Kuga
Website ChatWhatsAppInstagramAI FormsHuman HandoverAI InsightsClient PortalEcommerce
OverviewShopifyMagentoWooCommerceCal.comCalendlyWebhooks
OverviewDentalPropertyTradesVenuesLawEcommerce
All resourcesGuidesPlaybooksChecklistsTemplatesReportsCompare platformsvs Chatbasevs Dante AIvs Intercom / Finvs generic builders
Pricing
LoginGet started

Products

Website ChatWhatsAppInstagramAI FormsHuman HandoverAI InsightsClient PortalEcommerce

Integrations

OverviewShopifyMagentoWooCommerceCal.comCalendlyWebhooks

Solutions

OverviewDentalPropertyTradesVenuesLawEcommerce

Resources

All resourcesGuidesPlaybooksChecklistsTemplatesReportsCompare platformsvs Chatbasevs Dante AIvs Intercom / Finvs generic builders
Pricing
Login Get started
Updated 12 June 2026

Data Processing Addendum

This Data Processing Addendum sets out the data protection terms that apply when KUGA AI LTD processes Customer Personal Data through Kuga's white-label AI chat platform and related services.

Contents

OverviewDefinitionsRolesInstructionsCustomer obligationsKuga obligationsSecurityConfidentialitySub-processorsTransfersRights requestsPersonal data breachesDeletion and returnAuditsLiabilityProcessing detailsSecurity measuresContact

1. Overview

This Data Processing Addendum ("DPA") applies from 12 June 2026 and was last updated on 12 June 2026. It forms part of the Kuga Terms and Conditions, order form, signed agreement, or other written agreement between KUGA AI LTD ("Kuga", "we", "us", or "our") and the customer using the Services ("Customer", "you", or "your").

This DPA applies where Kuga processes Customer Personal Data on behalf of Customer as a processor or sub-processor. It is intended to satisfy applicable requirements under Data Protection Laws for processor contracts, including Article 28 of the UK GDPR and, where applicable, equivalent EU GDPR requirements.

If Customer uses the Services for a client, Customer is responsible for ensuring it has authority to bind that client or otherwise provide lawful instructions to Kuga.

2. Definitions

"Customer Personal Data" means personal data processed by Kuga on behalf of Customer through the Services under the Agreement.

"Data Protection Laws" means all privacy, data protection, electronic communications, security and breach notification laws applicable to the processing of Customer Personal Data, including the UK GDPR, Data Protection Act 2018, Privacy and Electronic Communications Regulations, EU GDPR where applicable, and any successor or replacement laws.

"EU GDPR" means Regulation (EU) 2016/679. "UK GDPR" has the meaning given in the Data Protection Act 2018. "Personal data", "processing", "controller", "processor", "sub-processor", "data subject", "personal data breach" and "supervisory authority" have the meanings given in applicable Data Protection Laws.

"Services" means Kuga's websites, accounts, dashboards, hosted agents, chat widgets, scripts, APIs, integrations, client portals, previews, support and related services provided under the Agreement.

3. Roles of the parties

3.1 Customer as controller or processor

Customer determines the purposes and means of processing Customer Personal Data submitted to or collected through the Services. Customer may act as controller, or as processor for its own client. Where Customer acts as processor for a client, Customer is responsible for ensuring its instructions to Kuga are authorised by the relevant controller.

3.2 Kuga as processor or sub-processor

Kuga processes Customer Personal Data as processor where Customer is controller, and as sub-processor where Customer is processor. Kuga will process Customer Personal Data only as described in this DPA, the Agreement, Customer's documented instructions, or as required by law.

3.3 Kuga as independent controller

Kuga may act as an independent controller for account administration, billing, legal compliance, security, abuse prevention, product analytics, service improvement, marketing, business communications and other purposes described in the Kuga Privacy Policy. This DPA does not apply to Kuga's independent controller processing.

4. Customer instructions

Customer instructs Kuga to process Customer Personal Data to provide, secure, support, maintain and improve the Services, to comply with the Agreement, to follow Customer's configuration choices, to support integrations and deployments, and to comply with applicable law.

Customer's documented instructions include this DPA, the Agreement, order forms, account settings, dashboard configurations, support requests, API calls, integration settings, deployment choices and other written instructions accepted by Kuga.

Kuga will notify Customer if, in Kuga's reasonable opinion, an instruction infringes Data Protection Laws, unless prohibited by law. Kuga is not required to follow unlawful instructions.

5. Customer obligations

Customer is responsible for ensuring that Customer Personal Data is collected and processed lawfully, fairly and transparently. Customer must have all required notices, consents, lawful bases, permissions, contracts, data protection impact assessments, legitimate interest assessments, records, security measures and authority before submitting or collecting Customer Personal Data through the Services.

Customer is responsible for the accuracy, quality, legality and relevance of Customer Personal Data, prompts, knowledge sources, agent instructions, integrations, scripts, deployments, outputs and end-user communications. Customer must not submit unnecessary sensitive data, excessive data, unlawful data or data it is not authorised to process.

Customer is responsible for account administration, user permissions, client access, role configuration, endpoint security, integration credentials, domain permissions, widget deployment, export controls, deletion instructions and responding to data subject requests where Customer is controller.

6. Kuga obligations

Kuga will process Customer Personal Data only on documented instructions from Customer, unless required by law. If legally required to process Customer Personal Data outside Customer's instructions, Kuga will inform Customer of that legal requirement before processing unless law prohibits notice.

Kuga will take reasonable steps to ensure that personnel authorised to process Customer Personal Data are subject to appropriate confidentiality obligations and process such data only as necessary to provide, secure and support the Services.

Kuga will implement appropriate technical and organisational measures designed to protect Customer Personal Data, taking into account the nature of processing, implementation costs, state of the art and risks to individuals.

7. Security

Kuga will maintain a security programme designed to protect Customer Personal Data against unauthorised or unlawful processing and against accidental loss, destruction or damage. Security measures may include access controls, authentication, encryption in transit, logging, monitoring, backups, personnel controls, network security, secure development practices, vulnerability management and incident response.

Customer acknowledges that security is a shared responsibility. Customer must maintain secure credentials, limit user access, configure roles appropriately, protect connected systems, use strong authentication where available, review agent deployments and promptly report suspected security incidents.

8. Confidentiality

Kuga will ensure that persons authorised to process Customer Personal Data are bound by confidentiality obligations or are under an appropriate statutory obligation of confidentiality. Kuga will limit access to Customer Personal Data to personnel and sub-processors who need access to provide, secure, support or maintain the Services.

9. Sub-processors

9.1 General authorisation

Customer gives Kuga general written authorisation to engage sub-processors to process Customer Personal Data for the purposes described in this DPA and the Agreement. Kuga may use sub-processors for hosting, infrastructure, security, monitoring, communications, analytics, payment support, customer support, storage, AI-related processing, professional services and other service operations.

9.2 Sub-processor obligations

Kuga will impose data protection obligations on sub-processors that are materially equivalent to those in this DPA to the extent applicable to the services provided by the sub-processor. Kuga remains responsible to Customer for the performance of sub-processor obligations as required by Data Protection Laws.

9.3 Changes to sub-processors

Kuga may add, replace or remove sub-processors from time to time. Kuga will provide notice of material sub-processor changes by reasonable means, which may include account notice, email, documentation, policy update or another method. Customer may object to a new sub-processor on reasonable data protection grounds within 14 days after notice. If the parties cannot resolve the objection, Kuga may suspend or terminate the affected Services without liability beyond any refund required by the Agreement.

10. International transfers

Customer authorises Kuga and its sub-processors to process Customer Personal Data in the United Kingdom, European Economic Area and other countries where Kuga or its sub-processors operate, provided Kuga uses a lawful transfer mechanism where required.

For restricted transfers from the United Kingdom, Kuga may rely on UK adequacy regulations, the UK International Data Transfer Agreement, the UK Addendum to the EU Standard Contractual Clauses, or another valid transfer mechanism. For restricted transfers from the European Economic Area, Kuga may rely on EU adequacy decisions, EU Standard Contractual Clauses, supplementary measures or another valid transfer mechanism.

Where Standard Contractual Clauses, UK Addendum or IDTA terms are required, they are incorporated into this DPA by reference to the extent necessary for the relevant transfer. If there is a conflict between those transfer terms and this DPA, the transfer terms control for the restricted transfer.

11. Data subject requests and assistance

Taking into account the nature of processing, Kuga will provide reasonable assistance to Customer, insofar as possible, to help Customer respond to data subject requests relating to Customer Personal Data. Kuga may require Customer to use available product functionality before requesting manual assistance.

If Kuga receives a request directly from a data subject relating to Customer Personal Data, Kuga may direct the requester to Customer, notify Customer, or respond as legally required. Customer is responsible for responding to requests where Customer is controller.

Kuga will provide reasonable assistance with security obligations, breach notifications, data protection impact assessments and supervisory authority consultations, taking into account the nature of processing and information available to Kuga. Kuga may charge reasonable fees for assistance that is not caused by Kuga's breach of this DPA.

12. Personal data breaches

Kuga will notify Customer without undue delay after becoming aware of a personal data breach affecting Customer Personal Data. The notice will include information reasonably available to Kuga to help Customer meet its breach notification obligations, such as the nature of the incident, categories of data affected, likely consequences and measures taken or proposed, where known.

Kuga's notification is not an admission of fault or liability. Customer is responsible for determining whether notification to regulators, data subjects, clients or other parties is required, unless law requires Kuga to notify directly.

Customer must promptly notify Kuga of any suspected breach, vulnerability, unauthorised access or security incident involving the Services, Customer accounts, integrations, credentials, endpoints or Customer Personal Data.

13. Deletion and return

On termination, expiry or Customer's written request, Kuga will delete or return Customer Personal Data in accordance with the Agreement, product functionality, backup cycles, technical limitations and legal obligations.

Kuga may retain Customer Personal Data where required or permitted by law, for dispute resolution, compliance, security, fraud prevention, backups, audit logs, accounting, legal claims, enforcement, or where data has been anonymised or aggregated.

14. Audits and information

Kuga will make available information reasonably necessary to demonstrate compliance with this DPA. Customer may request an audit no more than once per year unless required by a supervisory authority or following a confirmed material breach affecting Customer Personal Data.

Audits must be reasonable, proportionate, limited to relevant records, conducted during normal business hours, subject to confidentiality, avoid disruption, avoid compromising Kuga security or other customers' data, and be performed by qualified personnel approved by Kuga. Kuga may satisfy audit requests through security summaries, questionnaires, certifications, third-party reports, documentation or remote review where appropriate.

15. Liability and order of precedence

The liability limits, exclusions, remedies and indemnities in the Agreement apply to this DPA unless Data Protection Laws require otherwise. This DPA does not increase Kuga's aggregate liability beyond the limits in the Agreement.

If there is a conflict between this DPA and the Agreement, this DPA controls only to the extent of the conflict for processing Customer Personal Data. Transfer terms required by Data Protection Laws control for the restricted transfer they govern.

16. Processing details

16.1 Subject matter

Kuga's provision of white-label AI chat, dashboard, agent, widget, script, API, integration, client portal, support, account, billing and related services to Customer.

16.2 Duration

For the term of the Agreement and thereafter as necessary for deletion, return, backup, legal, security, audit, dispute, compliance or legitimate business purposes described in this DPA.

16.3 Nature and purpose

Collection, receipt, hosting, storage, organisation, structuring, transmission, retrieval, consultation, use, disclosure, analysis, generation, deletion, logging, support, troubleshooting, security, monitoring and other processing necessary to provide, secure, support and improve the Services.

16.4 Categories of data subjects

Customer personnel, agency personnel, client personnel, authorised users, administrators, end users, website visitors, leads, prospects, support contacts, business contacts and other individuals whose data is submitted to or collected through the Services by or on behalf of Customer.

16.5 Categories of personal data

Names, email addresses, phone numbers, business details, account identifiers, user roles, authentication identifiers, messages, chat transcripts, prompts, agent responses, knowledge-source content, support records, integration payloads, metadata, IP addresses, device data, usage data, logs, billing contacts and other personal data submitted to or collected through the Services.

16.6 Special category data

The Services are not designed to require special category data, criminal offence data or highly sensitive data. Customer must not submit such data unless it has a lawful basis, has completed required assessments, has obtained any required consent or authorisation, and has agreed appropriate safeguards with Kuga where necessary.

17. Security measures

Kuga's technical and organisational measures are designed to provide a level of security appropriate to the risk and may include:

  • Access controls and role-based permissions for internal and customer-facing systems.
  • Authentication controls and credential protection measures.
  • Encryption in transit where appropriate for service communications.
  • Logging, monitoring and alerting for security, operational and abuse-prevention purposes.
  • Backup, recovery and resilience practices appropriate to the Services.
  • Secure development, change management and vulnerability management processes.
  • Incident response procedures for suspected security events.
  • Personnel confidentiality obligations and access limited by business need.
  • Sub-processor due diligence and contractual data protection obligations.
  • Policies and procedures for data handling, account administration and support access.

Kuga may update these measures from time to time, provided updates do not materially reduce the overall level of protection for Customer Personal Data.

18. Contact

For questions about this DPA, contact legal@kuga.ai or write to KUGA AI LTD, 128 City Road, London, EC1V 2NX, United Kingdom.

White-label AI infrastructure for agencies.

KUGA AI LTD

128 City Road, London, EC1V 2NX

Company number 16189235

ICO ZC015340

Workspace

  • Agency workspace
  • Client Portal
  • AI Insights

Channels

  • Website Chat
  • WhatsApp
  • Instagram
  • AI Forms

Delivery

  • Human Handover
  • Ecommerce
  • Integrations
  • Webhooks
  • Security

Company

  • Solutions
  • Compare
  • Pricing
  • Resources
  • Help centre
  • Contact
  • Login

© 2026 KUGA AI LTD

PrivacyTermsDPAAUPCookies

We use analytics cookies to see which pages are useful. Cookie policy