Data Processing Addendum
Last updated 2026
This addendum applies where, in using kitset.io, you act as a controller of personal data and we act as your processor. It supplements the Terms of Service. Terms such as controller, processor, personal data, processing and supervisory authority have the meanings given in applicable data protection law.
1. Roles
You are the controller of the personal data in your workspace and determine why and how it is processed. We are your processor and process it only to provide the service.
2. Subject matter and duration
Processing lasts for as long as your workspace exists, plus the deletion period in clause 8.
3. Nature and purpose
Hosting, storing, transmitting, indexing for search, generating notifications and reminders, sending transactional email, and maintaining an audit trail — all so that the service works as described.
4. Categories of data subject
Your employees, contractors and other participants; and any individual named in a record your users create, such as a vendor contact, an approver or a visitor.
5. Types of personal data
Identification and contact data; employment data such as job title, department, team, manager, cost centre and work location; account and authentication data; activity and audit data including IP address and browser user-agent; content your users choose to enter; and any personal data inside files they attach.
Special-category data is not permitted without prior written agreement — see the Acceptable Use Policy.
6. Our obligations
- Process personal data only on your documented instructions, of which using the service is one, unless the law requires otherwise — in which case we will tell you unless prohibited.
- Ensure everyone authorised to process it is bound by confidentiality.
- Apply appropriate technical and organisational security measures, described on the security page.
- Assist you, so far as we reasonably can, with data subject requests, impact assessments and consultations with supervisory authorities.
- Notify you of a personal data breach affecting your data without undue delay and within 72 hours of becoming aware of it.
- Delete or return personal data on termination, as set out in clause 8.
- Make available the information reasonably necessary to demonstrate compliance, and permit an audit no more than once in any 12 months, on 30 days' notice, at your cost, subject to confidentiality and to not disrupting other customers.
7. Subprocessors
You give general authorisation for us to engage the subprocessors listed at /subprocessors. We will give at least 30 days' notice before adding one and you may object on reasonable data protection grounds, as described on that page. Each subprocessor is bound by obligations no less protective than these, and we remain responsible for its performance.
8. Deletion and return
On termination, or on your written request, we will delete personal data within 30 days, except where the law requires retention. Backups expire in the ordinary course within 30 days. The product exports the user directory, the audit trail, vendors, assets, systems, purchase requests and workplace records as CSV, at any time while the workspace is live and including during a read-only period following an expired trial or subscription. For uploaded files, ask us at [email protected] before termination and we will extract them for you.
9. International transfers
Processing locations are listed on the subprocessors page. Note in particular that transactional email is processed in the United States. Where a transfer requires a safeguard, we rely on the relevant standard contractual clauses, which are incorporated into this addendum by reference.
10. Liability
Each party's liability under this addendum is subject to the limits in the Terms of Service.
11. Contact
FLOW FN PTE. LTD. (UEN 202617303Z), Singapore. Data protection contact: [email protected], [email protected].