This Data Processing Addendum (“DPA”) forms part of the Terms of Service (“TOS”) between the customer (“Controller”, “you”) and Ad Astra Studios (“Processor”, “Kompound”) and applies whenever Kompound processes personal data contained in your Store Data. Where the GDPR, UK GDPR or India’s DPDP Act applies, this DPA is intended to satisfy the requirements those laws place on contracts between controllers and processors.
This DPA defines the conditions under which the Processor processes Personal Data on behalf of the Controller in providing the Services.
The Processor warrants that Processing performed on behalf of the Controller will comply with Data Privacy Laws and will notify the Controller if it can no longer meet its obligations. The Controller is solely responsible for the quality and accuracy of the Personal Data, for the lawfulness of how it was obtained, and for meeting transparency and consent requirements toward Data Subjects, including the consent banner on its own storefront.
All Personal Data processed by the Processor in performing the Services remains the property of the Controller.
Processing continues for as long as the Processor provides the Services to the Controller and until deletion under Clause 17.
The Processor processes the categories of Personal Data and Data Subjects set out in Schedule 1.
The Processor processes Personal Data only on the Controller’s documented instructions, which are the TOS, this DPA, the specific instructions in Schedule 2 and the settings the Controller selects in the Services, except where otherwise required by law, in which case the Processor will inform the Controller before Processing unless the law prohibits it. The Processor will inform the Controller if it believes an instruction infringes Data Privacy Laws.
AI processing notice. Where the Services include features powered by artificial intelligence (Ask Kompass, Kompound MCP), the Processor sends only aggregated figures and the user’s question to its AI Subprocessor, never customer-identifying Personal Data, and does not use Personal Data to train AI models.
The Processor will promptly notify the Controller of any request received directly from a Data Subject and will assist the Controller, taking into account the nature of the Processing, in responding to requests to exercise rights under Data Privacy Laws, including through the platform data-request and redaction mechanisms described in Schedule 2.
The Processor will assist the Controller with data-protection impact assessments and prior consultations with supervisory authorities by providing, on request, information about data flows, storage, methods of processing, encryption and deletion.
Both parties will keep Personal Data confidential and disclose it only as this DPA permits. The Processor ensures that all Personnel authorised to process Personal Data are bound by confidentiality obligations and access it only as needed to provide the Services.
Each party is liable for its own breaches of this DPA as determined under Data Privacy Laws, subject to the limitations of liability in the TOS, which apply in aggregate to the TOS and this DPA together.
The Processor implements and maintains appropriate technical and organisational measures to ensure a level of security appropriate to the risk, protecting Personal Data against accidental or unlawful destruction, loss, alteration, unauthorised disclosure or access. Those measures are at least equivalent to Schedule 3.
The Processor will notify the Controller without undue delay and in any case within seventy-two (72) hours of becoming aware of a Breach Event, providing all information reasonably available to help the Controller assess the breach and meet its own notification obligations, and will cooperate in the investigation and remediation.
The Processor will not use, or authorise the use of, Personal Data for any purpose other than performing its obligations under the TOS and this DPA. In particular, the Processor does not sell Personal Data, does not use it for advertising, and does not surface customer-identifying fields in any Report or export.
The Controller authorises the Subprocessors listed in Schedule 4. The Processor may engage additional or replacement Subprocessors provided that: (a) each is bound by obligations equivalent to this DPA; (b) the Processor remains fully liable for their acts and omissions; and (c) the Processor gives the Controller at least thirty (30) days’ notice, by email to the account owner, giving the Controller the opportunity to object on reasonable data-protection grounds. If an objection cannot be resolved, the Controller may terminate the affected Services.
The Services are hosted in the United States and operated from India. The Processor will not transfer Personal Data originating in the EEA, UK or Switzerland to a country without an adequacy decision except under appropriate safeguards, namely the Standard Contractual Clauses (Module Two, controller-to-processor) approved by the European Commission and the UK International Data Transfer Addendum, which are incorporated by reference, with the parties, subject matter and measures completed by reference to this DPA and its Schedules. Transfers of Personal Data originating in India comply with the DPDP Act and any restrictions notified under it.
Collection stops immediately when a store is disconnected or the Apps are uninstalled. At the Controller’s choice, the Processor will delete or return the Personal Data within thirty (30) days of disconnection, termination or a written request, except to the extent storage is required by applicable law. Deletion requests received through a platform (for example Shopify’s customer or shop redaction webhooks) are honoured within forty-eight (48) hours. The Controller may export its Reports at any time before disconnecting.
On request, no more than once in any twelve-month period unless required by a supervisory authority or following a Breach Event, the Processor will make available the information necessary to demonstrate compliance with this DPA, including third-party reports where they exist, and will permit an audit or inspection by the Controller or an independent auditor bound by confidentiality, on reasonable notice, during business hours, limited to the systems, procedures and documentation relevant to the Processing.
The Processor maintains records of Processing carried out on behalf of the Controller as required by Data Privacy Laws and will make them available to the Controller on request within a reasonable period.
| Subprocessor | Purpose | Location |
|---|---|---|
| Supabase, Inc. | Database, authentication, file storage, secrets vault | United States |
| Vercel, Inc. | Application hosting and edge network | United States (global edge) |
| Upstash, Inc. | Background job queue and scheduling | United States / EU |
| Anthropic, PBC | AI answers for Ask Kompass and Kompound MCP (aggregate figures only) | United States |
| Functional Software, Inc. (Sentry) | Error monitoring | United States |
| Axiom, Inc. | Log management | United States |
| Resend, Inc. | Transactional email to the Controller’s users | United States |
| PostHog, Inc. | Product analytics of the Services (Controller’s users only) | United States / EU |
| Crisp IM SAS | Support chat | European Union |
| Shopify Inc.; payment provider | Subscription billing (no Store Data) | Canada / United States |
Questions about this DPA and requests for a signed copy: support@kompound.app.
Questions about this document: support@kompound.app · Ad Astra Studios, Mumbai, Maharashtra, India.