This Data Processing Agreement ("DPA") is entered into between you ("Customer", "Controller") and Bearworks Limited, a company registered in England & Wales (company number 12215420, registered office Unit J, Williams Yard, Melbourne, Derbyshire DE73 7GQ) ("Koo", "Processor"). It is automatically incorporated into our Terms of service when you use the Service to process personal data about your end users or website visitors.
1. Roles
For personal data you submit to the Service about your end users or the visitors to websites you publish through Koo, you are the Controller and Koo is the Processor under UK GDPR Art. 28 (and EU GDPR Art. 28 where applicable). Personal data Koo collects directly from you about your own account is covered by our Privacy policy, where Koo is the controller.
2. Subject matter, duration, nature and purpose
- Subject matter: processing of personal data necessary to provide the Koo Service to you.
- Duration: for as long as your account is active, plus the retention windows set out in the Privacy policy.
- Nature & purpose: hosting, storage, transmission, analysis, AI generation, search-engine and AI-search optimisation, lead capture, transactional email and other operations needed to deliver the Service.
3. Types of personal data and categories of data subjects
- Data subjects: your end users, website visitors, leads and contacts.
- Categories of data: contact details (name, email, phone), IP address, browser/device metadata, content submitted via forms, lead and analytics data, and any other personal data the Controller chooses to upload or generate via the Service.
4. Processor obligations
- Process personal data only on documented instructions from the Controller (these Terms and use of the product constitute documented instructions).
- Ensure personnel authorised to process the data are bound by confidentiality.
- Implement appropriate technical and organisational measures (TLS in transit, encryption at rest, role-based access, RLS in the database, MFA on administrative accounts, logging).
- Assist the Controller, taking into account the nature of the processing, in fulfilling its obligations to respond to data-subject requests.
- Assist with security, breach notification, data-protection impact assessments and prior consultations (UK GDPR Art. 32–36).
- Notify the Controller without undue delay (and in any event within 72 hours of becoming aware) of any personal-data breach affecting the Controller's data.
- At the Controller's choice, delete or return all personal data at the end of the relationship, save where law requires retention.
- Make available to the Controller the information necessary to demonstrate compliance with this DPA.
5. Sub-processors
The Controller gives general authorisation for Koo to engage the sub-processors listed below. Koo will notify the Controller of any intended changes to this list by updating this page; if the Controller objects within 14 days of the change being posted, the parties will use reasonable endeavours to find a workaround, failing which the Controller may terminate the relevant part of the Service.
- Cloudflare, Inc. — edge hosting, DNS, DDoS protection.
- Supabase, Inc. — database, authentication, storage.
- Inngest, Inc. — background job processing.
- OpenAI, OpCo, LLC — AI inference (enterprise terms; no training on Customer data).
- Anthropic, PBC — AI inference (enterprise terms; no training on Customer data).
- Google LLC — Google OAuth sign-in and Google Business Profile integration where the Controller connects them.
- Lovable Email (Lovable AB) — transactional and authentication email delivery.
- Semrush Inc. — SEO and keyword research data, where used.
6. International transfers
Where Koo or a sub-processor processes personal data outside the UK, transfers are made under the UK International Data Transfer Agreement (IDTA), the UK Addendum to the EU Standard Contractual Clauses, or the UK Extension to the EU–US Data Privacy Framework where the importer is certified.
7. Audit
Koo will respond to reasonable written requests for information about its data-protection measures. On reasonable notice and during normal business hours, the Controller may audit Koo's compliance once per twelve-month period, at the Controller's cost, subject to confidentiality and reasonable security restrictions.
8. Liability
The liability provisions in our Terms of service (including the exclusions and the legal carve-outs that cannot be excluded under English law) apply to this DPA in full.
9. Term and termination
This DPA continues for as long as Koo processes personal data on behalf of the Controller. On termination Koo will, at the Controller's choice, delete or return Customer personal data within a reasonable period unless retention is required by law.
10. Governing law
This DPA is governed by the laws of England & Wales and the courts of England and Wales have exclusive jurisdiction.
11. Contact
Bearworks Limited · Unit J, Williams Yard, Melbourne, Derbyshire DE73 7GQ · Contact: hello@koo.co.
