Data Processing Addendum

Last Updated: August 7, 2026

This Data Processing Addendum ("DPA") forms part of, and is incorporated by reference into, the Katsed Terms of Service (the "Master Agreement") between the entity or person that has accepted the Master Agreement ("Controller") and Koalatative OÜ, a company incorporated under the laws of the Republic of Estonia, operating the Katsed platform ("Processor"), together the "Parties."

Execution of the Master Agreement constitutes execution of this DPA by both Parties on the same date.

1. Background and Purpose

1.1 The Processor provides the Katsed service to the Controller in accordance with the Master Agreement, which requires the Processor to Process Personal Data on the Controller's behalf.

1.2 This DPA sets out the terms on which the Processor shall Process Personal Data on behalf of the Controller, and is intended to satisfy the requirements of Article 28(3) of Regulation (EU) 2016/679 ("GDPR").

1.3 Capitalized terms not defined in this DPA have the meanings given in the Master Agreement. Terms such as "Personal Data," "Processing," "Controller," "Processor," "Data Subject," "Personal Data Breach," and "Supervisory Authority" have the meanings given in the GDPR.

2. Roles of the Parties

2.1 The Controller retains control of the Personal Data and remains responsible for its compliance obligations under applicable data protection law, including providing any required notices and obtaining any required consent, and for the Processing instructions it gives to the Processor.

2.2 The parties acknowledge that, in respect of the Personal Data described in Annex A, the Controller is the controller and the Processor is the processor.

2.3 This DPA governs the Processor's activities as a processor described in Section 2.2 only. It does not govern the Processor's processing of the Controller's own account, billing, and usage data (e.g. account holder contact details, billing records, product usage telemetry, support communications), which the Processor carries out as an independent controller for its own purposes. That processing is instead governed by the Processor's privacy notice, available at https://katsed.com/privacy/, and by applicable data protection law directly. The sub-processors relevant to that separate controller relationship are listed for transparency in Annex B, Table 2.

3. Details of Processing

The subject matter, duration, nature and purpose of Processing, types of Personal Data, and categories of Data Subjects are set out in Annex A (Description of Processing).

4. Processor Obligations

The Processor shall:

  • (a) Process Personal Data only on documented instructions from the Controller, including with regard to transfers of Personal Data to a third country, unless required to do so by EU or EU Member State law to which the Processor is subject; in such case, the Processor shall inform the Controller of that legal requirement before Processing, unless that law prohibits this on important grounds of public interest, and shall promptly notify the Controller if, in the Processor's opinion, an instruction would not comply with applicable data protection law;

  • (b) Ensure that persons authorized to Process Personal Data are informed of its confidential nature, are bound by confidentiality obligations or an appropriate statutory duty of confidentiality, and are aware of their obligations under this DPA;

  • (c) Implement the technical and organizational measures set out in Annex A (Security Measures) to ensure a level of security appropriate to the risk, taking into account the state of the art, costs of implementation, and the nature, scope, context and purposes of Processing;

  • (d) Respect the conditions for engaging sub-processors set out in Section 6 below;

  • (e) Taking into account the nature of the Processing, assist the Controller by appropriate technical and organizational measures, insofar as this is possible, for the fulfilment of the Controller's obligation to respond to requests for exercising Data Subject rights under Chapter III of the GDPR, and notify the Controller promptly if the Processor receives such a request directly, without responding to it unless authorized by the Controller;

  • (f) Assist the Controller in ensuring compliance with its obligations under Articles 32 to 36 GDPR (security, breach notification, data protection impact assessments, and prior consultation), taking into account the nature of Processing and the information available to the Processor;

  • (g) At the choice of the Controller, delete or return all Personal Data to the Controller after the end of the provision of the relevant services, and delete existing copies, unless EU or EU Member State law requires continued storage of the Personal Data;

  • (h) Make available to the Controller all information reasonably necessary to demonstrate compliance with the obligations in Article 28 GDPR, and allow for and contribute to audits as set out in Section 8 below.

5. International Transfers

5.1 The Controller authorizes the Processor to transfer or otherwise Process Personal Data outside the European Economic Area ("EEA") only under the conditions set out in this Section 5.

5.2 The Processor may Process, or permit the Processing of, Personal Data outside the EEA only where: (a) the Processing takes place in a territory subject to a current adequacy decision of the European Commission under Article 45 GDPR; or (b) appropriate safeguards are in place in accordance with Article 46 GDPR (for example, Standard Contractual Clauses).

5.3 As of the effective date of this DPA, the Processor's primary data storage infrastructure (Supabase, hosted on eu-central-1, Frankfurt, Germany) is located within the EEA, and no transfer of Personal Data outside the EEA is required for the core Processing described in Annex A. Any sub-processor location outside the EEA, and the applicable transfer mechanism, is identified in Annex B.

6. Sub-processors

6.1 Given the architecture described in Annex A, no sub-processor engaged by the Processor currently receives Personal Data in identifiable form. This Section 6 nonetheless establishes the authorization and notice mechanism that would apply to any sub-processor with access to Personal Data, whether under current or future architecture.

6.2 The Processor may not authorize a third party ("sub-processor") to Process Personal Data unless: (a) the Controller has given specific or general written authorization to the engagement; (b) the Processor enters into a written contract with the sub-processor imposing data protection obligations no less protective than those in this DPA; and (c) the Processor maintains control over all Personal Data it entrusts to the sub-processor.

6.3 The Controller gives the Processor general written authorization to engage the sub-processors listed in Annex B, Table 1. Where the Processor intends to add or replace a sub-processor with access to Personal Data described in Annex A, it shall notify the Controller in advance, giving the Controller the opportunity to object on reasonable data-protection grounds. If the parties cannot resolve an objection, the Controller may terminate the Master Agreement with respect to the affected services.

6.4 The Processor remains fully liable to the Controller for a sub-processor's performance of its obligations.

7. Personal Data Breach

7.1 The Processor shall notify the Controller without undue delay, and in any event within 48 hours, after becoming aware of a Personal Data Breach affecting the Controller's Personal Data.

7.2 Such notification shall, at a minimum and to the extent the information is available, describe: the nature of the breach, including where possible the categories and approximate number of Data Subjects and records concerned; the likely consequences; and the measures taken or proposed to address the breach, including measures to mitigate its adverse effects.

7.3 The Processor shall reasonably cooperate with the Controller in the investigation, mitigation, and remediation of the breach, including providing relevant records, logs, and access reasonably required by the Controller.

7.4 The Controller has the sole right to determine whether to notify affected Data Subjects or Supervisory Authorities, and the content of any such notice. The Processor shall not itself notify any third party of a Personal Data Breach without the Controller's prior written consent, except where required by law.

7.5 The Processor shall bear its own reasonable costs of investigating and remediating a Personal Data Breach, unless the breach arose from the Controller's own instructions, negligence, or breach of this DPA, in which case the Controller shall bear those costs.

8. Audit

8.1 The Processor shall make available to the Controller all information reasonably necessary to demonstrate compliance with this DPA. Where the Controller reasonably believes a Personal Data Breach has occurred, or that the Processor is in material breach of this DPA, the Processor shall permit the Controller (or a mandated third-party auditor bound by confidentiality) to audit the Processor's compliance, on at least 30 days' notice, no more than once per 12-month period absent a Personal Data Breach or Supervisory Authority requirement.

8.2 The Controller shall bear its own reasonable costs, and the Processor's reasonable costs, of an audit under this Section.

9. Term and Termination

9.1 This DPA takes effect on the effective date of the Master Agreement and remains in effect for as long as the Processor Processes Personal Data on behalf of the Controller.

9.2 If a change in applicable data protection law prevents either Party from fulfilling its obligations under this DPA, the Parties shall suspend the affected Processing until it can be brought into compliance. If the Parties are unable to bring the Processing into compliance, either Party may terminate the Master Agreement, insofar as it concerns the affected Processing, on written notice to the other Party.

9.3 Upon termination of the Master Agreement, Section 4(g) (deletion/return of data) applies.

10. General

10.1 In the event of a conflict between this DPA and the Master Agreement, this DPA shall prevail with respect to the Processing of Personal Data.

10.2 This DPA is governed by the laws of the Republic of Estonia.

Annex A - Description of Processing

A. Categories of Data Subjects

Controller's own website visitors, whose interaction data is captured by Controller's Google Analytics 4 (GA4) implementation and optionally exported to Controller's Google BigQuery environment.

B. Categories of Personal Data

Processed transiently, during query execution against Controller's own BigQuery export, and not persisted by Processor in identifiable form:

  • Pseudonymous identifiers (GA4 client_id, user_id where set by Controller, device/session identifiers)

  • Coarse geolocation (country/region/city, as derived by GA4 - not raw IP address)

  • Device and browser data (user agent, device category, operating system, browser)

  • Traffic source and campaign data

  • Event-level parameters as configured by Controller in its own GA4 implementation

Stored by Processor, in aggregate form only:

  • Aggregate statistical outputs (e.g., counts of users triggering a given event, conversion rates per test variant, statistical significance and correlation values), subject to a minimum cell-size / small-count suppression threshold designed to prevent re-identification of individuals.

  • Event and parameter data - specifically event names, event parameter names, and the most frequent values observed for each parameter - used in defining metrics to be used in subsequent queries.

Residual risk disclosure: while the Processor does not transmit or store individual-level identifiers, the most frequent parameter values described above reflect the values that are actually present in the Controller's own GA4 event parameters. If the Controller's own website or application instrumentation places Personal Data into an event parameter value (for example an email address appearing in a URL parameter), there is a chance - though minimal due to the nature of such a placement being at a small scale - that the value could be surfaced in Katsed by this feature. Placing Personal Data into event parameters or page URLs is already prohibited by the Google Analytics terms of service and the Controller is responsible for ensuring its own GA4 implementation prevents this.

C. Sensitive / Special Category Data

Processor does not intentionally process special category data (Article 9 GDPR) or data relating to criminal convictions. Controller is responsible for ensuring its own GA4/BigQuery configuration does not push special category data or other data disproportionate to Controller's analytics purposes into properties, event parameters, or user properties accessible to Processor.

D. Nature and Purpose of Processing

Processor queries Controller's GA4 property and BigQuery export, at Controller's direction and configuration, to compute experimentation and analytics outputs (e.g., A/B test result analysis, sample ratio mismatch detection, event correlation) for display to Controller's authorized users within the Katsed platform.

All operations involving individual-level identifiers (including any joins, filters, or lookups referencing a specific client_id, user_id, or device/session identifier) are performed exlusively within the Controller's own GA4 or BigQuery environment. Queries issued by the Processor do not reference individual identifiers, and no response returned to the Processor's infrastructure contains user-level data. This is an architectural constraint of the Katsed platform and not merely current practice.

E. Duration of Processing

For the duration of the Agreement, and thereafter only as necessary to comply with Section 4(g) of this DPA (deletion/return of data).

F. Frequency of Processing

On demand, when Controller's users choose to fetch or refresh data from Controller's GA4 property or BigQuery dataset, either manually or on a schedule.

G. Technical and Organizational Security Measures

Access Control

  • Role-based access control for Processor personnel

  • Role-based access control for Controller personnel

  • Application access to Controller's GA4 and BigQuery is handled through Google's OAuth2, and optionally for BigQuery through service account AIM permissions, all of which can be revoked at any time by the Controller

Encryption

  • All data stored in the Processor's Supabase databse is encrypted at rest (AES-256) and in transit (TLS 1.2+), enabled by default at the platform level. Encryption keys are managed by the underlying cloud infrastructure provider.

Data Minimization

  • Personal Data, including user-level identifiers, remains within the Controller's own GA4 and BigQuery environments, and are not transferred or persisted to the application layer.

  • Minimum cell-size / small-count suppression threshold applied by default to all aggregate outputs before storage or display

  • Any breach of access to the application would not result in unauthorized access to the Controller's Personal Data.

Availability and Resilience

  • Processor relies on Supabase's platform-managed daily backups with 7-day retention. Processor has performed and verfied at least one production restore from backup.

Testing and Evaluation

  • Processor uses Aikido Security for continuous static application security testing (SAST), dependency/software composition analysis (SCA) with vulnerability scanning against known CVEs, and secrets/credential leakage detection, connected to processor's source code repositories only (no access to cloud infrastructure or production data).

Annex B - Sub-processors

Table 1 identifies sub-processors that Processor engages as part of delivering the Katsed service, whose activity forms part of the processing chain described in Annex A. consistent with Section 6.1, none of the sub-processors listed in Table 1 receive Personal Data in identifiable form1.

Table 2 identifies providers used by the Processor to run its own business - billing, support, and similar functions relating to the Controller's account as the Processor's own customer. These providers do not have access to the Personal Data described in Annex A.

Table 1 - Sub-processors engaged by Processor as part of the Katsed service

Sub-processor

Activity

Personal Data received

Location

Supabase Pte. Ltd.

Application database and authentication

None - aggregate output without identifiers1

Entity: Singapore

Data: Germany

Netlify, Inc.

Website and application hosting

None - query requests and responses1

USA

1 - See residual risk discloure in Annex A.

Table 2 - Providers used for the Processor's own business operations

Provider

Service Provided

Location

Stripe, Inc.

Billing and payment

USA

Plus Five Five, Inc.

Resend - account-related transactional email

USA

Crisp IM SAS

Support chat and communication

France