Data Processing Addendum
Last updated: 25 August 2026
This addendum applies where Pybex processes personal data on your organization's behalf. It forms part of the Terms of Service.
1. Scope and roles
Where you use Krrim to store personal data — in tasks, comments, documents, attachments or custom fields — your organization is the controller and Pybex Technology Private Limited is the processor.
For our own account, billing and website data we act as controller. That processing is described in the privacy policy and is outside this addendum.
2. Processing details
| Subject matter | Provision of the Krrim project management service |
|---|---|
| Duration | For the term of the agreement, plus the deletion window in section 9 |
| Nature and purpose | Hosting, storage, transmission, backup and display of customer content, and the notifications and integrations you enable |
| Types of personal data | Names, email addresses, profile details, and any personal data the controller chooses to place in workspace content |
| Categories of data subject | The controller’s personnel, its guests and clients, and any individual referenced in workspace content |
3. Our obligations
Pybex will:
- Process personal data only on documented instructions from the controller, including for international transfers, unless legally required otherwise — in which case we will tell you where we may.
- Ensure that personnel authorised to process personal data are bound by confidentiality.
- Implement the measures described in section 4.
- Not sell personal data, and not use customer content to train machine learning models.
- Assist the controller, so far as reasonable, with data subject requests, impact assessments and consultations with supervisory authorities.
4. Security measures
The technical and organisational measures we apply include, at minimum:
- Separation. Each organization’s data is held in its own PostgreSQL schema, so isolation between customers is enforced by the database rather than by application logic.
- Encryption. TLS for all data in transit. Stored credentials — webhook signing secrets, SSO client secrets — encrypted at rest. API tokens stored only as a hash.
- Access control. Role-based access within the product, optional OIDC single sign-on, and least-privilege access for our own personnel.
- Auditability. Every write records the actor, time, source IP, user agent and request identifier — with automated actions attributed to a named service account.
- Egress control. Customer-configured outbound requests are validated at save time and again at every send, against all resolved addresses.
The security page describes these in more detail, including the certifications we do not currently hold.
5. Sub-processors
The controller gives general authorisation for Pybex to engage sub-processors. The current list is published at krrim.com/legal/subprocessors.
We will give at least 30 days’ notice before adding one, and the controller may object on reasonable data protection grounds within that period. Each sub-processor is bound by data protection obligations no less protective than those in this addendum, and we remain liable for their performance.
6. International transfers
Where personal data is transferred outside the region in which it was collected, that transfer is covered by an appropriate safeguard — typically Standard Contractual Clauses, which are incorporated by reference and available on request.
7. Personal data breaches
Pybex will notify the controller without undue delay, and in any event within 72 hours of becoming aware of a personal data breach affecting their data. The notification will describe what is known about the nature of the breach, the categories and approximate number of records affected, the likely consequences, and the measures taken or proposed.
8. Audit
On reasonable written request, and no more than once a year unless required by a supervisory authority, Pybex will make available the information necessary to demonstrate compliance with this addendum and will contribute to an audit conducted by the controller or an independent auditor it appoints. Audits are subject to confidentiality and must not compromise the security of other customers’ data.
9. Return and deletion
The controller may export its data at any time while the agreement is in force. After termination the data remains available for export for 30 days, after which it is deleted from the Service.
Backups follow their own retention cycle and expire within 30 days; data in an unexpired backup is not restored to the Service.
10. Order of precedence
Where this addendum conflicts with the Terms of Service on the processing of personal data, this addendum prevails.
11. Requesting a signed copy
If your organization needs an executed copy on file, write to privacy@krrim.com with your workspace name and the signing entity, and we will send one.