This Data Processing Agreement ("DPA") is incorporated by reference into the Kendri Terms of Service and governs Techytal Ltd's processing of personal data on behalf of a Customer, where Techytal acts as Processor and the Customer acts as Controller.
Provision of an AI-powered institutional website assistant, including website crawling, content indexing, retrieval, generation of responses, escalation of unanswered questions, safety-related routing, administration, support and service monitoring.
For the duration of the Customer's use of the Services and such additional period as required for deletion, security, legal or contractual purposes.
Processing is performed to provide the Services; retrieve relevant Customer Content; generate answers; maintain conversation context; route unanswered questions to Customer staff; process optional visitor contact information; perform security and service management; and maintain usage records.
Potentially prospective students, current students, former students, staff, applicants, parents/guardians, members of the public, website visitors, and Customer administrators.
Potentially question text, contact email address where voluntarily supplied, session identifier, conversation context, IP/request information where present in technical logs, website URL/page information, administrator name and email, audit data, and service usage data.
The Services may unintentionally receive special-category personal data where an End User voluntarily includes such information in a question. The Company does not require End Users to submit special-category information. The Customer is responsible for determining the lawful basis and applicable condition for its processing of such information where required. The Company will process such information only in accordance with the Customer's documented instructions and applicable law.
See the current Sub-Processor List at kendri.co.uk/subprocessors, incorporated into this DPA by reference.
Where the Company makes a restricted international transfer of personal data subject to UK GDPR, it will use an appropriate lawful transfer mechanism, which may include an applicable adequacy decision, the UK International Data Transfer Agreement, the UK Addendum to the EU Standard Contractual Clauses, or another lawful mechanism recognised by applicable data protection law.
The Company maintains technical and organisational measures including logical tenant separation, authentication controls, least-privilege access, encryption in transit and (where supported) at rest, secrets management, access and administrative audit logging, vulnerability management, backups, incident-response procedures, and controlled production access.