Legal

Data Processing Agreement

Last updated: 31 July 2026

If you process personal data through Karibu and need a Data Processing Agreement (DPA) — for your own GDPR, POPIA, or NDPR compliance, or as part of a procurement review — we’ll provide and counter-sign one. This page explains how to request it and what it covers.

How to request a DPA

Email legal@usekaribu.com from your account email with your legal entity name and the signatory’s details. The founder reads procurement requests directly and typically responds within 1 business day. We can send our standard DPA for counter-signature, or review yours. Enterprise customers can fold the DPA into a custom MSA.

What our DPA covers

  • The roles of the parties (you as controller, Karibu as processor) and the subject matter, duration, nature, and purpose of the processing.
  • The categories of personal data and data subjects processed — your account and workspace data, and the prospect contact data Karibu handles on your behalf.
  • Our use of sub-processors, the commitment to give at least 30 days notice before adding or changing one, and the published list. See our sub-processors page.
  • International-transfer safeguards, including EU Standard Contractual Clauses where a sub-processor operates outside the EEA. Primary storage is in the EU (Supabase, Frankfurt).
  • The technical and organisational security measures we apply — described in detail on our Security page.
  • Assistance with data-subject requests, personal-data-breach notification, and deletion or return of personal data on termination.

Ready to request one?

Email legal@usekaribu.com and we’ll get a DPA to you.