Skip to content

Legal

Data processing addendum

The Art. 28 GDPR terms that apply where we process personal data on your behalf.

Last updated July 25, 2026

1.Parties and roles

This addendum forms part of the contract between you (the controller) and {{legalName}} (the processor).

For assessment answers and account data you are the controller and we act as processor. For our own website analytics, billing records and marketing, we are the controller and the privacy policy applies.

2.Subject matter, duration, nature and purpose

Subject matter
Provision of the Ready4KI assessment and reporting service
Duration
For the term of the main contract and any agreed retention period
Nature and purpose
Collection, storage, structuring and analysis of assessment answers to produce a report
Categories of data subjects
Your employees and contractors who use the service or are named in answers
Categories of personal data
Name, business contact details, job role, authentication data, usage logs

3.Processing on instructions

We process personal data only on your documented instructions, including regarding transfers to a third country, unless required to do otherwise by law. In that case we inform you before processing, unless the law prohibits it.

The main contract, this addendum and your use of the service constitute your complete instructions.

4.Confidentiality

Personnel authorised to process personal data are bound to confidentiality and trained on their obligations. Access is granted on a need-to-know basis and revoked when it is no longer needed.

5.Security of processing

We implement appropriate technical and organisational measures under Art. 32 GDPR, including:

  • Row-level security scoping every record to the owning organisation.
  • Server-side entitlement checks before content is rendered, so unpurchased content is never transmitted.
  • Encryption in transit, and at rest at the storage layer.
  • Least-privilege access, with privileged operations restricted to service credentials that are never exposed to a browser.
  • Audit trails for authentication, payment and administrative events.
  • Regular restore testing of backups.

6.Sub-processors

You give general authorisation for the sub-processors listed below. We inform you at least {{subprocessorNotice}} before adding or replacing one, and you may object on reasonable data protection grounds.

Processors engaged by Ready4KI
ProcessorPurposeLocation

Supabase

Database, authentication and file storage

{{supabaseRegion}}

Stripe

Payment processing, tax calculation and invoicing

EU / US (SCCs)

{{hostingProvider}}

Application hosting and content delivery

{{hostingRegion}}

{{emailProvider}}

Transactional email (confirmations, password resets)

{{emailRegion}}

7.Assistance

We assist you, taking into account the nature of processing, in responding to data subject requests, and in meeting your obligations under Art. 32 to 36 GDPR: security, breach notification and data protection impact assessments.

Where a data subject contacts us directly, we refer them to you and inform you promptly.

8.Personal data breach

We notify you without undue delay, and in any event within {{breachNotice}} of becoming aware of a personal data breach, with the information available at that time and further detail as it emerges.

We do not notify a supervisory authority or data subjects on your behalf unless you instruct us to.

9.Return and deletion

On termination, and at your choice, we delete or return all personal data and delete existing copies, unless storage is required by law.

Deleting your account triggers deletion of your organisation's data where you are the last member, subject to statutory retention of invoices.

10.Audits

We make available the information necessary to demonstrate compliance with Art. 28 and allow for and contribute to audits, including inspections, conducted by you or an auditor you mandate.

Audits take place during business hours, with reasonable notice, no more than once a year unless there is a specific cause, and subject to confidentiality.

11.International transfers

Where a sub-processor is located outside the EEA, the transfer is covered by Standard Contractual Clauses and, where required, supplementary measures. On request we provide the relevant documentation.

12.Annexes

Annex I, Details of processing: as set out in section 2 above. Annex II, Technical and organisational measures: as set out in section 5 above. Annex III, Sub-processors: as set out in section 6 above.

A countersigned copy of this addendum is available on request for procurement files.

This document is provided by Ready4KI for its own service. It is not legal advice, and it is under review by counsel before launch. Fields shown in braces are pending that review.

Data processing addendum · Ready4KI