Skip to Content

Legal

Data Processing Agreement

How Wyzie LLC processes the personal data in an organization’s Kilter workspaces on that organization’s behalf, and what each side promises about it.

Issued by Wyzie LLC. Last updated .

What This Agreement Is

This Data Processing Agreement is part of the Terms of Service between Wyzie LLC and each company or other organization that runs a Kilter workspace and accepts those terms. It governs how Wyzie LLC processes the personal data in that organization’s workspaces on the organization’s behalf. Here, “you” means that organization, and “we” and “us” mean Wyzie LLC.

Nothing needs to be signed or requested. Accepting the terms for an organization accepts this agreement for it, and the version in force is the one dated at the top of this page. Save or print this page for your records.

This agreement does not cover a person’s own account, or a personal workspace somebody uses for themselves. Wyzie LLC is the controller of those, and the Privacy Policy says what it does with them.

If your organization and Wyzie LLC sign a separate data processing agreement, that agreement controls wherever the two conflict.

Words Used Here

  • Data protection law means every law that applies to processing Your Personal Data under the terms, including the GDPR, the UK GDPR, the Swiss Federal Act on Data Protection and United States state privacy laws such as the California Consumer Privacy Act.
  • Your Personal Data means the personal data in what you and the people in your workspaces put into Kilter (cards, notes, events, reminders, comments, files, assistant conversations and everything else in a workspace), together with the membership, roles, invitations and audit records that belong to a workspace. Annex 1 describes it.
  • Controller, processor, data subject, personal data breach and supervisory authority mean what the GDPR says they mean, and the matching words in other data protection law, such as business and service provider, are read the same way.
  • Subprocessor means a service Wyzie LLC chooses that processes Your Personal Data on our behalf.
  • Standard Contractual Clauses means the clauses adopted by the European Commission in Implementing Decision (EU) 2021/914.

Your Role and Ours

You are the controller of Your Personal Data, or a processor acting for a controller of your own, and Wyzie LLC is your processor. Where you are a processor, you confirm that your controller has authorized the instructions you give us and the subprocessors this agreement names.

Wyzie LLC is a controller, and not your processor, of what it needs to run Kilter as a service: each person’s account and how they sign in, the security records about an account, the waitlist, and the email Kilter sends about accounts. The privacy policy covers that data.

Your Instructions

We process Your Personal Data only to provide, secure and support Kilter for you, and only on your documented instructions. Your instructions are the terms and this agreement, and what you and your workspace’s people do in Kilter: what they put in, share, connect, export and delete, and the settings its admins choose. If we believe an instruction breaks data protection law, we tell you.

We also process it where a law we are subject to requires it. When that happens, we tell you first, unless that law forbids telling you.

We do not sell Your Personal Data, do not use it for advertising, and do not use it to train any model.

Confidentiality and Access

Only people who need access to run Kilter can reach Your Personal Data, and each of them is bound by an obligation of confidentiality.

Wyzie LLC’s operators can open an internal panel that shows the data Kilter holds. They use it only to answer a support request you or your people make, to keep Kilter secure, to investigate abuse, or to comply with the law, and what they do there is recorded.

Security

We keep the technical and organizational measures in Annex 2, which are designed to protect Your Personal Data against accidental or unlawful destruction, loss and alteration, and against disclosure or access nobody authorized. We can change them as Kilter changes, but never in a way that leaves Your Personal Data less protected overall.

Some of that protection is in your hands: who you invite, the roles and permissions you set, whether your people turn on a second factor or sign in through your own identity provider, the board links you share, and the accounts and model providers you connect.

Subprocessors

You authorize Wyzie LLC to use the subprocessors named on the Subprocessors list, which Annex 3 incorporates. We stay responsible to you for how each one meets the obligations in this agreement.

Cloudflare, which hosts Kilter and keeps its database and files, is bound by its data processing terms. PurelyMail, which sends Kilter’s email, offers no data processing agreement, and the list says so. The email it sends can include a workspace’s name and words from its content, such as a card’s title in a notification. A person who does not want that can turn notification email off in Settings.

Before a new subprocessor receives any of Your Personal Data, we add it to the list and email every account holder at least thirty days ahead. If a subprocessor has to be replaced at short notice to keep Kilter running or secure, we email as soon as we can instead.

If you have a reasonable objection to a new subprocessor based on data protection, write to support@kilter.work within thirty days of that email. We will try to resolve it. If we cannot, you may stop using Kilter for the workspaces concerned and delete them, and we refund anything you paid in advance for time you will not use.

Services You Connect

The model providers your workspace’s admins connect, the accounts your people connect, your own identity provider for single sign on and provisioning, an MCP server, and any other service you point Kilter at are not our subprocessors. Kilter sends data to them on your instruction, and your agreement with each of them governs what it does with that data. Choosing them, and having the agreements you need with them, is up to you.

Requests From People

Kilter gives you the tools to answer requests from the people whose data is in your workspaces: admins can find, correct and delete content, remove members and download the audit log, and every person can download or erase their own account from Settings. Where those tools are not enough, we help you by other reasonable means.

If a person asks us directly about Your Personal Data, we ask them to contact you and, where we can tell which organization it concerns, we tell you, unless the law forbids it. We do not answer the request on your behalf without your instruction.

Personal Data Breaches

We notify you of a personal data breach affecting Your Personal Data without undue delay, and in any case within 72 hours after we become aware of it.

The notice is emailed to your workspace’s owners and says what we know: what happened, which kinds of data and roughly how many people it concerns, its likely consequences, what we have done, and what we recommend you do. What we do not know yet follows as we learn it.

We take reasonable steps to contain the breach and limit its harm, and we keep a record of it. You decide whether to notify supervisory authorities and the people concerned, unless the law requires us to. Notifying you of a breach is not an admission of fault.

Assessments and Regulators

We give you reasonable help with a data protection impact assessment, and with consulting a supervisory authority, about Kilter’s processing of Your Personal Data. That help is first this agreement, the privacy policy, the subprocessor list and the security page, and then answers to your reasonable questions about what they do not cover.

Transfers From Europe, the UK and Switzerland

Wyzie LLC is in the United States, and Your Personal Data is processed there and wherever Annex 3 says. Where data protection law requires a safeguard for a transfer of Your Personal Data to us from the European Economic Area, the United Kingdom or Switzerland, this agreement incorporates the Standard Contractual Clauses, and you and Wyzie LLC enter into them as follows:

  • Module Two (controller to processor) applies where you are a controller, and Module Three (processor to processor) where you are a processor. You are the data exporter and Wyzie LLC is the data importer.
  • Clause 7, the docking clause, does not apply.
  • In Clause 9, Option 2 applies: a general written authorization for subprocessors, with at least thirty days of notice, as described above.
  • The optional wording in Clause 11 does not apply.
  • In Clause 13, the competent supervisory authority is the one that clause names for your situation.
  • In Clause 17, Option 1 applies and the clauses are governed by the law of Ireland. In Clause 18, disputes go to the courts of Ireland.
  • Annexes I, II and III of the clauses are Annexes 1, 2 and 3 of this agreement.
  • Accepting the terms for your organization is signing the clauses, on the day you accept.

For a transfer from the United Kingdom, the International Data Transfer Addendum to the EU Commission Standard Contractual Clauses, issued by the Information Commissioner under section 119A of the Data Protection Act 2018, applies as well. Its Table 1 is completed by Annex 1, its Tables 2 and 3 by the choices above and Annexes 1 to 3, and either party may end it when the approved Addendum changes, as the Addendum allows.

For a transfer from Switzerland, the Standard Contractual Clauses apply with these changes: references to the GDPR are to the Swiss Federal Act on Data Protection, the Federal Data Protection and Information Commissioner is the competent supervisory authority for those transfers, and “Member State” does not stop people in Switzerland from bringing a claim where they usually live.

If the Standard Contractual Clauses conflict with the rest of this agreement or with the terms, the clauses prevail.

United States Privacy Laws

Where a United States state privacy law applies, Wyzie LLC is your service provider or processor for Your Personal Data, and:

  • we do not sell it or share it, as those laws define selling and sharing;
  • we do not keep, use or disclose it for any purpose other than providing Kilter to you under the terms, or outside our direct business relationship with you, except as those laws allow;
  • we do not combine it with personal data we receive from anybody else, except as those laws allow;
  • we comply with those laws and give it the level of protection they require of you;
  • we tell you if we decide we can no longer meet these obligations; and
  • you may take reasonable steps to stop and correct any use of it you did not authorize.

We certify that we understand these restrictions and will comply with them.

Showing Compliance, and Audits

We make available the information reasonably needed to show that we meet this agreement: this agreement, the privacy policy, the subprocessor list and the security page, and once a year, on request, written answers to a reasonable security questionnaire.

If that information is not enough to show compliance, or a supervisory authority requires it, you may audit our compliance with this agreement yourself or through an independent auditor who is bound by confidentiality and is not our competitor. Give us at least thirty days’ written notice with the scope you propose. An audit happens no more than once in twelve months unless a personal data breach or a supervisory authority calls for another, during business hours, without disrupting Kilter and without reaching any other customer’s data. You pay for your audit, and we may charge for our reasonable time. A subprocessor is audited through the reports and terms it makes available.

What You Are Responsible For

  • Having a lawful basis for putting Your Personal Data into Kilter, and giving the people it is about any notice, and getting any consent, the law requires.
  • Making sure your instructions comply with data protection law.
  • Not putting into Kilter health information covered by HIPAA, payment card numbers, government identification numbers such as Social Security numbers, or passwords for other services, unless we have agreed to it in writing. Kilter is not built to the standards those kinds of data require, and Wyzie LLC signs no business associate agreement.
  • The services you connect, and the agreements you need with them.
  • Keeping who can reach your workspaces, and what they can do there, under your control.

Returning and Deleting Data

While a workspace exists, its admins can download its audit log and its calendar, and each person can download everything held about their own account. If you need a copy of a workspace beyond those, write to support@kilter.work before you delete it, and we provide one in a common machine readable format within thirty days.

When a workspace is deleted, its content is deleted from Kilter’s database at once, and the contents of its files from Cloudflare R2 within five minutes. Database backups age out within thirty days, and server logs within seven. Records that name the workspace in passing, such as the security record that it was deleted, are deleted within ninety days. After that, nothing of Your Personal Data remains, except what the law requires us to keep, which stays protected under this agreement and is used for nothing else.

Liability and Precedence

Each party’s liability arising from this agreement, including under the Standard Contractual Clauses, is subject to the limitations and exclusions of liability in the terms, to the extent data protection law and the clauses allow. Nothing in this agreement limits a data subject’s rights under the clauses.

Where this agreement conflicts with the terms about processing Your Personal Data, this agreement prevails, and the Standard Contractual Clauses prevail over both. Everything else about this agreement follows the terms, including their sections on governing law and disputes, except where the clauses name a law and courts of their own.

How Long It Lasts, and Changes

This agreement lasts as long as Wyzie LLC processes Your Personal Data. The sections on confidentiality, deletion and liability continue until that data is gone.

We may change this agreement to follow changes in the law, in Kilter or in its subprocessors, and the date at the top says when. A change that reduces your protection is a material change to the terms, so account holders are emailed at least thirty days before it takes effect, unless the law or a supervisory authority requires it sooner. The Standard Contractual Clauses themselves change only as the bodies that issue them change them.

Annex 1: Details of the Processing

ItemDetails
Data exporterYou, the organization that runs the workspace, reached through its workspace owners’ email addresses. Your role is controller, or processor where you act for a controller of your own.
Data importerWyzie LLC, a North Carolina limited liability company in the United States, reached at support@kilter.work. Its role is processor, or subprocessor where you are a processor.
People the data is aboutThe people in your workspaces and the people invited to them; the people named or described in their content, such as colleagues, clients and contacts; and the senders of mail a member asks the assistant to read into proposals.
Kinds of personal dataNames, email addresses, pictures, membership, roles and permissions; anything people write or attach, including cards, notes and their earlier versions, events, reminders, comments, checklists, custom fields, templates, saved views, sticky notes, saved links and what was read at them, files, assistant conversations and their attachments; a proposal’s mail subject, sender, link and time; notifications; invitations; the workspace’s audit records, with the IP addresses and browsers they hold; and what your identity provider sends for single sign on and provisioning.
Sensitive dataNone is intended. Special categories of personal data are not processed except where your people put them into Kilter, and the kinds of data listed under What You Are Responsible For are not to be put in at all.
How oftenContinuously, for as long as you use Kilter.
Nature of the processingHosting, storing and backing up; keeping work in sync between people and devices; searching; sending notifications and email; sending data to the services you connect, on your instruction; exporting and deleting.
PurposeProviding, securing and supporting Kilter for you under the terms.
How long it is keptUntil you or your people delete it, or the workspace is deleted, and then as Returning and Deleting Data says. The privacy policy lists the periods Kilter’s code enforces.
Transfers to subprocessorsFor the subject matter, nature and duration of each subprocessor’s processing, see Annex 3.
Competent supervisory authorityThe one Clause 13 of the Standard Contractual Clauses names for your situation.

Annex 2: Security Measures

Encryption

  • Every connection to kilter.work, app.kilter.work and Kilter’s realtime service is encrypted with TLS.
  • Tokens from sign in providers and connected accounts, calendar server passwords, model provider keys, and second factor secrets and backup codes are encrypted by Kilter before they are stored.
  • Passwords are stored only as salted hashes, and secrets somebody presents, such as a board’s share link or a provisioning token, only as digests.

Access Inside a Workspace

  • Every request that reads or changes a workspace is checked against the person’s membership and permissions in that workspace, and the build fails if a workspace route is added without that check.
  • Owners and admins set roles and each person’s permissions, and nobody can grant a permission they do not hold.
  • A private card, note, event or reminder is seen only by the people named on it. An admin reads the workspace’s audit log, never a person’s own sign ins.
  • Removing a member ends their access within ten seconds.

Signing In

  • An email address is verified before its account can sign in.
  • A second factor by authenticator app, with single use backup codes, for anyone who turns it on; a passkey or security key (WebAuthn), for anyone who adds one; single sign on over OIDC or SAML, and provisioning over SCIM, for an organization that sets them up.
  • A session expires thirty days after it was last renewed, and its cookie is sent to app.kilter.work alone.
  • Repeated attempts at a password, a second factor code or a backup code are limited, and a sign in from an unfamiliar device is emailed to the account holder.

Separation and Outbound Requests

  • Every record belongs to one workspace and is read through it.
  • Addresses Kilter fetches on somebody’s behalf (an MCP server, a calendar server, a model endpoint, a saved link) are checked so they cannot reach Kilter’s own network.

Wyzie LLC’s People and Systems

  • Everybody who operates Kilter has a named account of their own on each system that can reach Your Personal Data, with a second factor that is not a text message, and the narrowest role that does the job.
  • Access is approved and recorded, removed the same business day it is no longer needed, and reviewed every quarter.
  • Access to the internal panel is granted person by person at one of three levels, and everything done there is recorded with who did it.

Logging and Records

  • Each request writes one log line, without the IP address it came from and with anything that looks like a password, token or cookie removed first.
  • Security events (sign ins, second factor and password changes, role and permission changes, invitations and removals) are recorded and kept for ninety days.

Backups and Recovery

  • The database can be restored to any point in the last thirty days through Cloudflare D1 Time Travel.
  • A release that causes a problem can be rolled back to the last good version.

Vulnerabilities and Incidents

  • Before a change is pushed to the main branch, the dependencies that reach production are checked for known vulnerabilities.
  • A published vulnerability disclosure policy, How to Report a Vulnerability, with a safe harbor for research in good faith.
  • A written incident response policy: declare and record the incident, preserve what shows what happened, contain it, investigate, notify the people who must be told, and review what allowed it.

Keeping Less

  • When the assistant reads a watched mailbox, Kilter keeps the proposal and the message’s subject, sender, link and time, never its body.
  • Read notifications, settled proposals, expired sessions, security records and operator records are deleted on the schedules in the Privacy Policy.

Infrastructure

The physical and network security of the data centers Kilter runs in is Cloudflare’s, under its own data processing terms.

Annex 3: Subprocessors

The subprocessors are the services under The Services Kilter Runs On on the Subprocessors list, which says what each one does, what it receives and where it processes it. The list as it stands at any time is this annex, and it changes only as Subprocessors, above, describes.