Kanvify

Data Processing Addendum

Last updated: July 20, 2026

1. Formation and Scope

This Data Processing Addendum (“DPA”) forms part of the agreement governing a customer’s use of Kanvify (the “Agreement”) between Plus Ultra Industries, LLC (“Plus Ultra”) and the customer identified through the Service (“Customer”).

Customer accepts this DPA through the Service’s self-serve clickwrap. The person clicking to accept represents that they have authority to bind Customer. The DPA becomes effective when accepted and does not require a countersignature. Acceptance records maintained by the Service identify the Customer and acceptance time.

This DPA applies only when Plus Ultra processes Customer Personal Data on Customer’s behalf to provide the Service. It does not govern personal data for which Plus Ultra independently determines the purposes and means, such as account relationship, billing, fraud prevention, platform security, legal compliance, and direct communications, except where applicable law provides otherwise.

If this DPA conflicts with the Agreement on processing Customer Personal Data, this DPA controls. Mandatory transfer terms control over both documents for a covered transfer.

2. Definitions

“Applicable Data Protection Law” means privacy and data-protection law applicable to the processing under this DPA, including the GDPR, UK GDPR, Swiss Federal Act on Data Protection, and CCPA where each applies.

“CCPA” means the California Consumer Privacy Act, as amended. “Customer Personal Data” means Personal Data processed by Plus Ultra on Customer’s behalf through the Service. “Data Subject,” “Controller,” “Processor,” “Process,” “Personal Data,” “Personal Data Breach,” and “Supervisory Authority” have the meanings given by Applicable Data Protection Law. “GDPR” means Regulation (EU) 2016/679. “Subprocessor” means a third party appointed by Plus Ultra to process Customer Personal Data on Customer’s behalf.

3. Roles and Instructions

Customer is a Controller and appoints Plus Ultra as its Processor for Customer Personal Data. If Customer is itself a Processor for another Controller, Customer appoints Plus Ultra as its Subprocessor. Each party is responsible for its own legal obligations.

Plus Ultra will process Customer Personal Data only on Customer’s documented instructions, including the Agreement, this DPA, Customer’s use and configuration of the Service, and written instructions accepted by Plus Ultra, unless law requires other processing. Where legally permitted, Plus Ultra will inform Customer before processing required by law. Plus Ultra will inform Customer if, in its reasonable opinion, an instruction violates Applicable Data Protection Law and may suspend an unlawful or technically infeasible instruction while the parties seek a lawful alternative.

Customer instructs Plus Ultra to process Customer Personal Data to provide, secure, maintain, support, and improve the operation of the Service; prevent and investigate abuse; and comply with law as described in Schedule 1. Customer’s selection of a customer-provided Anthropic or OpenAI route instructs Plus Ultra to transmit the selected request to that provider using Customer’s provider credential.

Customer is responsible for the legality, accuracy, and proportionality of Customer Personal Data and instructions; required notices and consents; its end users; configuring access, caching, fallbacks, retention, and integrations; and determining whether the Service is appropriate for its data.

4. Confidentiality and Personnel

Plus Ultra will ensure that people authorized to process Customer Personal Data are bound by confidentiality obligations and access it only as needed for their assigned functions. Plus Ultra will apply role-based access and remove access when it is no longer required.

5. Security

Plus Ultra will maintain appropriate technical and organizational measures designed to protect Customer Personal Data against accidental or unlawful destruction, loss, alteration, unauthorized disclosure, or access, taking into account the nature of processing and risk. Current measures are summarized in Schedule 2 and on the Security page.

Customer is responsible for securely configuring its accounts, roles, credentials, network policies, provider routes, sandboxes, software, and backups. No security measure eliminates all risk.

Plus Ultra may update measures as the Service changes, provided the overall protection for Customer Personal Data is not materially reduced during the Agreement without a lawful basis and reasonable notice.

6. Subprocessors

Customer gives Plus Ultra general written authorization to engage the entities on the Subprocessor List. Plus Ultra will require a Subprocessor to protect Customer Personal Data under written obligations appropriate to its processing and, where Article 28 applies, substantially equivalent to the relevant obligations in this DPA. Plus Ultra remains responsible for a Subprocessor’s performance to the extent required by Applicable Data Protection Law.

Plus Ultra will post an addition or replacement on the Subprocessor List at least 30 calendar days before the provider begins processing Customer Personal Data and will make reasonable efforts to notify affected Customers through available account or email channels. Customer may object during that period on reasonable data-protection grounds by emailing privacy@plusultra.industries. The parties will work in good faith on a reasonable solution. If none is available, Plus Ultra may avoid or disable the affected feature, or Customer may terminate the affected Service before the change takes effect.

If an urgent security, availability, legal, or provider event makes 30 days’ advance notice impracticable, Plus Ultra may replace a provider sooner and will provide notice without undue delay with an explanation.

7. Data-Subject Requests

Taking into account the nature of processing, Plus Ultra will provide reasonable assistance through Service functionality and available organizational measures so Customer can respond to requests to exercise data-subject rights.

If Plus Ultra receives a request concerning Customer Personal Data, it will refer the requester to Customer and will not respond on Customer’s behalf unless Customer instructs it, Customer is unavailable and law requires a response, or law otherwise requires Plus Ultra to act. Customer remains responsible for verifying requests and determining the response.

8. Assessments and Regulatory Assistance

Taking into account the nature of processing and information available to Plus Ultra, Plus Ultra will provide reasonable assistance with Customer’s obligations concerning security, breach assessment and notification, data-protection impact assessments, and prior consultation with Supervisory Authorities. Assistance outside ordinary Service functionality may be subject to reasonable fees agreed in advance, unless the need for assistance results from Plus Ultra’s breach of this DPA.

9. Personal Data Breaches

After becoming aware of a Personal Data Breach affecting Customer Personal Data processed under this DPA, Plus Ultra will notify Customer without undue delay. Notice will include available information reasonably needed for Customer’s assessment, such as the nature of the breach, affected data and Data Subject categories, likely consequences, mitigation taken or proposed, and a contact for follow-up. Plus Ultra may provide information in phases as it becomes available and will reasonably cooperate with mitigation and investigation.

Customer, as Controller, determines whether notice to a Supervisory Authority or affected people is required. Under the GDPR, a Controller notifies the competent Supervisory Authority without undue delay and, where feasible, within 72 hours after awareness when the breach is likely to create a risk to rights and freedoms. A Controller notifies affected people without undue delay when the breach is likely to create a high risk, subject to applicable exceptions. Plus Ultra does not make a flat promise to notify every affected person within 72 hours.

Notice or cooperation is not an admission of fault or liability.

10. Return, Deletion, and Retention

During the Agreement, Customer may use available Service controls to retrieve or delete Customer Personal Data. After termination of the affected Service, Plus Ultra will, at Customer’s choice and subject to technically available export functionality, return or delete Customer Personal Data and delete remaining copies unless law requires retention.

Account deletion disables access after verification and is processed through automated lifecycle steps and manual remediation where necessary. Checkpoint records and backend snapshots are pruned daily after the account-configured operational period, which defaults to 90 days. LLM response-cache content expires at its configured time-to-live and is purged by a recurring sweep. Sessions are swept after 14 days idle or 30 days absolute. Processed Stripe webhook payloads are swept after 30 days.

Deleted Customer Personal Data may remain in restricted backups for no more than 30 days before aging out, unless a legal hold requires longer retention. Restored backups remain subject to deletion. Plus Ultra may retain minimized, de-identified billing records for tax, accounting, audit, and legal requirements and may retain limited security or legal records where required by law or needed to establish, exercise, or defend claims.

11. Information and Audits

Plus Ultra will make available information reasonably necessary to demonstrate compliance with this DPA. Customer should first use current policies, architecture and control descriptions, completed questionnaires, and other documentation Plus Ultra can lawfully provide.

If that information is insufficient and Applicable Data Protection Law requires an audit, Customer may request one no more than once annually, unless a Personal Data Breach or regulator requires more. Audits require reasonable advance notice, must occur during normal business hours, and must avoid access to other customers’ data, vulnerabilities, privileged information, and unrelated systems. An independent auditor must be bound by confidentiality. Customer bears reasonable audit costs unless the audit identifies a material breach by Plus Ultra. This section does not limit a Supervisory Authority’s powers.

Nothing in this DPA states that Plus Ultra holds a certification, audit report, or compliance attestation that it has not expressly published.

12. International Transfers

Customer authorizes processing in the locations on the Subprocessor List. Where a restricted transfer requires a contractual safeguard, the parties will use the European Commission’s 2021 Standard Contractual Clauses (“EU SCCs”) and the UK International Data Transfer Agreement (“UK IDTA”), as applicable.

For an EEA transfer, Module Two applies when Customer is a Controller and Plus Ultra is a Processor, and Module Three applies when Customer is a Processor and Plus Ultra is a Subprocessor, in each case only to the extent the module fits the parties’ actual roles. Schedule 1 supplies the processing description, the Subprocessor List supplies recipient locations, and Schedule 2 supplies the security measures.

For a restricted UK transfer, the parties will complete the UK IDTA tables and include its mandatory clauses. The EU SCCs alone do not govern a restricted UK transfer. The applicable SCC selections, annex details, UK IDTA tables, transfer assessment, and supplementary measures must be finalized for the specific transfer before the parties rely on them. If an adequacy decision or another lawful transfer mechanism applies, the parties may rely on it instead.

Mandatory EU SCC or UK IDTA terms prevail over conflicting provisions of the Agreement for the covered transfer. The parties will not modify mandatory wording in a way that reduces required protection.

13. U.S. State Privacy Terms

To the extent the CCPA applies and Plus Ultra processes Personal Information as Customer’s service provider or contractor, Customer discloses Personal Information only for the limited and specified business purposes in the Agreement and Schedule 1. Plus Ultra will:

  • Not sell or share that Personal Information
  • Not retain, use, or disclose it outside the direct business relationship or for another purpose except as permitted by the CCPA
  • Not combine it with personal information from another source except as permitted by the CCPA
  • Provide the level of privacy protection required of a service provider or contractor
  • Notify Customer if Plus Ultra determines it can no longer meet these obligations
  • Permit Customer to take reasonable and appropriate steps to help ensure compliant use and, after notice, stop and remediate unauthorized use

Independent account, billing, fraud-prevention, security, legal, and direct-communication processing by Plus Ultra is outside these service-provider instructions to the extent Plus Ultra acts as a business or Controller for that processing.

14. Government Requests

If Plus Ultra receives a legally binding demand for Customer Personal Data, it will, where legally permitted, notify Customer, review the demand for validity, limit disclosure to what is legally required, and reasonably challenge disproportionate or unlawful demands when appropriate. Plus Ultra may respond without advance notice when prohibited from notifying Customer or when an emergency request is lawful and credible.

15. Liability, Term, and Termination

The Agreement’s liability limits and exclusions apply to this DPA to the maximum extent permitted by law. Nothing limits rights or liability that cannot lawfully be limited or alters mandatory liability under the EU SCCs or UK IDTA.

This DPA remains effective while Plus Ultra processes Customer Personal Data under the Agreement. Sections that by their nature survive termination, including confidentiality, deletion, audit, transfers, and liability, remain effective for as long as relevant Customer Personal Data is retained.

16. Notices and Changes

Legal notices under this DPA must be sent to legal@plusultra.industries. Privacy and data-protection notices must be sent to privacy@plusultra.industries. Plus Ultra accepts these notices by email only.

We may update this DPA. We post changes with an updated effective date and make reasonable efforts to notify affected Customers. A change does not materially reduce protections for Customer Personal Data during an active paid term unless required by law or agreed by Customer.

Schedule 1 — Processing Details

Subject Matter and Duration

Processing needed to provide and secure Kanvify for the Agreement’s duration, plus the limited retention periods described in this DPA and the Privacy Policy.

Nature and Purpose

Hosting, organizing, isolating, transmitting, retrieving, caching, deleting, and otherwise processing data to operate sandbox compute and storage; workspaces; authentication; APIs and integrations; customer-selected LLM routing; support; security; abuse response; metering; and Service administration.

Data Subjects

Customer personnel, users, contractors, agents, collaborators, support contacts, integration users, and individuals whose Personal Data Customer or its users submit to the Service.

Personal Data Categories

Names, email addresses, account identifiers, roles, IP addresses, browser and device information, authentication and activity records, billing and usage metadata, customer code and files, environment data, support material, prompts and responses, integration metadata, and any other Personal Data Customer chooses to process.

Sensitive Data

The Service is not designed for categories of sensitive or regulated data unless Plus Ultra expressly agrees in writing. Customer must not submit special-category data, protected health information, payment-card data, government identifiers, biometric templates, or similarly sensitive data unless it has confirmed a lawful basis and obtained Plus Ultra’s written agreement for that use.

Frequency

Processing occurs continuously or intermittently as Customer and its authorized users use and configure the Service.

Schedule 2 — Technical and Organizational Measures

  • Tenant separation: isolated micro-VM sandboxes and PostgreSQL row-level security on scoped account and workspace tables
  • Network controls: encrypted transport for Service traffic, per-sandbox outbound-network policy at creation, and application and endpoint rate limits
  • Credentials: bcrypt one-way hashing for user API keys, hashing for OAuth secrets, revocable short-lived execution-token identifiers, and encryption for recoverable registry and customer-provided LLM credentials
  • Access: scoped customer roles and application authorization; personnel access limited by function and confidentiality obligations
  • Logging: session, request, selected activity, billing, security, and operational records used for troubleshooting, audit, and incident response
  • Retention automation: daily checkpoint record and backend-snapshot pruning; recurring LLM-cache purge; session and OAuth sweeps; and 30-day processed Stripe-webhook cleanup
  • Availability and lifecycle: sandbox lifecycle operations, scheduled jobs, monitoring, and provider-supported infrastructure; checkpoints are not a backup service
  • Incident handling: assessment, containment, investigation, mitigation, and role-appropriate notification under Section 9
  • Vendor management: written data-protection terms appropriate to the processing and a public Subprocessor List with 30-day change notice

These measures describe current controls and do not promise absolute security or uninterrupted availability.