KS-Merge emblem KS-Merge Merge and share — be in control.

Version 2 · effective 31 Jul 2026

Data Processing Agreement

Effective date: 31 July 2026 This DPA is incorporated into the KS-Merge Terms of Service for every paid workspace ("Customer"). It gives effect to the Jamaica Data Protection Act, 2020 ("DPA 2020") and, where the Customer or its data subjects are in the EEA/UK, the EU/UK GDPR. Capitalised terms have the meaning given in those laws.

1. Roles and scope

The Customer is the controller of personal data contained in uploaded documents, bundles and delivery records ("Customer Data"). Kokoro Solutions Ltd. (Jamaica) is the processor. Processing subject-matter: storage, assembly, watermarking, rendering, certified signing (cryptographic sealing and trusted timestamping of the document hash) and delivery of legal document bundles. Duration: the subscription term plus the retention schedule.

2. Processor obligations

KS-Merge shall: process Customer Data only on documented instructions (including delivery instructions issued in-app), unless required by law, in which case it will inform the Customer first where legally permitted; ensure personnel are bound by confidentiality; implement and maintain the technical and organisational measures in Annex II and not materially diminish them; assist the Customer (taking into account the nature of processing) with data-subject requests and its security, breach-notification and impact-assessment obligations; make available information reasonably necessary to demonstrate compliance; notify the Customer of a personal-data breach without undue delay and within 72 hours of confirmation, with the required information as it becomes available; and, at the Customer's choice, delete or return Customer Data at termination per the retention schedule, providing a certificate of deletion on request. Customer obligations and warranties. The Customer warrants that its instructions (including each delivery it initiates) comply with applicable law, that it has a lawful basis and all necessary notices and consents for the Customer Data it uploads and shares, and that it is solely responsible for the accuracy, legality and content of that data and for configuring retention and legal holds appropriately. KS-Merge may suspend processing of any instruction it reasonably believes is unlawful.

3. Sub-processors

The Customer grants general authorisation for KS-Merge's sub-processors. The current categories are: cloud hosting and object storage, payment processing, transactional email, and an independent time-stamp authority (which receives only the document hash for certified signing, never its content). The current named list is made available to the Customer on request (dpo@kokorosolutions.com). KS-Merge gives 30 days' notice of additions or replacements, during which the Customer may object on reasonable data-protection grounds. Each sub-processor is bound by written terms imposing data-protection obligations no less protective than this DPA. Where the Customer connects its own external storage (e.g. Google Drive), that provider acts under the Customer's own relationship and is not a KS-Merge sub-processor.

4. International transfers

Some processing takes place outside Jamaica (including the United States and the European Union). Such transfers are made only where the destination ensures an adequate level of protection under the DPA 2020 or appropriate contractual safeguards are in place. Where EEA/UK personal data is transferred to a country without an adequacy decision, the parties incorporate the EU Standard Contractual Clauses (2021/914), module two (controller → processor), and the UK Addendum where applicable.

5. Retention, deletion and legal hold

6. Annex I — processing details

Data subjects: the Customer's clients, opposing parties, court personnel, workspace members. Categories: identification, contact, case and matter data; special categories where contained in legal documents. Frequency: continuous during the term. Where the Customer connects external storage, the location of stored files is the Customer's own account.

7. Annex II — security measures

KS-Merge maintains appropriate technical and organisational measures to protect Customer Data, including:

8. Audit

KS-Merge provides audit-log export and, on reasonable notice no more than annually, responds to written security questionnaires or independent audit reports (e.g. SOC 2 when available).

9. Liability and indemnity

Each party's liability under this DPA is subject to the limitations and exclusions in the Terms of Service, and any amounts claimed under this DPA count toward, and do not add to, the aggregate cap there. As between the parties, the Customer is responsible for its acts and omissions as controller (including the lawfulness of the data and instructions), and KS-Merge is responsible for its acts and omissions as processor. The Customer will indemnify KS-Merge against claims arising from Customer Data or instructions that breach applicable law or this DPA.

10. United States state privacy addendum (CCPA/CPRA and similar laws)

Where the Customer is subject to the California Consumer Privacy Act as amended (CCPA/CPRA) or a comparable US state privacy law, KS-Merge acts as a "service provider" (or "processor"/"contractor" as those laws define it) and, with respect to personal information processed on the Customer's behalf:

11. Precedence

In the event of a conflict between this DPA and the Terms of Service or any other agreement between the parties with respect to the processing of personal data, this DPA prevails. All other terms remain in full force.