top of page
Original on Transparent.png

Knakl Cloud — Data Processing Addendum

Last Updated: August 18, 2026

 

DRAFT FOR ATTORNEY REVIEW — NOT YET LEGALLY VERIFIED. This document has cross-border legal effect and should be reviewed by counsel with data protection experience before publication. Bracketed items [like this] must be completed.

This Data Processing Addendum (the “DPA”) forms part of the Terms of Service between Knakl Cloud LLC (“Knakl”, “Processor”) and the customer agreeing to those Terms (“Customer”, “Controller”, “you”).

This DPA applies where Knakl processes Personal Data on Customer’s behalf in the course of providing the Services and where that processing is subject to Data Protection Laws.

1. Definitions

 

Data Protection Laws — all laws applicable to the processing of Personal Data under this DPA, including the EU General Data Protection Regulation 2016/679 (“GDPR”), the UK GDPR and Data Protection Act 2018, the Swiss Federal Act on Data Protection, the California Consumer Privacy Act as amended (“CCPA”), and other applicable US state privacy laws.

Personal Data — information relating to an identified or identifiable natural person that is contained in Customer Content and processed by Knakl on Customer’s behalf.

Processing, Controller, Processor, Data Subject, Personal Data Breach — as defined in the GDPR (or the closest equivalent under other Data Protection Laws).

Sub-processor — a third party engaged by Knakl to process Personal Data on Customer’s behalf.

Standard Contractual Clauses or SCCs — the clauses annexed to European Commission Implementing Decision (EU) 2021/914.

Customer Content, Customer Workloads, Service Data, Services — as defined in the Terms of Service.

 

 

 

2. Roles of the Parties

 

2.1 Customer is the Controller of Personal Data contained in Customer Content. Customer determines the purposes and means of processing and is responsible for the lawfulness of that processing.

2.2 Knakl is the Processor of that Personal Data and processes it only on Customer’s documented instructions.

2.3 Knakl is an independent Controller of Service Data and of account, billing, and support information, which it processes for its own legitimate purposes as described in the Privacy Policy. This DPA does not apply to that processing.

2.4 Under the CCPA, Knakl acts as a service provider. Knakl does not sell or share Personal Data, does not retain, use, or disclose it for any purpose other than performing the Services, and does not combine it with Personal Data received from other sources except as permitted by the CCPA.

3. Precedence

 

Where this DPA conflicts with the Terms of Service in relation to the processing of Personal Data on Customer’s behalf, this DPA controls. Where this DPA conflicts with the SCCs, the SCCs control.

4. Scope and Details of Processing

 

Subject matter. Provision of cloud infrastructure services.

Duration. For the term of the Terms of Service, plus any retention period described in Section 11.

Nature and purpose. Hosting, storage, transmission, computation, backup (where the Customer enables such a feature), and technical support — as necessary to provide the Services and as instructed by Customer.


Types of Personal Data. Determined entirely by Customer. Because Knakl provides unmanaged infrastructure, Knakl does not control, inspect, or classify what Personal Data Customer chooses to store. This may include contact details, identifiers, account credentials, usage records, communications, and any other categories Customer places on the Services.

Categories of Data Subjects. Determined entirely by Customer — typically Customer’s own customers, users, employees, contractors, or website visitors.

Special category data. Customer must not store special category data (GDPR Article 9), children’s data, government identifiers, payment card data subject to PCI DSS, or health data subject to HIPAA unless the relevant safeguards are expressly included in Customer’s plan or agreed in writing with Knakl (Terms of Service, Section 5.7). Knakl does not currently offer a HIPAA Business Associate Agreement.

 

 

 

5. Knakl’s Obligations

 

5.1 Documented instructions. Knakl processes Personal Data only on Customer’s documented instructions, which comprise the Terms of Service, this DPA, and Customer’s use and configuration of the Services. Knakl will notify Customer if it believes an instruction infringes Data Protection Laws, unless prohibited from doing so by law.

5.2 Legal compulsion. If law requires Knakl to process Personal Data beyond Customer’s instructions, Knakl will inform Customer of that requirement before processing, unless the law prohibits such notice on important grounds of public interest.

5.3 No independent use. Knakl will not access, use, disclose, sell, or share Personal Data for its own purposes, including for advertising, profiling, or training machine-learning models.

5.4 Confidentiality. Knakl ensures that personnel authorized to process Personal Data are bound by confidentiality obligations and receive appropriate data protection training. Access is limited to personnel who need it to provide or support the Services.

5.5 Security. Knakl implements the technical and organizational measures described in Annex II.

5.6 Assistance. Taking into account the nature of the processing and the information available to it, Knakl will provide reasonable assistance to Customer with data protection impact assessments, prior consultations with supervisory authorities, and its obligations under GDPR Articles 32–36.

6. Customer’s Obligations

6.1 Customer warrants that it has a lawful basis for processing, has provided all required notices, and has obtained all required consents.

6.2 Customer is responsible for configuring the Services appropriately for the sensitivity of its data — including encryption at rest and in transit, access controls, network security, patching, and backups. Knakl provides unmanaged infrastructure and does not configure Customer Workloads.

6.3 Customer’s instructions must comply with Data Protection Laws. Customer is responsible for the accuracy, quality, and legality of Personal Data it places on the Services.

 

 

 

7. Sub-processors

 

7.1 Customer provides general authorization for Knakl to engage Sub-processors. A current list is maintained at [knakl.com/legal/subprocessors].

7.2 Knakl imposes data protection obligations on each Sub-processor that are no less protective than those in this DPA, and remains fully liable to Customer for each Sub-processor’s performance.

7.3 Notice of changes. Knakl will give at least thirty (30) days’ notice before adding or replacing a Sub-processor, by updating the Sub-processor page and notifying Customers who have subscribed to updates at that page.

7.4 Objection. Customer may object on reasonable data protection grounds within the notice period. The parties will discuss the objection in good faith. If it cannot be resolved, Customer may terminate the affected Services without penalty and receive a pro-rata refund of prepaid fees for the unused period.

8. Data Subject Requests

 

8.1 Where Knakl receives a request from a Data Subject relating to Personal Data processed on Customer’s behalf, Knakl will not respond substantively but will direct the individual to Customer, unless legally required to respond (Terms of Service, Section 6.8).

8.2 Knakl will provide reasonable assistance to enable Customer to respond to requests for access, rectification, erasure, restriction, portability, or objection. Because Customer retains full administrative control over its servers, Customer can generally fulfill such requests directly.

8.3 Where assistance requires significant engineering effort beyond the Services’ standard functionality, Knakl may charge a reasonable fee, notified in advance.

 

 

 

9. Personal Data Breach

 

9.1 Knakl will notify Customer without undue delay, and in any event within seventy-two (72) hours, after becoming aware of a Personal Data Breach affecting Personal Data processed on Customer’s behalf.

9.2 The notification will describe, to the extent known: the nature of the breach, the categories and approximate number of Data Subjects and records affected, likely consequences, measures taken or proposed, and a contact point for further information. Knakl will provide updates as the investigation progresses.

9.3 Customer is responsible for determining whether the breach requires notification to supervisory authorities or Data Subjects, and for making any such notification. Knakl’s notification is not an acknowledgement of fault or liability.

9.4 Customer is solely responsible for security incidents arising from Customer Workloads, Customer configurations, or Customer credentials (Terms of Service, Section 12.5).

10. Audits

 

10.1 Knakl will make available information reasonably necessary to demonstrate compliance with this DPA, including any third-party audit reports or certifications it holds.

10.2 Where such documentation is insufficient to satisfy Customer’s audit obligations under GDPR Article 28(3)(h), Customer may request an audit no more than once per twelve (12) month period, on at least thirty (30) days’ written notice, during business hours, subject to confidentiality obligations, and conducted so as not to disrupt Knakl’s operations or other customers’ data.

10.3 Audits are at Customer’s expense unless they reveal material non-compliance by Knakl. Audits may not extend to other customers’ data, third-party data center premises Knakl does not control, or Knakl’s proprietary information.

 

 

 

 

11. Deletion and Return

 

11.1 On termination of the Services, Customer must export Personal Data before cancellation, as Customer Content may be deleted immediately (Terms of Service, Section 6.5).

11.2 On Customer’s written request made within thirty (30) days of termination, Knakl will delete or return remaining Personal Data in its possession, except where retention is required by law.

11.3 Residual copies in backup, disaster-recovery, security, or archival systems may persist until overwritten on Knakl’s normal retention cycle. Such copies remain protected by this DPA and will not be restored to active use except for legitimate backup, disaster-recovery, security, or legal purposes (Terms of Service, Section 6.6).

12. International Transfers

 

12.1 Knakl is established in the United States. Personal Data may be processed in the United States and in any region where Customer deploys resources.

12.2 EEA transfers. Where Personal Data is transferred from the EEA to a country without an adequacy decision, the Standard Contractual Clauses apply and are incorporated by reference, with Module Two (Controller to Processor) applying, or Module Three (Processor to Processor) where Customer is itself a processor. The parties agree: the optional docking clause (Clause 7) applies; general written authorization under Clause 9(a) Option 2 applies, with the notice period in Section 7.3 above; the governing law under Clause 17 is the law of Ireland; and the forum under Clause 18(b) is the courts of Ireland. Annexes I and II to this DPA serve as the SCC annexes.

12.3 UK transfers. The UK International Data Transfer Addendum to the SCCs applies, with Tables 1–4 completed by reference to the Annexes below and the “Importer” being Knakl.

12.4 Swiss transfers. The SCCs apply with references to the GDPR read as references to the Swiss FADP, the competent authority being the Federal Data Protection and Information Commissioner, and “member state” not excluding Data Subjects in Switzerland.

12.5 Government access. Knakl will challenge any legally invalid request for Personal Data from a public authority and will notify Customer of any such request unless legally prohibited. Knakl maintains records of the requests it receives.

 

 

 

 

13. Liability

 

Each party’s liability under this DPA is subject to the limitations and exclusions in Section 12 of the Terms of Service, except where Data Protection Laws prohibit such limitation.

Annex I — Details of Processing

 

A. Parties :

 Data Exporter The Customer identified in the Account.

 Contact: the email address on the Account.

 Role: Controller (or Processor, where Module Three applies).

Data Importer: Knakl Cloud LLC, 215 37th Ave NE, Saint Petersburg, FL 33704, USA.

Contact: support@knakl.com.

Role: Processor.

B. Description of Transfer

  • Data Subjects, categories of Personal Data, special categories — as set out in Section 4 above. Determined by Customer.

  • Frequency — continuous, for the duration of the Services.

  • Nature and purpose — hosting, storage, transmission, computation, and support, as described in Section 4.

  • Retention — for the term of the Services plus the periods in Section 11.

  • Sub-processor transfers — as listed at [knakl.com/legal/subprocessors], for the duration of their engagement.

C. Competent Supervisory Authority. Determined under Clause 13 of the SCCs by reference to Customer’s establishment or its Article 27 representative.

 

 

 

Annex II — Technical and Organizational Measures

 

[TO BE COMPLETED — describe the measures Knakl actually has in place. Do not publish aspirational controls; under GDPR Article 32 these are contractual commitments and must be accurate. Confirm each item below against your real infrastructure before publishing, and delete anything not yet implemented.]

 

  • Encryption — TLS for data in transit across public networks; encryption at rest for [specify which storage products].

  • Access control — role-based access to production systems; multi-factor authentication for staff; least-privilege provisioning; access reviewed [quarterly]; revocation on personnel departure.

  • Physical security — data centers operated by providers maintaining [SOC 2 / ISO 27001 / specify] certification, with access control, surveillance, and environmental controls.

  • Network security — segmentation, firewalling, DDoS mitigation, and intrusion detection.

  • Logging and monitoring — administrative action logging, security event monitoring, retention of [90] days.

  • Resilience — redundant power and network; documented incident response and disaster recovery procedures; recovery testing [annually].

  • Data separation — logical isolation of customer environments through virtualization and network segmentation.

  • Personnel — confidentiality agreements, background checks where permitted by law, and security training on hire and [annually].

  • Vendor management — security review of Sub-processors before engagement and [annually] thereafter.

  • Deletion — secure erasure or cryptographic erasure of storage media on decommissioning.

Contact

 

Knakl Cloud LLC 215 37th Ave NE Saint Petersburg, FL 33704, USA Email: support@knakl.com

© 2026 Knakl Cloud LLC. All rights reserved.

bottom of page