Data processing addendum
Data processing addendum.
Last updated July 2, 2026.
This DPA forms part of the Terms of Service between the customer ("Customer," "Controller," or "you") and Ape on a Bike Industries LLC (operating as "Kijito") ("Kijito," "Processor," or "we"). It applies where Kijito processes personal data on Customer's behalf and where data protection law (GDPR, UK GDPR, and similar) applies. In case of conflict on data protection matters, this DPA controls over the Terms.
1. Roles
- For end-user account data and memory content that Customer's users submit, Customer (or its end users) is the Controller and Kijito is the Processor, processing only on documented instructions (this DPA + the Terms + use of the Service).
- For Kijito's own operational data (e.g., billing relationship, security telemetry where Kijito determines purposes), Kijito acts as an independent Controller under its Privacy Policy.
- No joint controllership. No processing under this DPA is intended to constitute joint controllership. For Customer's users' account data and memory content, Customer (or its end users) is the sole Controller and Kijito acts solely as Processor; for Kijito's own operational data, Kijito acts as an independent Controller. The parties do not jointly determine the purposes and means of any processing.
2. Scope, nature & purpose of processing
- Subject matter: provision of the Kijito persistent semantic-memory service.
- Nature & purpose: storing memory content (encrypted at rest), recalling it by meaning, forming a memory graph (edges/themes), authentication, and operating/securing the Service.
- Duration: for the term of the Customer's account, plus the retention/grace and backup windows stated in the Privacy Policy (grace window of 30 days).
- Categories of data subjects: Customer's authorized users/agents.
- Categories of personal data: account/identity (email; hashed password; hashed recovery codes); memory content and derived metadata; graph structure; consent log; security/operational data (IP, user-agent, audit/rate-limit data); billing metadata when paid plans are live. Prohibition on special-category data. Customer must not submit, and must not permit its users to submit, special-category personal data (GDPR Article 9) or other highly sensitive data (for example, government identifiers, financial-account data, or children's data) to the Service unless Customer has established its own lawful basis and has notified Kijito in writing. The Service is not designed or warranted for special-category data. Customer controls what memory content is submitted and remains solely responsible for the lawfulness of any data it chooses to submit. On the hosted Service, memory content is persisted as ciphertext at rest and is transiently decrypted in RAM only to answer an authenticated request or perform allowed processing; it is therefore encrypted at rest, not operator-blind. Kijito disclaims liability arising from Customer's submission of prohibited data.
3. Processor obligations
Kijito will:
- Process personal data only on the Controller's documented instructions, unless required by law (and will inform the Controller of such a requirement unless prohibited).
- Ensure persons authorized to process data are bound by confidentiality.
- Implement the technical and organizational measures in Section 5.
- Assist the Controller with data-subject requests and with its obligations under Articles 32-36 GDPR (security, breach, DPIA), taking into account the nature of processing and information available.
- Make available information necessary to demonstrate compliance and allow for/contribute to audits. Kijito will satisfy these audit obligations primarily by making available its then-current security documentation, policies, and any third-party audit reports or certifications (for example, SOC 2 when available) in response to a written request, no more than once in any twelve (12) month period, on at least thirty (30) days' prior written notice, subject to confidentiality. On-site or hands-on audits are permitted only where required by a supervisory authority or by mandatory law, must be conducted during business hours without disrupting operations, must not access other customers' data or compromise cross-tenant isolation or security, and are at the Controller's expense.
4. Subprocessors
Customer authorizes Kijito to engage the subprocessors below. Kijito will impose data protection obligations on each subprocessor that are no less protective than this DPA (flow-down), and remains liable for their performance. Kijito will give at least thirty (30) days' prior notice of the addition or replacement of a subprocessor (by email to the account address and/or by updating a subprocessor list on our website, to which Customer may subscribe). Customer may object on reasonable, documented data-protection grounds within that notice period. The parties will work in good faith to resolve the objection; if it cannot be resolved, Customer's sole and exclusive remedy is to terminate the affected portion of the Service and stop submitting the affected data. Absent a timely objection, the change is deemed approved.
| Subprocessor | Purpose | Location | Data exposed |
|---|
| DigitalOcean | Compute + Managed PostgreSQL 18 (control-plane) | US (SFO3 / San Francisco) | Encrypted memory blobs at rest; account/consent/billing metadata |
| Cloudflare | DNS, CDN/TLS, Turnstile bot-check | Global edge | Traffic metadata, IPs; Turnstile token |
| Mailgun | Transactional email | US | Email address + message content |
| Sentry | Error monitoring | US | Error traces (configured to scrub request data; a CI guard fails the build if memory content could reach error telemetry) |
| Stripe | Billing (when live) | US/global | Email, billing details (card data held by Stripe) |
Anthropic is not a subprocessor of memory content.
5. Security measures (Article 32)
Kijito implements, at minimum:
- Encryption at rest of memory content/embeddings/theme data under a per-user key derived from the user's password (scrypt KDF).
- No third-party content egress: memory content is never sent to any external LLM or embedding API; embeddings are computed locally (in-process ONNX model); consolidation is mechanical.
- Cross-tenant isolation enforced on every scoped query; per-user content keys.
- Encryption in transit (TLS, Cloudflare Full (strict) to origin).
- Credential protection: scrypt-hashed passwords with per-user salt; hashed recovery codes.
- Access controls & auth: JWT access/refresh with token-version revocation; OAuth for connectors.
- Abuse controls: Turnstile, per-IP/per-email rate limits, disposable-email blocking; audit logging.
- Backups - encrypted backups written daily, with point-in-time recovery on the Managed PostgreSQL control plane.
Note on operator visibility: the hosted tier is encrypted at rest, not operator-blind - content is transiently decrypted in RAM to serve requests. Operator-blind processing is available only via the local/self-host tiers.
6. International transfers
Where Kijito transfers EU/UK personal data to the US, the parties rely on:
- The EU Standard Contractual Clauses (SCCs) (Commission Decision 2021/914) - Module Two (Controller-to-Processor) for personal data Kijito processes on Customer's behalf, and Module Three (Processor-to-Processor) for onward transfers to subprocessors - incorporated by reference; and
- The UK International Data Transfer Addendum (UK IDTA) / UK Addendum to the SCCs, as applicable.
The SCCs (Module 2 primary, Module 3 for subprocessors) and the UK IDTA are incorporated by reference. Annex I (parties and description of processing), Annex II (technical & organizational measures - as described in Section 5), and Annex III (subprocessors - as listed in Section 4) are populated from this DPA. A Swiss addendum (applying the SCCs with the Swiss FADP amendments and the Swiss Federal Data Protection and Information Commissioner as the competent authority) applies where Customer is subject to Swiss data-protection law. An EU/UK Article 27 representative has not yet been appointed.
7. Data-subject requests
Kijito will, taking into account the nature of processing, assist the Controller by appropriate technical and organizational measures to respond to data-subject requests, including the self-serve export, deletion, and rectification mechanisms in the Service, and consent-withdrawal handling. If Kijito receives a request directly from a data subject, it will refer them to the Controller where appropriate.
8. Personal data breach
Kijito will notify the Controller without undue delay after becoming aware of a personal data breach affecting the Controller's data, providing the information reasonably available to enable the Controller to meet its own notification obligations.
9. Deletion & return on termination
On termination or expiry, and at the Controller's choice, Kijito will delete or return the personal data and delete existing copies, except where storage is required by law, and subject to the grace/backup retention windows in the Privacy Policy (after which residual copies are purged). Return is effected by Customer's use of the self-serve export (GET /api/export), which returns Customer's data in a machine-readable format (JSON) and is available throughout the term and during the 30-day post-termination grace window. After the grace window, Kijito deletes the data (subject to the backup-retention schedule in the Privacy Policy), and no further return obligation applies. Kijito is not obligated to provide data in any bespoke or alternative format.
10. Liability & order of precedence
Liability under this DPA is subject to the limitations in the Terms. This DPA controls over the Terms with respect to data protection matters; the SCCs/IDTA control over this DPA with respect to their subject matter.
11. Signatures / acceptance
This DPA is incorporated by reference into, and forms part of, the Terms of Service, and is accepted electronically (click-accept) when Customer accepts the Terms or uses the Service - no separate signature is required. A Customer that requires a signed counterpart may request one at [email protected]. The Annexes referenced in Section 6 are populated from Sections 2, 4, and 5 of this DPA.