1. Scope, Hierarchy & Regulatory Roles
1.1 Roles of the Parties: The parties acknowledge and agree that with respect to Customer Personal Data processed through the Service:
- Customer is the Data Controller (or “Data Fiduciary” under India DPDP Act 2023, “Business” under CCPA/CPRA). Customer determines the purposes and means of processing by setting keyword automation rules, Reel triggers, and destination resource links.
- KRYSKAFLOW is the Data Processor (or “Data Processor” under DPDP Act 2023, “Service Provider” under CCPA/CPRA). KRYSKAFLOW processes Customer Personal Data solely on behalf of Customer and strictly in accordance with Customer's documented instructions.
1.2 Order of Precedence: In the event of any conflict between the terms of this DPA and the Terms of Service, the provisions of this DPA shall prevail with respect to data protection obligations.
2. Applicable Data Protection Legislation
This DPA implements and satisfies the mandatory contractual requirements under:
- European Union: Regulation (EU) 2016/679 (General Data Protection Regulation — “EU GDPR”) and Directive 2002/58/EC (ePrivacy Directive).
- United Kingdom: The Data Protection Act 2018 and UK GDPR as incorporated into UK law (“UK GDPR”).
- United States: The California Consumer Privacy Act of 2018, as amended by the California Privacy Rights Act of 2020 (Cal. Civ. Code §§ 1798.100 et seq. — “CCPA/CPRA”), and comprehensive state privacy laws (Virginia VCDPA, Colorado CPA, Connecticut CTDPA, Texas TDPSA).
- India: The Digital Personal Data Protection Act, 2023 (“DPDP Act”) and the Information Technology Act, 2000.
- International: Canada PIPEDA, Australia Privacy Act 1988, and Brazil LGPD.
3. Details of Processing Operations
| Item | Specification |
|---|---|
| Subject Matter | Automated Comment-to-DM routing, trigger keyword analysis, link dispatch, and analytics reporting via the official Meta Instagram Graph API. |
| Duration | For the term of the Customer’s subscription plus statutory post-termination retention purges (ephemeral comments purged in 24 hours; logs in 30 days). |
| Nature & Purpose | Sub-1.2s delivery of customer-specified links or digital lead magnets to users who post public comments matching customer automation triggers. |
| Categories of Data | Instagram Scoped ID (IGSID/PSID), public comment timestamp, public comment text, keyword trigger match, automation execution status. Zero personal passwords, zero payment card numbers, zero private camera/photo data. |
| Data Subjects | Instagram users (followers and public commenters) who voluntarily engage with Customer's public Reels, posts, and Live streams. |
4. Processor Obligations & Compliance
- Processing Instructions: KRYSKAFLOW shall process Personal Data solely on documented instructions from Customer (including with respect to cross-border transfers), unless required to do so by applicable law to which KRYSKAFLOW is subject.
- Confidentiality: KRYSKAFLOW ensures that personnel authorized to process Customer Personal Data have committed themselves to confidentiality or are under an appropriate statutory obligation of confidentiality.
- Data Minimization: KRYSKAFLOW collects only the minimum data elements necessary to execute the automation triggered by the Data Subject.
- No Selling or Sharing: Under the CCPA/CPRA, KRYSKAFLOW certifies that it acts strictly as a “Service Provider” and shall not sell, retain, use, or disclose Customer Personal Data for any commercial purpose other than providing the Services specified in the Agreement.
- Assistance with Data Subject Rights (GDPR Art. 28(3)(e) & DPDP Act Sec. 6(4)): Taking into account the nature of the processing, KRYSKAFLOW assists Customer by implementing automated, self-serve capabilities directly in the Creator Dashboard (Profile Avatar > Account Settings & Data Rights) that enable Customer to export Customer Personal Data in structured machine-readable formats (JSON and CSV) and execute programmatic erasure upon withdrawal of consent.
5. Technical & Organisational Measures (TOMs)
KRYSKAFLOW implements state-of-the-art security safeguards to protect Customer Personal Data:
- Encryption in Transit: Mandatory TLS 1.3 encryption across all public web endpoints, Webhook listeners, and Meta Graph API calls.
- Encryption at Rest: AES-256 encryption across cloud database partitions, auth session stores, and encrypted token vaults.
- Access Control: Strict Principle of Least Privilege (PoLP) and role-based access control (RBAC). Multi-factor authentication (MFA) required for all cloud infrastructure administration.
- Automated Data Purge: Ingestion queues automatically purge raw comment payloads within 24 hours of successful message dispatch. Analytical performance records expire and are permanently erased after 30 days.
- DDoS & Web Application Firewall: Enterprise edge security powered by Cloudflare with automated rate-limiting and bot deterrence.
6. Authorized Sub-Processors
Customer provides general written authorization for KRYSKAFLOW to engage the following infrastructure sub-processors:
| Sub-Processor | Role / Service | Location | Transfer Mechanism |
|---|---|---|---|
| Google Firebase Auth (Google LLC) | Identity token verification, user authentication, and OAuth login | US / Global | EU Standard Contractual Clauses (SCCs) |
| Supabase Inc. & AWS India | Encrypted cloud PostgreSQL database, audit ledgers, and creator automations | India (ap-south-1 Mumbai) / US | EU SCCs & India DPDP Addendum |
| Upstash Inc. | Serverless Redis clusters, distributed rate limiting, and webhook deduplication | US / Global Edge | EU Standard Contractual Clauses (SCCs) |
| Meta Platforms Ireland Ltd. / Meta Platforms, Inc. | Official Instagram Graph API and Messenger Platform API execution | Ireland / US | Meta Platform Terms & Controller-to-Processor Agreements |
| Telegram Messenger Inc. | Multi-channel creator alerting, bot webhooks, and automation notifications | Global | Service Provider Agreement |
| Razorpay Software Pvt. Ltd. | RBI-authorized payment aggregation, UPI AutoPay, and net-banking (INR ₹) | India | RBI Regulated & PCI-DSS Level 1 |
| PayPal Inc. | International card processing, multi-currency checkout, and subscriptions (USD $) | US / EU / Global | PCI-DSS Level 1 & EU SCCs |
| Cloudflare, Inc. | Edge CDN, SSL/TLS termination, DDoS mitigation, and WAF defense | Global Edge | EU Standard Contractual Clauses (SCCs) |
KRYSKAFLOW remains fully liable to Customer for the performance of each sub-processor’s data protection obligations. Customer may subscribe to notifications of new sub-processors by contacting [email protected].
7. Personal Data Breach Notification
In accordance with GDPR Article 33 and the Indian DPDP Act 2023:
- 72-Hour Notification: KRYSKAFLOW shall notify Customer without undue delay and, in any event, within seventy-two (72) hours of becoming aware of a confirmed Personal Data Breach affecting Customer Personal Data.
- Incident Details Provided: The notification shall describe the nature of the breach, the categories and approximate number of Data Subjects concerned, likely consequences, and remediation actions taken or planned.
- Assistance: KRYSKAFLOW shall cooperate with Customer to fulfill Customer's statutory obligation to inform supervisory authorities (e.g., Data Protection Commission, ICO, Data Protection Board of India) and affected individuals.
8. International Data Transfers (EU SCCs & UK Addendum)
Where the processing of Customer Personal Data involves a cross-border transfer from the European Economic Area (EEA), United Kingdom, or Switzerland to a country not recognized as providing an adequate level of data protection:
- Incorporation of EU SCCs: The parties hereby incorporate by reference the Standard Contractual Clauses approved by the European Commission under Commission Implementing Decision (EU) 2021/914 (“EU SCCs”), specifically Module 2 (Controller-to-Processor).
- Clause 7 (Docking Clause): Shall apply.
- Clause 9 (Sub-processors): Option 2 (General written authorization) shall apply with a minimum notice period of 14 calendar days.
- Clause 11 (Redress): The optional wording is not included.
- Clause 17 (Governing Law): The laws of the Republic of Ireland shall govern.
- Clause 18 (Choice of Forum): Courts of Dublin, Ireland.
- UK International Data Transfer Addendum: For UK transfers, the UK Addendum to the EU SCCs (Version B1.0 issued by the ICO) is incorporated by reference.
9. Pre-Signed Contractual Execution
This DPA is legally valid, binding, and mutually executed as of the date Customer accepts the KRYSKAFLOW Terms of Service or connects an Instagram Business account.
Need an individually executed PDF countersigned for your corporate legal team? Request a customized enterprise DPA via [email protected].