Data Processing Agreement (DPA)
Last updated: July 2026 · Beta draft — a signed version is required before paid activation
1. Parties & Roles
This agreement is between the Customer (“Controller”) and MOAAYD MOHAMMEDMAHMOU M ALSHANQITI, an independent professional licensed under Saudi Freelance Certificate no. FL-143060777, trading as “Kuvo AI”, operator of Kuvo AI (“Processor”). It governs the processing of the Controller’s end-customer personal data under the Saudi PDPL and, where applicable, the GDPR, and forms part of the Terms of Service.
2. Subject Matter & Scope
Subject: operating an AI assistant that answers the Controller’s customers. Duration: the subscription term plus the 30-day deletion window. Data: conversation content, WhatsApp phone numbers, website identifiers, names where provided. Data subjects: the Controller’s end customers. Purpose: generating replies, showing conversations in the dashboard, and operational analytics for the Controller.
3. Processor Obligations
We process data only on the Controller’s documented instructions; ensure personnel confidentiality; apply appropriate technical and organizational measures (encryption in transit and at rest, tenant isolation via RLS, audit logging of sensitive operations); assist the Controller with data-subject requests and impact assessments where needed; and notify the Controller without undue delay upon becoming aware of a breach affecting its data.
4. Sub-processors
The Controller authorizes the current sub-processors: Meta Platforms (WhatsApp), Supabase, OpenAI, Tap Payments, Sentry (full list and locations in the Privacy Policy). We give reasonable prior notice of material additions with a right to object, and remain liable for our sub-processors meeting the same level of protection.
5. International Transfers
All processing takes place outside the Kingdom. The database is hosted with Supabase in the region stated in the Privacy Policy, replies are generated by OpenAI in the United States, handover alerts are sent via Resend in Japan, and WhatsApp messages pass through Meta’s servers. These transfers are made as strictly necessary to perform the contract, under data processing agreements and contractual safeguards with each sub-processor, and in line with the cross-border transfer requirements of the PDPL and its Implementing Regulations.
We do not currently offer in-Kingdom hosting. If your business is subject to mandatory data localization requirements, contact us before subscribing.
6. Deletion & Return
At termination the Controller may request either return of the data or its deletion. A machine- readable export (JSON) is provided on written request to privacy@aikuvo.com within 30 days. Absent a request, data is deleted within 30 days except where retention is legally required.
7. Audit
On request we provide reasonable information to demonstrate compliance and allow one audit per year with 30 days’ notice, conducted without compromising other customers’ security.
Reference draft — the signed version will be prepared and reviewed by qualified counsel before the first paid subscription.