Data Processing Agreement
Effective date: 31 July 2026 This DPA is incorporated into the KS-Merge Terms of Service for every paid workspace ("Customer"). It gives effect to the Jamaica Data Protection Act, 2020 ("DPA 2020") and, where the Customer or its data subjects are in the EEA/UK, the EU/UK GDPR. Capitalised terms have the meaning given in those laws.
1. Roles and scope
The Customer is the controller of personal data contained in uploaded documents, bundles and delivery records ("Customer Data"). Kokoro Solutions Ltd. (Jamaica) is the processor. Processing subject-matter: storage, assembly, watermarking, rendering, certified signing (cryptographic sealing and trusted timestamping of the document hash) and delivery of legal document bundles. Duration: the subscription term plus the retention schedule.
2. Processor obligations
KS-Merge shall: process Customer Data only on documented instructions (including delivery instructions issued in-app), unless required by law, in which case it will inform the Customer first where legally permitted; ensure personnel are bound by confidentiality; implement and maintain the technical and organisational measures in Annex II and not materially diminish them; assist the Customer (taking into account the nature of processing) with data-subject requests and its security, breach-notification and impact-assessment obligations; make available information reasonably necessary to demonstrate compliance; notify the Customer of a personal-data breach without undue delay and within 72 hours of confirmation, with the required information as it becomes available; and, at the Customer's choice, delete or return Customer Data at termination per the retention schedule, providing a certificate of deletion on request. Customer obligations and warranties. The Customer warrants that its instructions (including each delivery it initiates) comply with applicable law, that it has a lawful basis and all necessary notices and consents for the Customer Data it uploads and shares, and that it is solely responsible for the accuracy, legality and content of that data and for configuring retention and legal holds appropriately. KS-Merge may suspend processing of any instruction it reasonably believes is unlawful.
3. Sub-processors
The Customer grants general authorisation for KS-Merge's sub-processors. The current categories are: cloud hosting and object storage, payment processing, transactional email, and an independent time-stamp authority (which receives only the document hash for certified signing, never its content). The current named list is made available to the Customer on request (dpo@kokorosolutions.com). KS-Merge gives 30 days' notice of additions or replacements, during which the Customer may object on reasonable data-protection grounds. Each sub-processor is bound by written terms imposing data-protection obligations no less protective than this DPA. Where the Customer connects its own external storage (e.g. Google Drive), that provider acts under the Customer's own relationship and is not a KS-Merge sub-processor.
4. International transfers
Some processing takes place outside Jamaica (including the United States and the European Union). Such transfers are made only where the destination ensures an adequate level of protection under the DPA 2020 or appropriate contractual safeguards are in place. Where EEA/UK personal data is transferred to a country without an adequacy decision, the parties incorporate the EU Standard Contractual Clauses (2021/914), module two (controller → processor), and the UK Addendum where applicable.
5. Retention, deletion and legal hold
- Default retention for client files: 90 days from upload (configurable per plan tier).
- Erasure lifecycle: T-14 warning → soft delete (7-day grace) → hard delete of the storage objects. Encrypted disaster-recovery backups are retained on a rolling schedule and expired within 24 months; data restored from a backup is re-deleted at the next erasure cycle. Individual records are not restored from backup on request. A certificate of erasure is available on request.
- Legal hold suspends deletion for affected matters; holds require a documented reason and are audit-logged.
- Erasure requests are honoured within 30 days on all tiers.
6. Annex I — processing details
Data subjects: the Customer's clients, opposing parties, court personnel, workspace members. Categories: identification, contact, case and matter data; special categories where contained in legal documents. Frequency: continuous during the term. Where the Customer connects external storage, the location of stored files is the Customer's own account.
7. Annex II — security measures
KS-Merge maintains appropriate technical and organisational measures to protect Customer Data, including:
- Encryption of data in storage and in transit
- Access restricted to a customer's own workspace, on a least-privilege basis, with fail-closed tenant isolation
- Strong passwords and recommended two-factor sign-in; mandatory two-factor for platform staff
- Malware scanning and quarantine of uploads
- A tamper-evident, hash-chained, append-only activity log
- Content-integrity verification (SHA-256) for certified and externally-stored files
- Regular, encrypted backups with tested restores
- Independent security testing and ongoing vulnerability monitoring
- Staff confidentiality obligations and security training Further detail on these measures is available to the Customer on request.
8. Audit
KS-Merge provides audit-log export and, on reasonable notice no more than annually, responds to written security questionnaires or independent audit reports (e.g. SOC 2 when available).
9. Liability and indemnity
Each party's liability under this DPA is subject to the limitations and exclusions in the Terms of Service, and any amounts claimed under this DPA count toward, and do not add to, the aggregate cap there. As between the parties, the Customer is responsible for its acts and omissions as controller (including the lawfulness of the data and instructions), and KS-Merge is responsible for its acts and omissions as processor. The Customer will indemnify KS-Merge against claims arising from Customer Data or instructions that breach applicable law or this DPA.
10. United States state privacy addendum (CCPA/CPRA and similar laws)
Where the Customer is subject to the California Consumer Privacy Act as amended (CCPA/CPRA) or a comparable US state privacy law, KS-Merge acts as a "service provider" (or "processor"/"contractor" as those laws define it) and, with respect to personal information processed on the Customer's behalf:
- processes it only to perform the service and for the business purposes set out in this DPA, and for no other purpose;
- does not sell or share personal information, and does not process it for cross-context behavioural advertising;
- does not retain, use, or disclose it outside the direct business relationship or combine it with data from other sources, except as permitted by the applicable law;
- certifies that it understands and will comply with these restrictions; and
- assists the Customer in responding to verifiable consumer requests. The Customer may take reasonable steps to confirm KS-Merge's use of personal information is consistent with its obligations. This addendum controls over any conflicting term for personal information governed by these US state laws.
11. Precedence
In the event of a conflict between this DPA and the Terms of Service or any other agreement between the parties with respect to the processing of personal data, this DPA prevails. All other terms remain in full force.