Last updated September 15, 2026.
Beta notice. This is the data processing addendum we intend to offer. During the beta it is provided as-is, and it has not yet been reviewed by counsel.
This DPA forms part of the Terms of Service between the customer ("Customer," "Controller," or "you") and Ape on a Bike Industries LLC (operating as "Kijito") ("Kijito," "Processor," or "we"). It applies where Kijito processes personal data on Customer's behalf and where data protection law (GDPR, UK GDPR, and similar) applies. In case of conflict on data protection matters, this DPA controls over the Terms.
Kijito will:
Customer authorizes Kijito to engage the subprocessors below. Kijito will impose data protection obligations on each subprocessor that are no less protective than this DPA (flow-down), and remains liable for their performance. Kijito will give at least thirty (30) days' prior notice of the addition or replacement of a subprocessor (by email to the account address and/or by updating a subprocessor list on our website, to which Customer may subscribe). Customer may object on reasonable, documented data-protection grounds within that notice period. The parties will work in good faith to resolve the objection; if it cannot be resolved, Customer's sole and exclusive remedy is to terminate the affected portion of the Service and stop submitting the affected data. Absent a timely objection, the change is deemed approved.
| Subprocessor | Purpose | Location | Data exposed |
|---|---|---|---|
| DigitalOcean | Compute + Managed PostgreSQL 18 (control-plane) | US (SFO3 / San Francisco) | Encrypted memory blobs at rest; account/consent/billing metadata |
| Cloudflare | DNS, CDN/TLS | Global edge | Traffic metadata, IPs |
| Mailgun | Transactional email | US | Email address + message content |
| Sentry | Error monitoring | US | Error traces (configured to scrub request data; a CI guard fails the build if memory content could reach error telemetry) |
| Stripe | Billing (when live) | US/global | Email, billing details (card data held by Stripe) |
Anthropic is not a subprocessor of memory content.
Kijito implements, at minimum:
Note on operator visibility: the hosted tier is encrypted at rest, not operator-blind - content is transiently decrypted in RAM to serve requests. Operator-blind processing requires the decryption to run off our servers - via Enterprise on-premises self-hosting or a local helper you run, both on our roadmap and not yet available.
Where Kijito transfers EU/UK personal data to the US, the parties rely on:
The SCCs (Module 2 primary, Module 3 for subprocessors) and the UK IDTA are incorporated by reference. Annex I (parties and description of processing), Annex II (technical & organizational measures - as described in Section 5), and Annex III (subprocessors - as listed in Section 4) are populated from this DPA. A Swiss addendum (applying the SCCs with the Swiss FADP amendments and the Swiss Federal Data Protection and Information Commissioner as the competent authority) applies where Customer is subject to Swiss data-protection law. An EU/UK Article 27 representative has not yet been appointed.
Kijito will, taking into account the nature of processing, assist the Controller by appropriate technical and organizational measures to respond to data-subject requests, including the self-serve export, deletion, and rectification mechanisms in the Service, and consent-withdrawal handling. If Kijito receives a request directly from a data subject, it will refer them to the Controller where appropriate.
Kijito will notify the Controller without undue delay after becoming aware of a personal data breach affecting the Controller's data, providing the information reasonably available to enable the Controller to meet its own notification obligations.
On termination or expiry, and at the Controller's choice, Kijito will delete or return the personal data and delete existing copies, except where storage is required by law, subject to the grace/backup retention windows in the Privacy Policy (after which residual copies are purged), and except for abuse and safety reports. Abuse reports survive account deletion and are retained after termination - including the reporting user id, the subject and target of the report, and the free-text details submitted with it - as a record of a trust-and-safety decision, so that deletion and re-registration cannot clear it. Kijito processes those records as controller for its own platform-integrity and legal-compliance purposes, on the basis of its legitimate interest in operating a safe service; they are not processed on the Controller's behalf and are not returned on termination. Return is effected by Customer's use of the self-serve export (GET /api/export), which returns Customer's data in a machine-readable format (JSON) and is available throughout the term and during the 30-day post-termination grace window. After the grace window, Kijito deletes the data (subject to the backup-retention schedule in the Privacy Policy), and no further return obligation applies. Kijito is not obligated to provide data in any bespoke or alternative format.
Liability under this DPA is subject to the limitations in the Terms. This DPA controls over the Terms with respect to data protection matters; the SCCs/IDTA control over this DPA with respect to their subject matter.
This DPA is incorporated by reference into, and forms part of, the Terms of Service, and is accepted electronically (click-accept) when Customer accepts the Terms or uses the Service - no separate signature is required. A Customer that requires a signed counterpart may request one at [email protected]. The Annexes referenced in Section 6 are populated from Sections 2, 4, and 5 of this DPA.