KO
  • How it works
  • Features
  • Integrations
  • Case studies
  • Pricing
  • FAQ
Sign in
Legal

Data Processing Agreement

Last updated: April 6, 2026

1. Introduction

This Data Processing Agreement ("DPA") is entered into between you, the customer ("Controller"), and KO Data Oy ("Processor", "KO"), and forms part of the Terms of Service for the KO platform.

This DPA governs the processing of personal data that the Controller submits to or through the KO platform, in accordance with the General Data Protection Regulation (EU) 2016/679 (GDPR) and applicable national data protection laws.

2. Roles & Responsibilities

  • Controller — The customer who determines the purposes and means of data processing. You decide what data is connected to KO and how it is used.
  • Processor — KO Data Oy, which processes personal data on behalf of the Controller, strictly to deliver the agreed Service.

KO processes data only on documented instructions from the Controller, as set out in this DPA and the Terms of Service. If KO is required by law to process data beyond these instructions, it will notify the Controller in advance unless prohibited by law.

3. Scope of Processing

Subject matter

KO processes personal data to provide marketing intelligence, revenue attribution, and reporting services connecting the Controller's advertising, CRM, and analytics data.

Nature of processing

Collection via API, storage, aggregation, analysis, and display of data within the platform.

Categories of data subjects

  • Leads and prospects in the Controller's CRM
  • Customers and contacts whose data is stored in connected systems
  • End users whose behavioral data flows through connected ad and analytics platforms

Categories of personal data

  • Contact information (names, email addresses, company details)
  • Marketing interaction data (ad clicks, form submissions, UTM data)
  • CRM data (deal stages, pipeline values, close dates)
  • Analytics events (page views, session identifiers, conversion events)

Duration

For the duration of the active subscription, plus 30 days following termination.

4. Infrastructure & Data Location

All personal data processed under this DPA is stored and handled on self-hosted, privately managed server infrastructure. Our hosting provider is Hetzner Online GmbH, operating within the European Union (data centers in Germany and Finland).

KO does not use third-party SaaS data warehouses to store Controller data. Data remains within infrastructure that KO directly controls and manages.

Data is not transferred outside the EEA unless explicitly required by an integration the Controller configures (e.g., connecting to a platform whose API is hosted outside the EU). In such cases, the Controller is responsible for ensuring appropriate legal bases for the transfer.

5. Sub-processors

KO relies on the following sub-processors to deliver the Service. All sub-processors are bound by written agreements ensuring equivalent data protection standards.

Sub-processor Role Location
Hetzner Online GmbH Primary hosting & infrastructure Germany / Finland (EU)
External platform APIs (Meta, Google, LinkedIn, TikTok, HubSpot, Pipedrive, GA4, etc.) Data source integrations authorized by the Controller Varies (Controller's responsibility to authorize)

KO will notify the Controller of any intended changes to sub-processors with reasonable advance notice. The Controller may object to new sub-processors within 14 days of notification.

6. Technical & Organisational Security Measures

KO implements the following measures to protect personal data:

  • Encryption of all data in transit using TLS 1.2 or higher
  • Encryption of data at rest on production servers
  • Role-based access control limiting data access to authorized personnel only
  • Regular security patching and vulnerability management
  • Isolated server environments — no shared multi-tenant data storage
  • Logging of access to production systems
  • Incident response procedures for detecting, reporting, and managing data breaches

KO does not guarantee absolute security. No system is entirely risk-free. In the event of a personal data breach, KO will notify the Controller without undue delay and no later than 72 hours after becoming aware of the breach, in line with GDPR Article 33.

7. Data Subject Rights

KO will assist the Controller in responding to data subject requests under the GDPR (access, rectification, erasure, restriction, portability, objection). Where technically feasible, KO provides tooling to support these workflows. For requests that require manual intervention, KO will respond within 10 business days of receiving the request from the Controller.

8. Confidentiality

KO ensures that all personnel authorized to process personal data are bound by confidentiality obligations, either by contract or by applicable law. Access is granted on a need-to-know basis only.

9. Audits & Compliance

KO will provide the Controller with information reasonably necessary to demonstrate compliance with this DPA. The Controller may request an audit of KO's data processing practices with at least 30 days' written notice. Audits are conducted at the Controller's expense and must not unreasonably disrupt KO's operations.

10. Termination & Data Deletion

Upon termination of the Service agreement, KO will:

  • Retain the Controller's data for 30 days to allow for recovery or export
  • Securely and permanently delete all personal data within 30 days of the end of that retention period
  • Provide written confirmation of deletion upon request

If the Controller requests earlier deletion, KO will complete it within 14 business days.

11. Governing Law

This DPA is governed by Finnish law and forms an integral part of the KO Terms of Service. In the event of conflict, this DPA takes precedence with respect to data processing obligations.

12. Contact

For DPA-related inquiries, contact us at hello@kodata.pro.

KO Data Oy — Helsinki, Finland

We've received your request!

Our team will reach out within one business day to schedule your demo.

Book a free demo

Tell us a bit about yourself — we'll get back within one business day to schedule. No spam.

Vitaly, co-founder of KO Azat, co-founder of KO Your demo is with the founders, Vitaly & Azat — not a sales rep.
Please enter your first name.
Please enter your last name.
Please enter a valid phone number.
Please enter a valid email address.
Please enter your company name.
Please select your role.

By submitting this form, you agree that KO may contact you as described in our Privacy Policy.

KO

See what drives revenue —
and know what to do next.

GDPR-compliant EU Hosting Encrypted

Product

  • Features
  • Integrations
  • Pricing
  • Case Studies
  • FAQ

Legal

  • Terms of Service
  • Privacy Policy
  • Customer DPA
  • Cookie Policy

Contact

  • hello@kodata.pro

© KO Data Oy. All rights reserved.

By clicking "Accept All Cookies", you agree to the storing of cookies on your device to enhance site navigation, analyse site usage and assist in our marketing efforts. More info

Cookie Settings

We use cookies to enhance your browsing experience, analyse site traffic, and personalise content. You can manage your preferences below. For more details see our Cookie Policy.

Necessary Cookies

Required for the website to function properly. These cannot be disabled.

Always On

Analytics Cookies

Help us understand how visitors interact with the site by collecting anonymous usage data.

Marketing Cookies

Used to display relevant advertisements and track campaign performance across websites.