Data Processing Agreement

Last updated: August 5, 2026

This Data Processing Agreement (“DPA”) forms an integral part of the Terms of Service available at helpkit.so/terms (the “Agreement”) between the customer identified in the applicable account registration (“Customer”) and Seven Degrees Labs LLC (HelpKit.so), 30 N Gould St Ste R, Sheridan, WY 82801, USA (“HelpKit”), together the “Parties”.

This DPA is hereby incorporated by reference into the Agreement and is entered into automatically when Customer accepts the Agreement or uses the Services. No additional signature is required for this DPA to be legally binding (Art. 28(9) GDPR). If the Parties have separately executed an individually negotiated data processing agreement, that agreement prevails over this DPA to the extent of any conflict.

This DPA applies to the extent HelpKit processes Customer Personal Data on behalf of Customer in the course of providing the Services and such processing is subject to Data Protection Laws.

1. Definitions

1.1 In this DPA, the following terms have the meaning set out below. Capitalized terms not defined here have the meaning given in the Agreement.

  • “Customer Personal Data” means any Personal Data processed by HelpKit (or a Subprocessor) on behalf of Customer pursuant to or in connection with the Agreement;
  • “Data Protection Laws” means all applicable laws relating to the processing of Personal Data, including the GDPR, the UK GDPR, the Swiss Federal Act on Data Protection (FADP) and, to the extent applicable, the data protection or privacy laws of any other country;
  • “GDPR” means Regulation (EU) 2016/679 (General Data Protection Regulation);
  • “EEA” means the European Economic Area;
  • “Services” means the HelpKit services provided to Customer under the Agreement, i.e. software that turns Customer’s Notion content into hosted knowledge bases, help centers and documentation sites, including related widgets, AI assistance and support;
  • “Standard Contractual Clauses” or “SCCs” means the standard contractual clauses for the transfer of personal data to third countries adopted by the European Commission in Implementing Decision (EU) 2021/914 of 4 June 2021;
  • “Subprocessor” means any third party engaged by or on behalf of HelpKit to process Customer Personal Data in connection with the Agreement.

1.2 The terms “Controller”, “Processor”, “Data Subject”, “Member State”, “Personal Data”, “Personal Data Breach”, “Processing” and “Supervisory Authority” have the same meaning as in the GDPR, and their cognate terms shall be construed accordingly.

2. Roles of the Parties

2.1 As between the Parties, Customer is the Controller of Customer Personal Data and HelpKit is a Processor acting on behalf of Customer. Where Customer itself acts as a Processor for a third-party Controller, HelpKit acts as Customer’s Subprocessor; Customer warrants that its instructions and this DPA are consistent with its obligations towards that Controller.

2.2 This DPA does not apply to Personal Data that HelpKit processes as an independent Controller for its own purposes (e.g. Customer’s account and billing relationship with HelpKit), which is described in the HelpKit Privacy Policy.

3. Processing of Customer Personal Data

3.1 HelpKit shall:

  • comply with all applicable Data Protection Laws when processing Customer Personal Data; and
  • process Customer Personal Data only on Customer’s documented instructions, unless processing is required by applicable law to which HelpKit is subject, in which case HelpKit shall inform Customer of that legal requirement before processing (unless prohibited by law).

3.2 The Agreement, this DPA and Customer’s use and configuration of the Services constitute Customer’s complete and documented instructions to HelpKit. Additional instructions require prior written agreement of the Parties.

3.3 The subject matter, duration, nature and purpose of the processing, and the categories of Personal Data and Data Subjects, are described in Annex 1.

3.4 Customer is responsible for the accuracy, quality and legality of Customer Personal Data and for ensuring it has a lawful basis for the processing instructed under this DPA. The Services are not intended for the processing of special categories of Personal Data (Art. 9 GDPR, e.g. health data) or data relating to criminal convictions (Art. 10 GDPR), and Customer shall not submit such data to the Services.

4. Confidentiality of Personnel

HelpKit shall take reasonable steps to ensure the reliability of any employee, agent or contractor who may have access to Customer Personal Data, ensuring in each case that access is strictly limited to those individuals who need to know or access the relevant Customer Personal Data for the purposes of the Agreement, and that all such individuals are subject to confidentiality undertakings or professional or statutory obligations of confidentiality.

5. Security

5.1 Taking into account the state of the art, the costs of implementation and the nature, scope, context and purposes of processing, as well as the risk of varying likelihood and severity for the rights and freedoms of natural persons, HelpKit shall implement and maintain appropriate technical and organizational measures to ensure a level of security appropriate to the risk, including, as appropriate, the measures referred to in Art. 32(1) GDPR. The measures currently implemented are described in Annex 2.

5.2 HelpKit may update the measures in Annex 2 from time to time, provided such updates do not materially reduce the overall level of security.

6. Subprocessing

6.1 Customer provides a general written authorization for HelpKit to engage the Subprocessors listed in Annex 3, and additional or replacement Subprocessors subject to this Section 6.

6.2 HelpKit shall give Customer prior notice of the addition or replacement of any Subprocessor (by updating Annex 3 and/or by email) at least ten (10) days before the new Subprocessor processes Customer Personal Data. Customer may object in writing to support@helpkit.so within ten (10) days of such notice on reasonable data protection grounds. The Parties shall then discuss the objection in good faith; if no resolution is found within thirty (30) days, either Party may terminate the affected Services, and HelpKit shall refund any prepaid fees covering the remaining term after the effective date of termination.

6.3 HelpKit shall impose data protection obligations on each Subprocessor by way of a written contract that provides in substance the same level of protection for Customer Personal Data as this DPA, and HelpKit remains fully liable to Customer for the performance of each Subprocessor’s obligations.

7. Data Subject Rights

7.1 Taking into account the nature of the processing, HelpKit shall assist Customer by appropriate technical and organizational measures, insofar as this is possible, in fulfilling Customer’s obligation to respond to requests for exercising Data Subject rights under Data Protection Laws (Art. 12–23 GDPR).

7.2 HelpKit shall:

  • promptly notify Customer if it receives a request from a Data Subject under any Data Protection Law in respect of Customer Personal Data; and
  • not respond to that request except on Customer’s documented instructions or as required by applicable law, in which case HelpKit shall, to the extent permitted by law, inform Customer of that legal requirement before responding.

8. Personal Data Breach

8.1 HelpKit shall notify Customer without undue delay after becoming aware of a Personal Data Breach affecting Customer Personal Data, providing Customer with sufficient information to allow Customer to meet its obligations to report the breach or inform Data Subjects under Data Protection Laws.

8.2 HelpKit shall cooperate with Customer and take reasonable commercial steps as directed by Customer to assist in the investigation, mitigation and remediation of each such Personal Data Breach.

9. Data Protection Impact Assessment and Prior Consultation

Taking into account the nature of the processing and the information available to HelpKit, HelpKit shall provide reasonable assistance to Customer with any data protection impact assessments and prior consultations with Supervisory Authorities which Customer reasonably considers to be required by Art. 35 or 36 GDPR or equivalent provisions of any other Data Protection Law, in each case solely in relation to the processing of Customer Personal Data under this DPA.

10. Deletion or Return of Customer Personal Data

10.1 Upon termination or expiry of the Agreement (the date of cessation of the Services, the “Cessation Date”), HelpKit shall, at Customer’s choice, delete or return all Customer Personal Data. Unless Customer requests earlier deletion, HelpKit retains Customer Personal Data for up to ninety (90) days after the Cessation Date to allow Customer to reactivate the Services, after which it is deleted from production systems. Upon Customer’s written deletion request, deletion from production systems occurs within thirty (30) days of the request. Copies contained in encrypted backups are overwritten in the course of routine backup rotation within one hundred eighty (180) days of deletion from production systems. HelpKit may retain Customer Personal Data to the extent required by applicable law, for as long as and to the extent so required.

10.2 Upon Customer’s written request, HelpKit shall confirm in writing that it has complied with this Section 10.

10.3 This Section 10 does not apply to aggregated or anonymized data that no longer identifies, and can no longer reasonably be linked to, any natural person; HelpKit may retain such data for statistical purposes and service improvement.

11. Audit Rights

11.1 HelpKit shall make available to Customer on request all information reasonably necessary to demonstrate compliance with this DPA and Art. 28 GDPR, and shall allow for and contribute to audits, including inspections, conducted by Customer or an auditor mandated by Customer.

11.2 Audit requests shall in the first instance be satisfied by HelpKit providing relevant, up-to-date documentation and written responses to reasonable information requests (a “documentation audit”). More extensive audit measures, including inspections, apply only where a documentation audit is demonstrably insufficient, where they are required by a Supervisory Authority, or following a Personal Data Breach affecting Customer Personal Data.

11.3 Any audit under this Section 11 shall (a) be limited to no more than once per twelve (12) month period unless required by a Supervisory Authority or following a Personal Data Breach, (b) be subject to at least thirty (30) days’ prior written notice, with scope, duration and timing agreed between the Parties in advance, (c) be conducted during normal business hours and conducted remotely wherever reasonably possible, in a manner that does not unreasonably disrupt HelpKit’s business, (d) not grant access to data of other HelpKit customers or to information concerning HelpKit’s own security measures where disclosure would create a security risk, and (e) be at Customer’s expense; Customer shall further reimburse HelpKit for reasonable time and costs incurred in supporting audit measures that go beyond the provision of existing documentation. Any third-party auditor mandated by Customer must not be a competitor of HelpKit and must enter into a confidentiality agreement before the audit.

12. International Data Transfers

12.1 HelpKit is established in the United States, and the Subprocessors listed in Annex 3 include providers established in or operating from the United States. Customer Personal Data originating from the EEA, the United Kingdom or Switzerland is therefore transferred to third countries within the meaning of Chapter V GDPR.

12.2 To the extent Customer Personal Data is transferred to a country that does not provide an adequate level of data protection within the meaning of the Data Protection Laws, the Parties agree that the Standard Contractual Clauses are hereby incorporated by reference and form an integral part of this DPA, applied as follows:

  • Module Two (Controller to Processor) applies where Customer is a Controller; Module Three (Processor to Processor) applies where Customer is a Processor; in each case Customer is the “data exporter” and HelpKit is the “data importer”;
  • the optional docking clause in Clause 7 does not apply;
  • in Clause 9, Option 2 (general written authorization) applies, with the notice period set out in Section 6.2 of this DPA;
  • the optional language in Clause 11(a) does not apply;
  • in Clause 17, Option 1 applies and the SCCs are governed by the laws of Ireland; in Clause 18(b), disputes shall be resolved before the courts of Ireland;
  • Annexes I and II of the SCCs are deemed completed with the information set out in Annexes 1, 2 and 3 of this DPA; the competent Supervisory Authority is the authority of the EU Member State in which the data exporter is established.

12.3 For transfers from the United Kingdom, the SCCs apply as amended by the UK International Data Transfer Addendum to the EU Commission Standard Contractual Clauses (version B1.0), issued by the UK Information Commissioner and in force from 21 March 2022, completed with the information in the Annexes to this DPA. For transfers from Switzerland, the SCCs apply with the adaptations required by the Swiss Federal Data Protection and Information Commissioner (FDPIC), and references to the GDPR are understood as references to the FADP.

13. Liability

Each Party’s liability arising out of or related to this DPA (including the SCCs) is subject to the exclusions and limitations of liability set out in the Agreement. Nothing in this Section limits a Data Subject’s rights or either Party’s liability towards Data Subjects under the SCCs or Data Protection Laws.

14. General Terms

14.1 In the event of a conflict between this DPA and the Agreement with respect to the processing of Customer Personal Data, this DPA prevails. In the event of a conflict between this DPA and the SCCs, the SCCs prevail.

14.2 This DPA is governed by the law governing the Agreement, except where the SCCs mandatorily require otherwise (see Section 12.2).

14.3 Should any provision of this DPA be invalid or unenforceable, the remainder of this DPA remains valid and in force.

14.4 HelpKit may update this DPA from time to time to reflect changes in the Services, Subprocessors or Data Protection Laws. Material changes will be notified to Customer (e.g. by email or in-app notice). The version published at helpkit.so/dpa applies as of its “Last updated” date.

Questions about this DPA can be directed to support@helpkit.so.


Annex 1 — Description of the Processing

Subject matter: Provision of the HelpKit Services, i.e. hosting and publishing Customer’s Notion content as knowledge bases, help centers and documentation sites, including related widgets, search, optional AI-powered features and customer support.

Duration: The term of the Agreement, plus the deletion periods set out in Section 10.

Nature and purpose of the processing: Collecting, storing, retrieving, caching, displaying, transmitting and deleting Customer Personal Data as necessary to synchronize Customer’s Notion content, render and host Customer’s public or protected knowledge base, operate embedded widgets and AI-assisted answers, deliver transactional email, and provide customer support.

Categories of Data Subjects:

  • Customer’s authorized users of the Services (e.g. employees and contractors of Customer);
  • visitors and end users of Customer’s published knowledge bases and widgets;
  • any individuals whose Personal Data is contained in the content Customer chooses to publish through the Services.

Categories of Personal Data:

  • account and contact data of Customer’s authorized users (name, email address);
  • technical usage data of knowledge base visitors (IP address, browser and device information, aggregated and anonymized page analytics);
  • email addresses of end users, where Customer enables optional features that collect them (e.g. AI chat follow-up);
  • any Personal Data contained in Customer’s Notion content published through the Services (determined solely by Customer).

Special categories of data: None. The Services are not intended for, and Customer agrees not to submit, special categories of Personal Data (Art. 9 GDPR), including health data, or data subject to sector-specific protection such as patient data.

Frequency of the processing: Continuous, for the duration of the Agreement.

Annex 2 — Technical and Organizational Measures

HelpKit implements and maintains, in particular, the following technical and organizational measures within the meaning of Art. 32 GDPR:

  • Encryption in transit: all connections to the Services are encrypted using TLS; unencrypted HTTP access is not offered.
  • Encryption at rest: production data is stored on managed cloud infrastructure with disk-level encryption at rest.
  • Hosting location: primary application hosting and databases are located in data centers in Germany (EU); a global content delivery network is used for caching and DDoS protection.
  • Access control: access to production systems is restricted to authorized personnel on a need-to-know basis, secured by strong authentication (including multi-factor authentication where supported) and unique credentials; access rights are reviewed and revoked when no longer required.
  • Data minimization: the Services are designed to process minimal Personal Data; website and knowledge base analytics are cookieless and anonymized.
  • Availability and resilience: production data is backed up regularly with encrypted backups; infrastructure providers maintain redundancy and disaster recovery capabilities.
  • Logging and monitoring: system events and errors are logged and monitored to detect anomalies and security incidents.
  • Vendor management: Subprocessors are bound by data processing agreements and selected with regard to their security certifications and GDPR compliance.
  • Personnel: all personnel with access to Customer Personal Data are bound by confidentiality obligations.
  • Incident response: a defined process exists for identifying, assessing, containing and notifying Personal Data Breaches (see Section 8).

Annex 3 — Authorized Subprocessors

Customer has authorized the use of the following Subprocessors as of the “Last updated” date of this DPA:

Subprocessor Purpose Location of processing
DigitalOcean, LLC Cloud hosting (application & database) Germany (Frankfurt)
Render Services, Inc. Cloud hosting (application & database) Germany (Frankfurt)
Cloudflare, Inc. Content delivery network, caching, security Global (incl. USA)
Cloudinary Ltd. Image storage and delivery USA
Twilio Inc. (SendGrid) Transactional email delivery USA
Google LLC (Gmail / Workspace) Email communication & customer support USA / EU
Slack Technologies, LLC Internal communication (support requests) USA
Paddle.com Market Ltd. Payment processing & billing (merchant of record) UK / USA
OpenAI, L.L.C. AI answer generation and text embeddings (HelpKit AI, where enabled by Customer) USA
OpenRouter, Inc. LLM API routing for AI answers (HelpKit AI) USA
Pinecone Systems, Inc. Vector search index for AI answers (HelpKit AI) USA
Inngest, Inc. Background job processing USA
LogSnag Product event monitoring USA

HelpKit will update this list and notify Customer in accordance with Section 6 before any new Subprocessor processes Customer Personal Data.

Customer-enabled services are not Subprocessors. Notion Labs, Inc. is Customer’s own content platform, engaged directly by Customer under Customer’s own agreement with Notion. Likewise, any integrations Customer chooses to enable on its knowledge base — such as live chat providers (e.g. Crisp, Intercom, HubSpot, Freshchat), Customer’s own analytics (e.g. Google Analytics, Plausible), license validation providers, or custom JavaScript — are engaged by and act on behalf of Customer, and Customer is responsible for its own data processing arrangements with those providers.