# Kaabist Data Processing Agreement

*Version 1.0. Forms part of the [Terms of Service](terms-of-service.md) between the
customer ("Controller") and Kaabist Bilişim ve Yazılım Hizmetleri Limited Şirketi ("Processor").*

## 1. Roles and scope

- The customer is the **controller** of the personal data its programs collect, the inputs it
  passes them and the session state it stores ("Customer Personal Data"). Kaabist processes it as a
  **processor**, only to run the customer's programs and provide the service.
- Kaabist is a controller only for account, billing and security data, under the
  [Privacy Policy](privacy-policy.md).

## 2. Details of processing (Annex I)

| | |
|---|---|
| Subject matter | Running web automation programs: visiting websites, filling forms, extracting data, storing results, snapshots and sessions |
| Duration | The term of the agreement, then deletion as in section 8 |
| Nature and purpose | Automated retrieval, storage, transformation and delivery of data the customer's programs specify |
| Data subjects | Whoever the customer's targets and inputs concern; decided by the customer |
| Categories of data | Decided by the customer: page content, extracted fields, inputs (including credentials the customer chooses to store), session cookies and storage state |
| Special categories | None intended; the customer must not process them without a legal basis (see the [Acceptable Use Policy](acceptable-use-policy.md)) |

## 3. Kaabist's obligations

Kaabist will:

1. process Customer Personal Data only on the customer's documented instructions (the programs,
   options and settings it submits), and tell the customer if an instruction appears to break the
   law;
2. ensure its personnel are bound by confidentiality;
3. apply the measures in section 4;
4. use sub-processors only as in section 5;
5. assist the customer, as far as the service allows, with data subjects' requests (export,
   deletion, access) and with impact assessments;
6. notify personal data breaches as in section 6;
7. delete or return data at the end of the service as in section 8;
8. make available the information needed to demonstrate compliance and allow audits as in
   section 7.

## 4. Security measures (Annex II)

- **Encryption.** Session storage state, stored passwords and secret inputs, webhook signing
  secrets and bring-your-own provider credentials are encrypted with a data key per organisation,
  wrapped by a master key held in a separate key-management service (OpenBao Transit). Plaintext
  never leaves the worker process's memory and never appears in logs, snapshots, screenshots or
  webhooks; password fields are redacted before a page is captured. TLS protects data in transit.
- **Isolation.** Browser contexts are isolated per job; jobs that use a session or secret inputs run
  in a browser process of their own organisation. Every outbound request leaves through one gateway
  that refuses private, loopback, link-local and metadata addresses.
- **Access.** Role-based access within organisations; two-factor authentication required for
  owners and admins; API keys stored as hashes; every privileged action recorded in an audit log
  the application cannot change.
- **Hardening.** Containers run as non-root with a read-only filesystem and no capabilities; the
  code and dependencies are scanned for secrets and vulnerabilities on every change.
- **Resilience.** Backups are taken continuously, and restoring them is rehearsed.
- **Data minimisation.** Live view frames are never stored; snapshots exclude session state;
  retention follows the customer's plan.

## 5. Sub-processors

The customer authorises the sub-processors on the [sub-processor list](subprocessors.md).
Kaabist gives at least 30 days' notice of a new sub-processor by e-mail and on that page; the
customer may object on reasonable data-protection grounds and, if no solution is found, terminate
the affected service. Kaabist imposes data-protection obligations on each sub-processor no less
protective than this agreement and remains responsible for them. Providers the customer connects
itself (bring-your-own proxies, models or CAPTCHA solvers) are the customer's, not Kaabist's
sub-processors.

## 6. Personal data breaches

Kaabist notifies the customer without undue delay, and within 48 hours, after becoming aware of a
breach affecting Customer Personal Data, with what is known: nature, categories and approximate
numbers, likely consequences, measures taken. It updates the customer as more is known. The
customer remains responsible for notifying authorities and data subjects (GDPR: 72 hours; KVKK:
72 hours).

## 7. Audits

Kaabist provides, on request and at most once a year, the information reasonably needed to show
compliance (policies, the [threat model](../security/threat-model.md), test reports). On-site audits
need 30 days' notice, happen during business hours and are at the customer's cost.

## 8. Deletion and return

- The customer can export its data at any time (a zip linked by e-mail, valid seven days) and ask
  for its organisation's data to be deleted (`POST /v1/org/data-deletion`).
- Deletion is carried out within 24 hours: object storage, sessions, programs, provider settings,
  webhooks, schedules, members and keys are erased; job records are emptied and dropped after 30
  days; the credit ledger and payment records are kept as accounting law requires; the audit log
  is kept with every person replaced by a pseudonym; usage statistics are kept under a random token
  that no longer names the customer. The requester receives an e-mail when it is done.
- Backups age out within two years.

## 9. International transfers

Kaabist hosts Customer Personal Data in the EU (Germany) by default. Transfers to sub-processors
outside the EU or Türkiye rely on the mechanisms named on the [sub-processor list](subprocessors.md).

## 10. Liability

Liability under this agreement follows the [Terms of Service](terms-of-service.md).
