Data Processing Addendum
This Data Processing Addendum ("DPA") forms part of the agreement between Klair Technology Solutions Private Limited (Klair Labs), Hyderabad, India ("the processor", "we"), and the business holding a Cancel Desk workspace ("the controller", "you"). It applies whenever Cancel Desk processes personal data on your behalf — chiefly, your customers' data passing through your cancel flow. It applies automatically to every workspace; if your compliance records need a countersigned copy, the route is at the bottom.
1. Subject matter and duration
The subject matter is the processing described in section 3, performed so we can provide Cancel Desk to you under our Terms of Service. The DPA lasts as long as your workspace exists, plus the period needed to complete deletion under section 9.
2. Nature and purpose of processing
Storing, retrieving, and displaying cancellation-session data; sending you notification emails when a session finishes; delivering signed webhooks to endpoints you configure; and generating aggregate views (reason counts, outcomes) inside your own dashboard. We do not use this data for our own purposes — no advertising, no model training, no resale, no contacting your customers except as part of the flow itself.
3. Categories of data and data subjects
- Data subjects: your end-customers who go through your cancel flow, and your own workspace users (account holders).
- Categories of data: for end-customers — email address, the cancellation reason they picked, any free-text feedback they typed, the outcome (saved or cancelled), and session timestamps. For account holders — email address, workspace configuration, and subscription records. No payment-card data ever reaches us; that stays with Razorpay.
- The flow asks for no special-category data. Free-text feedback is your customer's own words — you decide what to do with anything they volunteer there.
4. Our obligations as your processor
- Process personal data only on your documented instructions — which are, in practice, your workspace configuration and your use of the product — unless law requires otherwise, in which case we'll tell you before processing unless the law forbids it.
- Apply the technical and organisational measures described on our security page (encryption at rest and in transit, isolated infrastructure, an append-only audit trail, point-in-time backups).
- Keep access limited — today that is one named person, as the security page states plainly.
- Assist you, within reason, in responding to data-subject requests concerning sessions in your workspace, and in your own security and impact assessments.
- Notify you without undue delay after becoming aware of a personal-data breach affecting your workspace's data.
- Delete or return the data at the end of the relationship, per section 9.
5. Confidentiality
Everyone authorised to process the data (currently the founder alone) is bound to confidentiality. We do not read your sessions except where needed to operate the service — debugging a fault you've reported, for example — or where law requires.
6. Sub-processors
You give general authorisation for the sub-processors listed at cancel.klairlabs.com/subprocessors.html. That page is the canonical list; it carries a dated change log, and we commit to updating it at least 14 days before a new sub-processor starts handling personal data. If you object to an addition on reasonable data-protection grounds and we can't resolve it, you can end the service and take your data out under section 9. Each sub-processor is bound by terms materially no less protective than this DPA.
7. International transfers
Personal data is stored and processed in AWS's Asia Pacific (Mumbai, ap-south-1) region and stays there. Amazon CloudFront serves pages from edge locations worldwide, but it caches pages and static assets, not the personal data described in section 3. If you are outside India, your use of Cancel Desk is itself a transfer of your customers' data to India — factor that into your own transfer assessment; we'll answer questions about the setup honestly at hello@klairtech.com.
8. Audit rights
You may audit our compliance with this DPA to the extent reasonably necessary: written questions first, and — where those genuinely don't suffice — a review conducted at your cost, at most once a year, on reasonable notice, during business hours, and without access to other customers' data. We're a one-person company; audits scaled to that reality get honest, complete answers.
9. Deletion and return on termination
Both are self-serve. You can export every session as CSV on every plan, at any time, from the dashboard. Deleting your workspace from Settings removes your account, every session record, every flow, and any branding — immediately, with no email to us required. Where law requires us to retain a record of a payment for tax purposes, we keep only that. Note the retention-setting caveat in our privacy policy: the automated purge job for the configurable retention window is built but not yet switched on, so deletion today means workspace deletion or a specific request to hello@klairtech.com.
10. Getting a countersigned copy
Email hello@klairtech.com with the subject line "DPA — <your workspace email>". We'll return a countersigned copy of this document naming your business. No sales call, no negotiation theatre — though if your legal team needs specific edits, say so in the email and we'll look at them honestly.