Kortexio — Data Processing Agreement (DPA)
Version: 1.0 · Effective Date: 12 July 2026
This Data Processing Agreement ("DPA") forms part of the Kortexio Terms of Service (the "Agreement") between:
- Processor: the operator of the Kortexio platform at kortexio.io, contact hello@kortexio.io ("Kortexio", "Processor"); and
- Controller: the customer accepting the Agreement ("Customer", "Controller").
Registered legal entity details for the Processor will be published on this page when confirmed.
It reflects the parties' agreement on the processing of Personal Data by Kortexio on behalf of the Customer in connection with the Kortexio platform (the "Service"), pursuant to Article 28 of Regulation (EU) 2016/679 ("GDPR").
Acceptance. By creating an account and accepting the Terms of Service, the Customer enters into this DPA. No separate signature is required for online sign-up.
1. Definitions
Terms such as "Personal Data", "Processing", "Data Subject", "Personal Data Breach", "Supervisory Authority" have the meanings given in the GDPR. "Customer Data" means Personal Data contained in content submitted to or generated through the Service under the Customer's account, including prompts, responses, memory/wiki content, documents, and tool inputs/outputs.
2. Roles, Scope, and Duration
2.1. The Customer is the Controller (or, where acting for its own clients, a Processor engaging Kortexio as sub-processor — in which case the Customer warrants that its instructions and this DPA are consistent with its obligations to the ultimate controller).
2.2. Kortexio processes Customer Data only as a Processor, on the Customer's documented instructions, for the duration of the Agreement, as further described in Annex I.
2.3. The Agreement, the Customer's configuration of the Service, and use of its features constitute the Customer's complete documented instructions. Additional instructions require mutual written agreement.
3. Processor Obligations (Art. 28(3) GDPR)
Kortexio shall:
(a) Instructions. Process Customer Data only on documented instructions from the Customer, including with regard to transfers to third countries, unless required by Union or Member State law; in such case, Kortexio will inform the Customer of that legal requirement before processing, unless the law prohibits it. Kortexio will inform the Customer if, in its opinion, an instruction infringes the GDPR.
(b) Confidentiality. Ensure that persons authorized to process Customer Data are bound by confidentiality obligations (contractual or statutory).
(c) Security. Implement and maintain the technical and organizational measures set out in Annex II (Art. 32 GDPR), reviewing and updating them as appropriate, provided the level of protection is not materially reduced.
(d) Sub-processing. Engage sub-processors only in accordance with Section 5.
(e) Data Subject Rights. Taking into account the nature of the processing, assist the Customer by appropriate technical and organizational measures, insofar as possible, in fulfilling the Customer's obligation to respond to Data Subject requests under GDPR Chapter III. If a Data Subject contacts Kortexio directly, Kortexio will promptly forward the request to the Customer and not respond on the merits except on the Customer's instruction or where legally required.
(f) Assistance. Assist the Customer in ensuring compliance with Arts. 32–36 GDPR (security, breach notification, data protection impact assessments, prior consultation), taking into account the nature of processing and information available to Kortexio.
(g) Deletion/Return. At the end of the provision of the Service, at the Customer's choice, delete or return all Customer Data and delete existing copies within 30 days, unless Union or Member State law requires storage. Self-service export tools are available during the Agreement and for 30 days after termination.
(h) Audit. Make available to the Customer all information necessary to demonstrate compliance with Art. 28 GDPR and allow for and contribute to audits, in accordance with Section 7.
4. Customer Obligations
4.1. The Customer is responsible for: the lawfulness of Customer Data and of the instructions given to Kortexio; providing required notices to and obtaining any required consents from Data Subjects; and configuring and using the Service (including retention settings, access control, memory content, and connected endpoints/tools) in a manner consistent with its obligations under data protection law.
4.2. The Customer acknowledges that the Service routes data to LLM inference endpoints and external tools designated and configured by the Customer. Such recipients act on the Customer's behalf and under the Customer's responsibility; they are not sub-processors of Kortexio unless expressly listed in Annex III.
4.3. The Customer shall not submit special categories of data (Art. 9 GDPR) or data relating to criminal convictions (Art. 10 GDPR) unless expressly agreed in writing with appropriate additional safeguards.
5. Sub-processors
5.1. The Customer provides general written authorization for the sub-processors listed in Annex III.
5.2. Kortexio will notify the Customer at least 30 days in advance of any intended addition or replacement of sub-processors (via email to the account holder or at https://kortexio.io/dpa#annex-iii). The Customer may object on reasonable data protection grounds within 15 days of notice. If the parties cannot resolve the objection in good faith, the Customer may terminate the affected subscription with a pro-rata refund of prepaid fees.
5.3. Kortexio will impose on each sub-processor, by written contract, data protection obligations materially equivalent to those in this DPA, and remains fully liable to the Customer for the performance of the sub-processor's obligations.
6. Personal Data Breach
6.1. Kortexio will notify the Customer without undue delay, and in any event within 48 hours, after becoming aware of a Personal Data Breach affecting Customer Data.
6.2. The notification will, to the extent known, describe the nature of the breach, categories and approximate numbers of Data Subjects and records concerned, likely consequences, measures taken or proposed, and a contact point. Information may be provided in phases as it becomes available.
6.3. Kortexio will reasonably cooperate with the Customer's obligations under Arts. 33–34 GDPR. Kortexio's notification is not an acknowledgment of fault or liability.
7. Audits
7.1. Kortexio will make available, upon written request no more than once per 12 months, documentation demonstrating compliance (security documentation, summaries of penetration tests, certifications where available).
7.2. Where such information is insufficient to demonstrate compliance, the Customer (or an independent auditor bound by confidentiality, not a competitor of Kortexio) may conduct an audit, subject to: 30 days' prior written notice; agreement on scope, timing, and duration; business hours; no access to other customers' data; and the Customer bearing its own costs. Audits triggered by a Supervisory Authority requirement or following a Personal Data Breach are not counted against the frequency limit.
8. International Transfers
8.1. Kortexio processes and stores Customer Data in datacenters located in the European Economic Area (Annex III). Kortexio will not transfer Customer Data outside the EEA without ensuring a valid transfer mechanism under GDPR Chapter V (adequacy decision or the European Commission's Standard Contractual Clauses (EU) 2021/914, with supplementary measures where required), and without following the sub-processor change procedure in Section 5.
9. Liability and Order of Precedence
9.1. Each party's liability under this DPA is subject to the limitations and exclusions of liability in the Agreement, except where such limitation is prohibited by law (including Art. 82 GDPR as between the parties and Data Subjects).
9.2. In the event of conflict between this DPA and the Agreement regarding the processing of Personal Data, this DPA prevails.
10. Term
This DPA takes effect upon acceptance of the Agreement and remains in force as long as Kortexio processes Customer Data.
Annex I — Description of Processing (Art. 28(3) GDPR)
Subject matter: Provision of the Kortexio agentic gateway platform: proxying and orchestrating LLM requests, maintaining persistent memory (wiki-based context store), executing Customer-configured tools, and related logging, storage, and administration.
Duration: Term of the Agreement plus the deletion period in Section 3(g).
Nature and purpose: Hosting; storage; retrieval; transmission to Customer-designated endpoints; structuring and indexing of memory content; audit logging; backup; deletion. Purpose: delivery of the Service as configured by the Customer.
Categories of Data Subjects: The Customer's employees, contractors, and end users; individuals referenced in content submitted by the Customer (e.g., customers, suppliers, contacts).
Categories of Personal Data: Identification and contact data; professional data; user identifiers and authentication metadata; any personal data included by the Customer in prompts, documents, memory content, and tool inputs/outputs. Special categories: none, unless separately agreed (Section 4.3).
Retention: Customer-controlled during the term; deletion/return per Section 3(g).
Annex II — Technical and Organizational Measures (Art. 32 GDPR)
- Encryption: TLS 1.2+ for all data in transit; encryption at rest for databases and backups.
- Tenant isolation: Logical multi-tenant isolation at application and database level; per-tenant scoping of memory stores, API keys, and audit logs.
- Access control: Role-based access control; SSO/identity management via a dedicated identity provider (OIDC); MFA for administrative accounts; least-privilege provisioning; periodic access reviews.
- Administrative access: Restricted to encrypted VPN (WireGuard) with key-based authentication; no public administrative interfaces.
- Sandboxing: Tool/code execution isolated in hardened sandboxes (gVisor-based) with restricted network egress.
- Logging and monitoring: Centralized audit logging of administrative and data-processing operations; anomaly and abuse monitoring; time-synchronized logs.
- Vulnerability management: Regular patching of OS and dependencies; dependency scanning; periodic security assessments.
- Backups and continuity: Encrypted, regularly tested backups on EU infrastructure; documented restore procedures.
- Data minimization and retention: Configurable retention; secure deletion procedures for data and backups within defined cycles.
- Personnel: Confidentiality undertakings; security awareness measures; controlled onboarding/offboarding.
- Incident response: Documented incident response procedure with defined roles and the notification commitments in Section 6.
- Physical security: Provided by the hosting provider's ISO 27001-aligned EU datacenters (Annex III).
<span id="annex-iii"></span>
Annex III — Authorized Sub-processors
| Sub-processor | Service | Location / Region | Safeguard |
|---|---|---|---|
| Hostinger International Ltd | Cloud VPS infrastructure hosting | EU (Germany) | EEA processing; vendor DPA in place |
| Plausible Insights OÜ | Website analytics (aggregated, cookieless) | EU (Estonia) | EEA processing; privacy-oriented analytics |
Note: Mollie B.V. processes payment data for billing purposes outside the scope of Customer Data and is addressed in the Privacy Policy. LLM endpoints, MCP servers, and tools configured by the Customer are engaged by the Customer directly and are not Kortexio sub-processors.
Current list maintained at: https://kortexio.io/dpa#annex-iii