Legal

Data Processing Addendum

sauble.ai is a product of Kinara Systems Inc.  ·  Version 0.1  ·  Effective July 20th, 2026

This Data Processing Addendum (“DPA”) forms part of, and is subject to, the Terms of Service (the “Agreement”) between the customer (“Customer”) and Kinara Systems Inc. (“Kinara”). It applies where Kinara processes Personal Data contained in Customer Data on Customer’s behalf in the course of providing the Service.

For that processing, Customer acts as the controller (or “business”) and Kinara acts as the processor (or “service provider”). Personal data that Kinara handles as a controller in its own right — such as account data about Customer’s users — is described in the Privacy Policy, not this DPA. To the extent of any conflict on the processing of Personal Data, this DPA prevails over the rest of the Agreement.

1. Definitions

“Applicable Data Protection Law” means all privacy and data-protection laws applicable to the processing of Personal Data under the Agreement, including Canada’s PIPEDA, the EU General Data Protection Regulation (“GDPR”), the UK GDPR, and the California Consumer Privacy Act as amended (“CCPA”).

“Personal Data,” “controller,” “processor,” “data subject,” “processing,” and “personal data breach” have the meanings given in the GDPR; “business,” “service provider,” “sell,” and “share” have the meanings given in the CCPA. “Sub-processor” means a third party engaged by Kinara to process Personal Data.

“Standard Contractual Clauses” or “SCCs” means the clauses approved by the European Commission for the transfer of Personal Data to third countries, and, for the UK, the UK International Data Transfer Addendum.

2. Roles and scope

This DPA applies only to Kinara’s processing of Personal Data as a processor on Customer’s behalf. Kinara will process such Personal Data only to provide, secure, and support the Service and only on Customer’s documented instructions, which consist of the Agreement, this DPA, and Customer’s configuration and use of the Service.

Kinara will inform Customer if, in its opinion, an instruction infringes Applicable Data Protection Law (without obligation to provide legal advice). Customer is responsible for the accuracy and legality of the Personal Data it makes accessible and for having a lawful basis for the processing it instructs.

3. Confidentiality of processing

Kinara will ensure that personnel authorized to process Personal Data are bound by appropriate obligations of confidentiality and process Personal Data only as necessary to provide the Service.

4. Security measures

Kinara will implement and maintain appropriate technical and organizational measures designed to protect Personal Data against accidental or unlawful destruction, loss, alteration, unauthorized disclosure, or access, taking into account the state of the art and the risks of the processing. A current description is set out in Annex II.

5. Sub-processors

Customer provides a general authorization for Kinara to engage Sub-processors to process Personal Data. The current Sub-processors are listed on Kinara’s Sub-processors page.

Kinara will impose data-protection obligations on each Sub-processor that are substantially equivalent to those in this DPA, and remains responsible for its Sub-processors’ performance. Kinara will give Customer notice before adding or replacing a Sub-processor (by updating the Sub-processors page and, where Customer has subscribed to notifications, by notice), and Customer may object on reasonable data-protection grounds, in which case the parties will work in good faith to resolve the objection.

6. Assistance with data-subject requests

Taking into account the nature of the processing, Kinara will provide reasonable assistance, including appropriate technical and organizational measures, to help Customer respond to requests from data subjects to exercise their rights. If Kinara receives such a request directly, it will not respond except on Customer’s instruction, and will refer the request to Customer without undue delay.

7. Personal data breach

Kinara will notify Customer without undue delay after becoming aware of a personal data breach affecting Customer’s Personal Data, and will provide information reasonably available to help Customer meet its own notification obligations. Kinara’s notification is not an acknowledgement of fault or liability.

8. Data protection impact assessments

Taking into account the nature of the processing and the information available to Kinara, Kinara will provide reasonable assistance to Customer with data protection impact assessments and prior consultations with supervisory authorities that Customer is required to carry out under Applicable Data Protection Law.

9. International transfers

Kinara may process and transfer Personal Data in Canada, the United States, and the European Union as described in the Privacy Policy and the Sub-processors page. Where Kinara processes Personal Data originating from the EEA or the UK in a country without an adequacy decision, the Standard Contractual Clauses (and, for the UK, the UK International Data Transfer Addendum) are incorporated into this DPA by reference, with Kinara acting as data importer, and apply to that transfer.

10. Deletion or return

On termination of the Agreement, Kinara will, at Customer’s choice, delete or return Personal Data processed on Customer’s behalf, and delete existing copies, within the period described in the Agreement, except to the extent retention is required by law or for the retention periods described in the Privacy Policy.

11. Audits and information

Kinara will make available to Customer information reasonably necessary to demonstrate compliance with this DPA and will allow for and contribute to audits, including inspections, conducted by Customer or an auditor it mandates. To minimize disruption, Kinara may satisfy audit requests by providing relevant third-party reports or documentation, and audits are subject to reasonable notice, confidentiality, and frequency limits.

12. CCPA service-provider terms

To the extent Kinara processes Personal Data that is subject to the CCPA on Customer’s behalf, Kinara acts as a service provider. Kinara will not sell or share such Personal Data; will not retain, use, or disclose it for any purpose other than the specific business purpose of providing the Service, or outside the direct business relationship, except as permitted by the CCPA; and will not combine it with data from other sources except as the CCPA permits. Kinara certifies that it understands and will comply with these restrictions.

13. Liability, term, and precedence

Each party’s liability under this DPA is subject to the exclusions and limitations of liability in the Agreement. This DPA takes effect on the effective date of the Agreement and continues while Kinara processes Personal Data on Customer’s behalf. This DPA is governed by the same law and dispute-resolution terms as the Agreement.

14. Annex I — Description of the processing

Parties: Customer is the controller / data exporter; Kinara Systems Inc. is the processor / data importer.

Data subjects: Customer’s authorized users of the Service; and individuals whose Personal Data appears in the systems Customer connects to the Service (for example, network, device, or client identifiers in telemetry, logs, or topology data).

Categories of Personal Data: account and contact identifiers of authorized users (name, work email, company, role); and any Personal Data contained in Customer Data or read from connected systems, which may include usernames, device or client identifiers, and IP or network addresses. Special categories of Personal Data are not intended to be processed and should not be provided.

Nature and purpose: hosting, processing, and analysis of Customer Data to provide AIOps functionality — including root-cause analysis, recommendations, and related support — as described in the Agreement.

Frequency and duration: continuous, for the term of the Agreement and the post-termination deletion period.

15. Annex II — Technical and organizational measures

Access control and least privilege: role-based access control; connectors to Customer systems are designed for read-only, least-privilege access using credentials Customer scopes.

Encryption: Personal Data is encrypted in transit using industry-standard protocols, and connector credentials are encrypted at rest.

Pseudonymization: product-analytics identifiers are pseudonymous, and raw identifiers, names, and emails are kept out of the analytics provider.

Operational measures: authentication of users and services, logging and monitoring, environment separation, and diligence on Sub-processors. These measures may be updated as the Service evolves, provided the level of protection is not materially decreased.

16. Annex III — Sub-processors

The authorized Sub-processors, with the purpose and processing region of each, are listed on Kinara’s Sub-processors page, which forms part of this Annex and is updated in accordance with the “Sub-processors” section above.

Requesting a signed DPA

Customers who require a countersigned DPA may request one, and view the current sub-processors on our Sub-processors page, by contacting Kinara Systems Inc. via our contact page.