Skip to content
Kaiya
ProductWorkflowsPricingSecurity
Resources
Best AI for executive searchBest AI for InveniasChatGPT vs specialist AIImplementing AI in executive searchAI confidentialityAll resourcesHelp centreSystem status
Book a demo Start free month

Legal

Data Processing Agreement

Our data processing agreement sets out how Kaiya processes personal data for customers.

Last updated: May 2026

Contents
Data Processing AgreementPersonal Data ProcessingApproved Sub-ProcessorsPersonal Data TypesData Subject TypesAcceptable Use and Security Policies

Background

This Data Processing Agreement forms part of and is incorporated into the agreement between the Customer and Kaiya comprised of the Order Form, Terms of Service and any schedules incorporated into them, together the "Agreement", where Kaiya processes Personal Data on behalf of the Customer in connection with the Services.

This Data Processing Agreement sets out the additional terms, requirements and conditions on which Kaiya will process Personal Data when providing services under the Terms. It contains the mandatory clauses required by Article 28(3) of the retained EU law version of the General Data Protection Regulation ((EU) 2016/679) for contracts between controllers and processors and the General Data Protection Regulation ((EU) 2016/679).

It is hereby agreed as follows.

1. Definitions and Interpretation

The following definitions and rules of interpretation apply in this Data Processing Agreement. Capitalised but undefined terms shall have the meaning given in the Terms.

Business Purposes: the services to be provided by Kaiya to the Customer as described in the Terms and any other purpose specifically identified in the processing details below.

Commissioner: the Information Commissioner (see Article 4(A3), UK GDPR and section 114, DPA 2018).

Controller: has the meaning given to it in the Data Protection Legislation.

Data Protection Legislation: all applicable data protection and privacy legislation in force from time to time in the UK, EU and US (as applicable) including without limitation the UK GDPR; the Data Protection Act 2018 (and regulations made thereunder) (DPA 2018); the EU GDPR, the US Privacy Laws and the Privacy and Electronic Communications Regulations 2003 (SI 2003/2426) as amended; and all other legislation and regulatory requirements in force from time to time which apply to a party relating to the use of Personal Data (including, without limitation, the privacy of electronic communications).

Data Protection Policy: the Kaiya Data Protection Policy in force and as amended from time to time, including the measures which Kaiya takes to manage data security within its organisation.

Data Subject: the identified or identifiable living individual to whom the Personal Data relates.

EU GDPR: the General Data Protection Regulation ((EU) 2016/679).

EEA: the European Economic Area.

Personal Data: any information relating to an identified or identifiable living individual that is processed and held by Kaiya on behalf of the Customer as a result of, or in connection with, the provision of the services under the Terms; an identifiable living individual is one who can be identified, directly or indirectly, in particular by reference to an identifier such as a name, email address, software application identification number, location data, an online identifier or to one or more factors specific to the physical, physiological, genetic, mental, economic, cultural or social identity of the individual.

Processing, processes, processed, process: any activity that involves the use of the Personal Data. It includes, but is not limited to, any operation or set of operations which is performed on the Personal Data or on sets of the Personal Data, whether or not by automated means, such as collection, recording, organisation, structuring, storage, adaptation or alteration, retrieval, consultation, disclosure by transmission, dissemination or otherwise making available, alignment or combination, restriction, erasure or destruction. Processing also includes transferring the Personal Data to third parties.

Personal Data Breach: a breach of security leading to the accidental, unauthorised or unlawful destruction, loss, alteration, disclosure of, or access to, the Personal Data.

Processor: a natural or legal person, public authority, agency or other body which processes personal data on behalf of the Controller.

Records: has the meaning given to it in Clause 12.

Software: means the Kaiya conversational AI tool as further described in the Customer Order Confirmation.

Standard Contractual Clauses: the standard contractual clauses published on June 4, 2021 by the European Commission adopting Implementing Decision and Annex on SCCs for the transfer of personal data from the EEA to non-EEA third countries to ensure compliance with the EU GDPR and nationally adopting legislation.

Term: the term of this Data Processing Agreement as defined in Clause 10.

UK GDPR: has the meaning given to it in section 3(10) (as supplemented by section 205(4)) of the Data Protection Act 2018.

US Privacy Laws: Cal. Civ. Code §§ 1798.100 et seq., as amended by the California Privacy Rights Act of 2020 (the California Consumer Privacy Act) (CCPA), Colo. Rev. Stat. §§ 6-1-1301 et seq. (the Colorado Privacy Act) (CPA), Connecticut's Data Privacy Act (CTDPA), Utah Code Ann. §§ 13-61-101 et seq. (the Utah Consumer Privacy Act) (UCPA), VA Code Ann. §§ 59.1-575 et seq. (the Virginia Consumer Data Protection Act) (VCDPA).

This Data Processing Agreement is subject to the terms of the Terms and is incorporated into the Terms. Interpretations and defined terms set forth in the Terms apply to its interpretation.

The processing details, approved sub-processor list, personal data categories, data subject categories, and acceptable use and security policies form part of this Data Processing Agreement and the Terms as a whole.

A reference to writing or written includes email and digital forms of writing.

In the case of conflict or ambiguity between the main body of this Data Processing Agreement and any supporting section, the main body will prevail unless it expressly states otherwise. If there is any conflict between this Data Processing Agreement and the Terms, this Data Processing Agreement will prevail for matters concerning Personal Data processing.

2. Personal Data Types and Processing Purposes

The Customer and Kaiya agree and acknowledge that for the purpose of the Data Protection Legislation the Customer is the Controller and Kaiya is the Processor.

The Customer retains control of the Personal Data and remains responsible for its compliance obligations under the Data Protection Legislation, including but not limited to, providing any required notices and obtaining any required consents, and for the written processing instructions it gives to Kaiya.

The processing details below describe the subject matter, duration, nature and purpose of the processing and the Personal Data categories and Data Subject types in respect of which Kaiya may process the Personal Data to fulfil the Business Purposes.

3. Kaiya Obligations

Kaiya will only process the Personal Data to the extent, and in such a manner, as is necessary for the Business Purposes or in accordance with the Customer's written instructions. Kaiya will not process the Personal Data for any other purpose or in a way that does not comply with the Terms, this Data Processing Agreement or the Data Protection Legislation. Kaiya agrees to promptly notify the Customer if, in its opinion, the Customer's instructions do not comply with the Data Protection Legislation.

Kaiya agrees to comply with any Customer written instructions requiring Kaiya to amend, transfer, delete or otherwise process the Personal Data (including without limitation the Personal Data of specific individuals), or to stop, mitigate or remedy any unauthorised processing. This is on the understanding that Kaiya may not be able to provide its Services as a result of such instructions.

Kaiya will maintain the confidentiality of the Personal Data and will not disclose the Personal Data to third parties unless the Customer or this Data Processing Agreement specifically authorises the disclosure, or as required by domestic or EU law, court or regulator (including the Commissioner). Disclosure is expressly authorised where a disclosure is made as part of Kaiya's services to the Customer.

If a domestic or EU law, court or regulator (including the Commissioner) requires Kaiya to process or disclose the Personal Data to a third party, Kaiya shall first inform the Customer of such legal or regulatory requirement and give the Customer an opportunity to object or challenge the requirement, unless the domestic or EU law prohibits the giving of such notice.

Kaiya will reasonably assist the Customer with meeting the Customer's compliance obligations referenced in clause 3.4 under the Data Protection Legislation, taking into account the nature of Kaiya's processing and the information available to Kaiya, including in relation to Data Subject rights, data protection impact assessments and reporting to and consulting with the Commissioner or other relevant regulator under the Data Protection Legislation.

4. Kaiya's Employees

Kaiya will ensure that all of its employees are informed of the confidential nature of the Personal Data and are bound by written confidentiality obligations and use restrictions in respect of the Personal Data; have reviewed its data protection and security policies and how they govern their handling of the Personal Data and how it applies to their particular duties; and are aware both of Kaiya's duties and their personal duties and obligations under the Data Protection Legislation and this Data Processing Agreement.

5. Security

Kaiya shall at all times implement appropriate technical and organisational measures against accidental, unauthorised or unlawful processing, access, copying, modification, reproduction, display or distribution of the Personal Data, and against accidental or unlawful loss, destruction, alteration, disclosure or damage of Personal Data.

Kaiya shall implement such measures to ensure a level of security appropriate to the risk involved in accordance with its Data Protection Policy.

6. Personal Data Breach

Kaiya will without undue delay notify the Customer in writing if it becomes aware of the loss, unintended destruction or damage, corruption, or unusability of part or all of the Personal Data; any accidental, unauthorised or unlawful processing of the Personal Data; or any Personal Data Breach.

Where Kaiya becomes aware of such an event, it will, without undue delay, provide the Customer with a written description of the nature of the event, including the categories of in-scope Personal Data and approximate number of both Data Subjects and the Personal Data records concerned; the likely consequences; and a description of the measures taken or proposed to be taken to address the event, including measures to mitigate its possible adverse effects.

Immediately following any accidental, unauthorised or unlawful Personal Data processing or Personal Data Breach, the parties will coordinate with each other to investigate the matter. Kaiya will reasonably cooperate with the Customer at no additional cost to the Customer, including assisting with any investigation, facilitating interviews with Kaiya personnel involved in the matter, making available relevant records, logs, files, data reporting and other materials required to comply with Data Protection Legislation or otherwise reasonably required by the Customer, and taking reasonable and prompt steps to mitigate the effects and minimise any damage.

Kaiya will not inform any third party of any accidental, unauthorised or unlawful processing of all or part of the Personal Data and/or a Personal Data Breach without first obtaining the Customer's written consent, except when required to do so by domestic or EU law.

Kaiya agrees that the Customer has the sole right to determine whether to provide notice of the accidental, unauthorised or unlawful processing and/or Personal Data Breach to any Data Subjects, the Commissioner, other in-scope regulators, law enforcement agencies or others, as required by law or regulation or in the Customer's discretion, including the contents and delivery method of the notice, and whether to offer any type of remedy to affected Data Subjects.

Kaiya will cover reasonable expenses associated with the performance of the obligations under clause 6.1 to clause 6.3 unless the matter arose from the Customer's specific written instructions, negligence, wilful default or breach of this Data Processing Agreement or other part of the Terms as a whole, in which case the Customer will cover all reasonable expenses.

7. Cross-Border Transfers of Personal Data

The parties acknowledge that Kaiya is established in the United Kingdom. To the extent that Personal Data is transferred from the EEA to Kaiya in the United Kingdom, the parties agree that, for so long as the United Kingdom benefits from a valid adequacy decision under Article 45 EU GDPR covering such transfer, no additional transfer mechanism is required in respect of that transfer.

Kaiya shall ensure that any onward transfer of Personal Data by Kaiya or any Sub-processor to a country or recipient outside the United Kingdom or the EEA is carried out only where a valid transfer mechanism under applicable Data Protection Legislation is in place. Kaiya confirms that, as of the effective date of this Data Processing Agreement, it has implemented the legally required measures for such onward transfers to the extent applicable to the Services, including, where required, entry into applicable standard contractual clauses, the UK International Data Transfer Addendum, or reliance on an adequacy decision or other lawful transfer mechanism.

Where applicable law requires supplementary measures in connection with any onward transfer, Kaiya shall implement such supplementary technical, organisational and contractual measures as are reasonably required to ensure that the transferred Personal Data is afforded a level of protection essentially equivalent to that required under applicable Data Protection Legislation.

Upon reasonable written request, Kaiya shall provide the Customer with reasonable information regarding the transfer mechanism relied on for any onward transfer of Personal Data under this clause, subject to confidentiality, security and third party confidentiality obligations.

If the legal basis relied upon under this clause ceases to be valid or available, Kaiya shall use reasonable efforts to implement an alternative valid transfer mechanism without undue delay and shall cooperate reasonably with the Customer to the extent required for continued lawful processing.

8. Subcontractors

Kaiya may authorise the sub-processors listed in the Approved Sub-Processors section, and any replacement or additional sub-processor appointed in accordance with this clause, to process Personal Data provided that Kaiya imposes data protection obligations on such sub-processor that are no less protective in substance than those set out in this Data Processing Agreement.

Kaiya shall provide reasonable prior notice of any intended appointment of a new sub-processor that will process Personal Data. The Customer may object on reasonable data protection grounds within 10 Business Days of receiving such notice. The parties shall discuss such objection in good faith. If the parties cannot resolve the objection, Kaiya may elect not to appoint the relevant sub-processor, or the Customer may terminate the affected Services on written notice.

Where a sub-processor fails to fulfil its obligations under the written agreement with Kaiya, Kaiya remains fully liable to the Customer for the performance of that sub-processor's obligations.

Kaiya shall remain responsible for the processing of Personal Data carried out by its sub-processors on Kaiya's behalf.

Kaiya shall provide the Customer with reasonable prior notice if a current sub-processor processes Personal Data outside the location(s) indicated in the Approved Sub-Processors section.

9. Complaints, Data Subject Requests and Third-Party Rights

Kaiya shall, at no additional cost to the Customer, take such technical and organisational measures as may be appropriate, and promptly provide such information to the Customer as the Customer may reasonably require, to enable the Customer to comply with the rights of Data Subjects under the Data Protection Legislation, including subject access rights, the rights to rectify, port and erase personal data, object to the processing and automated processing of personal data, and restrict the processing of personal data, and information or assessment notices served on the Customer by the Commissioner or other relevant regulator under the Data Protection Legislation.

Kaiya must notify the Customer immediately in writing if it receives any complaint, notice or communication that relates directly or indirectly to the processing of the Personal Data or to either party's compliance with the Data Protection Legislation.

Kaiya must notify the Customer without undue delay if it receives a request from a Data Subject for access to their Personal Data or to exercise any of their other rights under the Data Protection Legislation.

Kaiya will give the Customer, at no additional cost to the Customer, its full cooperation and assistance in responding to any complaint, notice, communication or Data Subject Access Request.

Kaiya must not disclose the Personal Data to any Data Subject or to a third party other than in accordance with the Customer's written instructions, or as required by domestic or EU law.

10. Duration and Termination

This Data Processing Agreement will remain in full force and effect so long as the Terms remain in effect or Kaiya retains any of the Personal Data related to the Terms in its possession or control (Term).

Any provision of this Data Processing Agreement that expressly or by implication should come into or continue in force on or after termination of the Terms in order to protect the Personal Data will remain in full force and effect.

If a change in any Data Protection Legislation prevents either party from fulfilling all or part of its Terms obligations, the parties may agree to suspend the processing of the Personal Data until that processing complies with the new requirements. If the parties are unable to bring the Personal Data processing into compliance with the Data Protection Legislation within 90 days, either party may terminate the Terms on written notice to the other party.

11. Data Return and Destruction

At the Customer's request, Kaiya will give the Customer, or a third party nominated in writing by the Customer, a copy of or access to all or part of the Personal Data in its possession or control in the format and on the media reasonably specified by the Customer.

On termination of the Terms for any reason or expiry of its term, Kaiya will securely delete or destroy or, if directed in writing by the Customer, return and not retain, all or any of the Personal Data related to this Data Processing Agreement in its possession or control within 30 days from termination of the Terms in line with Kaiya's internal processes, subject to Kaiya's legal requirements to retain certain data.

If any law, regulation, or government or regulatory body requires Kaiya to retain any documents, materials or Personal Data that Kaiya would otherwise be required to return or destroy, it will notify the Customer in writing of that retention requirement, giving details of the documents, materials or Personal Data that it must retain, the legal basis for such retention, and establishing a specific timeline for deletion or destruction once the retention requirement ends.

Kaiya shall not be obligated to interact directly with any Data Subject whose Personal Data is being processed by Kaiya on behalf of a Customer without the Customer's prior written approval. If contacted by such a Data Subject, Kaiya shall first refer such contact to the Customer directly, and the Customer shall be responsible for processing the applicable request with Kaiya directly, save where Customer requests and authorises Kaiya to do so on its behalf.

12. Records

Kaiya will keep accurate written records regarding any processing of the Personal Data, including but not limited to, the access, control and security of the Personal Data, subcontractors, the processing purposes, categories of processing, and a general description of the technical and organisational security measures referred to in Clause 5.1 (Records).

Kaiya will ensure that the Records are sufficient to enable the Customer to verify Kaiya's compliance with its obligations under this Data Processing Agreement and the Data Protection Legislation and Kaiya will provide the Customer with copies of the Records upon request.

13. Audit

If a Personal Data Breach occurs or is occurring, or Kaiya becomes aware of a breach of any of its obligations under this Data Processing Agreement or any of the Data Protection Legislation, Kaiya will conduct an internal audit to determine the cause, produce a written report that includes detailed plans to remedy any deficiencies identified by the audit, provide the Customer with a copy of the written audit report, and seek to remedy any deficiencies identified by the audit within 30 days.

Where a Personal Data Breach occurs or is occurring, at the Customer's written request, Kaiya will produce a written report that includes detailed plans to remedy any security deficiencies identified by the audit, provide the Customer with a copy of the written audit report, and remedy any deficiencies identified by the audit without undue delay.

On the Customer's written request, Kaiya will make all of the relevant audit reports available to the Customer for review. The Customer will treat such audit reports as Kaiya's confidential information under the Terms.

Kaiya will promptly address any exceptions noted in the audit reports with the development and implementation of a corrective action plan by Kaiya's management.

14. Confirmations

Kaiya confirms that its employees, agents, sub-contractors and any other persons accessing the Personal Data on its behalf are reliable and trustworthy and understand their obligations under the Data Protection Legislation; it and anyone operating on its behalf will process the Personal Data in compliance with the Data Protection Legislation and other laws, enactments, regulations, orders, standards and other similar instruments; it has no reason to believe that the Data Protection Legislation prevents it from providing any of the contracted services as set out in the Terms; and it will take appropriate technical and organisational measures to prevent the accidental, unauthorised or unlawful processing of Personal Data and the loss or damage to the Personal Data.

The Customer warrants and represents that Kaiya's expected use of the Personal Data for the Business Purposes and as specifically instructed by the Customer will comply with the Data Protection Legislation.

15. Liability

This Data Processing Agreement is subject to the liability, exclusions and limitations of liability set out in the Agreement.

Nothing in this Data Processing Agreement limits or excludes either party's liability to the extent such liability cannot lawfully be limited or excluded under applicable law or under the Agreement, including for fraud, fraudulent misrepresentation, wilful misconduct or gross negligence.

16. Notice

Any notice or other communication given to a party under or in connection with this Data Processing Agreement must be in writing and delivered in accordance with the Terms.

Clause 16.1 does not apply to the service of any proceedings or other documents in any legal action or, where applicable, any arbitration or other method of dispute resolution.

A notice given under this Data Processing Agreement is valid if sent by email.

Personal Data Processing

Subject matter of processing: Kaiya processes Personal Data provided by Customer when using Kaiya's Software and services as detailed in the Terms. Kaiya is expected to access such Personal Data in order to successfully deliver those services to the Customer, and in particular to enable the Customer to use the Software in its day-to-day recruitment service operations.

Duration of processing: the duration of the Terms.

Business Purposes: as set out in the Terms. The Processing of Personal Data is required in order to deliver the services as set out in the Terms. Kaiya is authorised to process Personal Data as part of delivery of this service. For example, Kaiya's systems may process Personal Data of candidates for roles within the Customer's recruitment activities and this Personal Data will be processed within the Software and used by the Customer.

Approved Sub-Processors: Personal Data may be disclosed to and processed by the Sub-processors listed in the Approved Sub-Processors section only to the extent necessary to provide the Services requested by the Customer, including where a Customer User submits a search request, prompt or workflow containing Personal Data and Kaiya uses an approved Sub-processor to execute that request.

Kaiya shall not permit any Sub-processor to process Customer Personal Data where the relevant Sub-processor's applicable terms permit the Sub-processor to use such Customer Personal Data for training, fine-tuning or improving AI models.

Approved Sub-Processors

Legal EntityPurposeLocationSub-processor information
Elasticsearch Ltd Hosting and Cloud Computing United Kingdom https://www.elastic.co/agreements/external_subprocessors
Microsoft Ltd (for Customers using Teams for Kaiya) Hosting, Cloud Computing and Messaging United Kingdom https://www.microsoft.com/en-gb/trust-center/privacy/data-access
Slack Technologies LLC (for Customers using Slack for Kaiya) Messaging United Kingdom https://slack.com/intl/en-gb/slack-subprocessors
Amazon Web Services Inc Cloud Computing United Kingdom https://aws.amazon.com/compliance/sub-processors/what_has_changed/
OpenAI LLC Cloud Computing United States https://platform.openai.com/subprocessors/openai-subprocessor-list
Perplexity AI Inc Search United States https://trust.perplexity.ai/subprocessors
AlphaAI Technologies Inc Search United States https://trust.tavily.com/subprocessors
Apify Technologies s.r.o. Search European Union https://trust.apify.com/subprocessors
Google LLC Search United States https://cloud.google.com/terms/subprocessors
Exa Labs Inc. Search United States https://trust.exa.ai/subprocessors
Parallel Web Systems Inc Search United States https://trust.parallel.ai
Bullhorn Search United States https://www.bullhorn.com/legal/sub-processors/
SideGuide Technologies, Inc. Search United States https://trust.firecrawl.dev/subprocessors

Personal Data Types

Personal Data obtained as part of the Customer's use of the Software may include personal information which is publicly shared and available, for example through LinkedIn or other websites in which the Data Subject has input their own details in a public forum; personal information which the Data Subject has provided to the Customer when applying for a role, and which Kaiya may Process as Data Processor for the Customer, including CV, job history, work experience and qualifications; information provided by third-party data providers or platforms that the Customer has instructed, engaged or otherwise authorised Kaiya to access; other Personal Data input or otherwise exposed by the Customer to the Software; data automatically captured by the Software during use of it such as input information, transcriptions, and automatically generated information provided by the Software based on prompts input to it; and professional information of the Data Subject, for example their title, qualifications, work experience and job history.

Data Subject Types

Personal Data processed through the Customer's use of the Services may include Personal Data submitted by Customer Users to Kaiya, including prompts, requests, messages, uploaded content, notes, documents and other information entered into the Services; Personal Data stored in or retrieved from Customer-authorised systems, databases or third party platforms that Kaiya is instructed or authorised to access, including Invenias data relating to individuals stored in the Customer's Invenias environment, for the purposes of providing search, reporting and analytics functionality; professional and recruitment-related information, including names, contact details, employer, title, qualifications, work history, candidate records, interview notes, assessments and similar profile data; technical and usage data generated through use of the Services, including logs, audit data and service-generated metadata; and outputs, summaries, reports and analyses generated by the Services based on the foregoing.

Acceptable Use and Security Policies

These Acceptable Use and Security Policies apply to the Customer's and Customer Users' access to and use of the Services.

The purpose of these policies is to protect the security, integrity and availability of the Services; support lawful, safe and responsible use of Kaiya; reduce risk to the Customer, Kaiya, third parties, and data subjects; and define the administrative and security responsibilities of each party.

Customer Responsibility for Access and Administration

The Customer is responsible for determining which individuals are permitted to access the Services; applying any internal restrictions on availability or use of the Services; managing access through its internal controls and any administrative functionality made available by Kaiya; ensuring that Customer Users comply with the Agreement and these policies; and all acts and omissions of Customer Users in connection with the Services, including licence-tier selections or changes made through the Services, as if such acts or omissions were those of the Customer.

Unless the Customer elects to restrict availability of the Services, any individual who falls within the definition of Customer User may begin using the Services by accessing Kaiya.

Permitted Use

The Customer and Customer Users may use the Services only for the Customer's internal business purposes; in accordance with the Agreement, these policies, and applicable law; in a manner consistent with Kaiya's documented intended purpose and functionality; and using only authorised accounts, access methods and integrations.

Prohibited Use

  • Use the Services in breach of applicable law or regulation.
  • Use the Services to infringe the intellectual property, confidentiality, privacy, data protection or other rights of any person.
  • Use the Services to generate, distribute or facilitate unlawful, harmful, threatening, abusive, harassing, defamatory, obscene, discriminatory or fraudulent content.
  • Use the Services to facilitate phishing, spam, malware distribution, credential theft, social engineering, fraud, scams or deceptive practices.
  • Use the Services to store, distribute or transmit viruses, malware or other malicious code.
  • Attempt to gain unauthorised access to the Services, related systems, or any data processed through them.
  • Interfere with, disrupt, probe, scan or test the vulnerability of the Services or related systems except as expressly authorised in writing by Kaiya.
  • Reverse engineer, decompile, disassemble or attempt to extract source code from the Services except to the extent such restriction is prohibited by law.
  • Use the Services to create competing products or services, or to benchmark the Services for external publication, without Kaiya's prior written consent.
  • Use the Services to conduct or facilitate unlawful surveillance, social scoring, unlawful biometric identification, or unlawful profiling of individuals.
  • Use the Services in a way that exploits, harms or sexualises minors.
  • Use the Services to make solely automated decisions producing legal or similarly significant effects on individuals without appropriate human review and legal basis.
  • Use the Services to submit or process data through third-party systems where the Customer lacks the necessary rights, permissions, subscriptions or authorisations.
  • Circumvent or attempt to circumvent rate limits, access controls, safety features or restrictions in the Services.

Sensitive Uses and Human Review

The Customer acknowledges that AI-generated outputs may be probabilistic and may be inaccurate, incomplete or inappropriate.

Accordingly, the Customer shall ensure that appropriately qualified human review is applied before relying on the Services or Outputs for legal advice or legal decision-making; regulated hiring, candidate evaluation or employment decisions; compliance determinations; financial, credit or investment decisions affecting individuals; processing involving special category personal data or similarly sensitive information; or any use case where inaccurate output could reasonably cause material harm.

Input, Source Systems and Permissions

The Customer is responsible for the legality, quality, accuracy and integrity of Input and Customer Data; ensuring it has all necessary rights, permissions and consents to provide Input and Customer Data to Kaiya; ensuring it has all necessary rights, permissions and consents for Kaiya to access and interact with any Third Party Systems on the Customer's behalf where access to Third Party Systems has been enabled by the Customer; and configuring and using the Services in compliance with the Customer's internal policies and regulatory obligations.

The Customer must not instruct Kaiya to take any action that the Customer knows would breach applicable law or the Customer's binding obligations to a third-party provider.

Accounts, Credentials and Access Security

The Customer shall ensure that Customer Users keep login credentials, tokens and access methods confidential and secure; do not share accounts except where expressly permitted by Kaiya; use appropriate password hygiene and, where available, multi-factor authentication; promptly report suspected credential compromise, unauthorised access, or suspicious activity to the Customer and Kaiya; and do not allow access by persons outside the Customer or the named companies identified in the Order Form unless expressly permitted under the Agreement.

Integrations, Apps and Connected Data

Where the Services support integrations, apps, connectors or connected data sources, the Customer is responsible for deciding which such features are enabled for its users; ensuring that only authorised persons and authorised data sources are connected; and ensuring that connected systems are configured in accordance with its internal security and access policies.

Kaiya may disable, limit or suspend any integration, app or connector where reasonably necessary for security, legal compliance, third-party requirements, or platform integrity. Kaiya does not warrant that third-party systems will remain continuously available, compatible or unchanged.

Monitoring, Abuse Prevention and Suspension

Kaiya may monitor use of the Services to protect the security and integrity of the Services; prevent abuse, fraud or unlawful use; investigate suspected breaches of the Agreement or these policies; and comply with law or requests of competent authorities.

Kaiya may limit, suspend or disable access to all or part of the Services where reasonably necessary to comply with law or regulation; where the Customer or a Customer User materially breaches the Agreement or these policies; to prevent or address a security incident, abuse event, infringement risk, credible risk of harm, or other security emergency; or to protect Kaiya, the Customer, other customers, third parties or the Services.

Where reasonably practicable, Kaiya shall use reasonable efforts to notify the Customer in advance of any limitation or suspension, narrow the scope and duration of any limitation or suspension to what is reasonably necessary, and restore access promptly once the relevant issue has been resolved.

Security Measures

Kaiya shall implement and maintain reasonable administrative, physical and technical safeguards designed to protect the security, confidentiality and integrity of Customer Data in Kaiya-controlled environments.

Such safeguards may include, where appropriate, logical access controls, authentication and authorisation controls, encryption in transit and at rest, logging and monitoring, vulnerability management and patching practices, malware protection, backup and recovery measures, incident response procedures, and confidentiality obligations for personnel and subcontractors with access to relevant systems or data.

Security Incidents

Each party shall promptly notify the other upon becoming aware of any confirmed security incident affecting the Services or Customer Data for which that party is responsible, where such notification is required by applicable law or reasonably necessary to mitigate material risk.

Kaiya shall investigate confirmed security incidents within Kaiya-controlled environments and take reasonable steps to contain, mitigate and remediate them.

The Customer shall cooperate reasonably with Kaiya in relation to security incidents arising from the Customer's systems, accounts, credentials, connected data sources, or Customer User actions.

Data Retention and Deletion

The Services may retain data for the period necessary to provide functionality, support security, maintain logs, meet legal obligations and perform the Agreement.

Upon termination, or during the Term where functionality permits, Customer Data shall be handled in accordance with the Agreement and the Data Processing Agreement.

Deleted Customer Data may remain in backup systems or legally required retention environments for a limited period before final deletion, subject to applicable law and Kaiya's standard retention and backup processes.

Policy Updates and Conflict

Kaiya may update these policies from time to time on reasonable prior notice, provided that no update shall materially reduce the Customer's rights or materially expand the Customer's obligations during the then-current Term.

If there is any conflict between these policies and the main body of the Agreement, the main body of the Agreement shall prevail, except to the extent the main body expressly states otherwise.

Kaiya

Product

What is Kaiya?AI for executive searchInvenias assistant

Workflows

Market mappingCandidate longlistsInterview notesPartner prep

Company

PricingSecurityBook a demoFree trial

Legal & docs

PrivacyTermsHelp centreSystem status
© 2026 Kaiya AI Ltd. All rights reserved. hello@kaiya.ai