This Data Processing Addendum ("DPA") forms part of the Terms of Service ("Agreement") between DKY Technologies Ltd ("Cheku", "Processor", "we", "us") and the Customer ("Controller", "you", "your") who uses the Cheku platform to process personal data.
This DPA applies to all Cheku plans, including the Free plan.
1. Definitions
"Applicable Data Protection Laws" means UK GDPR (the UK General Data Protection Regulation as retained under the Data Protection Act 2018), the EU GDPR (Regulation 2016/679) to the extent applicable, and the Australian Privacy Act 1988, in each case as applicable to the processing of Personal Data under this DPA.
"Customer Data" means all personal data that the Controller uploads, enters, or stores within the Cheku platform, including data relating to the Controller's clients, contacts, staff, engagements, and documents.
"Data Subject" means an identified or identifiable natural person whose personal data is processed within the Service.
"Personal Data" has the meaning given in the UK GDPR: any information relating to an identified or identifiable natural person.
"Processing" has the meaning given in the UK GDPR: any operation performed on personal data, including collection, storage, retrieval, use, disclosure, or deletion.
"Sub-processor" means a third party engaged by the Processor to process Customer Data on behalf of the Controller.
"Security Incident" means any accidental or unlawful destruction, loss, alteration, unauthorised disclosure of, or access to, Customer Data.
2. Roles and Scope
2.1 Roles
- You (the Customer) are the data controller. You determine the purposes and means of processing the personal data of your clients, contacts, and other individuals stored in Cheku.
- Cheku is the data processor. We process Customer Data solely on your documented instructions and as necessary to provide the Service.
2.2 Scope of Processing
| Detail | Description |
|---|---|
| Subject Matter | Provision of the Cheku practice management platform |
| Duration | For the term of your Account, plus the data retention period (90 days post-deletion) |
| Nature and Purpose | Storage, retrieval, display, search, and AI-assisted analysis of Customer Data to provide the Service |
| Categories of Data Subjects | Your clients, contacts, staff members, and other individuals whose data you enter into the platform |
| Types of Personal Data | Names, contact details, addresses, financial information, engagement records, documents, timesheets, and other data you choose to store |
3. Controller Obligations
You are responsible for:
- Ensuring you have a lawful basis for collecting and processing personal data before entering it into Cheku.
- Providing any required notices to Data Subjects and obtaining any necessary consents.
- Ensuring the accuracy and relevance of personal data you enter into the Service.
- Responding to Data Subject requests (with our reasonable assistance as described below).
- Complying with all Applicable Data Protection Laws in your use of the Service.
4. Processor Obligations
We will:
- Process Customer Data only on your documented instructions and as necessary to provide the Service. If we are required by law to process data for another purpose, we will inform you (unless prohibited by law).
- Ensure that persons authorised to process Customer Data are bound by appropriate obligations of confidentiality.
- Implement and maintain appropriate technical and organisational security measures (see Section 7).
- Not engage any Sub-processor without meeting the requirements in Section 6.
- Assist you, taking into account the nature of processing, in responding to Data Subject requests (see Section 5).
- Assist you in meeting your obligations under Applicable Data Protection Laws with respect to security, breach notification, data protection impact assessments, and prior consultation with supervisory authorities.
- At your choice, delete or return all Customer Data upon termination of your Account, except where retention is required by law.
- Make available to you information reasonably necessary to demonstrate compliance with this DPA.
5. Data Subject Rights
If we receive a request from a Data Subject relating to Customer Data, we will promptly notify you and will not respond to the request directly unless instructed by you or required by law.
We will provide you with reasonable technical assistance to fulfil Data Subject requests, including requests for access, rectification, erasure, restriction, portability, and objection.
6. Sub-processors
6.1 Current Sub-processors
We use the following Sub-processors to provide the Service:
| Sub-processor | Purpose | Data Location |
|---|---|---|
| Supabase, Inc. (on AWS) | Database hosting, authentication, file storage | EU-WEST-2 (London, UK) |
| Stripe, Inc. | Payment processing | EU/US |
| Microsoft Corporation (Azure) | AI feature processing | EU regions |
6.2 Changes to Sub-processors
We will notify you at least 30 days before engaging any new Sub-processor or replacing an existing one. Notification will be sent to the email address associated with your Account.
If you have a reasonable objection to a new Sub-processor based on data protection grounds, you may notify us within 14 days of receiving our notice. We will work with you in good faith to address your concerns. If we cannot resolve the objection, you may terminate your Account and we will provide a pro-rata refund of any prepaid fees.
6.3 Sub-processor Agreements
We ensure that each Sub-processor is bound by data protection obligations no less protective than those in this DPA, including obligations regarding confidentiality, security, and data handling. We remain fully liable for the acts and omissions of our Sub-processors.
7. Security Measures
We implement and maintain the following technical and organisational measures to protect Customer Data:
7.1 Technical Measures
- Encryption in transit: All data transmitted between your browser and our servers is encrypted using TLS 1.2 or higher.
- Encryption at rest: Customer Data stored in our database and file storage is encrypted using AES-256 encryption.
- Access control: Row-level security (RLS) enforces firm-level data isolation — each firm's data is logically separated and inaccessible to other firms.
- Authentication: Secure authentication with support for strong password requirements.
- Backup and recovery: Regular automated backups with point-in-time recovery capability.
7.2 Organisational Measures
- Least privilege access: Internal access to production systems and Customer Data is restricted to authorised personnel on a need-to-know basis.
- Confidentiality: All personnel with access to Customer Data are bound by confidentiality obligations.
- Monitoring: We monitor our systems for security events and unauthorised access attempts.
- Vendor management: Sub-processors are assessed for their security and data protection practices before engagement.
8. Security Incidents
8.1 Notification
We will notify you of any confirmed Security Incident without undue delay and in any event within 72 hours of becoming aware of it. Notification will be sent to the email address associated with your Account.
8.2 Notification Content
Our notification will include, to the extent available:
- A description of the nature of the Security Incident, including the categories and approximate number of Data Subjects and records affected.
- The name and contact details of the point of contact for further information.
- A description of the likely consequences of the Security Incident.
- A description of the measures taken or proposed to address the Security Incident, including measures to mitigate its possible adverse effects.
8.3 Our Response
We will take reasonable steps to contain, investigate, and remediate any Security Incident. We will cooperate with you and provide reasonable assistance to enable you to meet your obligations to notify supervisory authorities and Data Subjects where required by Applicable Data Protection Laws.
8.4 What Is Not a Security Incident
Unsuccessful access attempts (e.g., failed logins, port scans, denial of service attacks that do not result in a breach) are not Security Incidents for the purposes of this DPA, though we monitor and respond to them as part of our security practices.
9. International Data Transfers
Customer Data is stored in the EU-WEST-2 (London, UK) region on AWS infrastructure.
Where Customer Data is transferred to a Sub-processor outside the United Kingdom:
- We ensure appropriate safeguards are in place, including Standard Contractual Clauses (SCCs), International Data Transfer Agreements (IDTAs), or adequacy decisions, as required by Applicable Data Protection Laws.
- Details of transfer mechanisms for each Sub-processor are available upon request.
10. Data Retention and Deletion
10.1 During Your Account Term
We retain Customer Data for the duration of your Account to provide the Service.
10.2 After Account Termination
Upon termination or deletion of your Account:
- We will provide a 30-day window for you to export your Customer Data.
- After the export window, Customer Data will be permanently deleted within 90 days.
- We may retain limited data where required by law (e.g., billing records for tax purposes).
10.3 Deletion on Request
You may request deletion of specific Customer Data at any time through the Platform or by contacting support@cheku.ai. We will process deletion requests within 30 days.
11. Audits
You have the right to verify our compliance with this DPA. To exercise this right:
- You may request, no more than once per year, written information about our security measures and processing activities.
- We will respond within 30 days with relevant documentation, certifications, or third-party audit reports where available.
- If documentation alone is not sufficient to demonstrate compliance, we will discuss and agree upon the scope, timing, and conditions of any further audit, taking into account confidentiality and the security of other customers' data.
12. Liability
Each party's liability under this DPA is subject to the limitations of liability set out in the Terms of Service.
13. Term and Termination
This DPA takes effect when you create a Cheku Account and remains in effect for as long as we process Customer Data on your behalf, including any data retention period following account termination.
If there is any conflict between this DPA and the Terms of Service, this DPA shall prevail with respect to data processing matters.
14. Contact
For questions about this DPA, contact us at:
DKY Technologies Ltd
Flat 12, 134 Hatfield Road
St Albans, AL1 4HY
United Kingdom
Email: support@cheku.ai