KaiRise Data Processing Addendum (DPA)

Effective Date: August 8, 2026  ·  Last Updated: August 8, 2026

1. Purpose

This Data Processing Addendum ("DPA") forms part of the agreement between KaiRise, LLC ("KaiRise," "Processor," "we," "our") and the customer organization ("Customer," "Controller") governing KaiRise's processing of Personal Data on behalf of the Customer.

This DPA supplements the KaiRise Terms of Service, Privacy Statement, applicable Order Forms, Subscription Agreements, or other written agreements.

If there is a conflict between this DPA and another agreement regarding Personal Data processing, this DPA controls with respect to those processing activities.

2. Definitions

Unless otherwise defined in the governing agreement:

Controller means the entity determining the purposes and means of processing Personal Data.

Processor means KaiRise acting on behalf of the Controller.

Personal Data means information relating to an identified or identifiable individual as defined by applicable privacy law.

Processing includes collection, storage, organization, retrieval, transmission, analysis, deletion, and other operations performed on Personal Data.

Subprocessor means a third party engaged by KaiRise to process Personal Data in support of the Services.

3. Scope

This DPA applies whenever KaiRise processes Personal Data on behalf of an Enterprise Customer in connection with:

  • AskMe™
  • KaiRise online learning
  • Instructor-led learning support
  • Learning management integrations
  • Enterprise reporting
  • AI-assisted coaching
  • Assessments
  • Certifications
  • Related professional services

4. Roles of the Parties

For Personal Data covered by this DPA:

  • Customer acts as the Controller.
  • KaiRise acts as the Processor.

KaiRise processes Personal Data only on documented instructions from the Customer, as necessary to provide the Services, or as otherwise required by applicable law.

5. Nature of Processing

Processing activities may include account administration, authentication, learner enrollment, course delivery, AI coaching, assessment processing, learner progress reporting, instructor analytics, certification management, customer support, security monitoring, and system administration.

6. Categories of Personal Data

Depending upon the Services used, Personal Data may include names, email addresses, organization identifiers, learner identifiers, job titles, course enrollment information, assessment responses, AI conversation history, uploaded documents, completion records, certifications, technical logs, and usage information.

KaiRise does not require Customers to upload special categories of personal data unless expressly agreed in writing. Customers should avoid submitting sensitive personal information unless necessary for the intended educational purpose.

7. Categories of Data Subjects

Data subjects may include employees, contractors, students, instructors, facilitators, administrators, customers, and prospective learners.

8. Customer Responsibilities

Customer is responsible for:

  • Ensuring an appropriate legal basis for processing
  • Providing required privacy notices
  • Obtaining required consents where applicable
  • Ensuring uploaded content is authorized
  • Responding to data subject requests unless otherwise agreed

9. KaiRise Responsibilities

KaiRise agrees to:

  • Process Personal Data only as authorized
  • Implement reasonable technical and organizational safeguards
  • Limit access to authorized personnel
  • Maintain confidentiality obligations
  • Assist Customer where reasonably appropriate in responding to privacy requests
  • Notify Customer of confirmed Personal Data breaches as required by law or contract

10. Confidentiality

KaiRise personnel with access to Personal Data are subject to appropriate confidentiality obligations. Access is limited to personnel with a legitimate business need.

11. Security Measures

KaiRise maintains administrative, technical, and organizational safeguards designed to protect Personal Data, including:

  • Encryption in transit
  • Authentication controls
  • Access management
  • Logical separation of customer environments
  • Operational monitoring
  • Backup procedures
  • Vulnerability management

Additional information is available in the KaiRise Security & Trust Center documentation.

12. AI Processing

AskMe uses artificial intelligence to generate coaching, assessments, summaries, and instructional responses. AI processing is performed solely for providing the contracted Services.

Customer-uploaded knowledge is processed only for that Customer's learning environment unless otherwise agreed in writing. KaiRise does not intentionally use one customer's proprietary content to generate responses for another customer.

13. Subprocessors

Customer authorizes KaiRise to engage Subprocessors necessary to provide the Services. KaiRise shall:

  • Maintain a list of Subprocessors
  • Require appropriate contractual safeguards
  • Remain responsible for the performance of its Subprocessors as required by applicable law

Current Subprocessors are listed in the KaiRise Subprocessor List.

14. International Transfers

KaiRise and its Subprocessors may process Personal Data in countries other than the Customer's jurisdiction. Where required, KaiRise will implement appropriate safeguards for international data transfers, including contractual protections recognized under applicable privacy laws.

15. Data Subject Requests

If KaiRise receives a request directly from a data subject regarding Personal Data processed on behalf of a Customer, KaiRise will, where legally permitted, notify the Customer or direct the individual to the Customer. KaiRise will reasonably assist Customers in responding to valid requests where appropriate.

16. Security Incidents

If KaiRise becomes aware of a confirmed Personal Data breach affecting Customer data, KaiRise will notify Customer without undue delay after confirming the incident. Notifications will include available information reasonably necessary for Customer to understand the nature of the incident and fulfill applicable legal obligations.

17. Retention and Deletion

Upon termination of the applicable Services, KaiRise will retain or delete Personal Data in accordance with Customer instructions, contractual obligations, legal requirements, and backup and disaster recovery practices. Certain information may be retained where required by law or reasonably necessary to protect legal rights.

18. Audits

Upon reasonable written request and subject to appropriate confidentiality protections, KaiRise may provide documentation reasonably necessary to demonstrate compliance with this DPA. To protect the security of all customers, KaiRise may satisfy audit requests through documentation, questionnaires, certifications, or other reasonable means rather than permitting unrestricted on-site inspections.

19. Regulatory Assistance

Upon reasonable request, KaiRise will provide commercially reasonable assistance to Customer regarding privacy impact assessments, regulatory inquiries, security questionnaires, and compliance documentation, to the extent such assistance relates to the Services provided. Additional assistance beyond standard support may be subject to professional services fees.

20. Changes to This DPA

KaiRise may update this DPA from time to time to reflect changes in law, technology, or our Services. Material changes will not reduce Customer protections without appropriate notice.

Contact

KaiRise Privacy & Compliance
Email: privacy@kairise.com
General inquiries: info@kairise.com

© 2026 KaiRise, LLC. All rights reserved.