If you process personal data through Karibu and need a Data Processing Agreement (DPA) — for your own GDPR, POPIA, or NDPR compliance, or as part of a procurement review — we’ll provide and counter-sign one. This page explains how to request it and what it covers.
How to request a DPA
Email legal@usekaribu.com from your account email with your legal entity name and the signatory’s details. The founder reads procurement requests directly and typically responds within 1 business day. We can send our standard DPA for counter-signature, or review yours. Enterprise customers can fold the DPA into a custom MSA.
What our DPA covers
- The roles of the parties (you as controller, Karibu as processor) and the subject matter, duration, nature, and purpose of the processing.
- The categories of personal data and data subjects processed — your account and workspace data, and the prospect contact data Karibu handles on your behalf.
- Our use of sub-processors, the commitment to give at least 30 days notice before adding or changing one, and the published list. See our sub-processors page.
- International-transfer safeguards, including EU Standard Contractual Clauses where a sub-processor operates outside the EEA. Primary storage is in the EU (Supabase, Frankfurt).
- The technical and organisational security measures we apply — described in detail on our Security page.
- Assistance with data-subject requests, personal-data-breach notification, and deletion or return of personal data on termination.
Related documents
On request we can also provide this sub-processor list as a PDF and a DPIA covering our network-learning aggregation. See also our Privacy Policy and Terms of Service.