Data Processing Agreement
This Data Processing Agreement (DPA) applies whenever Kuro Studio processes personal data on behalf of a customer of Kuro Engage. It supplements our Terms of Service (https://engage.kurostudio.io/terms) and is concluded together with them. Version 1.0, effective 2026-07-16.
In this agreement, the customer is the controller and Kuro Studio is the processor within the meaning of Art. 4 and Art. 28 GDPR.
1. Parties and subject matter
- Processor
- Kuro Studio, Lukas Wirth
- Address
- Hirschberger Str. 24, 90559 Burgthann, Germany
- Contact
- legal@kurostudio.io
- Controller
- The customer operating the workspace
The subject matter is the processing of personal data that occurs when we provide Kuro Engage to you: running your automation campaigns on your connected social accounts, delivering the resulting messages and assets, and capturing the leads those campaigns produce. The duration of the processing matches the term of the main contract.
2. Nature, purpose, data subjects, and data categories
Nature and purpose of the processing: collecting, storing, matching, using, and transmitting personal data in order to run automated Comment-to-DM campaigns and provide the related logs and lead records, exclusively to provide the service to you.
Categories of data subjects
- People who interact with your connected social accounts, in particular those who comment a campaign keyword and receive an automated message.
- Members of your workspace whom you invite and manage.
Categories of personal data
- Social platform identifiers and usernames of the people who interact with your campaigns.
- The content of their comments and the delivery status of messages sent to them.
- Email addresses and related campaign attribution where a person submits an email in a campaign conversation.
- Workspace member email addresses, roles, and access data.
Special categories of personal data under Art. 9 GDPR are not part of the intended processing. You must not configure campaigns in a way that makes such data the subject of the processing.
3. Processing on documented instructions
We process personal data only on your documented instructions, including with regard to transfers to a third country, unless we are required to process by Union or Member State law. In that case we inform you of that legal requirement before processing, unless the law prohibits it.
Your configuration in the product is your primary instruction: the campaigns, keywords, message copy, assets, and connected accounts you set up, together with this agreement and the main contract. Instructions beyond that must be given in text form to legal@kurostudio.io.
We will inform you immediately if, in our opinion, an instruction infringes the GDPR or other data protection provisions, and may suspend the execution of that instruction until you confirm or change it.
4. Confidentiality
We ensure that the persons authorised to process the personal data have committed themselves to confidentiality or are under an appropriate statutory obligation of confidentiality. That commitment survives the end of their engagement. Access is granted strictly on a need-to-know basis.
5. Technical and organisational measures
We implement appropriate technical and organisational measures under Art. 32 GDPR, taking into account the state of the art, the costs of implementation, and the nature, scope, context, and purposes of processing, as well as the risk to the rights and freedoms of natural persons. In particular:
- Encryption of all data in transit using TLS, and encryption at rest by our infrastructure providers.
- Tenant isolation enforced in the database itself through row level security, so that one workspace cannot read another workspace's data.
- Access credentials for social platforms held in a dedicated encrypted secret store, readable only by server-side processes and never exposed to users of the product.
- Role-based access control within each workspace, and least-privilege access for internal service processes.
- Authentication without passwords, using magic links and passkeys.
- Operational logging of security-relevant events, and separation of production data from development environments.
- Backups and restore capability provided by our database infrastructure provider.
We may change these measures over time provided that the level of protection is not reduced. The measures in force are documented in this agreement as amended from time to time.
6. Subprocessors
You grant us general written authorisation to engage the subprocessors listed below. We impose data protection obligations on each subprocessor that are no less protective than those in this agreement, and we remain fully liable to you for their performance.
- Supabase
- Database, authentication, storage, and encrypted secret storage. Processing in the EU.
- Vercel
- Hosting, CDN, and application runtime. Runtime processing in the EU (Frankfurt region).
- Meta Platforms
- Delivery of the Instagram API, webhooks, and the messages your campaigns send.
We inform you of any intended addition or replacement of a subprocessor at least 30 days in advance, in text form or in the product. You may object on reasonable data protection grounds within that period. If we cannot resolve your objection, you may terminate the main contract with effect from the date the change takes effect.
7. Assistance with data subject rights
Taking into account the nature of the processing, we assist you with appropriate technical and organisational measures, insofar as this is possible, in fulfilling your obligation to respond to requests for exercising data subject rights under Chapter III GDPR.
If a data subject contacts us directly about data we process on your behalf, we will not respond on the merits ourselves. We will forward the request to you without undue delay, and we will delete the data we hold about that person where the request is for deletion and no legal obligation requires retention.
8. Assistance with your other obligations
We assist you in ensuring compliance with your obligations under Art. 32 to 36 GDPR, taking into account the nature of the processing and the information available to us. This includes assistance with security of processing, data protection impact assessments, and prior consultation with a supervisory authority.
We notify you without undue delay after becoming aware of a personal data breach affecting personal data processed on your behalf, and provide the information you need to meet your own notification duties under Art. 33 and Art. 34 GDPR.
9. Deletion and return of data
At your choice, we delete or return the personal data processed on your behalf after the end of the provision of services, and delete existing copies, unless Union or Member State law requires storage of the personal data.
In practice: after your paid subscription ends we keep your workspace data for 30 days so that you can export it or resume the subscription, and delete it automatically afterwards. You can request an export at any time during that window under section 19 of the Terms of Service. Records that we must keep to meet commercial or tax retention duties, such as invoices, are excluded from deletion and their processing is restricted to that purpose.
10. Information and audits
We make available to you all information necessary to demonstrate compliance with the obligations laid down in Art. 28 GDPR, and allow for and contribute to audits, including inspections, conducted by you or another auditor you mandate.
Audits are announced with reasonable notice, take place during normal business hours, must not disproportionately disrupt our operations, and must respect the confidentiality and the data of our other customers. We may first provide current certifications, reports, or documentation from us or our subprocessors where these are suitable to demonstrate compliance.
11. International transfers
Personal data may be processed outside the EU or EEA, in particular where a subprocessor operates there. Where that happens, we ensure an adequate level of protection through an adequacy decision including the EU-US Data Privacy Framework, through Standard Contractual Clauses, or through other appropriate safeguards under Chapter V GDPR, together with any supplementary measures required.
Data transmitted to Meta in order to deliver your campaign messages is transferred to Meta on the basis of your instruction and Meta's own platform terms, which you accept as the operator of the connected account.
12. Order of precedence and final provisions
In the event of contradictions between this agreement and the Terms of Service, this agreement prevails for the processing of personal data on your behalf. Where this agreement is silent, the Terms of Service apply, including their provisions on liability and governing law.
Should individual provisions of this agreement be or become invalid, the validity of the remaining provisions is unaffected. Questions about this agreement: legal@kurostudio.io.