KramaAI
Book a demo

Data Processing Agreement

Last updated: June 4, 2026

This Data Processing Agreement (“DPA”) forms part of your agreement with KramaAI when you use KramaAI BMS to process personal data on behalf of your organization. Capitalized terms not defined here have the meaning in our Terms of Service.

1. Roles

You are the controller (or business, under applicable U.S. privacy laws) for data about your customers, staff, and children in your programs. KramaAI is the processor and processes personal data only on your documented instructions, including through configuration of the Services.

2. Subject matter and duration

Processing covers BMS operations: account management, programs, scheduling, attendance, payments, payouts, reporting, support tickets, and optional AI features that analyze data you already store in the system. Processing continues for the subscription term and any agreed wind-down period.

3. Categories of data and subjects

  • Subjects: owners, managers, staff, parents/guardians, children, and payers.
  • Data: contact details, enrollment and attendance records, transaction and payout data, child profile fields you configure, communications in support tickets, and audit logs.

4. Processor obligations

KramaAI will:

  • Process personal data only on your instructions, including regarding transfers and subprocessors.
  • Ensure personnel with access are bound by confidentiality obligations.
  • Implement appropriate technical and organizational security measures.
  • Assist with data subject requests where feasible, subject to your ability to use in-product tools or export functions.
  • Notify you without undue delay after becoming aware of a personal data breach affecting your data.
  • Delete or return personal data at the end of the Services, subject to legal retention requirements.

5. Subprocessors

You authorize us to use subprocessors for hosting, monitoring, email, and integrated payment services you enable. We remain responsible for subprocessors’ performance of data protection obligations. We will provide notice of material subprocessor changes where required by law or contract.

6. International transfers

Where personal data is transferred outside your jurisdiction, we implement appropriate safeguards (such as standard contractual clauses) as required by applicable law.

7. Audits

Upon reasonable written request, we will provide information necessary to demonstrate compliance with this DPA, subject to confidentiality and reasonable frequency limits. Onsite audits may be conducted no more than annually with thirty (30) days’ notice, during business hours, and without disrupting operations.

8. Children’s program data

For youth and enrichment operators, you instruct us to process child and guardian data needed for enrollment, check-in, and billing. You represent that you have a lawful basis and, where required, parental consent for such processing. We will not use children’s personal data for unrelated advertising profiles.

9. Order of precedence

If this DPA conflicts with the Terms regarding processing of personal data, this DPA controls. Signed enterprise agreements may supersede this standard DPA.

10. Contact

Data protection inquiries: privacy@kramaai.com.

← Back to homepage

© 2025 KramaAI. Terms · Privacy · Data processing