Skip to content

Legal

Data Processing Addendum

Last updated: July 12, 2026. This Data Processing Addendum (“DPA”) forms part of the agreement between the customer identified in that agreement (“Customer”) and Kuudo, an Openbridge Inc. company (“Kuudo”) for the Kuudo service (the “Agreement”).

The essential commitment

Kuudo does not host or have access to Customer Amazon Data. Data obtained from Amazon Ads or the Selling Partner API, and every report, analysis, file, table, response, or other output derived from it, is processed by resources deployed in Customer's private cloud account. Requests and responses are exchanged directly between those private-cloud resources and the client tools Customer chooses to connect. Kuudo is not in that data path: the data does not enter Kuudo's systems, support tools, logs, or subprocessor chain. Customer controls its Amazon credentials, connected client tools, storage, access, retention, and deletion.

Kuudo does process limited Control Plane Data needed to provide the Service. This includes Cloud Orchestration Data—such as scoped cloud keys or tokens, account and resource identifiers, deployment configuration, and service status—and, when Customer uses Kuudo's authorization service, Amazon Authorization Data such as OAuth tokens and connected-account metadata. Control Plane Data is not Amazon business data or Customer Outputs and is not used to inspect those private contents.

1. Definitions

Capitalized terms not defined in this DPA have the meanings given in the Agreement. “Applicable Data Protection Law” means privacy, data protection, and data security law applicable to a party's processing under the Agreement, including, where applicable, the GDPR, UK GDPR, and U.S. state privacy laws. The terms “controller,” “processor,” “personal data,” “process,” and “personal data breach” have the meanings given in Applicable Data Protection Law.

“Customer Amazon Data” means the business, advertising, order, inventory, listing, financial, reporting, audience, measurement, and other substantive data Customer obtains from or sends to Amazon Ads, Amazon Marketing Cloud, the Amazon Selling Partner API (“SP-API”), Vendor Central, or another Amazon service through Customer's deployment.

“Customer Amazon Credentials” means access tokens, refresh tokens, secrets, keys, roles, and other credentials used to connect to an Amazon service. “Customer Outputs” means any report, analysis, recommendation, audience, query result, export, file, table, model response, or other output created from Customer Amazon Data. Customer Amazon Data and Customer Outputs together are “Protected Customer Data.”

“Customer Cloud Resources” means the Service runtime, connectors, compute, storage, networking, and related resources deployed in a cloud account owned or controlled by Customer. “Customer-Selected Client Tools” means the AI clients, models, workflow tools, business-intelligence tools, applications, or other interfaces Customer chooses to connect to Customer Cloud Resources.

“Cloud Orchestration Data” means the information Kuudo receives or generates to deploy, configure, update, monitor, and orchestrate Customer Cloud Resources on Customer's behalf. It may include cloud account, tenant, subscription, project, region, resource, role, and deployment identifiers; infrastructure configuration; service health and deployment status; and “Cloud Orchestration Credentials” such as scoped keys, tokens, service identities, or role-assumption details. Cloud Orchestration Data excludes Customer Amazon Credentials, Customer Amazon Data, and Customer Outputs.

“Amazon Authorization Data” means information Kuudo processes to establish, maintain, verify, or revoke Customer-authorized connections to Amazon. It may include OAuth authorization codes and state records; Amazon refresh and short-lived access tokens; Customer-supplied Amazon application client IDs and client secrets; Amazon user, selling-partner, advertising-profile, marketplace, region, account, and connection identifiers and metadata; connection status and timestamps; and authorization audit records. It excludes Customer Amazon Data and Customer Outputs.

Cloud Orchestration Data and Amazon Authorization Data together are “Control Plane Data.” Customer Amazon Credentials processed by Kuudo as part of its authorization service are Amazon Authorization Data. Credentials configured solely inside Customer Cloud Resources and never provided to Kuudo are not Control Plane Data.

2. Scope and roles

This DPA applies only to personal data, if any, that Kuudo processes on Customer's behalf in connection with the Service (“Customer Personal Data”). Customer is the controller or processor that determines the permitted use of Customer Personal Data. Kuudo is a processor or subprocessor only to the limited extent Kuudo actually receives or can access Customer Personal Data.

In the standard customer-controlled deployment, Kuudo does not receive or have access to Protected Customer Data and therefore does not act as its processor. Protected Customer Data is exchanged directly between Customer Cloud Resources and Customer-Selected Client Tools without passing through Kuudo. Customer and the providers Customer chooses for its cloud, Amazon account, client tools, models, data warehouse, or other connected systems are responsible for processing inside those systems under Customer's agreements with them.

Kuudo acts as Customer's processor for Control Plane Data to the extent it constitutes personal data. Kuudo processes Cloud Orchestration Data to provision, configure, update, monitor, secure, support, and decommission Customer Cloud Resources. Kuudo processes Amazon Authorization Data to establish, maintain, verify, and revoke Amazon connections and to issue short-lived credentials to Customer-authorized service runtimes. Kuudo performs those activities only on Customer's documented instructions and as described in this DPA.

Kuudo may separately process account, billing, sales, website, and business-contact information as an independent controller. That processing is governed by the Privacy Policy, not this DPA.

3. Customer-controlled architecture

For the standard deployment, Kuudo contractually commits that:

  • Customer infrastructure. The Service runtime and Amazon connectors execute as Customer Cloud Resources in an AWS, Google Cloud, Microsoft Azure, Cloudflare, or other environment owned or controlled by Customer.
  • Direct Amazon data connection. Customer Cloud Resources connect directly to Amazon's business-data APIs. Substantive API requests and responses do not proxy, relay, or route through Kuudo infrastructure.
  • Amazon authorization service. When Customer uses Kuudo-managed or bring-your-own-app authorization, Kuudo may receive an OAuth authorization code; encrypt and store an Amazon refresh token and, for bring-your-own-app connections, the Customer-supplied client secret; exchange those credentials with Amazon's authorization endpoint; and issue a short-lived Amazon access token to an authenticated, Customer-authorized service runtime. Kuudo does not disclose refresh tokens to client tools or browsers.
  • Connection metadata. Kuudo may perform limited verification and identity calls and store the resulting Amazon user, seller, advertising-profile, marketplace, region, and connection metadata needed to identify and route the authorized connection. Kuudo does not use that authorization path to collect Amazon business data or Customer Outputs.
  • Limited management-plane access. Customer provides or authorizes Cloud Orchestration Credentials so Kuudo can deploy and orchestrate Customer Cloud Resources. Those credentials must be limited to the cloud-management permissions reasonably necessary to provide the Service and must not authorize Kuudo to retrieve or inspect Protected Customer Data.
  • Direct client-tool exchange. Customer-Selected Client Tools connect directly to Customer Cloud Resources. Their requests and the resulting Amazon data or Customer Outputs are exchanged on that direct connection and do not proxy, relay, or route through Kuudo infrastructure.
  • Customer-selected destinations. When Customer directs Customer Cloud Resources to return Protected Customer Data to a Customer-Selected Client Tool, that tool receives the data under Customer's configuration and Customer's direct agreement with its provider. Kuudo does not select the tool or control the tool's processing.
  • Kuudo outside the business-data path. Except for the Amazon Authorization Data described above, Kuudo does not host, copy, cache, inspect, retrieve, intercept, transmit, sell, disclose, or otherwise access Customer Amazon Data, substantive Amazon API requests or responses, or Customer Outputs exchanged between Customer Cloud Resources and Customer-Selected Client Tools.
  • No content telemetry. Kuudo does not place Protected Customer Data in its application telemetry, diagnostics, analytics, crash reports, support systems, or logs.
  • No training or product improvement. Kuudo does not use Protected Customer Data to train, fine-tune, evaluate, or improve any artificial-intelligence or machine-learning model, or to create benchmarks, aggregated datasets, or product analytics.
  • No Kuudo support access. Kuudo personnel have no standing or remote access to Protected Customer Data. Customer must redact Protected Customer Data from any support material it voluntarily sends to Kuudo.
  • Customer lifecycle control. Customer configures access, regions, retention, backup, export, and deletion in its own environment. Termination of the Agreement does not require Kuudo to delete Protected Customer Data because Kuudo does not possess it.

Kuudo will not materially change the standard deployment to begin receiving or accessing Protected Customer Data without Customer's express written agreement and an appropriate written amendment describing the new processing before it begins.

4. Processing obligations

Kuudo will process Control Plane Data only on Customer's documented instructions, including the Agreement and this DPA, and only as necessary to provide the orchestration and authorization activities described in Section 2 and Annex A, unless law requires otherwise. If legally permitted, Kuudo will notify Customer before processing required by law.

For Control Plane Data, Kuudo will:

  • ensure that authorized personnel are bound by confidentiality obligations;
  • not sell Customer Personal Data, combine it with data received from another person except as permitted by law, or process it for Kuudo's own advertising or model-training purposes;
  • use Cloud Orchestration Credentials only to deploy and orchestrate Customer Cloud Resources and not to access Protected Customer Data;
  • use Amazon Authorization Data only to establish, maintain, verify, route, or revoke Customer-authorized Amazon connections and to vend short-lived access tokens to authenticated, Customer-authorized service runtimes;
  • notify Customer if, in Kuudo's opinion, an instruction infringes Applicable Data Protection Law; and
  • process Customer Personal Data only for the subject matter, duration, nature, purposes, data types, and data-subject categories documented in Annex A or a signed order form.

Kuudo will not use Cloud Orchestration Credentials to access Protected Customer Data. Any exceptional service that would give Kuudo such access requires Customer's express written agreement and an amendment describing that processing before it begins.

5. Security

Each party will implement appropriate technical and organizational measures for the systems it controls. Customer is responsible for the security and configuration of Customer Cloud Resources, Amazon accounts, the permissions and connections Customer authorizes, Customer-Selected Client Tools, models, warehouses, networks, user access, backups, and output destinations. Kuudo is responsible for the integrity of the software and delivery mechanisms it provides and for protecting Control Plane Data, including Cloud Orchestration Credentials and Amazon Authorization Data, in its possession or control. Kuudo's measures are described in Annex B.

6. Subprocessors

Kuudo uses no subprocessor to process Protected Customer Data in the standard deployment because Kuudo does not receive that data. Customer's cloud provider, Amazon, AI provider, and other Customer-selected services are engaged directly by Customer and are not Kuudo subprocessors for Protected Customer Data.

Kuudo's providers for its website, business operations, and any hosting, database, or secrets-management systems used for Control Plane Data are listed on the Subprocessors page. They do not receive Protected Customer Data. Kuudo will provide notice of a new subprocessor that will process Control Plane Data and an opportunity to object as required by the Agreement or Applicable Data Protection Law. Kuudo will impose data-protection obligations no less protective than those in this DPA and remains responsible for the subprocessor's performance to the extent required by law.

7. Assistance, rights requests, and incidents

Taking into account the nature of its processing and the information available to Kuudo, Kuudo will provide reasonable assistance for data-subject requests, data-protection impact assessments, regulator consultations, security obligations, and breach notifications required by Applicable Data Protection Law. Customer remains responsible for responding to requests and demonstrating the lawfulness of its processing.

Kuudo will notify Customer without undue delay after becoming aware of a personal data breach affecting Customer Personal Data in Kuudo's possession or control. Kuudo will provide information reasonably available to it and take reasonable steps to contain and remediate the breach. An incident confined to Customer's data plane that does not involve Control Plane Data or a system under Kuudo's control is not a breach of Kuudo's systems.

8. Return and deletion

At Customer's choice and as required by Applicable Data Protection Law, Kuudo will return or delete Control Plane Data after the relevant service ends, unless law requires retention. Kuudo will revoke or delete active Cloud Orchestration Credentials and Amazon refresh tokens without undue delay when they are no longer needed to provide the Service. Limited non-secret connection and audit records may be retained as required by the Agreement, law, or security obligations. This obligation does not apply to Protected Customer Data in Customer's environment because Kuudo has no copy to return or delete. Customer remains responsible for revoking Kuudo's cloud and Amazon permissions and for its own data deletion, backup, and legal-retention settings.

9. Demonstrating compliance

Kuudo will make available information reasonably necessary to demonstrate compliance with this DPA. Where that information is insufficient, Customer may conduct an audit no more than once annually, or following a substantiated breach, on reasonable written notice, during normal business hours, and subject to confidentiality, security, and non-disruption requirements. The parties will first use current independent reports, certifications, architecture documentation, and written responses where they reasonably satisfy the request. Customer bears its audit costs unless the audit identifies a material Kuudo breach.

10. International transfers

Kuudo does not transfer Protected Customer Data because it does not receive it or participate in the exchange between Customer Cloud Resources and Customer-Selected Client Tools. Customer selects the regions and transfer mechanisms for its environment and connected providers. If Kuudo transfers Control Plane Data from the EEA, United Kingdom, or Switzerland to a country without an adequacy decision, the parties will enter into the applicable Standard Contractual Clauses, UK International Data Transfer Addendum, or other valid transfer mechanism before that transfer begins. The applicable transfer terms will prevail over conflicting terms in this DPA.

11. U.S. state privacy laws

To the extent a U.S. state privacy law applies to Control Plane Data, Kuudo acts as Customer's service provider or contractor. Kuudo will process Customer Personal Data only for the limited business purposes stated in the Agreement; will not sell or share it for cross-context behavioral advertising; will not retain, use, or disclose it outside the direct business relationship or for a commercial purpose other than providing the Service; and will provide the same level of privacy protection required of Customer. Customer may take reasonable and appropriate steps to confirm Kuudo's compliance and to stop and remediate unauthorized use.

12. General terms

This DPA begins on the effective date of the Agreement and continues while Kuudo processes Customer Personal Data. If this DPA conflicts with the Agreement on data protection, this DPA controls. The Agreement's governing law, dispute, limitation-of-liability, and termination provisions apply to this DPA except where Applicable Data Protection Law requires otherwise. Changes to this DPA must be in writing and agreed by both parties, except that Kuudo may update a public reference or measure without reducing the protection provided or changing the no-access commitments in Section 3.

Annex A — Details of processing

Standard deploymentKuudo processes Control Plane Data to deploy and orchestrate Customer Cloud Resources and, when enabled, provide Amazon authorization and token services. Kuudo does not process Protected Customer Data, which is exchanged directly between Customer Cloud Resources and Customer-Selected Client Tools.
Subject matter and purposeProvisioning, configuring, updating, monitoring, securing, supporting, and decommissioning Customer Cloud Resources; establishing, maintaining, verifying, routing, and revoking Amazon connections; and vending short-lived Amazon access tokens to authenticated, Customer-authorized service runtimes.
DurationFor the term of the Service and only as long afterward as needed for return, deletion, security, audit, or legal obligations under Section 8.
Nature of processingCollection, storage, organization, encryption, use, transmission, token exchange, credential issuance, rotation, revocation, and deletion of Control Plane Data.
Data subjectsCustomer administrators, operators, personnel, contractors, and authorized Amazon account users whose identifiers appear in cloud or Amazon authorization records.
Personal-data categoriesNames, business email addresses, user and role identifiers, cloud account and resource identifiers, deployment configuration and status, audit metadata, Cloud Orchestration Credentials, Amazon OAuth credentials, seller and advertising-account identifiers, profiles, marketplaces, regions, connection status, and related authorization metadata. No Protected Customer Data or sensitive or special-category personal data is intended.
Customer instructionsThe Agreement, this DPA, the applicable signed order form or amendment, and further lawful written instructions consistent with them.

Annex B — Technical and organizational measures

Kuudo will maintain measures appropriate to the risk for systems it controls, including:

  • access controls, least privilege, authentication, and confidentiality obligations for authorized personnel;
  • encryption in transit and at rest for secret Control Plane Data;
  • envelope encryption for stored cloud credentials, Amazon refresh tokens, and Customer-supplied Amazon application secrets;
  • controls designed to prevent credentials, authorization codes, token values, and ciphertext from appearing in source code, browser responses, ordinary application logs, analytics, audit metadata, or support tools;
  • short-lived Amazon access tokens issued only to authenticated, Customer-authorized service runtimes, with refresh tokens withheld from those runtimes;
  • credential scoping, organization isolation, rotation, revocation, and deletion procedures;
  • secure development, dependency management, change control, and vulnerability remediation practices;
  • logical separation between Kuudo's operational systems and Customer-controlled data planes;
  • logging and monitoring designed not to collect Protected Customer Data;
  • incident response, business continuity, and recovery procedures proportionate to the systems Kuudo controls; and
  • periodic review of the effectiveness of these measures.

Privacy questions and requests relating to this DPA may be sent to contact@kuudo.com. See also our Privacy Policy, Subprocessors, and Terms.