Kip

Kip Data Processing Agreement

Effective date: October 1, 2026

This Data Processing Agreement ("DPA") forms part of the Kip Terms of Service (the "Agreement") between Kippenhuck Industries Inc., trading as Kipnetic, 30 Hartland Avenue, Paradise, NL A1L 0V3, Canada ("Kipnetic", "Processor", "we"), and the customer that accepts it ("Customer"). It applies when Kipnetic processes Personal Data on the Customer's behalf through Kip on the web or Kip agent access. It does not apply to Kip for desktop, where Customer data is stored on the Customer's own devices and Kipnetic does not host it. A Customer accepts this DPA by emailing support@kipnetic.com from the address on its Kip account to say so, or by signing a copy we provide.

1. Definitions

"Personal Data", "Processing", "Controller", "Processor", "Data Subject" and "Personal Data Breach" have the meanings given in the GDPR (Regulation (EU) 2016/679) and, for Canada, correspond to "personal information" and related terms under PIPEDA. "Data Protection Law" means PIPEDA, the GDPR, the UK GDPR, and any other privacy law that applies to the Processing. "Subprocessor" means a third party that Kipnetic engages to process Customer Personal Data.

2. Roles

The Customer is the Controller (or a Processor acting for its own Controller). Kipnetic is a Processor and processes Customer Personal Data only on the Customer's documented instructions. The Agreement, this DPA and the Customer's use and configuration of Kip are the Customer's complete instructions. Kipnetic will tell the Customer if it believes an instruction violates Data Protection Law.

3. Details of the Processing (Annex 1)

Subject matterProviding an email and calendar client that syncs with the Customer's Google or Microsoft accounts
DurationThe term of the Agreement plus the deletion period in section 10
Nature and purposeSyncing, storing, indexing, displaying, searching and organising mail, calendar and contact data; sending mail and calendar changes the user initiates or approves; delivering notifications; running AI features the user invokes or enables
Categories of Data SubjectsCustomer's users; people who correspond with them; calendar attendees; contacts; poll invitees
Categories of Personal DataNames, email addresses, message headers and bodies, attachment metadata, calendar events, contact details and photos, content users create in Kip, sign-in identifiers, push notification endpoints
Special categoriesNot intentionally processed. Email may incidentally contain any category of data; Kip processes it only as message content.
FrequencyContinuous while a mailbox is connected
LocationUnited States (Railway, US West region)

4. Kipnetic's obligations

Kipnetic will:

  1. Process Customer Personal Data only to provide Kip, never for advertising, sale, or training general AI or machine learning models.
  2. Ensure everyone authorised to access Customer Personal Data is bound by confidentiality. Kipnetic personnel do not read Customer mail except where the Customer asks (for example in a support request), for security investigations, or where the law requires.
  3. Implement the technical and organisational measures in Annex 2.
  4. Assist the Customer, taking into account the nature of the Processing, with Data Subject requests, security, breach notification, impact assessments and prior consultations.
  5. Make available the information reasonably needed to demonstrate compliance with this DPA. Kip is preparing for Google's Cloud Application Security Assessment (CASA); Kipnetic will provide its Letter of Validation once it is issued.

5. Subprocessors

The Customer authorises the Subprocessors listed below. Kipnetic will give at least 30 days' notice by email before adding or replacing a Subprocessor, and the Customer may object on reasonable data protection grounds, in which case the parties will discuss a solution in good faith and, failing that, the Customer may terminate the affected service. Kipnetic imposes data protection terms on each Subprocessor that are no less protective than this DPA and remains responsible for them.

SubprocessorPurposeLocation
Railway CorporationHosting, storage and backups for Kip on the webUnited States (US West)
OpenRouter, Inc.Routing AI requests to providers that do not retain or train on themUnited States
AI model providers reached through OpenRouter (currently Z.ai and Google)Running AI models, without retention or trainingWhere the provider's endpoint runs
Microsoft Corporation (Azure OpenAI Service, reached through OpenRouter's zero data retention endpoint)Computing embeddings for search by meaning, only where it is switched onWhere that endpoint runs
Google LLCCloud Pub/Sub new-mail signals (address and change marker only); Firebase Cloud Messaging for encrypted push notifications; Google Workspace for Kipnetic's support mailboxUnited States and worldwide
Microsoft CorporationGraph change notifications (identifiers only)Worldwide
Apple Inc., MozillaDelivery of end-to-end encrypted web push notificationsWorldwide
ResendService email (sign-in links, billing notices)United States
PostHog, Inc.Product analytics and error reporting: error reports and usage events, only while "Share anonymous usage and error reports" is on (on by default; Settings > Privacy), plus checkout, subscription and server-failure reports without mail or account details; no session recordingUnited States (PostHog US Cloud)

Google and Microsoft are also where the Customer's mail is stored in the first place; they act under the Customer's own agreements with them, not as Kipnetic's Subprocessors, except for the services listed above. Stripe acts as merchant of record and an independent controller of payment data, not as a Subprocessor of Customer mail.

6. International transfers

Customer Personal Data is processed in the United States and, for AI requests, where the model endpoint runs. Where the GDPR or UK GDPR applies to a transfer, the parties incorporate the EU Standard Contractual Clauses and the UK International Data Transfer Addendum as set out in Annex 3.

7. Security incidents

Kipnetic will notify the Customer without undue delay, and in any case within 72 hours, after becoming aware of a Personal Data Breach affecting Customer Personal Data, with the information the Customer reasonably needs to meet its own obligations, and will keep the Customer updated as more becomes known. Kipnetic keeps a record of every breach of security safeguards as PIPEDA requires.

8. Data Subject requests

Kipnetic will forward to the Customer any request it receives from a Data Subject about Customer Personal Data and will not answer it except on the Customer's instructions. Kip lets users remove mailboxes, delete assistant conversations and memories, revoke agent access, export all of their Kip data, and delete their Kip account themselves.

9. Audits

Kipnetic will answer reasonable written security questionnaires once a year and provide its most recent third-party assessment once one has been issued. Where Data Protection Law requires an on-site audit, the Customer may conduct one at its own cost, with 30 days' notice, during business hours, no more than once a year, under confidentiality.

10. Return and deletion

Before the Agreement ends, the Customer's users may export their data from Settings > Account. When an account is deleted, Kipnetic immediately deletes its database, storage folder and the recovery copies kept on the server, and destroys the key that protects its stored credentials. Copies inside Railway's volume backups are deleted when those backups expire, within about 3 months. When a subscription lapses and is not renewed, the account is deleted 60 days after it becomes read-only. In each case this applies unless the law requires Kipnetic to keep the data. Mail itself remains with Google or Microsoft and is not affected.

11. Liability and precedence

Each party's liability under this DPA is subject to the limits in the Agreement, except where Data Protection Law does not permit such a limit. If this DPA conflicts with the Agreement, this DPA prevails for the Processing of Personal Data. If the Standard Contractual Clauses conflict with this DPA, the Clauses prevail.

Annex 2: Technical and organisational measures

AreaMeasureWhere
Tenant isolationEach customer account has its own SQLite database and storage folder, served by its own worker. No database is shared between customers. Each account's credentials are sealed under its own data key, which is unwrapped only inside that account's worker.src/server/gateway/multi.ts, src/server/directory/dek.ts
Access controlSign-in by single-use email link, Google or Microsoft OpenID Connect, or passkey. No passwords are stored. Deleting an account needs the account's email address typed and a sign-in less than ten minutes old.src/server/gateway/magicLink.ts, src/server/gateway/passkeys.ts, src/server/gateway/signIn.ts, src/server/account/deleteRoute.ts
Session securityRandom session tokens stored only as SHA-256 hashes; HttpOnly, Secure, SameSite=Lax cookies; 30 days from last use; revocable.src/server/gateway/directorySession.ts
Encryption in transitTLS for all connections; HSTS sent by the web app.src/server/gateway/securityHeaders.ts
Encryption at rest (credentials)OAuth refresh tokens and API keys sealed with AES-256-GCM under a per-account data key, wrapped under a master key held only in the host's secret store.src/server/electron.ts, src/server/directory/dek.ts, docs/launch/security/key-management.md
Encryption at rest (content)Railway encrypts storage at rest at the disk level. Mail content has no additional application-level encryption.docs/launch/security/backups-and-retention.md section 4
BackupsNightly consistent snapshots of each account's database (newest three kept) and Railway volume backups.src/main/db/backup.ts, src/server/directory/snapshot.ts
Browser hardeningStrict Content Security Policy (script-src 'self', frame-ancestors 'none', form-action 'none'), nosniff, no-referrer, COOP.src/server/gateway/static.ts, src/server/gateway/securityHeaders.ts
Rate limitingPer-endpoint and per-address limits on sign-in, checkout and other public endpoints.src/server/gateway/endpointLimits.ts, src/server/gateway/rateLimit.ts
Untrusted contentIncoming email HTML sanitised through an allowlist; remote images, fonts and styles blocked by default.src/renderer/src/lib/emailHtml.ts, src/renderer/src/components/MessageBody.tsx
Webhook securityNew-mail notification endpoints require a secret path token compared in constant time, and only act on subscriptions Kip registered. Stripe webhooks are signature-checked.src/server/push.ts, src/server/gateway/pubsub.ts, src/server/billing/signature.ts
Agent accessOAuth 2.1 with PKCE; tokens stored hashed; read and write scopes separated; anything that sends mail or reaches another person requires in-client approval; grants expire after 90 days and are revocable.src/server/agentOauth.ts, src/server/mcpElicitApproval.ts, src/shared/types.ts agentNeedsApproval
AI data minimisationOnly the content a feature needs is sent; every request instructs the router to use only providers that do not retain or train on it; AI request records keep metadata only, for 90 days; users can switch AI off.src/main/ai/client.ts, src/main/ai/ledger.ts, src/main/ai/aiSwitch.ts
PersonnelProduction access limited to the founder, with multi-factor authentication.
Incident responseDocumented incident response procedure.docs/launch/security/incident-response.md

Annex 3: Transfer clauses

  1. EU transfers. Where the GDPR applies to a transfer of Customer Personal Data to Kipnetic or its Subprocessors outside the European Economic Area, the Standard Contractual Clauses adopted by Commission Implementing Decision (EU) 2021/914 (the "Clauses") are incorporated by reference, as follows:
    • Module 2 (controller to processor) applies where the Customer is a Controller, and Module 3 (processor to processor) where the Customer is a Processor.
    • Clause 7 (docking clause) applies.
    • Clause 9: option 2 (general written authorisation), with the notice period in section 5 of this DPA.
    • Clause 11: the optional language does not apply.
    • Clause 13: the supervisory authority is the one competent for the Customer under Article 3(2) or Article 27 of the GDPR, as applicable.
    • Clause 17: option 1, the law of Ireland.
    • Clause 18: the courts of Ireland.
    • Annex I of the Clauses is completed by section 3 of this DPA (the Customer is the data exporter and Kipnetic the data importer), Annex II by Annex 2, and Annex III by the list in section 5.
  2. UK transfers. Where the UK GDPR applies, the International Data Transfer Addendum to the EU Commission Standard Contractual Clauses issued by the UK Information Commissioner (version B1.0) is incorporated by reference. Its Tables 1 to 3 are completed with the information in this DPA and the paragraph above, and for Table 4 either party may end the Addendum as its Section 19 allows.
  3. Switzerland. Where the Swiss Federal Act on Data Protection applies, the Clauses apply with the Swiss Federal Data Protection and Information Commissioner as the competent authority and references to the GDPR read as references to that Act.
Kip data processing agreement · Kipnetic