Data Processing Agreement
This Data Processing Agreement ("DPA") supplements and is incorporated into the agreement (the "Agreement") between Optima Engineering LLC ("Optima," "Processor") and you ("Customer," "Controller") that governs your use of the Kraken AI platform: the Master Cloud Services Agreement where Customer has entered into one, and otherwise the Terms of Service. This DPA governs the processing of Personal Data by Optima on behalf of Customer in connection with the Kraken AI platform (also referred to as "Kraken" or the "Kraken Platform") and related services (the "Services").
This DPA applies to the extent that Optima processes Personal Data on behalf of Customer as a data processor (or equivalent role under applicable data protection laws). Where Customer acts as a processor on behalf of its own customers, references to "Controller" apply to Customer in its capacity as a sub-processor's instructing entity.
1. Definitions
- "Personal Data" means any information relating to an identified or identifiable natural person, as defined by applicable Data Protection Laws.
- "Processing" means any operation performed on Personal Data, including collection, storage, use, modification, transmission, deletion, or destruction.
- "Data Protection Laws" means all applicable laws relating to data protection and privacy, including the GDPR (Regulation (EU) 2016/679), UK GDPR, Swiss Federal Act on Data Protection (FADP), CCPA/CPRA, and any other applicable privacy legislation.
- "Sub-processor" means any third party engaged by Optima to process Personal Data on behalf of Customer.
- "Customer Data" means all data submitted by Customer to the Services, including any Personal Data contained therein.
- "Personal Data Breach" means a breach of security leading to the accidental or unlawful destruction, loss, alteration, unauthorized disclosure of, or access to, Personal Data.
- "SCCs" means the Standard Contractual Clauses for the transfer of personal data to third countries, as adopted by the European Commission on June 4, 2021 (Implementing Decision (EU) 2021/914), as may be amended or replaced.
- "Data Subject" means the identified or identifiable natural person to whom the Personal Data relates.
2. Scope and Purpose of Processing
Optima processes Personal Data solely on behalf of and in accordance with Customer's documented instructions to provide the Services. The details of processing are as follows:
- Subject matter: provision of the Kraken AI platform, including AI agent orchestration, monitoring, safety controls, observability, data integrations, and governance features.
- Duration: for the term of the Agreement, plus the period required to delete or return Personal Data as described in this DPA.
- Nature and purpose: processing Customer Data as necessary to provide, maintain, and support the Services, including agent execution, workflow processing, data pipeline operations, and platform administration.
- Categories of Data Subjects: Customer's employees, contractors, end users, and any other individuals whose Personal Data is submitted to the Services by Customer.
- Types of Personal Data: as determined by Customer, which may include names, email addresses, contact information, IP addresses, identifiers, operational data, and any other Personal Data submitted through the Services.
3. Customer Obligations
Customer agrees to:
- Comply with all applicable Data Protection Laws in its use of the Services and its processing instructions to Optima.
- Ensure that it has obtained all necessary consents, authorizations, and legal bases required for the processing of Personal Data through the Services.
- Provide processing instructions that comply with applicable law and this DPA.
- Be responsible for the accuracy, quality, and legality of Personal Data submitted to the Services.
4. Optima's Processing
In connection with providing the Services, Optima will:
- Process Personal Data only on documented instructions from Customer, unless required to do so by applicable law (in which case Optima will inform Customer of such legal requirement before processing, unless prohibited by law).
- Ensure that persons authorized to process Personal Data are subject to appropriate confidentiality obligations.
- Implement and maintain appropriate technical and organizational security measures as described in Section 7.
- Provide reasonable cooperation to Customer in fulfilling its obligations regarding Data Subject rights, security, breach notification, and data protection impact assessments, as required by Data Protection Laws, at Customer's expense.
- Process Personal Data to provide the Services, and to improve them only as permitted by Section 12 (De-identified and Aggregated Data).
5. Sub-processors
Customer provides general authorization for Optima to engage Sub-processors to process Personal Data in connection with the Services. Optima maintains a list of current Sub-processors, available on our Subprocessor List page.
Optima will give Customer at least thirty (30) days' prior written notice before engaging a new Sub-processor. Customer may object to a new Sub-processor on reasonable grounds within fifteen (15) days of receiving notice, and the parties will work in good faith to resolve the objection.
Optima will impose data protection obligations on each Sub-processor that are no less protective than those set forth in this DPA.
The preceding paragraph does not apply to third-party model providers that Customer chooses to use with the Services. They process Customer Data under their own terms, and Optima does not control them and is not responsible or liable for their acts or omissions, including their use of Customer Data.
6. Data Subject Rights
Customer is solely responsible for responding to Data Subject requests. If Optima receives a request directly from a Data Subject, Optima may redirect the request to Customer. Customer may use self-service tools available in the Services, if any. Any additional assistance is subject to separate agreement and fees.
7. Security Measures
Optima maintains commercially reasonable administrative, physical, and technical safeguards designed to protect Customer Data against unauthorized access, disclosure, alteration, loss, or destruction, including encryption at rest and in transit over untrusted networks, access controls and authentication, regular security assessments and vulnerability testing, incident detection and response procedures, and employee security awareness training. Our current practices and the status of any certifications are described on our Security Addendum.
8. Personal Data Breach Notification
Optima will notify Customer without undue delay, and in no event later than seventy-two (72) hours, after becoming aware of a confirmed Personal Data Breach affecting Customer Data. The notification will include, to the extent reasonably available at the time:
- A description of the nature of the breach, including the categories and approximate number of Data Subjects and records affected.
- The name and contact details of Optima's point of contact for further information.
- A description of the likely consequences of the breach.
- A description of the measures taken or proposed to address the breach, including measures to mitigate its effects.
Optima will take commercially reasonable steps to contain and remediate the breach and will cooperate with Customer in investigating and remediating it.
9. Data Deletion and Return
Upon Customer's written request made within thirty (30) days after termination or expiration of the Agreement or the applicable order form, Optima will make Customer Data available for export in a standard, machine-readable format. After that period, Optima will delete Customer Data within ninety (90) days, except for copies held in backups, which are deleted in the ordinary course, and data that applicable law requires Optima to retain.
10. International Data Transfers
Optima is based in the United States. To the extent that processing involves the transfer of Personal Data from the EEA, UK, or Switzerland to a country that has not been deemed to provide an adequate level of data protection, the parties agree that such transfers will be governed by the Standard Contractual Clauses (SCCs), which are incorporated into this DPA by reference.
For the purposes of the SCCs:
- Module Two (Controller to Processor) applies where Customer is a Controller and Optima is a Processor.
- Module Three (Processor to Processor) applies where Customer is a Processor acting on behalf of its own controller.
- In Clause 9, Option 2 (general written authorization) applies, with a 30-day prior notice period for Sub-processor changes.
- In Clause 17, the SCCs are governed by the laws of Ireland.
- In Clause 18, disputes will be resolved before the courts of Ireland.
For transfers from the UK, the International Data Transfer Addendum issued by the UK Information Commissioner's Office applies. For transfers from Switzerland, the SCCs apply with the modifications required by the Swiss Federal Data Protection Act.
11. Audit Rights
Upon Customer's reasonable written request, and no more than once per twelve (12) month period, Optima will make available the information necessary to demonstrate compliance with this DPA and will cooperate with and permit reasonable audits or inspections conducted by Customer or a qualified third-party auditor designated by Customer and reasonably acceptable to Optima, subject to reasonable confidentiality obligations. The status of any certifications or third-party audit reports is described on our Security Addendum.
12. De-identified and Aggregated Data
Optima may use aggregated, anonymized, and de-identified data about the use of the Services that is no longer Personal Data under applicable Data Protection Laws and cannot be attributed to Customer to improve the general performance and reliability of the Services. Optima will not use Customer Data to train or improve its models unless Customer expressly authorizes that use in an order form or other written agreement signed by both parties.
13. CCPA/CPRA Provisions
To the extent that the CCPA/CPRA applies, Optima acts as a "Service Provider" as defined by the CCPA/CPRA. Optima's obligations under the CCPA/CPRA are limited to the statutory minimums and are subject to Section 14 (Limitation of Liability). Specific CCPA/CPRA commitments may be addressed in the Agreement.
14. Limitation of Liability
OPTIMA'S TOTAL AGGREGATE LIABILITY ARISING OUT OF OR RELATED TO THIS DPA, THE PROCESSING OF PERSONAL DATA, ANY DATA PROTECTION LAWS, OR ANY SECURITY INCIDENT WILL BE SUBJECT TO THE LIMITATIONS OF LIABILITY SET FORTH IN THE AGREEMENT. IN NO EVENT WILL OPTIMA BE LIABLE FOR: (I) ANY INDIRECT, INCIDENTAL, SPECIAL, CONSEQUENTIAL, OR PUNITIVE DAMAGES; (II) ANY FINES OR PENALTIES IMPOSED BY SUPERVISORY AUTHORITIES, EXCEPT TO THE EXTENT SUCH FINES OR PENALTIES ARISE DIRECTLY FROM OPTIMA'S BREACH OF ITS OBLIGATIONS UNDER THIS DPA OR THE AGREEMENT; (III) ANY COSTS OF NOTIFICATION, CREDIT MONITORING, OR REMEDIATION, EXCEPT TO THE EXTENT SUCH COSTS ARISE DIRECTLY FROM OPTIMA'S BREACH OF ITS OBLIGATIONS UNDER THIS DPA OR THE AGREEMENT; OR (IV) ANY DAMAGES ARISING FROM CUSTOMER'S FAILURE TO EXPORT CUSTOMER DATA WITHIN THE PERIOD DESCRIBED IN SECTION 9 — IN EACH CASE ARISING FROM OR RELATED TO THIS DPA, REGARDLESS OF THE THEORY OF LIABILITY.
Where Customer has entered into a Master Cloud Services Agreement, the exceptions in Section 10.4 of that agreement also apply to this Section 14.
15. Term and Termination
This DPA terminates upon termination of the Agreement. Sections 12, 14, and 16 survive termination.
In the event of a conflict between this DPA and the Agreement with respect to the processing of Personal Data, this DPA prevails, except to the extent an order form or other written agreement signed by both parties expressly provides otherwise, including by authorizing Optima to use Customer Data for additional purposes. In the event of a conflict between this DPA and the SCCs, the SCCs prevail.
16. Modifications
We may update this DPA at any time in our sole discretion. Updated versions will be posted on our website. All modifications are immediately binding upon posting. We are not obligated to notify you of changes. It is solely your responsibility to review this DPA regularly. Your continued use of the Services constitutes your acceptance of the then-current DPA.
Notwithstanding the foregoing, for customers who have entered into a Master Cloud Services Agreement, modifications to this DPA shall be governed by the amendment provisions of that agreement (Section 15.4) and require mutual written agreement between the parties.
17. Contact
For questions about this DPA or to submit a data processing request, please contact us:
- Email: privacy@optima.engineering
- Legal inquiries: legal@optima.engineering
- Entity: Optima Engineering LLC