This Data Processing Addendum ("DPA") becomes effective only when executed by both parties or expressly incorporated into an executed Order Form. Once effective, it forms part of the agreement between Kronisys Inc. ("Kronisys", "we", "Processor") and the customer organization identified in the applicable Order Form ("Customer", "Controller") governing Customer's use of the Strata platform and related services (the "Services"). That agreement consists of our Terms of Service, together with the Privacy Policy, the Usage Policy, any executed Order Form or enterprise agreement, and — where expressly incorporated into an executed Order Form — the Service Level Agreement (collectively, the "Agreement").
This DPA applies where Kronisys processes Personal Data on behalf of Customer through the Services. In the event of a conflict between this DPA and the rest of the Agreement with respect to the processing of Personal Data, this DPA controls. In all other respects, the Agreement remains in full force and effect.
How to put this DPA in place. Enterprise customers may execute this DPA as part of their Order Form, or request a counter-signed copy, by contacting legal@kronisys.com. Capitalized terms not defined here have the meaning given in the Agreement or in applicable Data Protection Laws.
With respect to Personal Data processed in connection with the Services, Customer is the Controller and Kronisys is the Processor. Where Customer acts as a processor on behalf of a third-party controller, Kronisys acts as a sub-processor, and Customer is responsible for the third-party controller's authorizations and instructions.
Kronisys processes Personal Data only on Customer's documented instructions, including with regard to international transfers, unless required to do otherwise by applicable law — in which case Kronisys will inform Customer of that legal requirement before processing, unless the law prohibits such notice on important grounds of public interest.
The Agreement, this DPA, and Customer's configuration and use of the Services (including connecting integrations, deploying agents, defining roles, and setting retention and lock policies) constitute Customer's complete and final processing instructions. Additional instructions outside the scope of the Agreement require a separate written agreement.
Subject matter. Provision of the Strata AI enterprise intelligence platform and related support, as described in the Agreement.
Nature and purpose. Kronisys processes Customer Data to: authenticate users via Microsoft Entra ID Single Sign-On; provide AI chat and analysis by routing prompts to AI models through Microsoft Azure AI Foundry; retrieve live results from our web search provider (Brave Search) for conversations where web search is enabled; execute live queries against Customer-connected SQL Server databases; search, read, and (where authorized) save files in connected OneDrive; index and read documents from connected SharePoint sites for the organization knowledge base; search, read, draft, and send email via connected Outlook; create meetings and post messages via connected Microsoft Teams, including operating the Strata bot within Customer's Teams channels; search and read Jira Software issues and Jira Service Management requests, and, where the Customer's administrator has enabled writes, create issues and post internal comments on Customer's behalf; search Confluence spaces and read Confluence pages, and, where the Customer's administrator has enabled writes, create pages and post comments on Customer's behalf; authenticate and process requests made through the Strata API using organization-issued API keys and deliver event notifications to Customer-configured webhook endpoints; generate charts, Excel, PDF, and other deliverables; run scheduled and on-demand agents; and produce usage, audit, and billing records.
Duration. Kronisys processes Personal Data for the term of the Agreement, plus the retention periods described in Section 11 and Annex I.
Categories of Data Subjects and Personal Data. As determined by Customer's configuration and use of the Services. See Annex I. Customer is responsible for ensuring it has a lawful basis to submit Personal Data to the Services and, consistent with the Usage Policy, for not submitting special-category or specially regulated data (for example, data subject to HIPAA, PCI-DSS, FERPA, or GLBA) unless Customer has executed an enterprise agreement that expressly permits such data and Kronisys has implemented the corresponding controls.
Kronisys will:
Kronisys maintains appropriate technical and organizational measures designed to protect Personal Data, taking into account the state of the art, the costs of implementation, and the nature, scope, context, and purposes of processing. These measures, described in full in the Privacy Policy and the Security & Responsible Disclosure Policy, include without limitation:
No certifications are claimed. Strata runs on Microsoft Azure and inherits the platform security of the underlying Azure services, but Kronisys does not represent that it holds any independent certification (such as SOC 2, ISO 27001, or FedRAMP). Those are Microsoft's to certify for the platform, not ours to claim.
Kronisys ensures that personnel authorized to process Personal Data are bound by appropriate obligations of confidentiality (whether contractual or statutory), receive appropriate data-protection training, and are granted access only where needed to provide and support the Services. These obligations survive the end of each individual's engagement.
General authorization. Customer provides general written authorization for Kronisys to engage Sub-processors to process Personal Data, subject to this Section.
Flow-down and responsibility. Kronisys imposes on each Sub-processor data-protection obligations that are no less protective than those in this DPA, and remains responsible for each Sub-processor's performance of its obligations. Where a Sub-processor is reached through Customer's own account or tenant — as with Customer's Atlassian Cloud site — the terms governing that provider's processing are those of Customer's own agreement with it, and Kronisys's obligation is to access it only as Customer instructs.
Current list. The authoritative, current list of Sub-processors is maintained on the Sub-processors page and reproduced in Annex II. It includes Microsoft Azure (hosting, database, file storage, and transactional email), Microsoft Azure AI Foundry (AI model routing, through which the AI model providers — including OpenAI, Anthropic, xAI, DeepSeek, Mistral AI, Cohere, and Microsoft — are reached), Brave Search (the web search provider used for conversations where web search is enabled), Stripe, Inc. (payment processing, invoicing, and subscription billing), Mapbox, Inc. (maps, geocoding, and place lookup), Google LLC (venue photographs through the Google Places API), the IP geolocation chain of ipapi.co, ip-api.com and ipwho.is, CARTO and unpkg (the fallback map used when Mapbox is unavailable), and — where Customer enables the Jira or Confluence extension — Atlassian (Jira and Confluence Cloud). Microsoft 365 / Microsoft Graph services (Outlook, OneDrive, SharePoint, and Teams) act as data sources connected at Customer's direction. Where Customer brings its own Microsoft Azure AI Foundry deployment, AI model inference is routed to that Customer-controlled resource. Atlassian pins Customer's Jira and Confluence data to the region configured for Customer's Atlassian site; Kronisys's platform database and Customer's Azure AI Foundry deployment are separate systems with their own regions.
Change notice and objection. Kronisys will provide enterprise customers at least 30 days' notice before adding or replacing a Sub-processor, by email to designated administrators. Customer may object in writing on reasonable data-protection grounds within 30 days of notice by emailing legal@kronisys.com. If Kronisys cannot reasonably accommodate the objection, Customer may terminate the affected portion of the Services without penalty by giving written notice within 30 days of Kronisys's response.
Taking into account the nature of the processing, Kronisys will assist Customer by appropriate technical and organizational measures, insofar as possible, in fulfilling Customer's obligations to respond to Data Subject requests to exercise rights of access, rectification, erasure, restriction, portability, and objection.
Strata provides Customer and its administrators with self-service tooling that supports these obligations, including in-product deletion of individual conversations, viewing and deletion of memory entries, disconnection and deletion of database credentials, administrator management and deletion of user accounts, configurable audit-log retention, and export of conversation history, memory entries, and account data in a structured machine-readable (JSON) format.
If Kronisys receives a request directly from a Data Subject relating to Customer's Personal Data, it will, where permitted, promptly forward the request to Customer and will not respond directly except on Customer's documented instructions.
Kronisys will notify Customer without undue delay, and in any event within 72 hours of confirming a Personal Data Breach affecting Customer's Personal Data, in accordance with GDPR Article 33 and other applicable Data Protection Laws.
The notification will include, to the extent known: the nature of the breach, the categories and approximate number of Data Subjects and records affected, the likely consequences, and the measures taken or proposed to address and mitigate it. Where the information is not all available at once, Kronisys may provide it in phases without further undue delay.
Kronisys will reasonably cooperate with Customer in Customer's investigation and in any notifications Customer is required to make to Supervisory Authorities or Data Subjects. Notification of, or response to, a breach is not an acknowledgment by Kronisys of fault or liability.
Upon termination or expiry of the Agreement, and at Customer's choice, Kronisys will return or delete Customer's Personal Data, unless retention is required by applicable law. Customer may request export of conversation history, saved memory entries, and account data in JSON format within 30 days of termination, consistent with the Terms of Service; requests submitted after that window may not be fulfillable as data may have been purged.
For as long as the Agreement is in force, conversation history is retained indefinitely by default: a user removing a conversation from their own view hides it but does not erase it, because Customers commonly require complete chat history for supervision and recordkeeping. Customer's administrator may configure an organization-wide retention period, after which removed conversations are permanently deleted by an automated job; where no such period is configured, no automatic deletion occurs. Memory entries are removed on deletion. Audit logs are deleted on the organization's configured retention schedule (default 365 days). Activity logs are handled differently: on the same schedule their free-text and IP address columns are stripped, while the de-identified usage and cost row is retained as billing and usage-reporting data. Data flagged for safety review or required by law may be retained for up to three years. Customer may at any time instruct Kronisys to erase specific conversations or the organization's data in full, and Kronisys will act on that instruction as a Processor under Section 5. Where Customer's subscription is cancelled, Kronisys records a retention deadline 30 days after cancellation. No Personal Data is deleted during that period, and Customer's administrators retain access to the administrative surfaces to export data or instruct erasure sooner; reactivating the subscription clears the deadline. On expiry the organization is scheduled for permanent deletion and all records belonging to it are destroyed by a job that runs once a day, so deletion takes effect on the first run after the deadline passes: at least 30 days after cancellation, and never sooner. Kronisys does not send advance notice of this deletion.
Personal Data may be processed in the United States and other countries where Kronisys or its Sub-processors operate. The Azure region(s) used for hosting and processing are described in Annex I and the Privacy Policy.
Where processing involves a transfer of Personal Data from the European Economic Area, the United Kingdom, or Switzerland to a country that does not provide an adequate level of protection, the parties rely on an appropriate transfer mechanism, including European Commission adequacy decisions, the EU Standard Contractual Clauses (SCCs), the UK International Data Transfer Addendum to the SCCs for UK transfers, and other legally recognized mechanisms. The applicable mechanism is described in Annex III and incorporated by reference.
Kronisys will make available to Customer the information reasonably necessary to demonstrate compliance with this DPA, and will allow for and contribute to audits, including inspections, conducted by Customer or an auditor mandated by Customer. Audits are subject to reasonable confidentiality obligations and to reasonable limitations on scope, frequency (no more than once per twelve months absent a Supervisory Authority requirement or a confirmed breach), and advance notice. Where available, Kronisys may satisfy an audit request by providing relevant third-party reports, attestations, or summaries of the underlying Azure platform.
Each party's liability arising out of or related to this DPA is subject to the limitations and exclusions of liability set out in the Terms of Service, which apply in the aggregate across the Agreement and this DPA.
This DPA is governed by the same law and dispute-resolution provisions as the Agreement (the laws of the State of Florida, United States, as set out in the Terms of Service), except where Data Protection Laws require otherwise. Except as expressly amended by this DPA with respect to the processing of Personal Data, the Agreement remains unchanged and in full force.
| Item | Detail |
|---|---|
| Categories of Data Subjects | Customer's employees, contractors, and authorized users; and individuals whose Personal Data appears in Customer's connected data sources or submitted content (for example, recipients of emails, parties named in documents, or records in connected databases). |
| Categories of Personal Data | Names and business contact details; account identifiers and authentication metadata, including organization-issued API keys and configured webhook endpoints; the content of prompts, messages, files, and emails; query results; usage, audit, and billing records. |
| Special categories | None. Customer must not submit special-category or specially regulated data except under an enterprise agreement that expressly permits it (see the Usage Policy). |
| Processing operations | Authentication; AI chat and analysis via Microsoft Azure AI Foundry; SQL query execution; file and email search, read, and authorized write; Jira issue and service-request search, read, and authorized write; Confluence space and page search, read, and authorized write; deliverable generation; agent execution; programmatic processing via the Strata API and delivery of webhook notifications; operation of the Strata Microsoft Teams bot; usage, audit, and billing logging. |
| Frequency | Continuous, for the term of the Agreement. |
| Retention | As described in Section 11 and the Privacy Policy (conversation history retained indefinitely while the Agreement is in force, unless the Customer configures a retention period; on cancellation, all organization data is permanently deleted at least 30 days later; audit logs default 365 days; safety/legal holds up to 3 years). |
| Hosting region(s) | United States; the specific Azure region varies by deployment. Where Customer enables the Jira or Confluence extension, that content is additionally processed in the region of Customer's Atlassian Cloud site, which Atlassian pins to that site. That region is separate from the Azure region hosting the Strata platform and from the region of Customer's own Microsoft Azure AI Foundry deployment, so content passing between them crosses regions by design. |
The following is a point-in-time snapshot of the Sub-processors engaged to deliver the Services. The authoritative, current list — including change-notice and objection terms — is maintained on the Sub-processors page.
| Sub-processor | Purpose | Data Processed | Location |
|---|---|---|---|
| Microsoft Azure (App Service, SQL Database, Blob Storage, Communication Services) | Hosting, database, file storage, transactional email | All customer data | United States (Azure region varies by deployment) |
| Microsoft Azure AI Foundry | AI model routing and inference. Models from OpenAI, Anthropic, xAI, DeepSeek, Mistral AI, Cohere, and Microsoft are reached through Foundry under Microsoft's enterprise terms (no training on customer data). | Prompts and responses | United States |
| Brave Search (Brave Software, Inc.) | Live web results for conversations where web search is enabled | Search queries derived from prompts | United States |
| Stripe, Inc. | Payment processing, invoicing, and subscription billing (ACH debit, card, hosted invoices) | Billing contact details, billing address, tax ID; payment-method metadata (card/bank last four). Full card and bank account numbers are entered on Stripe-hosted surfaces and are not stored by Kronisys. | United States |
| Atlassian (Jira and Confluence Cloud) | Reading from, and — where Customer's administrator has enabled writes — creating content in, Customer's Atlassian Cloud site. Engaged only where Customer enables the Jira or Confluence extension. | Jira issue and request fields and comments; Confluence page and space content and comments; the project, queue, space, and participant metadata returned with them | Region of Customer's Atlassian Cloud site, as configured by Customer |
| Mapbox, Inc. | Rendering interactive maps, converting addresses into coordinates (geocoding), and looking up named places when Strata answers a location question. Engaged only where Customer allows geocoding. | Address, place-name and search text drawn from prompts, query results, or connected data, and the coordinates returned for it. Map styles and tiles load directly in the browser, so the viewing device's IP address and the map area being viewed also reach Mapbox. | United States |
| Google LLC (Google Places API) | Retrieving a photograph of a named venue for a place card, and only where a place lookup was run with venue detail requested. | The venue name, address and coordinate already resolved through Mapbox. Photographs are relayed through Kronisys, so no browser IP address reaches Google. | United States |
| ipapi.co | IP geolocation lookup for sign-in location display. First provider tried. Engaged only where remote geolocation is enabled for the deployment. | A truncated IP address only — the final octet of an IPv4 address is zeroed, and an IPv6 address is cut to its first three segments. | United States |
| ip-api.com | IP geolocation lookup. Fallback, used only when the provider above fails or times out. Reached over plain HTTP rather than TLS. | A truncated IP address only, as above. | Not disclosed by the provider |
| ipwho.is | IP geolocation lookup. Fallback, used only when both providers above fail or time out. | A truncated IP address only, as above. | Not disclosed by the provider |
| CARTO (Carto Inc.) and unpkg | Serving the fallback map. When Mapbox is unavailable, Strata draws the map with the Leaflet library (loaded from unpkg) over CARTO basemap tiles. | The viewing device’s IP address and the map area being viewed, because tiles and the library load directly in the browser. No address text, prompt content, or account data is sent. | United States |
The three IP geolocation providers form a single fallback chain and are tried in the order listed; the first to answer ends the request. Kronisys does not send a full IP address to any of them.
Atlassian pins Customer's Jira and Confluence data to the region configured for Customer's Atlassian Cloud site. That region is separate from the Azure region hosting Kronisys's platform database and from the region of Customer's own Microsoft Azure AI Foundry deployment; Jira and Confluence content therefore crosses regions by design when Strata reads it or writes to it. Customer's Atlassian Cloud site remains governed by Customer's own agreement with Atlassian.
For transfers of Personal Data subject to GDPR to a country without an adequacy decision, the parties incorporate the EU Standard Contractual Clauses (Commission Implementing Decision (EU) 2021/914), Module Two (Controller to Processor), with Kronisys as "data importer" and Customer as "data exporter." The optional docking clause applies; the governing law and competent Supervisory Authority are those of Customer's EU establishment or, where Customer has none, as determined under the SCCs. The technical and organizational measures in Section 6 and the processing details in Annex I serve as the corresponding SCC annexes.
For transfers subject to the UK GDPR, the parties incorporate the UK International Data Transfer Addendum to the EU SCCs. For transfers subject to Swiss law, references to the GDPR and the EU Supervisory Authority are read as references to the Swiss FADP and the Swiss Federal Data Protection and Information Commissioner. Where Customer requires a separately executed copy of these clauses, contact legal@kronisys.com.
Questions about this DPA, or requests to execute it, can be sent to: