Kaen
Česky Back to kaen.cz

Data Processing Agreement (DPA)

This agreement governs how we process personal data on your behalf when we analyse your funnel. It is the processing agreement required by Art. 28(3) GDPR, between you as the controller and us as the processor.

1. Parties and acceptance

Processor: Loops Collective s.r.o., Company ID 29932386, registered office Příčná 1892/4, Nové Město, 110 00 Prague 1, Czech Republic, registered in the Commercial Register kept by the Municipal Court in Prague, Section C, Insert 454220, operator of the Kaen service (the “Processor”). Contact: hello@kaen.cz.

Controller: the customer of the Service — the business whose website, product or analytics we analyse (the “Controller”). Where the customer is an agency analysing its own client’s website, the customer warrants that it is entitled to act as the controller or on the controller’s documented instructions.

This DPA is an integral part of the Terms of Service and the Controller accepts it by using the Service; a separate signature is not required. We will sign a copy on request. For matters of personal data processing, this DPA prevails over the Terms.

2. Subject, duration, nature and purpose

  • Subject: personal data contained in the analytics, product and payment data the Controller makes accessible to the Processor, and in the communication about it.
  • Duration: the term of the contract, plus the deletion period under clause 8.
  • Nature: read access, querying, aggregation, analysis (including by large language models), storage of derived findings, and preparation of reports, cases and experiment designs.
  • Purpose: finding where the Controller’s funnel loses customers, quantifying it, and proposing and evaluating fixes.

3. Categories of data subjects and personal data

  • Data subjects: visitors and users of the Controller’s website or product; the Controller’s customers; the Controller’s own staff who appear in the shared communication.
  • Personal data: pseudonymous identifiers (cookie, device and user IDs), events and behaviour in the funnel, approximate location derived from IP address, device and browser data, session recordings and heatmaps where the Controller uses such a tool, order and payment metadata, and — where the Controller’s data contains them — e-mail addresses and names.
  • Special categories of personal data (Art. 9 GDPR) are not the subject of the processing. The Controller undertakes not to make them accessible, and to mask or exclude them in session recordings where they could appear.

4. Obligations of the Processor

The Processor undertakes that it will (Art. 28(3) GDPR):

  • process personal data only on the documented instructions of the Controller — given by the configuration and use of the Service, the accepted offer and this DPA — unless required otherwise by EU or member-state law, in which case it will inform the Controller unless that law prohibits it;
  • ensure that persons authorised to process the data are bound by a duty of confidentiality;
  • implement the security measures under Art. 32 GDPR (clause 5);
  • respect the conditions for engaging subprocessors (clause 7);
  • assist the Controller with its own obligations (clause 6);
  • delete or return the personal data when the Service ends (clause 8);
  • make available the information needed to demonstrate compliance and allow audits (clause 9), and inform the Controller if an instruction infringes data protection law.

5. Security

Taking into account the state of the art and the risk, the Processor applies in particular:

  • encryption in transit (TLS) and at rest with its suppliers;
  • read-only access wherever it is sufficient, granted through the Controller’s own accounts, with the narrowest scope needed;
  • two-factor authentication on accounts that support it, and individual named access;
  • no copies of raw datasets beyond what the analysis requires; derived findings are kept instead;
  • logging of access, regular review of access rights, and removal of access when the contract ends;
  • suppliers selected with a data processing agreement in place and, where relevant, EU data residency.

6. Assistance to the Controller

The Processor will, taking into account the nature of the processing:

  • help the Controller respond to requests from data subjects; if a request reaches the Processor directly, it forwards it without undue delay and does not answer it on its own;
  • help with security, breach notification, data protection impact assessments and prior consultation (Art. 32–36 GDPR);
  • notify the Controller of a personal data breach without undue delay, at the latest within 48 hours of becoming aware of it, with the information available.

Assistance beyond a reasonable extent may be charged at the Processor’s standard rates, agreed in advance.

7. Subprocessors

The Controller gives the Processor general authorisation to engage subprocessors. The current list, with purpose, location and safeguards, is published at kaen.cz/subprocessors.

The Processor imposes on each subprocessor data protection obligations equivalent to those in this DPA and remains fully liable to the Controller for its performance.

The Processor will announce an intended addition or replacement of a subprocessor at least 30 days in advance by updating that page and e-mailing the Controller. The Controller may object on reasonable data protection grounds within that period; if the parties do not find a solution, the Controller may terminate the affected part of the Service with effect from the date the change takes effect, without penalty.

8. Deletion and return

When the Service ends, the Processor removes its access to the Controller’s systems without undue delay, and within 30 days deletes personal data it holds, or returns it to the Controller if the Controller asks within that period. Reports and cases already delivered remain with the Controller.

The Processor may keep data for longer only where EU or member-state law requires it, and only for that purpose.

9. Audit

The Processor provides the Controller, on request, with the information needed to demonstrate compliance with Art. 28 GDPR. The Controller may audit the Processor once per calendar year, at its own cost, with at least 30 days’ written notice, during business hours and without disrupting the Processor’s operations; more often only after a personal data breach or where a supervisory authority requires it. The auditor must be bound by confidentiality and must not be a competitor of the Processor.

10. International transfers

Personal data is processed primarily in the EU. Where a subprocessor processes data outside the EEA, the transfer is based on an adequacy decision or on the European Commission’s standard contractual clauses, together with any supplementary measures required. The location of each supplier is stated at Subprocessors.

11. Use of AI models

The analysis uses large language models supplied by the providers listed at Subprocessors. According to those providers’ terms, inputs are not used to train their models. The Processor sends the smallest amount of data the analysis needs and prefers aggregated and pseudonymised data over raw records.

12. Final provisions

This DPA is governed by Czech law and by the GDPR. If a provision is invalid, the rest stays in force. The Processor may update this DPA in line with clause 10 of the Terms of Service; a change that reduces the protection of personal data requires the Controller’s agreement.

This DPA is published in English and in Czech. In case of any discrepancy, the English version prevails.

Version 2026-09-18, effective from 18 September 2026.

Kaen

Kaen turns your data into experiments that drive growth.

hello@kaen.cz

Product

  • How it works
  • Who it's for
  • FAQ

Company

  • Blog
  • Contact

Legal

  • Privacy
  • Terms
  • DPA
  • Subprocessors
  • Cookies
Loops Collective s.r.o. IČO 29932386 · Příčná 1892/4, 110 00 Praha 1 © 2026 Kaen. All rights reserved.