Juridisch
Data Processing Agreement
Vraag een PDF aan? Mail privacy@karet.money.
Karet — Data Processing Agreement (Standard)
Draft — review pending. This document is the working draft of the Karet Data Processing Agreement. The legally-binding version is the counsel-reviewed text that supersedes this draft before launch. Until the launch gate is satisfied, this file is informational only.
Effective date: TBD · Version: 0.1-draft
This Data Processing Agreement ("DPA") supplements the Karet Terms of Service and forms part of the contract between Karet Finance B.V. i.o. ("Processor") and the Customer ("Controller") when the Controller's use of Karet involves the processing of personal data on the Controller's behalf.
1. Subject and duration
The Processor processes personal data for the Controller for the sole purpose of providing the Karet service as documented at karet.money. This DPA remains in effect for as long as the Processor processes personal data on the Controller's behalf.
2. Nature and purpose of processing
The Processor processes:
- Bank account metadata + transactions (from PSD2 / Salt Edge).
- Brokerage account positions + activity (from Saxo, IBKR, Bitvavo, SnapTrade).
- Journal entries + ledger data the Controller authors.
- AI-generated commentary, Cards, and chat history.
- Documents the Controller uploads (receipts, statements, voice memos).
- Account data of the natural persons accessing the Karet workspace.
Solely for the purposes of:
- Providing the Karet service.
- Sending transactional and (consent-gated) digest email.
- Producing AI-generated insights, with no model training.
- Operating security telemetry (logs, anomaly detection).
3. Categories of data subjects
- The natural-person workspace members (Controller's employees, family members, advisors).
- The natural-person counterparties referenced in transactions (only to the extent contained in bank statements / broker activity the Controller imports).
4. Sub-processors
The Processor uses the sub-processors listed at
docs/security/sub-processors.md
and on the public page /legal/sub-processors. Adding a new
sub-processor requires a PR that updates that file and gives the
Customer 30 days' notice before the new sub-processor is
activated. The Customer may terminate the contract during the notice
period if it does not consent to the new sub-processor.
5. Security
The Processor implements the technical and organisational measures listed in ADR-0011 (Security & Data Protection Baseline), including:
- EU data residency (Postgres, blob storage, LLM endpoints, email).
- KMS-backed envelope encryption for secrets.
- Two-tier audit (workspace
audit_events+ account-scopedsecurity_events). - Per-table retention enforced by cron.
- Step-up authentication for sensitive actions.
- TOTP / passkey enrolment, breach-password check on sign-up.
A current summary is published at /trust (PRD-0037).
6. Data subject rights
The Processor will assist the Controller in responding to data subject requests (access, rectification, erasure, restriction, portability, objection) within the deadlines set by GDPR Art. 12.
Self-service surfaces (Settings → Privacy & Data) cover most requests; the Controller can escalate to privacy@karet.money for anything not covered.
7. Breach notification
The Processor will notify the Controller without undue delay (no later than 48 hours) after becoming aware of a personal data breach affecting the Controller's data. Notice includes the nature of the breach, categories and approximate number of data subjects, and the measures taken.
8. International transfers
The Processor does not transfer personal data outside the EEA.
Sub-processors based outside the EEA are listed in
docs/security/sub-processors.md
with the applicable transfer mechanism (e.g. EU Standard Contractual
Clauses 2021/914) where relevant.
9. Return / deletion
On termination of the contract, the Processor will, at the Controller's choice:
- Return the personal data within 30 days via the standard DSR export ZIP, or
- Delete the personal data within 30 days (the default).
The 30-day window matches the DSR grace window described in /legal/privacy §7.
10. Audits
The Controller (or its independent auditor) may, no more than once per 12 months and with at least 30 days' written notice, audit the Processor's compliance with this DPA. The Processor will reasonably cooperate.
Appendix A — Sub-processors
See docs/security/sub-processors.md.
Appendix B — TOMs (Technical & Organisational Measures)
See ADR-0011 (Security & Data Protection Baseline) and the surfaces documented at /trust.