Data Processing Agreement
How Kasura processes personal data on behalf of rental operators when they use the platform.
Introduction
#This Data Processing Agreement ("DPA") forms part of the agreement between Kasura LLC ("Kasura", "we", "us") and the business entity that registers for and uses the Kasura platform ("Operator", "you"). It applies when Kasura processes personal data on your behalf in connection with your use of the Service, as described in our Terms of Service and Privacy Policy.
This DPA is intended to reflect the roles and obligations commonly expected under applicable data protection laws, including the EU General Data Protection Regulation ("GDPR") where it applies. It does not constitute legal advice, and you remain responsible for determining your own compliance obligations as a business.
Roles of the parties
#For personal data processed through the Service, the roles are generally as follows:
- Operator as controller. You determine why and how personal data relating to your rental business is processed — including data about your staff, your end customers (renters or bookers), bookings, payments you collect, and documents you upload. You are responsible for having a lawful basis, providing required notices to data subjects, and responding to their requests where you are the controller.
- Kasura as processor. When we store, transmit, display, or otherwise handle personal data solely on your instructions and for the purpose of providing the Service, we act as a processor (or service provider) on your behalf.
- Kasura as independent controller. For certain processing — such as billing your subscription, securing and operating the platform, preventing abuse, and complying with law — Kasura acts as an independent controller. That processing is described in our Privacy Policy and is outside the scope of this DPA.
- End customer relationship. Your end customers interact with your public booking pages and customer portal under your brand. Their contractual relationship for the rental is with you, not with Kasura.
Scope of processing
#Subject to your subscription plan and configuration, Kasura may process the following categories of personal data on your behalf:
- Identity and contact details for your team members and invited users
- End customer identity, contact, and profile information you collect or they submit
- Booking, rental, and operational records (dates, assets, locations, notes, status)
- Payment-related metadata processed through integrated payment providers (not full card numbers stored by Kasura)
- Documents, images, and messages you or your end customers upload or generate in the Service
- Technical logs necessary to deliver, secure, and support your workspace
Processing activities include hosting, backup, synchronization, display in dashboards and portals, email or notification delivery you configure, search and reporting within your workspace, and support assistance at your request. We do not sell personal data processed on your behalf.
Duration of processing
#Kasura processes personal data on your behalf for the duration of your active subscription and for any additional period reasonably necessary to complete deletion, return of data, backup rotation, legal obligations, dispute resolution, fraud prevention, or security requirements as described in this DPA.
Instructions
#Kasura will process personal data only on documented instructions from you, except where required by applicable law. Your instructions are reflected in:
- Your use of the Service and workspace settings
- The Terms of Service and this DPA
- Written requests to support@kasura.app or legal@kasura.app for specific processing actions
If we believe an instruction infringes applicable data protection law, we will inform you promptly. You are responsible for ensuring that your instructions — including forms, public booking flows, and communications sent through Kasura — comply with law and your privacy obligations toward end customers.
Operators are responsible for ensuring they have the necessary rights, permissions, and lawful basis to provide personal data to Kasura for processing under this DPA.
Assistance
#Taking into account the nature of the processing and the information available to us, Kasura will provide reasonable assistance to help Operators comply with applicable data protection obligations where required by law. This may include assistance relating to data subject requests, security incidents, data protection impact assessments (where applicable), and reasonable requests from supervisory authorities concerning processing carried out on the Operator's behalf.
Confidentiality
#Kasura ensures that personnel authorized to process personal data on your behalf are bound by confidentiality obligations appropriate to the nature of the Service. Access is limited to those who need it to operate, maintain, secure, or support the platform, or to comply with law.
We treat personal data processed under this DPA as confidential business information. We do not disclose it to third parties except as permitted by this DPA, the Terms, our Privacy Policy, or applicable law.
Confidentiality obligations continue after employment, contractual relationships, or access rights have ended.
Security measures
#Kasura implements technical and organizational measures designed to protect personal data against unauthorized access, loss, or alteration. These measures are described on our Security page, including access controls, encryption in transit, infrastructure practices, and monitoring.
Kasura personnel access personal data only where reasonably necessary to operate, maintain, secure, support, or improve the Services, investigate security incidents, or comply with applicable legal obligations.
Security is a shared responsibility. You are responsible for safeguarding your account credentials, configuring appropriate team access, and using strong authentication practices. You should only grant workspace access to individuals who need it.
Kasura periodically reviews and updates its technical and organizational measures as the platform evolves, taking into account operational requirements, security risks, and changes to the Services.
No certification claims
Subprocessors
#You authorize Kasura to engage subprocessors — third-party service providers that process personal data on our behalf — to deliver the Service. Current subprocessors, their roles, and regions are listed on our Subprocessors page.
We impose contractual or equivalent obligations on subprocessors requiring appropriate technical and organizational measures to protect personal data and comply with applicable data protection obligations. We remain responsible to you for subprocessors' performance of their data protection obligations, subject to the limitations in the Terms.
We will update the Subprocessors page when we add or replace subprocessors that handle personal data for the Service. If you have a material objection to a new subprocessor, contact legal@kasura.app within thirty (30) days of the update. We will work with you in good faith; if we cannot resolve the objection, you may terminate the affected Service in accordance with the Terms.
International transfers
#Kasura and our subprocessors may process and store personal data in the United States and other countries where we or they operate. Data protection laws in those countries may differ from those in your jurisdiction.
Where required for transfers from the European Economic Area, United Kingdom, or Switzerland, Kasura relies on appropriate safeguards such as the European Commission's Standard Contractual Clauses (and UK or Swiss addenda where applicable), or other mechanisms recognized by applicable law. Details of subprocessors and regions are on the Subprocessors page.
You may request additional information about transfer mechanisms by contacting legal@kasura.app.
Personal data breaches
#If Kasura becomes aware of a personal data breach affecting personal data we process on your behalf, we will notify you without undue delay after confirming the breach, to the extent permitted by law. Our notification will include information we reasonably have available to help you meet your obligations toward supervisory authorities and data subjects.
You are responsible for assessing whether a breach must be reported to authorities or data subjects under applicable law, and for making those notifications. Report suspected security incidents involving your workspace to security@kasura.app promptly.
Data subject requests
#Where data subjects (including your end customers or team members) exercise rights under applicable data protection law — such as access, correction, deletion, restriction, or portability — requests directed to you as controller should be handled by you.
Kasura will provide reasonable assistance through the Service features (for example, export, correction, or deletion tools in your workspace) and, where necessary, through support, so you can respond to such requests. If a request is sent directly to Kasura and clearly relates to data we process on your behalf, we will forward it to you or advise the individual to contact you, unless we are required by law to respond directly.
For requests about data for which Kasura is an independent controller (such as your Kasura account billing data), see our Privacy Policy.
Deletion and return of data
#During your subscription, you can access and export much of your workspace data through the Service. Upon termination or expiry of your subscription, Kasura will delete or return personal data processed on your behalf within a reasonable period, unless applicable law requires continued retention, subject to:
- Backup retention cycles (deleted data may persist in encrypted backups for a limited time before being overwritten)
- Legal obligations to retain certain records
- Data aggregated or anonymized such that it no longer identifies individuals
- Data you have exported or migrated before termination
You may request deletion assistance before or after termination by contacting support@kasura.app. Available export functionality may depend on your subscription plan and the features available at the time of export. Deletion of your workspace is generally irreversible.
Audit rights
#Kasura will make available information reasonably necessary to demonstrate compliance with this DPA, including the Security page and Subprocessors list. Upon written request, we will respond to reasonable questionnaires about our processing practices related to your workspace.
If you require an audit beyond published documentation, you must give at least thirty (30) days' notice, conduct it no more than once per twelve (12) months (unless required by law or following a confirmed breach), and accept confidentiality and security restrictions. Onsite audits may be replaced by third-party reports or additional documentation where available. You bear your own costs unless applicable law requires otherwise.
Audits must be conducted in a manner that does not unreasonably interfere with Kasura's operations or compromise the security, confidentiality, or availability of the Services or other customers' data.
Contact and order of precedence
#For questions about this DPA, data processing, or subprocessors:
- Legal and DPA inquiries: legal@kasura.app
- Privacy and data subject matters: legal@kasura.app
- Security incidents: security@kasura.app
- General support: support@kasura.app
- Questions regarding international data transfers: legal@kasura.app
If there is a conflict between this DPA and the Terms regarding processing of personal data on your behalf, this DPA prevails. If there is a conflict between this DPA and the Privacy Policy, this DPA prevails for processor activities; the Privacy Policy governs where Kasura acts as an independent controller, except where mandatory applicable law requires otherwise.
Related documents: Privacy Policy, Security, Subprocessors, Terms of Service.
Need help?
Questions about this page?
We're happy to help with anything legal, security or privacy related. Reach out and a human will get back to you.