Legal

Data Processing Agreement

GDPR Article 28 and Swiss FADP terms for personal data Kulissa processes on behalf of customers.

Version
1.0
Effective
4 September 2026
Last updated
4 September 2026

Purpose

This Data Processing Agreement ("DPA") applies when STEALTH, trading as Kulissa ("Processor"), processes personal data on behalf of a Customer ("Controller") in the Kulissa product. It forms part of the Terms of Service and any Order Form. Entity fields marked STEALTH are pending incorporation.

This DPA is offered for Customers who need an Article 28 GDPR / Swiss FADP processing contract. A signed Order Form may reference this URL and version. Prefer a countersigned copy for enterprise procurement; email hello@kulissa.com with subject [Legal] DPA.

Roles

Customer is the controller of Customer Content and end-user account data in its workspace. Kulissa is the processor. For website visitors, Maya demo participants and our own sales records, Kulissa is a controller under the Privacy Policy; that processing is outside this DPA.

Subject matter and duration

Processing: hosting and operating the Kulissa product, including account administration, storage of uploaded documents, live voice sessions, transcription, scoring, coaching feedback, credit accounting and support.

Duration: the term of the service agreement, plus the deletion period below.

Nature and purpose

To provide the service described in the Terms and Order Form, on documented instructions from Customer.

Types of personal data

May include: names, work email addresses, role titles, authentication identifiers, voice audio during practice sessions, transcripts, scores, evidence quotes, uploaded documents that contain personal data, IP addresses and device data related to product use, and support correspondence.

Categories of data subjects

Customer's employees, contractors and other authorised users; individuals whose personal data appears in Customer Content (for example names in a playbook).

Instructions

Processor processes personal data only on documented instructions from Controller, including regarding transfers, unless required by law (in which case Processor informs Controller before processing where lawful). These Terms, the Order Form, this DPA and configuration choices in the product are instructions. Additional written instructions may be agreed.

Confidentiality

Processor ensures persons authorised to process personal data are bound by confidentiality.

Security measures (TOMs)

Processor implements appropriate technical and organisational measures, including:

  • Encryption in transit (TLS 1.2 or higher) and encryption at rest as provided by hosting and database providers
  • Access control with least privilege, unique accounts and authentication (passwords with reset flow for Customer users; GitHub OAuth for internal operators)
  • Tenant isolation in the application data model and database row-level security
  • Logging of operator administrative actions
  • Dependency pinning and continuous integration checks in the software delivery pipeline
  • Incident response with notification duties below
  • Vendor review for subprocessors that process personal data

A more detailed public description lives on the Security page. Certifications (SOC 2, ISO 27001) are not claimed until held.

Subprocessors

Controller authorises Processor to use the subprocessors listed at /subprocessors. Processor will update that list before a new subprocessor starts processing and will give Controller at least 30 days to object on reasonable grounds related to data protection. If the parties cannot resolve an objection, Controller may terminate the affected service for a pro-rata refund of prepaid fees.

Assistance

Taking into account the nature of processing, Processor assists Controller with:

  • Responses to data-subject requests (access, deletion, rectification, portability, restriction, objection)
  • Data protection impact assessments and prior consultation, where relevant
  • Security and breach information needed for Controller's obligations

Controller remains responsible for responding to data subjects who contact Controller directly.

Breach notification

Processor notifies Controller without undue delay after becoming aware of a personal data breach affecting Controller's personal data, and provides information reasonably available to describe the nature of the breach, likely consequences and measures taken or proposed.

Deletion and return

On termination of the service, or on Controller's written request, Processor deletes or returns personal data within 30 days, except where law requires storage. Backups age out on the backup cycle. Certification of deletion is available on request.

Audits

Processor makes available information necessary to demonstrate compliance with this DPA. Controller may request an audit once per twelve months (or after a breach), with 30 days' notice, under a confidentiality agreement, during business hours, without disrupting operations. Processor may satisfy audit rights by providing current third-party security reports or questionnaires when available. Controller bears its own costs unless material non-compliance is found.

International transfers

Where Processor transfers personal data out of Switzerland or the EEA, it ensures an appropriate safeguard, typically the European Commission's Standard Contractual Clauses (and Swiss-recognised modules) with the subprocessor, or another lawful mechanism. Destinations are listed on the subprocessor page.

Liability

Liability under this DPA follows the liability section of the Terms, except where data-protection law requires otherwise.

Swiss FADP

Where Swiss FADP applies, references to Controller/Processor have the corresponding meaning under that Act, and data subjects may exercise rights under FADP via Controller, with Processor's assistance as above.

Contact

hello@kulissa.com with subject [Legal] DPA. Data protection contact: STEALTH. Postal address: STEALTH.

FAQ

Is this the signed DPA?

It is the public terms we offer. Enterprise Customers often countersign an Order Form that incorporates this version by URL. Ask us for a signed PDF if your procurement team requires one.

Where is the subprocessor list?

/subprocessors, updated before new processors are added.

Questions about this document: email hello@kulissa.com with the subject [Legal] Data Processing Agreement.

See it on your own playbook.

Twenty minutes. Your scenarios, your methodology, the reports your managers would read on Monday.