Data Processing Agreement (DPA)
Version 1.0
Du ser den engelska versionen av dokumentet; originalet är på spanska. Öppna det spanska originalet
1. Parties and scope
This Agreement forms an integral part of the Terms of Service and applies where the Customer (controller) brings personal data of its employees, contractors or learners onto the platform and KELVADO, SOCIEDAD LIMITADA (Sociedad Unipersonal) (processor) processes it on the Customer's behalf.
It is accepted when the organisation is created in Kelbado and is recorded with its version number and date. Customers who need a signed document may request one at support@kelbado.eu.
In the event of conflict, this Agreement prevails over the Terms on data-protection matters.
2. Subject matter, duration and nature
- Subject matter: provision of the online training platform described in the Terms.
- Duration: for the term of the contract, plus the retention period in section 10.
- Nature and purpose: hosting, organising, AI-assisted generation, translation, distribution and analysis of the training the Customer delivers to its learners.
- Types of data and categories of data subjects: Annex I.
3. Customer instructions
KELVADO, S.L.U. will process personal data only on documented instructions from the Customer, being: these Terms, this Agreement, and the actions the Customer and its users perform in the application and the API.
We will inform the Customer if, in our opinion, an instruction infringes the GDPR or other applicable law. Where a legal obligation requires us to process data beyond those instructions, we will notify the Customer beforehand unless legally prohibited.
4. Confidentiality
Personnel authorised to process the data are under a contractual duty of confidentiality and have access only at the minimum level required. Administrative access is recorded in the audit log. Support staff access a Customer's account only at the Customer's request or to resolve an incident, through an impersonation mode that is recorded in the audit log available to the Customer and is visibly flagged throughout the session.
5. Security
We apply the technical and organisational measures in Annex II, appropriate to the risk under article 32 GDPR, and review them regularly.
6. Sub-processors
The Customer gives general authorisation to the sub-processors published at Sub-processors. We will give thirty (30) days' notice of any addition or replacement; the Customer may object on reasonable data-protection grounds and, if we offer no alternative, terminate without penalty as regards the affected services. The notice is sent by email to the account address of the organisation owner and reflected on the public sub-processor page; objections are sent to support@kelbado.eu.
Each sub-processor is bound by obligations equivalent to this Agreement, and we remain liable to the Customer for their performance.
7. Assistance to the Customer
We will assist the Customer, so far as reasonable and taking into account the nature of the processing:
- in responding to data subject rights requests (the application provides per-user export and erasure);
- with data protection impact assessments and prior consultation, where applicable;
- in ensuring compliance with articles 32 to 36 GDPR.
If we receive a request directly from a learner, we will forward it to the Customer without responding ourselves, unless the Customer instructs otherwise.
8. Personal data breaches
We will notify the Customer without undue delay after becoming aware of a breach affecting its data, with the information available: nature, categories and approximate volume of data and data subjects, likely consequences and measures taken. We will assist with notification to the supervisory authority and to data subjects, which is the Customer's responsibility.
9. Audits
We will make available the information needed to demonstrate compliance with this Agreement. On reasonable request with thirty (30) days' notice, at most once a year — or following a significant breach — the Customer may carry out a documentary audit or mandate an independent third party bound by confidentiality, without access to other customers' data and at the Customer's cost.
10. Return and deletion
On termination the Customer has thirty (30) days to export the data from the application. After that period we will delete or anonymise the data, including copies, within a further thirty (30) days, save where retention is legally required. Backups are overwritten in their ordinary cycle. On request we will issue written confirmation of deletion.
11. International transfers
Data is hosted in OVHcloud data centres in France (European Union). Where a sub-processor is outside the EEA, the transfer relies on the Data Privacy Framework or on standard contractual clauses with supplementary measures, as stated at Sub-processors.
12. Liability
The liability caps in the Terms apply, without prejudice to article 82 GDPR as regards data subjects.
Annex I — Details of the processing
Categories of data subjects: the Customer's employees, contractors and learners; trainers and instructors; account administrators.
Types of personal data:
- identification and contact: first and last name, email address, language, profile photo where supplied;
- employment or organisational data: job title, department, group, manager, site;
- training data: assigned courses, progress, quiz answers, grades, certificates, time spent;
- technical data: IP address, browser, access and audit logs;
- content supplied by the Customer that may contain personal data (documents, images, voice recordings where consented voice cloning is used).
Special categories: not envisaged, with one exception: voice samples uploaded for voice cloning, which may qualify as biometric data under article 9 GDPR. Those samples are processed only with the explicit, documented consent of the voice owner (art. 9(2)(a) GDPR), recorded in the audit log; the Customer obtains and keeps that consent. The samples are sent to Mistral AI (France) to create the voice and are deleted at the Customer's request or when the feature is disabled. Outside that exception, the Customer undertakes not to upload article 9 GDPR data without prior written agreement.
Processing operations: collection, recording, organisation, storage, retrieval, AI-assisted generation, translation, dissemination to learners, export and erasure.
Annex II — Technical and organisational measures
- Encryption in transit (TLS) and passwords stored with a key-derivation function.
- Logical isolation per organisation in every data query; cross-organisation access is refused.
- Role-based access control and available two-factor authentication.
- Audit logging of administrative and access actions.
- Encrypted backups with a tested restore procedure.
- Rate limiting, SSRF protection, file-type validation and decompression limits.
- SCORM packages isolated on a separate content domain.
- Vulnerability management: dependency review and code-reviewed deployments.
- Production environment hosted in OVHcloud data centres in France (European Union).