Data Processing Agreement

Last updated: June 20, 2026

This Data Processing Agreement ("DPA") forms part of the agreement between Kembo (ByteStronauts) ( "Processor", "we", "us") and the entity that registers for a Kembo account ("Customer", "you", "Controller"). It applies when you use Kembo to authenticate end users in your application and/or when you enable Kembo Analytics for a project.

By creating a Kembo account, using the Kembo APIs or SDKs, or enabling analytics for a project, you agree to this DPA on behalf of the Controller entity you represent. If you do not have authority to bind that entity, do not accept this DPA.

1. Definitions

  • Personal Data means any information relating to an identified or identifiable natural person processed by Processor on behalf of Controller under the Kembo service.
  • End Users means individuals who sign in to or otherwise use Controller's application that integrates Kembo.
  • Services means Kembo authentication, session management, optional Kembo Analytics, and related hosting and APIs.
  • Applicable Data Protection Law means the EU General Data Protection Regulation (GDPR), the UK GDPR where applicable, and other data protection laws that apply to Controller's processing.

2. Roles of the parties

For Personal Data about End Users that Controller submits to or causes to be processed through the Services, Controller is the data controller and Processor is the data processor. Processor will process Personal Data only on documented instructions from Controller, including the configuration of projects, API keys, enabled features, and these Terms and this DPA.

For Personal Data about Controller's own dashboard users (account owners and team members), Processor acts as an independent controller as described in the Privacy Policy.

3. Subject matter, duration, and nature of processing

Subject matter: provision of Kembo authentication and optional analytics for Controller's mobile or web applications.

Duration: for the term of Controller's Kembo subscription or free-tier use, and until deletion in accordance with this DPA and the Privacy Policy.

Nature and purpose: hosting, storing, transmitting, and displaying authentication and usage data solely to provide the Services Controller has enabled.

4. Categories of data subjects and personal data

Data subjects: End Users of Controller's applications.

Authentication data (when End Users sign in through Kembo): email address, name, profile image URL, sign-in provider identifier, OAuth tokens and session identifiers, and related technical logs needed to operate sign-in.

Analytics data (only when Controller enables Kembo Analytics for a project): event names, platform, coarse location (city and country derived from connection metadata without storing IP addresses), browser/OS family, generic screen or page names, pseudonymous visitor counts (daily hash of a per-install random identifier or connection metadata; raw device identifiers and IP addresses are not stored by Processor), and non-PII custom event properties that pass Processor's validation filters.

Processor does not require Controller to send End User email addresses, names, or account IDs in analytics events.

5. Controller obligations

Controller represents and warrants that it will:

  • determine and document a lawful basis under Applicable Data Protection Law for all processing it instructs Processor to perform;
  • provide End Users with a clear privacy notice that accurately describes Kembo-powered sign-in and, if enabled, Kembo Analytics (including the privacy policy snippet provided in the Kembo dashboard for analytics);
  • not configure the Services or send data in a manner that instructs Processor to process special categories of data, children's data without appropriate safeguards, or other data Controller is not permitted to share;
  • not send personal identifiers, credentials, or other unnecessary PII in analytics events or custom properties;
  • respond to End User requests exercising data subject rights, using Kembo dashboard tools and Processor assistance where applicable.

6. Processor obligations

Processor will:

  • process Personal Data only on Controller's documented instructions unless required by law, in which case Processor will inform Controller unless prohibited;
  • ensure personnel with access to Personal Data are bound by confidentiality obligations;
  • implement appropriate technical and organizational measures, including encryption in transit, access controls, hashed credentials and tokens where applicable, PII filtering on analytics ingest, k-anonymity thresholds in analytics reports, and automatic deletion of analytics events after 12 months;
  • not sell Personal Data or use it for advertising or profiling unrelated to providing the Services;
  • assist Controller, taking into account the nature of processing, in responding to data subject requests and data protection impact assessments where reasonably required and at Controller's expense for disproportionate effort;
  • notify Controller without undue delay after becoming aware of a Personal Data breach affecting Controller's End User data, providing information reasonably available to assist Controller in meeting its breach notification obligations.

7. Sub-processors

Controller authorizes Processor to engage sub-processors that help operate the Services (such as cloud hosting, payment, and email providers). Processor will impose data protection obligations on sub-processors that are no less protective than this DPA. A current list of sub-processor categories is: infrastructure hosting (e.g. Vercel), payment processing (e.g. Stripe), and transactional email. Processor will notify Controller of material changes to sub-processors by updating this page or the Privacy Policy; Controller may object on reasonable grounds relating to data protection by contacting contact@bytestronauts.com.

8. International transfers

Personal Data may be processed in the European Economic Area and other countries where Processor or its sub-processors operate. Where transfers require safeguards under Applicable Data Protection Law, Processor relies on appropriate mechanisms such as the EU Standard Contractual Clauses or equivalent measures offered by sub-processors.

9. Deletion and return

Upon termination of the Services for a project or upon Controller's written request, Processor will delete or anonymize End User Personal Data within a reasonable period, except where retention is required by law or for legitimate backup cycles (typically not longer than 30 days). Analytics events are automatically deleted after 12 months. End User deletion requests are described on our Data Deletion page.

10. Audits

Processor will make available information reasonably necessary to demonstrate compliance with this DPA. Controller may audit Processor's compliance no more than once per year on 30 days' notice, during business hours, without disrupting operations, and subject to confidentiality. If an audit requires third-party costs beyond Processor's standard documentation, Controller bears those costs.

11. Liability

Liability arising from or related to this DPA is subject to the limitation of liability, disclaimer, and indemnification provisions in the Terms of Service. Nothing in this DPA limits either party's liability where limitation is not permitted by Applicable Data Protection Law.

12. Order of precedence

If there is a conflict between this DPA and the Terms regarding processing of End User Personal Data, this DPA prevails. If there is a conflict between Controller's instructions and Applicable Data Protection Law, Processor may refuse or suspend the conflicting instruction and notify Controller.

13. Governing law

This DPA is governed by the laws of the Republic of Slovenia, without regard to conflict-of-law rules, except where mandatory data protection law requires otherwise.

14. Contact

Data protection inquiries: contact@bytestronauts.com. Processor: ByteStronauts, Slovenia.