Version 1.0, effective 11 October 2026
1. How this DPA applies
1.1 This Data Processing Addendum ("DPA") is part of the KissMySkills Terms of Service ("Terms") and is incorporated into them by reference. It is accepted when the Customer accepts the Terms, including through the sign-in checkbox in our apps. We record that acceptance (user, Terms version, time, country and a short user agent). No separate signature is needed.
1.2 If you need a signed copy for your records, write to hello@kissmyskills.com and we will send a PDF countersigned by us. The countersigned PDF has the same content as this page.
1.3 Parties.
- Processor: Dzmitry Pliachko KREAL, trading as KissMySkills, ul. Stanisława Drabika 63/19, 52-131 Wrocław, Poland, NIP PL8992909337, REGON 520256406, hello@kissmyskills.com ("KissMySkills", "we").
- Controller: the business that accepted the Terms and uses the Services ("Customer", "you").
1.4 The DPA is made under Article 28 of Regulation (EU) 2016/679 ("GDPR") and the Polish Act of 10 May 2018 on the Protection of Personal Data.
2. Definitions
- Services: the KissMySkills AI CRM (crm.kissmyskills.com, app.kissmyskills.com), the KissMySkills connector for AI assistants (mcp.kissmyskills.com), Receptionist, Contracts, the Tools hub and free tools on kissmyskills.com, file delivery, and related APIs.
- Customer Personal Data: personal data that you or your users put into the Services, or that third parties submit to you through them (for example a website visitor in your Receptionist chat), and that we process for you.
- Account Data: data about you and your users as our customers (sign-in e-mail, plan, orders, billing, support messages, security logs, product analytics). We are the controller of Account Data; see Annex I, Part B and our Privacy Policy.
- Subprocessor: a third party we engage that processes Customer Personal Data.
- Security Page: www.kissmyskills.com/pages/security.
- Subprocessor List: www.kissmyskills.com/pages/subprocessors.
- Other terms (personal data breach, processing, data subject, supervisory authority) have their GDPR meaning.
3. Roles and instructions
3.1 You are the controller of Customer Personal Data and we are your processor. If you act as a processor for someone else, we are your sub-processor and you confirm that your instructions are authorised.
3.2 We process Customer Personal Data only on your documented instructions. Your instructions are: the Terms, this DPA, how you configure the Services, and the actions you, your users or your AI client take in the Services.
3.3 If EU or Member State law requires us to process otherwise, we will tell you first, unless that law forbids it. We will tell you promptly if we think an instruction breaks data protection law.
3.4 You are responsible for having a lawful basis for the data you put in, for informing data subjects, and for the accuracy of the data.
4. Confidentiality and personnel
4.1 KissMySkills is run by its founder, who is the only person with access to Customer Personal Data in production. If we engage a contractor who needs such access, we do so only under a written confidentiality undertaking and only to the extent strictly needed to run and support the Services.
4.2 We look at workspace content only (a) to give support you ask for, (b) to investigate a security incident or abuse, or (c) where the law requires it. Every platform-admin view or export is logged and alerted to the owner.
5. Security
5.1 We maintain the technical and organisational measures in Annex II, which summarises the measures described in more detail on the Security Page.
5.2 We may update these measures over time, but we will not reduce the overall level of protection of Customer Personal Data during your subscription.
6. Subprocessors
6.1 You give us general authorisation to use the Subprocessors on the Subprocessor List (Annex III).
6.2 We will announce a new or replacement Subprocessor, or a change in the country where an existing one processes Customer Personal Data, on the Subprocessor List and by e-mail to subscribers at least 30 days before the change takes effect. To subscribe, see the Subprocessor List.
6.3 You may object on reasonable data-protection grounds within 30 days of the notice by writing to hello@kissmyskills.com. We will try in good faith to address the objection (for example by not using the Subprocessor for your data, or by offering a configuration that avoids it). If we cannot do so before the change takes effect, you may terminate the affected Services and we will refund prepaid fees for the unused period.
6.4 Each Subprocessor is bound by written data protection terms that protect Customer Personal Data at least as well as this DPA. We remain responsible to you for its performance.
6.5 Your own AI client is not our Subprocessor. When you connect Claude, ChatGPT or another AI assistant to the Services through the connector, you choose that provider, you authorise it through OAuth, and it reads and writes your data under your own agreement with that provider. The same applies to any model API key you supply yourself ("bring your own key", currently switched off).
7. Artificial intelligence
7.1 No training. We do not use Customer Personal Data to train or fine-tune AI models, and we do not allow our Subprocessors to do so.
7.2 When customer data reaches an AI model. Customer Personal Data is sent to an AI model only in two cases:
- (a) by your own AI client, when you or your users ask it to read or act on your data through the connector. This is your choice and happens under your agreement with your AI provider (section 6.5); or
- (b) by features listed on the Subprocessor List that use Cloudflare Workers AI: Receptionist replies to your website visitors, and the free and paid tools on kissmyskills.com. These models run on Cloudflare's infrastructure as part of our hosting; we do not send this data to any third-party model provider, and no third-party model provider keeps it.
7.3 We will not add a third-party AI model provider for Customer Personal Data without the notice and objection process in section 6.
7.4 EU AI Act. The Services are not designed for, and you agree not to use them for, any practice prohibited by Regulation (EU) 2024/1689 (the AI Act), or for high-risk uses listed in its Annex III (for example deciding on hiring, credit or access to essential services) without your own human review and compliance measures. AI output in the Services supports decisions; humans make them. You review AI output before relying on it. The Receptionist chat widget labels itself as an AI assistant in its header, and you must not remove or obscure that label or otherwise suggest to visitors that they are talking to a human.
7.5 More detail is in our AI Terms.
8. International transfers
8.1 Some Subprocessors are located, or may access data, outside the European Economic Area (EEA). The Subprocessor List shows the transfer mechanism for each.
8.2 We transfer Customer Personal Data outside the EEA only where (a) the country has an EU adequacy decision (including the EU-US Data Privacy Framework for certified recipients), or (b) the transfer is covered by the Standard Contractual Clauses in Commission Implementing Decision (EU) 2021/914 ("SCCs"), with supplementary measures where a transfer assessment requires them.
8.3 Where you are outside the EEA and the SCCs are needed for our relationship, the SCCs are incorporated into this DPA by reference, as follows: Module 2 (controller to processor) where you are a controller; Module 3 (processor to processor) where you are a processor; Clause 7 (docking) applies; Clause 9 option 2 (general authorisation) with the notice period in section 6.2; Clause 11 optional language does not apply; Clauses 17 and 18: the law and courts of Poland; Clause 13: the competent supervisory authority is UODO. Annexes I, II and III of this DPA complete the SCC annexes. For UK or Swiss transfers, the UK Addendum or the Swiss adjustments apply as required.
8.4 We pass Customer Personal Data to our Subprocessors outside the EEA under SCCs Module 3 or an adequacy decision.
9. Help with data subject requests and compliance
9.1 We help you answer requests from data subjects (access, rectification, erasure, restriction, portability, objection). Self-service tools: members and admins can view, edit and delete records; admins can export the whole workspace as JSON and delete the workspace (section 12).
9.2 If a data subject contacts us about Customer Personal Data, we forward the request to you without undue delay and do not answer it ourselves, except to say we forwarded it.
9.3 Where the self-service tools are not enough, we help within 10 business days of your written request.
9.4 We help you, on reasonable request, with data protection impact assessments and prior consultations (Articles 35–36 GDPR), based on the information available to us.
10. Personal data breaches
10.1 We notify you of a personal data breach affecting Customer Personal Data without undue delay and in any case within 48 hours of becoming aware of it.
10.2 We send the notice to the e-mail addresses of your workspace admins. It includes, as far as known at the time: what happened, the categories and approximate number of data subjects and records, likely consequences, what we have done and propose to do, and a contact point. We send missing information in stages without further undue delay.
10.3 We take reasonable steps to contain the breach and limit its effects, and we cooperate so that you can meet your duties under Articles 33 and 34 GDPR. A notice from us is not an admission of fault.
11. Government and law enforcement requests
11.1 If a public authority asks us for Customer Personal Data, we will (a) try to redirect it to you; (b) notify you promptly before disclosing, unless the law prohibits it; (c) review the request's lawfulness and challenge it where we have reasonable grounds to think it is unlawful; and (d) disclose only the minimum the request lawfully requires.
11.2 If we are prohibited from notifying you, we will use reasonable efforts to obtain a waiver. We publish a summary of requests received at www.kissmyskills.com/pages/government-requests.
12. Return and deletion
12.1 During the subscription you can export your workspace and delete it at any time.
12.2 Workspace deletion. When an admin deletes a workspace, it is blocked at once and can be restored for 30 days. After that, an automatic job permanently deletes all workspace data, including files stored for the workspace (such as CVs) and the search index.
12.3 After termination. For 30 days after your subscription ends you can still export your data. After that window we delete Customer Personal Data within 30 days, unless EU or Member State law requires us to keep it.
12.4 Backups. Our database platform keeps point-in-time recovery data for up to 30 days. Deleted data therefore leaves recovery copies within 30 days after deletion from the live system.
12.5 At your request we confirm deletion in writing.
12.6 Deleting a user account. Each user can delete their own account without contacting us: in the CRM under Settings > Profile > "Delete account", or by asking their AI client to run the connector tool delete_my_account. Deleting the KissMySkills account also deletes the user's CRM account. A user who is the last admin of a workspace that still has other members must first hand over the admin role or delete the workspace.
13. Audits
13.1 We make available the information needed to show compliance with Article 28 GDPR: this DPA, the Security Page, the Subprocessor List and written answers to a reasonable security questionnaire, once every 12 months (or more often after a personal data breach affecting you).
13.2 If that information is not enough to show compliance, you may ask for further documentation. An on-site audit is possible only where a competent supervisory authority requires it. It needs at least 30 days' written notice, is done during business hours by you or an independent auditor bound by confidentiality, must not disrupt the Services or expose other customers' data, and is at your cost.
14. Liability
14.1 Each party's total liability under this DPA is limited as set out in the Terms. Unless the Terms say otherwise, our total liability under this DPA is limited to the fees you paid us for the Services in the 12 months before the event giving rise to the claim.
14.2 No limitation applies where the law does not allow it, including liability towards data subjects under Article 82 GDPR to the extent it cannot be limited.
15. Term, precedence and law
15.1 This DPA applies as long as we process Customer Personal Data for you.
15.2 If this DPA conflicts with the Terms, this DPA prevails for the processing of Customer Personal Data. If the SCCs apply, they prevail over this DPA.
15.3 We may update this DPA. We will announce material changes at least 30 days in advance by e-mail or in the app. Changes required by law may take effect sooner.
15.4 This DPA is governed by Polish law. The courts of Wrocław, Poland have jurisdiction, without prejudice to mandatory consumer rules. Our lead supervisory authority is the President of the Personal Data Protection Office (Prezes Urzędu Ochrony Danych Osobowych, UODO), ul. Stawki 2, 00-193 Warszawa, Poland.
Annex I — Description of processing
Part A — KissMySkills as processor (Customer Personal Data)
| Item | Description |
|---|---|
| Parties | Customer (controller / data exporter); KissMySkills (processor / data importer) |
| Subject matter | Hosting and operating the Services so that you can run your CRM, project boards, hiring pipeline, website chat and contract register, directly or through your own AI client |
| Duration | The subscription, plus the deletion periods in section 12 |
| Nature | Storage, structuring, search, display, transmission to your users and to the AI client you authorise, automated replies in Receptionist (Cloudflare Workers AI), e-mails you switch on (digests, contract reminders), export, deletion |
| Purpose | Only to provide the Services under the Terms and your instructions. No advertising, no sale, no AI training |
| Data subjects | Your contacts, leads and prospects; your customers and their staff; your team members; job candidates; visitors who use your Receptionist chat; counterparties named in contracts you upload |
| Data categories | Names; e-mail addresses; phone numbers; company, role, address; deal, project and task records; notes, comments and activity history; attachments; CVs and application answers; chat transcripts and contact details left in Receptionist; contract files and extracted text (parties, dates, amounts); content of custom and free-text fields |
| Special categories | Not intended. Do not put Article 9 or 10 GDPR data in the Services unless you have a lawful basis. CVs may incidentally contain such data; you control that pipeline |
| Frequency | Continuous |
| Subprocessors | See Annex III |
| Supervisory authority | UODO (Poland) |
Part B — KissMySkills as controller (for transparency; not covered by Part A)
We decide how to process the following, under our Privacy Policy: Account Data (sign-in e-mail, internal user ID, plan, orders and billing through Shopify), sign-in and session records, records of Terms acceptance, security and audit logs, rate-limit counters, product analytics (PostHog EU, pseudonymous), anonymous storefront analytics, support e-mails, and feedback you send us. We use these to run, secure, bill and improve the Services. We do not use Customer Personal Data for these purposes beyond aggregated, non-identifying service metrics (for example counts of records or requests).
Annex II — Technical and organisational measures (summary)
The Security Page describes these measures in more detail and is updated as they improve. We will not lower the overall level of protection described here (section 5.2).
- Infrastructure. All Services run serverless on Cloudflare (Workers, D1, KV, R2); no self-managed servers. Data in transit uses TLS; HSTS (1 year) is set. Data at rest is encrypted by the platform.
- Tenant isolation. Every query is scoped to the workspace; membership is re-checked on every request; all SQL is parameterised; invitations take effect only after the invitee accepts.
- Authentication. No passwords. Sign-in by a 6-digit e-mail code (stored only as a hash, valid 15 minutes, 5 attempts per code, protection against parallel guessing, limited code requests per e-mail address) or a one-tap link. The connector uses OAuth with PKCE and hashed tokens.
-
Sessions. Signed,
Secure,HttpOnly,SameSite=Laxhost-only cookie (__Host-kms_crm) carrying a session ID that can be revoked server-side per session or per account; logout and "log out everywhere"; 7-day idle timeout with sliding renewal and a 30-day maximum lifetime. Revoking sessions in the connector also ends CRM sessions. -
Application security. Enforced Content-Security-Policy with per-response nonces;
X-Frame-Options: DENY;nosniff;no-referrer. Write rate limits, storage quotas and field size limits per plan. Production dependencies checked for known vulnerabilities (none known on 10 October 2026). - Administrative access. Internal admin tools sit behind Cloudflare Access (owner only) plus server-side token verification. Every admin view and export is logged and alerted to the owner.
- Monitoring and logging. Operational alerts to the owner contain no names or e-mail addresses, only pseudonymised identifiers, workspace IDs and country. Product analytics are hosted in the EU (PostHog, Frankfurt); session replays mask all text and inputs, and error reports are scrubbed.
- Data lifecycle. Workspace deletion with 30-day restore, then permanent deletion of all workspace data including files (CVs) and the search index; the admin access log keeps only a blanked entry. Self-service account deletion (CRM Settings and the connector). Automatic retention limits: Receptionist conversations 180 days after last activity, Receptionist leads and bookings 24 months, operational and usage logs 6 to 24 months depending on type (see the retention section of our Privacy Policy). Full workspace export (JSON) for admins. Platform point-in-time recovery (Cloudflare D1 Time Travel) rolls off within 30 days.
- AI. No training on Customer Personal Data. Our own AI features run on Cloudflare Workers AI only. Third-party AI is used only through the customer's own AI client.
- Incident response. Written breach-response runbook; customer notice within 48 hours.
- Organisation. One owner-operator is responsible for security and data protection and is the only person with production access; any contractor works under a written confidentiality undertaking with access limited to what is strictly needed.
Annex III — Subprocessors
The current list, with purpose, data, location and transfer mechanism, is at www.kissmyskills.com/pages/subprocessors. Changes follow section 6.
Change history
| Version | Date | Change |
|---|---|---|
| 1.0 | 11 October 2026 | First published version |