Data Processing Addendum
The processor terms that apply when Kiko handles personal data on your behalf. It forms part of your agreement with us.
Last updated 1 September 2026
Kiko is a demonstration product. This document is written as a realistic sample and is not a binding agreement. Do not rely on it as legal advice.
1. Roles
Your organisation decides why and how employee data is processed. Under India's Digital Personal Data Protection Act 2023 your organisation is the Data Fiduciary; under the GDPR, where it applies to you, it is the controller. Kiko acts on your instructions as Data Processor.
This split matters in practice. We do not decide what to collect about your employees, how long you keep it, or whether you had a lawful basis to collect it. You do. We are accountable for processing it securely and only as instructed.
2. Subject matter and duration
The subject matter is the provision of the Kiko platform as described in your order form. Processing lasts for the subscription term, plus the retention window in the Data Retention and Deletion policy.
The nature and purpose of processing is the operation of recruitment, onboarding, attendance, leave, payroll, performance, engagement and exit functions on your behalf.
3. Categories of data subjects
We process data about the following groups of people on your behalf.
- Your current employees, including full time, part time and fixed term staff.
- Your former employees, for the period you retain their records.
- Candidates who apply to your organisation.
- Contractors and consultants you manage in the workspace.
- Emergency contacts and dependants, where an employee has provided them.
4. Categories of personal data
The exact set depends on which modules you enable and which fields you configure. Typically it includes the following.
- Identity and contact data: name, date of birth, photograph, personal and work contact details, address.
- Employment data: job title, department, location, reporting line, employment dates, contract type.
- Government identifiers: permanent account number, Aadhaar reference where you collect it, provident fund and employees state insurance numbers.
- Financial data: salary structure, payslips, bank account for salary credit, tax declarations and proofs.
- Attendance and leave data: check in and check out records, shift assignment, leave balances and requests.
- Performance data: goals, review ratings, feedback and one to one notes.
- Special category data, only where you configure it: health information supporting a leave or insurance claim, and disability status where required for statutory reporting.
5. Our obligations
As processor we commit to the following.
- Process personal data only on your documented instructions, which include your configuration of the workspace.
- Not sell personal data, and not use identifiable employee data to train models.
- Keep the security measures described in the Security page, and not materially weaken them during your term.
- Bind our personnel to confidentiality, and grant them access only where a named approval and a logged reason exist.
- Tell you without undue delay if we receive a government or law enforcement request for your data, unless we are legally prohibited from doing so, and direct the requester to you wherever we lawfully can.
- Tell you if an instruction you give us appears to breach applicable data protection law, and to pause rather than proceed.
6. Your obligations
You confirm that you have a lawful basis for the data you put into the workspace, that you have given your employees the notice their local law requires, and that your instructions to us comply with that law.
You are responsible for the roles you grant. Compensation visibility, export rights and administrator access are yours to assign, and the audit trail records who assigned them.
You are responsible for the accuracy of payroll inputs and for reviewing each run before approval. The approval step exists so that a person, not the software, signs off on what is paid.
7. Sub-processors
You give general authorisation for us to engage sub-processors. The current list, what each one does and where it operates is on the Sub-processors page.
We impose data protection obligations on each sub-processor no less protective than these terms, and we remain responsible to you for their performance. We give at least 30 days notice before adding one, and you may object on reasonable data protection grounds.
8. Assisting with data principal rights
Requests from your employees should come to you, because you are the fiduciary and the relationship is yours. The workspace is built so you can answer most of them yourself: access, correction, export and erasure are available from the admin console without needing us.
Where a request cannot be satisfied through the product, write to privacy@kiko.co and we will assist within 5 business days at no additional charge.
9. Personal data breach
If we become aware of a personal data breach affecting your data, we will notify your administrator and your stated security contact without undue delay and in any case within 48 hours of confirming it.
The notification will describe what we know, which categories and roughly how many records are affected, what we are doing about it, and what we recommend you do. We will keep updating you as the picture firms up rather than waiting for a complete account.
Notifying the Data Protection Board of India, or another regulator, and notifying affected employees, is your decision as fiduciary. We will give you what you need to make it and to meet your own deadlines.
10. Location and transfers
Production data for Indian customers is stored in Indian cloud regions by default. Backups stay in India.
Where a support engineer outside India needs access to diagnose a problem, that access is named, time bound, logged, and subject to the same confidentiality obligations. We will tell you if a transfer outside India would be needed for anything more than that.
11. Audits and information
On request, and no more than once a year unless a regulator or a breach requires otherwise, we will provide our current security documentation, our sub-processor list and answers to a reasonable security questionnaire.
Where your regulator requires an on site audit, we will agree a scope and timing that does not compromise other customers, and we will not charge for the first day of a reasonable audit.
12. Return and deletion
On termination you have a 90 day window to export everything in machine readable formats. After that window we delete your data from production within 30 days, and from backups as those backups age out on their normal cycle.
We will confirm deletion in writing on request. Where we are legally required to retain something, we will tell you what and why rather than deleting it quietly.
13. Precedence
This addendum forms part of your agreement. Where it conflicts with the Terms and Conditions on the handling of personal data, this addendum prevails. Where you have signed a negotiated data processing agreement with us, that one prevails over this page.
Still have a question?
Bring it to the demo and we will answer it on the call, or write to legal@kiko.co.
Book a demo