Legal
Data Processing Agreement
Current version: September 23, 2026
This agreement is accepted inside the product, not by PDF: your company's authorised signatory accepts it from the panel, and the version, date, name, email address and IP address are recorded. The list of sub-processors that forms part of this agreement is at Sub-processors.
Preamble
This data processing agreement (the "Agreement") sets out the data protection obligations of the parties arising from the use of KairosLink. It applies in addition to the Terms and Conditions and prevails over them on matters of data protection.
Controller (the "Customer") is the company that uses KairosLink to manage the IT systems of its own clients.
Processor is:
MITS GROUP LLC Limited Liability Company (LLC), State of New Mexico, USA 2201 Menaul Blvd NE Ste A, Albuquerque, NM 87107, USA Email: [email protected] · Phone: +1 317 735-8665
The Customer remains responsible for the lawfulness of the processing. The Customer decides which systems it connects to KairosLink and which data is processed as a result.
1. Subject matter and duration
1.1 The subject matter is the processing of personal data by the Processor in the course of providing KairosLink, a platform for remote monitoring and management (RMM) and IT service management (ITSM).
1.2 Processing begins when the first endpoint or client is added to the platform and ends when the contractual relationship ends.
1.3 The nature, scope and purpose of the processing, the types of data and the categories of data subjects are set out in Annex 1.
2. Instructions
2.1 The Processor processes personal data only on documented instructions from the Customer. Those instructions arise from this Agreement and from the Customer's use of the platform's features.
2.2 Instructions given outside the platform are issued in writing or by email to [email protected].
2.3 If the Processor considers that an instruction infringes data protection law, it will say so without delay and may suspend execution until the Customer confirms or amends it.
2.4 The Processor does not process the data for its own purposes. In particular, customer data is not used to train artificial intelligence models and is not sold.
3. Obligations of the Processor
3.1 Confidentiality. The Processor assigns processing only to persons bound by a duty of confidentiality and informed of the applicable data protection obligations. That duty survives the end of their engagement.
3.2 Security of processing. The Processor implements the technical and organisational measures required by Art. 32 GDPR, described in Annex 2. It may update them provided the level of protection is not reduced.
3.3 Assistance. The Processor assists the Customer, to the extent reasonable, in responding to requests for access, rectification, erasure and restriction, in data protection impact assessments and in enquiries from supervisory authorities.
3.4 Third-party requests. If an authority requires the Processor to disclose the Customer's data, the Processor informs the Customer without delay, to the extent legally permitted, and limits any disclosure to what is legally required.
3.5 Data protection contact. For any data protection matter: [email protected]. No data protection officer has been appointed; in the Processor's assessment the conditions of Art. 37 GDPR are not met.
4. Notification of personal data breaches
4.1 The Processor notifies the Customer of any personal data breach that comes to its attention without undue delay after becoming aware of it, so that the Customer can meet its own notification deadlines.
4.2 Notification is sent by email to the address on file for the Customer's account and includes, where available: the nature of the breach, the categories of data affected, the estimated number of records affected, the likely consequences and the measures taken or proposed.
4.3 Notification to the supervisory authority and to data subjects is the Customer's responsibility. The Processor assists the Customer with it.
5. Sub-processors
5.1 The Customer grants general authorisation for the use of sub-processors. The current list — with name, purpose, processing region and legal basis for the transfer — is published at kairoslink.io/en/subprocessors and forms part of this Agreement.
5.2 The Processor informs the Customer by email at least 30 days in advance of adding or replacing a sub-processor.
5.3 The Customer may object in writing within that period on data protection grounds. If the objection is not resolved, the Customer is entitled to terminate the contract. The financial consequences of termination are governed by the Terms and Conditions and the Refund Policy.
5.4 The Processor imposes on each sub-processor obligations equivalent to those of this Agreement and is liable for their performance as for its own acts.
6. Transfers to third countries
6.1 Where the platform's data resides. The panel, the database, files and outbound email run in a Hetzner Online GmbH data centre in Nuremberg, Germany. For that processing there is no transfer to a third country.
6.2 How remote access is transported. Remote control, remote terminal and file transfer are transported through a relay server. That server is currently at Akamai Technologies (Linode) in São Paulo, Brazil. A relay server in Falkenstein, Germany, is provisioned but not yet in operation; when it enters production, this Agreement will be amended accordingly and the sub-processor list updated.
6.3 What the relay cannot do. The relay server does not decrypt any content. It transports end-to-end encrypted traffic between the Customer's console and the managed endpoint and has no access to screen content, keystrokes, transferred files or terminal sessions.
6.4 Backups leave the European Union. Encrypted backups are stored with Google LLC (Google Drive) and Microsoft Corporation (OneDrive) in the United States. They are encrypted with AES-256 and carry encrypted file names; the keys do not leave the Processor's infrastructure. The Processor states this expressly because it constitutes a transfer to a third country, even though the content is not readable by the storage provider.
6.5 Other third-country transfers. Payment processing (Stripe), artificial intelligence features (Anthropic PBC), compilation and distribution of installers (GitHub) and the Microsoft 365 integration module process data, in part, in the United States.
6.6 Legal basis. Transfers to countries without an adequacy decision are made on the basis of the standard contractual clauses of Implementing Decision (EU) 2021/914, module 2 (controller to processor), supplemented by the measures described in Annex 2.
7. Artificial intelligence features
7.1 KairosLink includes features that use language models: the public chat, assisted command generation and the drafting of knowledge base articles. The sub-processor used for this is Anthropic PBC.
7.2 Only the context required for each request is transmitted. The data is not used to train models.
7.3 The Customer decides whether and to what extent it uses these features and is responsible for not including unnecessary personal data in requests.
8. Erasure and return
8.1 On termination of the provision of the services, the Processor erases or returns the Customer's personal data, at the Customer's choice, unless Union or Member State law requires storage of the data.
8.2 Before erasure, the Customer may extract the data using the platform's export features, which are available throughout the contractual relationship. On request, the Processor provides an export in a structured, commonly used format.
8.3 The security log is excluded. The sealed audit chain records accesses and actions as evidence and is not deleted on request: it expires according to the retention periods stated in Annex 2. A log that could be altered afterwards would not be evidence.
8.4 Encrypted backups expire according to their own rotation cycle.
9. Evidence and audit rights
9.1 On request, the Processor demonstrates compliance with its obligations through appropriate documentation: the description of the technical and organisational measures in Annex 2, the sealed audit chain records for the Customer's account, the published checksums of the agent installers and the data protection documentation of the sub-processors.
9.2 The Customer may carry out an audit on at least 30 days' notice, no more than once per calendar year and during normal business hours. The audit must not unreasonably disrupt operations or compromise the confidentiality of other customers' data.
9.3 The notice and frequency limits in clause 9.2 do not apply where the audit is required by a supervisory authority, in line with the duty to cooperate under Art. 31 GDPR.
10. Liability
10.1 Liability is governed by Art. 82 GDPR and by the Terms and Conditions.
10.2 The limitations of liability agreed in the Terms and Conditions do not apply to claims by data subjects under Art. 82 GDPR, nor to fines imposed by supervisory authorities.
11. Final provisions
11.1 Governing language. This Agreement is published in four languages. The German version is the legally binding text; in the event of any discrepancy between the versions, the German version prevails.
11.2 Amendments. Amendments to this Agreement are published as a new version. Substantive changes are notified to the Customer and require renewed acceptance; editorial corrections are published without requiring renewed acceptance.
11.3 Acceptance. Acceptance takes place inside the product, by the Customer's authorised signatory. The version, date and time, name, email address and IP address of the accepting person are recorded, together with the language in which the text was displayed. The record is entered in the sealed audit chain.
11.4 Severability. Should any provision be invalid, the validity of the remaining provisions is unaffected.
Annex 1 — Description of the processing
Purpose. Provision of remote monitoring and management and IT service management: monitoring, remote support, patch management, inventory, ticket handling, vulnerability and security assessment, and reporting on the IT systems managed by the Customer.
Categories of data subjects
- Customer personnel who use the platform (technicians, administrators)
- Personnel of the Customer's clients, whose endpoints are managed
- Persons who submit tickets through the client portal
Categories of personal data
- Account data: name, email address, role, language, time zone, sign-in records
- Endpoint data: host name, signed-in user name, IP and MAC addresses, operating system, installed software, patch status, system metrics
- Directory data: user accounts, groups and policies from Active Directory and Microsoft 365 Entra ID belonging to the Customer's clients
- Ticket data: content of requests, attachments, communication history, ratings
- Operational data: terminal sessions, executed commands, file transfers, remote access records
- Security data: antivirus events, account lockouts, DLP events, certificate inventory
Special categories. The platform is not intended for processing data under Art. 9 GDPR. If such data reaches the platform through the content of a ticket or a file, the Processor processes it only as part of that content and without any specific analysis.
Duration. For the duration of the contractual relationship and thereafter as set out in clause 8.
Annex 2 — Technical and organisational measures
Confidentiality
- Encryption of all connections with TLS; end-to-end encryption of remote access, which the relay server does not break
- Individual authentication per endpoint, with its own credential instead of a shared token; new accounts are created with that requirement enabled
- Two-factor authentication for the panel and the client portal, enforceable by the Customer; single sign-on with SAML and OIDC
- Fine-grained role and permission model; every sensitive action is bound to a named permission
- Encrypted credential vault with a record of every access
- IP block list, rate limiting, Content Security Policy and security headers
Integrity
- Sealed audit chain: each record contains the SHA-256 hash of the previous record, so that any later modification or removal becomes detectable
- The audit table accepts only new records; UPDATE and DELETE are rejected at database level
- Periodic external anchoring of the chain state, off the server
- Signed installers with published checksums
Availability
- Encrypted backups with AES-256 and encrypted file names, with verification that they can be restored
- External availability monitoring
- Retention of the security log according to a documented period; terminal session recordings according to the period configured by the Customer, with a minimum of 90 days
Organisation
- Access to production systems limited to named persons bound by a duty of confidentiality
- Separation of each Customer's data at application level, verified on every request
- A record of every access by the Processor to a Customer's data
Annex 3 — Sub-processors
The complete and current list is published at kairoslink.io/en/subprocessors. It is maintained there and not copied here so that only one version exists: a copy in this document would be out of date as soon as the list changes.
Postal address
MITS GROUP LLC 2201 Menaul Blvd NE Ste A Albuquerque, NM 87107 United StatesGoverning language
This document is published in four languages. The German-language version is the legally binding text, and in the event of any discrepancy or conflict between the versions, the German version shall prevail.