Location: United States / global.
© 2026 Kliio · The customer record creators own · We never sell your data

