Kreel Legal
Data Processing Agreement
Last updated: 2026-04-18
This Data Processing Agreement ("DPA") supplements Kreel's Terms of Service and governs the processing of personal data by Kreel (the "Processor") on behalf of the Customer (the "Controller") where required by the GDPR or equivalent data-protection laws.
1. Subject matter and duration
Kreel processes personal data as a Processor solely to provide the Service to the Customer, for the duration of the Customer's subscription. The categories of personal data processed, and the categories of data subjects, are set out in our Privacy Policy.
2. Processor obligations
- Process personal data only on documented Customer instructions.
- Ensure personnel authorised to process personal data are bound by confidentiality.
- Implement technical and organisational measures appropriate to the risk (see Security page).
- Assist the Customer with data-subject rights requests and data-protection impact assessments.
- Notify the Customer without undue delay after becoming aware of a personal data breach, and within 72 hours where feasible.
3. Sub-processors
The Customer authorises Kreel to engage sub-processors listed in the Privacy Policy. Kreel will give at least 30 days' notice before adding or replacing a sub-processor. The Customer may object in writing within that window; if the parties cannot resolve the objection, the Customer may terminate the affected Service.
4. International transfers
Primary storage is in the EU. Where Kreel transfers personal data to a country outside the EEA that is not subject to an adequacy decision, it does so under the Standard Contractual Clauses (EU Commission Decision 2021/914), which are incorporated into this DPA by reference.
5. Deletion and return of data
On termination of the Service, Kreel deletes or returns all personal data within 30 days, except where retention is required by law.
6. Audit
Kreel will provide the Customer with information reasonably necessary to demonstrate compliance with this DPA, including responses to security questionnaires, and will permit audits by the Customer or its mandated auditor no more than once per 12-month period, at the Customer's cost and subject to reasonable notice.
7. Signing
For an executed copy of this DPA countersigned by Kreel, email legal@kreel.ai with the Customer's legal entity name and the name, title, and email of the signatory.