KatembeData Processing Agreement

Data Processing Agreement

Version 1.0.0 Effective 2026-03-18 Updated 2026-03-18
Table of Contents

Data Processing Agreement (DPA)

Effective Date: March 18, 2026
Last Updated: March 18, 2026
Version: 1.0.0

This Data Processing Agreement (“DPA”) forms part of the Terms of Service between you (“Customer”) and Katembe (“Processor”) and governs the processing of Personal Data in connection with the Service.

1. Definitions

Personal Data: Any information relating to an identified or identifiable natural person as defined in applicable Data Protection Laws.

Data Protection Laws: All applicable laws and regulations relating to privacy and data protection, including GDPR, CCPA, and other applicable laws.

Processing: Any operation performed on Personal Data, including collection, storage, use, disclosure, and deletion.

Data Subject: The individual to whom Personal Data relates.

Controller: The entity that determines the purposes and means of processing Personal Data.

Processor: The entity that processes Personal Data on behalf of the Controller.

Sub-processor: Any third party engaged by the Processor to process Personal Data.

2. Roles and Responsibilities

2.1 Customer as Controller

Customer acts as the Controller and:

  • Determines the purposes and means of processing
  • Ensures lawful basis for processing
  • Obtains necessary consents from Data Subjects
  • Provides privacy notices to Data Subjects
  • Handles Data Subject requests

2.2 Katembe as Processor

Katembe acts as the Processor and:

  • Processes Personal Data only on documented instructions
  • Implements appropriate security measures
  • Assists with Data Subject requests
  • Notifies Customer of data breaches
  • Deletes or returns data upon termination

3. Processing Instructions

3.1 Scope of Processing

Purpose: To provide the messaging platform services as described in the Terms of Service.

Duration: For the term of the agreement and retention period thereafter.

Nature of Processing: Collection, storage, transmission, and deletion of messages and contact data.

Types of Personal Data:

  • Contact information (names, email addresses, phone numbers)
  • Message content
  • Usage data and analytics
  • Device and location information

Categories of Data Subjects:

  • Customer’s employees and authorized users
  • Customer’s end users and message recipients
  • Customer’s contacts

3.2 Customer Instructions

Katembe will process Personal Data only:

  • As necessary to provide the Service
  • As documented in this DPA and Terms of Service
  • As instructed by Customer through the Service interface
  • As required by applicable law

4. Security Measures

4.1 Technical Measures

  • Encryption: AES-256 encryption at rest, TLS 1.3 in transit
  • Access Control: Role-based access, multi-factor authentication
  • Network Security: Firewalls, intrusion detection, DDoS protection
  • Monitoring: 247 security monitoring and logging
  • Vulnerability Management: Regular security scans and patches

4.2 Organizational Measures

  • Security Policies: Documented security policies and procedures
  • Employee Training: Regular security awareness training
  • Background Checks: Screening of personnel with data access
  • Incident Response: Documented incident response plan
  • Business Continuity: Disaster recovery and backup procedures

4.3 Certifications

  • SOC 2 Type II certified
  • ISO 27001 certified
  • Regular third-party security audits

5. Sub-processors

5.1 Authorized Sub-processors

Customer authorizes Katembe to engage the following sub-processors:

Sub-processor Service Location
AWS Cloud hosting USA, EU
Twilio SMS delivery USA
SendGrid Email delivery USA
Stripe Payment processing USA

5.2 Sub-processor Requirements

Katembe ensures that sub-processors:

  • Are bound by data protection obligations equivalent to this DPA
  • Implement appropriate security measures
  • Process data only as instructed
  • Are subject to audit rights

5.3 Changes to Sub-processors

  • Katembe will notify Customer of new sub-processors 30 days in advance
  • Customer may object to new sub-processors within 14 days
  • If Customer objects, Katembe will use reasonable efforts to accommodate or allow termination

6. Data Subject Rights

6.1 Assistance with Requests

Katembe will assist Customer in responding to Data Subject requests for:

  • Access to Personal Data
  • Rectification of inaccurate data
  • Erasure (“right to be forgotten”)
  • Data portability
  • Restriction of processing
  • Objection to processing

6.2 Response Time

Katembe will respond to Customer’s requests for assistance within 5 business days.

6.3 Fees

Assistance with Data Subject requests is included in the Service. Excessive or repetitive requests may incur additional fees.

7. Data Breach Notification

7.1 Notification Obligation

Katembe will notify Customer without undue delay (and in any event within 72 hours) upon becoming aware of a Personal Data breach.

7.2 Breach Information

Notification will include:

  • Nature of the breach
  • Categories and approximate number of Data Subjects affected
  • Categories and approximate number of Personal Data records affected
  • Likely consequences of the breach
  • Measures taken or proposed to address the breach

7.3 Cooperation

Katembe will cooperate with Customer in investigating and mitigating the breach.

8. Data Transfers

8.1 International Transfers

Personal Data may be transferred to and processed in countries outside the EEA/UK.

8.2 Transfer Mechanisms

Transfers are protected by:

  • Standard Contractual Clauses (SCCs): EU Commission approved SCCs
  • Adequacy Decisions: Transfers to countries with adequacy decisions
  • Additional Safeguards: Supplementary measures as required

8.3 UK Transfers

For UK data, we use the UK International Data Transfer Agreement (IDTA) or UK Addendum to SCCs.

9. Audits and Inspections

9.1 Audit Rights

Customer may audit Katembe’s compliance with this DPA:

  • Once per year
  • Upon reasonable notice (30 days)
  • During business hours
  • At Customer’s expense

9.2 Audit Reports

Katembe will provide:

  • SOC 2 Type II reports annually
  • ISO 27001 certificates
  • Security questionnaires upon request

9.3 Third-Party Audits

Customer may engage a qualified third-party auditor subject to confidentiality obligations.

10. Data Retention and Deletion

10.1 Retention Period

Personal Data is retained:

  • While Customer’s account is active
  • For the retention period specified in Customer’s plan
  • As required by applicable law

10.2 Deletion

Upon termination or expiry:

  • Customer may export data within 30 days
  • Katembe will delete or anonymize data within 90 days
  • Backups are deleted within 180 days

Data subject to legal holds or litigation will be retained as required by law.

11. Liability and Indemnification

11.1 Liability Cap

Katembe’s total liability under this DPA is limited to the liability cap in the Terms of Service.

11.2 Indemnification

Each party indemnifies the other for:

  • Violations of Data Protection Laws caused by that party
  • Failure to comply with obligations under this DPA
  • Negligence or willful misconduct

12. Term and Termination

12.1 Term

This DPA is effective from the date Customer accepts the Terms of Service and continues until termination.

12.2 Termination

This DPA terminates automatically upon termination of the Terms of Service.

12.3 Survival

Sections relating to data deletion, confidentiality, and liability survive termination.

13. Governing Law

This DPA is governed by the same law as the Terms of Service.

14. Amendments

Katembe may update this DPA to reflect:

  • Changes in Data Protection Laws
  • New sub-processors
  • Enhanced security measures
  • Regulatory guidance

Material changes require 30 days notice.

15. Contact Information

For DPA-related inquiries:

  • Data Protection Officer: dpo@katembe.com
  • Legal Department: legal@katembe.com
  • Address: [Your Company Address]

16. Standard Contractual Clauses

The EU Standard Contractual Clauses (Module 2: Controller to Processor) are incorporated by reference and form part of this DPA.


By using the Service, Customer agrees to the terms of this Data Processing Agreement.

Last updated: March 18, 2026