Data Processing Agreement
Draft. This text is under legal review. The effective date will appear here once it is published.
This Data Processing Agreement (the "DPA") forms part of the Terms of Service between RELAYT STUDIO LLC («RELAYT STUDIO» MAS'ULIYATI CHEKLANGAN JAMIYAT), which runs the Kweko service ("Kweko", the "Processor"), and the Customer (the "Controller"). It is accepted together with the Terms. It applies to personal data contained in Customer Data that Kweko processes on the Customer's behalf. Terms defined in the Terms of Service have the same meaning here.
1. Roles
1.1. The Customer is the owner and operator of the personal data bases it keeps in Kweko, within the meaning of the Law of the Republic of Uzbekistan No. ZRU-547 of 2 July 2019 "On Personal Data" (the "Personal Data Law"). Kweko acts as a third party processing personal data on the Customer's behalf and on its instructions.
1.2. The Customer is responsible for the lawfulness of the collection of personal data, for obtaining its data subjects' consent where the law requires it, for informing them about the processing, for registering its personal data bases where required and for the instructions it gives to Kweko.
2. Subject and details of processing
| Subject matter | Provision of the Kweko CRM service under the Terms |
|---|---|
| Duration | The term of the Terms, plus the deletion periods in section 10 |
| Nature and purpose | Storing, organising, displaying, searching, transmitting (through Integrations the Customer enables), analysing (reports, Kweko Score) and, if the Customer turns it on, AI processing of Customer Data, only to provide the Service to the Customer |
| Data subjects | The Customer's clients and prospects, their contact persons, and the Customer's members |
| Categories of data | Names, phone numbers, email addresses, messenger identifiers and usernames, messages and attachments, call records and recordings where the Customer enables them, deal and invoice details, notes, tasks, custom fields the Customer creates |
| Special categories | Not intended. The Customer must not store special categories of personal data in Kweko unless the law allows it and the Customer has taken the required measures |
3. Instructions
3.1. Kweko processes personal data only on the Customer's documented instructions. The Terms, this DPA, the Customer's configuration of its workspace (for example, the channels, Integrations, automations and AI features it turns on) and the actions of its members are the Customer's complete instructions.
3.2. If Kweko is required by law to process personal data otherwise, it tells the Customer before processing unless the law forbids it. Kweko tells the Customer if it believes an instruction breaks the law.
4. Confidentiality and staff
4.1. Kweko ensures that its staff with access to Customer Data are bound by confidentiality obligations and are trained in handling personal data.
4.2. Access by Kweko staff to a workspace is limited to what is needed to provide support, keep the Service secure and meet legal obligations.
5. Support access
5.1. Kweko staff can view a Customer's workspace only through support access, which works as follows:
- a staff member must record a reason before access is granted;
- access is a one-time link valid for 5 to 60 minutes;
- the staff member sees the workspace as a member with the Viewer role would: client phone numbers and email addresses are masked, and nothing can be created, changed or deleted;
- the start and the end of every session appear in the workspace's audit log, visible to Owners and admins;
- Owners can turn support access off at any time in the workspace settings; while it is off, staff cannot open the workspace this way.
5.2. Staff use support access only to answer the Customer's request, to investigate a fault or abuse affecting the workspace, or where the law requires it.
6. Security measures
Kweko implements and maintains at least the following measures, and may improve them over time without reducing the overall level of protection:
- Tenant isolation: every workspace's data is separated in the database by row-level security; the application connects with a database role that cannot bypass it, and an automated test suite checks every endpoint for cross-workspace access.
- Encryption: all traffic uses HTTPS with HSTS; credentials for Integrations (channel tokens, payment and telephony keys) are encrypted at rest with a server key.
- Access control: personal accounts; passwords hashed with Argon2id; sign-in codes by email; limits on sign-in attempts; roles and permissions; masking of client contacts for the Viewer role; scoped and expiring API keys with an optional IP allowlist.
- Audit: security and administration events (members, roles, API keys, Integrations, exports, settings, deletion, support access) are recorded in the workspace audit log.
- Availability: nightly database backups, each verified to be readable before it is kept, kept for 14 days; monitoring and alerting on errors and performance.
- Development: changes are tested automatically, including tenant isolation and abuse tests, before release.
7. Location of data and transfers abroad
7.1. Kweko stores Customer Data on the servers of its hosting provider listed in section 8. Kweko tells the Customer in advance, as set out in section 8.4, before it moves Customer Data to another location.
7.2. Kweko transfers personal data from Customer Data abroad only:
- to the AI provider listed in section 8, and only if the Customer has turned Kweko AI on (section 9);
- to Integrations located abroad that the Customer itself connects and instructs Kweko to use (for example, sending a message through Telegram, Instagram or WhatsApp); such transfers are made on the Customer's instructions and the Customer is responsible for their legal ground.
8. Sub-processors
8.1. The Customer authorises Kweko to use the following sub-processors:
| Sub-processor | Purpose | Location |
|---|---|---|
| [HOSTING PROVIDER] | Hosting of servers, databases and backups | [DATA CENTRE LOCATION] |
| Resend (Resend, Inc.) | Delivery of emails sent by the Service (sign-in codes, invitations and notifications) | [RESEND DATA REGION] |
| Anthropic, PBC | Kweko AI features, only when turned on by the Customer | United States of America |
8.2. The following services are used by the Customer as its own providers when it connects them, under its own agreements with them. Kweko transmits data to them only on the Customer's instruction:
| Service | When data is sent | Location |
|---|---|---|
| Eskiz, Playmobile | The Customer sends SMS from Kweko | Republic of Uzbekistan |
| Payme, Click | The Customer creates payment links and invoices for its clients | Republic of Uzbekistan |
| Telegram, Meta (Instagram, WhatsApp) | The Customer connects these channels | Outside Uzbekistan |
| Telephony providers (OnlinePBX, Sipuni, Zadarma, the Customer's own Asterisk) | The Customer connects telephony | Depends on the provider |
| 1C, MoySklad, Didox, Odoo, Google Calendar and apps from the Kweko marketplace | The Customer connects them | Depends on the provider |
8.3. Kweko imposes on each sub-processor data protection obligations no less protective than this DPA and remains responsible for their performance.
8.4. Kweko informs the Customer's Owners by email at least 30 days before adding or replacing a sub-processor. The Customer may object on reasonable data protection grounds within that period. If the parties cannot resolve the objection, the Customer may terminate the affected service and receive a pro rata refund of prepaid fees for the remaining period.
9. Kweko AI
9.1. Kweko AI features (summaries, reply drafts, translation) are off by default in every workspace.
9.2. They are enabled only when a workspace admin accepts the consent text in Settings → Kweko AI. The consent records the text version, the admin and the time. An admin can withdraw consent or turn off individual AI features at any time; processing stops for new requests immediately.
9.3. When AI is used, only the text needed for the requested action is sent to the AI provider, and phone numbers, email addresses and card-like numbers are masked before it leaves Kweko. Every AI request is logged in the workspace.
9.4. Kweko does not use Customer Data to train AI models and does not allow its AI provider to do so under its agreement with that provider.
10. Deletion and return of data
10.1. The Customer can export Customer Data at any time (CSV or XLSX, and the API).
10.2. When an Owner deletes a workspace, deletion is scheduled 7 days ahead. During these 7 days only Owners can open the workspace, export data or cancel the deletion. After 7 days all records of the workspace are permanently removed from the live database. Backup copies are removed as backups rotate, within 14 days.
10.3. When a member deletes their account, the account is anonymised immediately; records they created in the workspace stay with the Customer, attributed to "Deleted user".
10.4. Individual records (for example, a contact whose data subject asked for erasure) can be deleted by the Customer's members with the right permissions at any time.
11. Assistance
11.1. Kweko helps the Customer, taking into account the nature of the processing, to answer data subjects' requests (access, correction, blocking, destruction, withdrawal of consent) mainly through the product's features: search, edit, export and delete. If Kweko receives a request directly from a data subject about Customer Data, it forwards the request to the Customer and does not answer it itself unless the Customer instructs it.
11.2. Kweko gives the Customer the information reasonably needed to demonstrate compliance with the Personal Data Law and cooperates with the authorised state body where the law requires it.
12. Personal data breaches
12.1. Kweko notifies the Customer's Owners without undue delay, and in any case within 72 hours after becoming aware of a breach affecting Customer Data.
12.2. The notice describes, as far as known: what happened, the categories and approximate number of data subjects and records concerned, the likely consequences, the measures taken or proposed, and a contact person. Information not available at once is provided as it becomes available.
12.3. Kweko takes immediate steps to contain the breach and helps the Customer meet its own obligations to notify the authorised state body and data subjects.
13. Audits
Kweko makes available, on request and no more than once a year, a written description of its security measures and answers the Customer's reasonable questions. On-site audits are possible for Enterprise customers under a separate agreement at the Customer's cost, with reasonable notice and confidentiality obligations.
14. Liability and order of precedence
The liability provisions of the Terms apply to this DPA. On matters of personal data processing this DPA prevails over the Terms.
15. Contact
Processor: RELAYT STUDIO LLC, Toshkent shahri, Yashnobod tumani, Yashnobod MFY, 4-Aviasozlar mavzesi, 13, 8/1-uy, STIR 313338686.
Personal data requests and breach contact: [email protected] · +998 50 800 84 47