Juridisch

Data Processing Agreement

Vraag een PDF aan? Mail privacy@karet.money.

Concept — review in afronding. Deze pagina toont de werkende versie van onze tekst. De juridisch bindende versie wordt door onze counsel beoordeeld vóór launch.

Karet — Data Processing Agreement (Standard)

Draft — review pending. This document is the working draft of the Karet Data Processing Agreement. The legally-binding version is the counsel-reviewed text that supersedes this draft before launch. Until the launch gate is satisfied, this file is informational only.

Effective date: TBD · Version: 0.1-draft

This Data Processing Agreement ("DPA") supplements the Karet Terms of Service and forms part of the contract between Karet Finance B.V. i.o. ("Processor") and the Customer ("Controller") when the Controller's use of Karet involves the processing of personal data on the Controller's behalf.

1. Subject and duration

The Processor processes personal data for the Controller for the sole purpose of providing the Karet service as documented at karet.money. This DPA remains in effect for as long as the Processor processes personal data on the Controller's behalf.

2. Nature and purpose of processing

The Processor processes:

  • Bank account metadata + transactions (from PSD2 / Salt Edge).
  • Brokerage account positions + activity (from Saxo, IBKR, Bitvavo, SnapTrade).
  • Journal entries + ledger data the Controller authors.
  • AI-generated commentary, Cards, and chat history.
  • Documents the Controller uploads (receipts, statements, voice memos).
  • Account data of the natural persons accessing the Karet workspace.

Solely for the purposes of:

  • Providing the Karet service.
  • Sending transactional and (consent-gated) digest email.
  • Producing AI-generated insights, with no model training.
  • Operating security telemetry (logs, anomaly detection).

3. Categories of data subjects

  • The natural-person workspace members (Controller's employees, family members, advisors).
  • The natural-person counterparties referenced in transactions (only to the extent contained in bank statements / broker activity the Controller imports).

4. Sub-processors

The Processor uses the sub-processors listed at docs/security/sub-processors.md and on the public page /legal/sub-processors. Adding a new sub-processor requires a PR that updates that file and gives the Customer 30 days' notice before the new sub-processor is activated. The Customer may terminate the contract during the notice period if it does not consent to the new sub-processor.

5. Security

The Processor implements the technical and organisational measures listed in ADR-0011 (Security & Data Protection Baseline), including:

  • EU data residency (Postgres, blob storage, LLM endpoints, email).
  • KMS-backed envelope encryption for secrets.
  • Two-tier audit (workspace audit_events + account-scoped security_events).
  • Per-table retention enforced by cron.
  • Step-up authentication for sensitive actions.
  • TOTP / passkey enrolment, breach-password check on sign-up.

A current summary is published at /trust (PRD-0037).

6. Data subject rights

The Processor will assist the Controller in responding to data subject requests (access, rectification, erasure, restriction, portability, objection) within the deadlines set by GDPR Art. 12.

Self-service surfaces (Settings → Privacy & Data) cover most requests; the Controller can escalate to privacy@karet.money for anything not covered.

7. Breach notification

The Processor will notify the Controller without undue delay (no later than 48 hours) after becoming aware of a personal data breach affecting the Controller's data. Notice includes the nature of the breach, categories and approximate number of data subjects, and the measures taken.

8. International transfers

The Processor does not transfer personal data outside the EEA. Sub-processors based outside the EEA are listed in docs/security/sub-processors.md with the applicable transfer mechanism (e.g. EU Standard Contractual Clauses 2021/914) where relevant.

9. Return / deletion

On termination of the contract, the Processor will, at the Controller's choice:

  • Return the personal data within 30 days via the standard DSR export ZIP, or
  • Delete the personal data within 30 days (the default).

The 30-day window matches the DSR grace window described in /legal/privacy §7.

10. Audits

The Controller (or its independent auditor) may, no more than once per 12 months and with at least 30 days' written notice, audit the Processor's compliance with this DPA. The Processor will reasonably cooperate.

Appendix A — Sub-processors

See docs/security/sub-processors.md.

Appendix B — TOMs (Technical & Organisational Measures)

See ADR-0011 (Security & Data Protection Baseline) and the surfaces documented at /trust.