KIDGE Data Processing Addendum (DPA)
Version 1.0 — Effective Date: September 10, 2026
This English version is provided for reference only. In the event of any inconsistency, the Traditional Chinese version prevails.
This Data Processing Addendum (the "Addendum") forms part of the KIDGE Terms of Service (the "Terms") between KIDGE Ltd. (格界科技有限公司; "the Company") and the Customer, and governs the Company's processing of personal data on the Customer's behalf. If this Addendum conflicts with the Terms, this Addendum prevails with respect to the processing of personal data. Terms not defined in this Addendum have the meanings given in the Terms.
1. Roles and Scope
1.1For personal data within Customer Content ("Customer Personal Data"), the Customer is the collector under the PDPA (or the controller under other applicable law), and the Company is the processor engaged by the Customer.
1.2For the Customer's account data, billing data, and usage records, the Company is the collector and processes them under the Privacy Policy; this Addendum does not apply.
1.3The subject matter, duration, nature, purpose, data categories, and data subject categories of processing are set out in Appendix A.
2. Processing Instructions
2.1The Company processes Customer Personal Data only on the Customer's documented instructions. The Terms, this Addendum, and the Customer's settings in the Service (including inviting External Participants, configuring permissions, and creating or deleting projects) constitute the Customer's instructions.
2.2If the Company considers that an instruction from the Customer violates applicable law, it may suspend execution of that instruction and notify the Customer.
2.3The Customer warrants that it has obtained, under applicable law, a lawful basis for collecting and processing Customer Personal Data and for engaging the Company to process it, including providing the required notices to Authorized Users and External Participants' personnel.
3. Confidentiality of Personnel
The Company ensures that personnel authorized to process Customer Personal Data are bound by confidentiality obligations and access Customer Personal Data only to the extent necessary to provide the Service, technical support, or security maintenance.
4. Security Measures
4.1The Company implements the technical and organizational measures listed in Appendix B and may update them provided the overall level of protection is not reduced.
4.2The Customer is responsible for the security settings it controls within the Service, including credential management, the permission settings of Authorized Users and External Participants, and the security awareness of its personnel.
5. Sub-processors
5.1The Customer generally authorizes the Company to engage the sub-processors listed in Appendix C to process Customer Personal Data.
5.2When the Company adds or replaces a sub-processor, it will update Appendix C and notify the Customer by email before the change takes effect.
5.3The Company requires its sub-processors, by written contract or commercial terms, to undertake data protection obligations no less stringent than those in this Addendum, and remains responsible to the Customer for the sub-processors' performance of those obligations as if for its own acts.
5.4Third-party services that the Customer connects itself under the Terms (including its own AI model providers) are not sub-processors of the Company.
6. Assistance to the Customer
6.1If a data subject exercises rights under Article 3 of the PDPA directly with the Company, the Company will forward the request to the Customer within a reasonable period and assist in responding in accordance with the Customer's instructions. Self-service features of the Service (such as correcting account data) form part of this assistance.
6.2Where the Customer requires information from the Company to conduct its security assessments, make statutory reports, or respond to regulatory requests, the Company will assist to the extent appropriate to the nature of the processing and the information available to it. The Company may charge a reasonable fee for assistance beyond the ordinary scope.
7. Personal Data Incident Notification
7.1Upon confirming a personal data incident affecting Customer Personal Data (including unauthorized access, disclosure, alteration, or loss), the Company will notify the Customer promptly and by appropriate means in accordance with Article 12 of the PDPA, without undue delay.
7.2The notification will include: the known nature of the incident, the categories of data and data subjects affected, the likely consequences, the measures taken or proposed, and the Company's contact point. Where information is incomplete, the Company will provide it in phases.
7.3The Company's notification does not constitute an admission of liability for the incident. Statutory notifications to data subjects or regulators are determined and carried out by the Customer under its applicable law; the Company provides necessary assistance.
8. Return and Deletion of Data
8.1After subscription termination, under Section 12.4 of the Terms: the Customer may request export of Customer Content during the thirty-day export period; within thirty days after the export period, the Company deletes Customer Content from production systems; residual data in backups is overwritten within a further sixty days at most.
8.2The minimum records required by law or necessary to evidence contract performance (hash values and timestamps of Confirmed Records, excluding content) are retained under Section 12.5 of the Terms.
8.3The Customer may request in writing that the Company confirm completion of deletion.
9. Audit and Information
9.1Upon the Customer's written request, the Company will provide information demonstrating compliance with this Addendum. The Company fulfills this obligation by providing Appendix B, Appendix C, and the publicly available security certification information of its sub-processors (for example, their trust center pages), without preparing additional documents.
9.2Audit rights are limited to Customers that have signed an Order Form with the Company, and their scope, method, frequency, and cost allocation are as set out in that Order Form and the Terms it references. For Customers without an Order Form, the Company's obligation is limited to the provision of information under Section 9.1.
9.3Information obtained by the Customer in the course of an audit is the Company's Confidential Information.
10. International Transfers
10.1Customer Personal Data is stored in the regions listed in Appendix C. The Customer acknowledges and agrees that Customer Personal Data may be processed in those regions.
10.2The Company ensures that international transfers comply with Article 21 of the PDPA and other applicable data protection laws. Where the law of the Customer's jurisdiction requires a specific transfer mechanism (such as standard contractual clauses), the Customer may submit a request, and the Company may, after evaluation, provide it by way of an Order Form or supplementary agreement.
11. Liability
The liability of both parties under this Addendum is subject to the exclusions and limitations in Section 14 of the Terms. This Addendum does not increase either party's aggregate liability.
12. Term and Survival
This Addendum takes effect when the Customer accepts the Terms and terminates when the Company completes deletion or return under Section 8. Sections 3, 8, 9.3, and 11 survive termination.
Appendix A: Processing Details
| Item | Details |
|---|---|
| Subject matter | Construction contract-performance data managed by the Customer through the Service |
| Duration | The Customer's subscription term and the export and deletion periods under Section 12.4 of the Terms |
| Nature and purpose | Storage, hosting, display, transmission, AI extraction, and backup, to provide contract-performance management and multi-party confirmation features |
| Data subject categories | The Customer's Authorized Users; personnel of External Participants (owners, supervising engineers, subcontractors, suppliers); other individuals referred to in Customer Content |
| Data categories | Name, email, organization, job title, account identifier; actions and confirmation records within the Service (time, confirming party); personal data contained in Customer Content |
| Special categories | The Service is not designed to process special categories of personal data under Article 6 of the PDPA (medical records, genetic data, sexual life, health examinations, criminal records, etc.); the Customer shall not upload such data |
Appendix B: Technical and Organizational Measures
- Encryption in transit: all data transmission uses TLS 1.2 or higher.
- Encryption at rest: databases and file storage use AES-256 encryption.
- Data isolation: database Row Level Security enforces logical isolation between Customers.
- Authentication: passwords are stored as hashes; sessions are encrypted.
- Access control: Company personnel access to Customer Personal Data follows the principle of least privilege, is limited to necessary personnel, and is logged.
- Record integrity: Confirmed Records are locked with a hash value and a snapshot of the content at the time of confirmation is retained, recording confirmation time and confirming party.
- Backups: regular encrypted backups, with retention periods per the infrastructure provider's settings.
- Monitoring: monitoring and alerting for system errors and anomalous access.
- Incident handling: per the notification procedure in Section 7.
- Vendor management: principal sub-processors hold third-party certifications such as SOC 2 or ISO 27001; preference is given to providers with equivalent certifications when adding sub-processors.
Appendix C: Sub-processor List
| Provider | Purpose | Data Location |
|---|---|---|
| Supabase (on AWS infrastructure) | Database, file storage, authentication | Tokyo, Japan (ap-northeast-1) |
| Vercel | Application deployment and content delivery | Global edge network |
| Paddle.com Market Ltd. | Payment, billing, and tax processing (Merchant of Record) | United Kingdom, United States, and Ireland |
| Anthropic, PBC | Model inference for AI extraction features (Claude API); does not use Service data for training under its commercial terms | United States |
| Resend | System notifications and transactional email | United States |
This list may be updated under Section 5.2.