Paius logo new - no backgroundPaius wordmark
HomeSign in

Legal

Data Processing Agreement

Data Processing Agreement

Effective Date: July 13, 2026
Last Updated: July 13, 2026

This Data Processing Agreement (“DPA”) forms part of the agreement between Kinard Applied Solutions LLC, through the product Paius (“Paius,” “Processor,” “we,” “us,” or “our”), and the customer or organization using the Paius Service (“Customer,” “Controller,” or “you”).

This DPA applies where Paius processes personal data on behalf of a Customer in connection with the Paius website, application, SaaS platform, dashboards, reports, preflight assessments, receipts, analytics, approvals, and related services (collectively, the “Service”).

1. Purpose

This DPA describes the parties’ respective obligations when Paius processes Customer Personal Data on behalf of Customer. It is intended to support professional B2B SaaS data processing practices and, where applicable, requirements under privacy laws that require written processing terms.

Paius is intended for U.S. users at launch and is not intentionally offered outside the United States unless expressly authorized in writing.

2. Definitions

“Customer Personal Data” means personal information or personal data contained in Customer Content that Paius processes on behalf of Customer through the Service.

“Customer Content” means data, files, prompts, workflow descriptions, task descriptions, cost assumptions, budgets, notes, approvals, receipts, analytics records, or other content submitted to, uploaded to, stored in, or generated through the Service by or for Customer.

“Data Protection Laws” means privacy, data protection, and security laws applicable to the parties and the processing of Customer Personal Data.

“Subprocessor” means a third party engaged by Paius to process Customer Personal Data on behalf of Paius in connection with the Service.

3. Roles of the Parties

Customer is the controller or business that determines the purposes and means of processing Customer Personal Data.

Paius is the processor or service provider that processes Customer Personal Data on behalf of Customer to provide the Service.

For account administration, billing, security, legal compliance, fraud prevention, product operations, and Paius’s own business records, Paius may act as an independent controller or business as described in the Paius Privacy Policy.

4. Subject Matter and Duration

The subject matter of processing is the provision of the Paius Service to Customer.

The duration of processing is the term of Customer’s use of the Service and any applicable retention period described in the Privacy Policy, Terms of Service, this DPA, or applicable law.

5. Nature and Purpose of Processing

Paius processes Customer Personal Data to:

  • Provide and operate the Service;
  • Host, store, and retrieve Customer Content;
  • Generate and maintain preflight assessments, receipts, analytics, reports, risk indicators, and approvals;
  • Authenticate users and manage access;
  • Provide customer support;
  • Process billing and subscriptions through Stripe;
  • Maintain security and prevent abuse;
  • Troubleshoot bugs and technical issues;
  • Comply with applicable legal, tax, accounting, and regulatory obligations;
  • Enforce agreements and policies.

6. Categories of Data Subjects

Customer Personal Data may relate to:

  • Customer users;
  • Organization administrators;
  • Employees, contractors, or representatives of Customer;
  • Individuals described in uploaded files, workflow descriptions, prompts, notes, or other Customer Content;
  • Other individuals whose information is submitted by Customer.

7. Categories of Personal Data

Customer Personal Data may include:

  • Name;
  • Email address;
  • Company or organization name;
  • Role or title;
  • Account credentials and authentication details;
  • Workspace membership and permissions;
  • Workflow descriptions;
  • Prompt-related information;
  • Uploaded files;
  • Approval notes;
  • Business usage data;
  • Cost, risk, budget, and analytics records;
  • Support communications;
  • Any personal data Customer chooses to submit.

Paius does not require Customer to submit sensitive personal data. If Customer submits sensitive or regulated data, Customer is responsible for ensuring it has lawful authority and that such processing is appropriate for the Service.

8. Customer Instructions

Paius will process Customer Personal Data only on Customer’s documented instructions, including as set out in the Terms of Service, Privacy Policy, this DPA, order forms, product settings, support requests, and Customer’s use of the Service, unless required by law.

Customer instructs Paius to process Customer Personal Data as necessary to provide, secure, support, and improve the Service in accordance with the agreement.

9. Customer Responsibilities

Customer is responsible for:

  • Providing required notices to data subjects;
  • Obtaining required consents or authorizations;
  • Ensuring it has a lawful basis or legal authority for submitting Customer Personal Data to Paius;
  • Ensuring Customer Content does not violate law or third-party rights;
  • Configuring permissions and administrator access appropriately;
  • Responding to data subject requests where Customer controls the relevant data;
  • Avoiding submission of data that is inappropriate for the Service.

10. Paius Responsibilities

Paius will:

  • Process Customer Personal Data in accordance with Customer’s instructions;
  • Implement reasonable administrative, technical, and organizational safeguards;
  • Limit access to Customer Personal Data to personnel or contractors who need access to provide the Service;
  • Require personnel with access to Customer Personal Data to maintain confidentiality;
  • Use Subprocessors in accordance with this DPA;
  • Assist Customer with data subject requests where reasonably possible and required by applicable law;
  • Notify Customer of a Security Incident as described below;
  • Delete or return Customer Personal Data as described in this DPA.

11. Security Measures

Paius uses reasonable safeguards designed to protect Customer Personal Data, including:

  • HTTPS encryption in transit;
  • Provider-supported encryption at rest;
  • Password hashing;
  • Email verification;
  • Password reset functionality;
  • Google OAuth;
  • Role-based access controls;
  • Administrative access restrictions;
  • Incident response procedures;
  • Vendor-supported infrastructure security.

Paius currently does not claim SOC 2, ISO 27001, HIPAA, PCI DSS, or similar certification unless expressly stated in writing.

12. Subprocessors

Customer authorizes Paius to use Subprocessors to provide the Service. Current or planned Subprocessors are listed in the Subprocessor List and may include Vercel, Neon, Stripe, PrivateEmail, OpenAI, Anthropic, Google Gemini, and Google OAuth-related services.

Paius will take reasonable steps to ensure Subprocessors are subject to contractual obligations designed to protect Customer Personal Data.

Paius may update the Subprocessor List from time to time. If Customer objects to a new Subprocessor on reasonable data protection grounds, Customer may contact support@getpaius.com.

13. AI Providers

Paius uses or may use AI service providers, including OpenAI, Anthropic, and Google Gemini, to support product functionality and service operations.

Under Paius's current architecture and feature configuration, customer-submitted prompts, workflow descriptions, uploaded files, and Customer Content are not transmitted to external AI model providers unless Paius discloses that processing, obtains any required consent, or the customer enables a feature that requires such transmission.

Paius does not use Customer Content to train Paius models and does not fine-tune AI models using Customer Content.

We may use anonymized, aggregated, or de-identified data to understand product usage, improve system performance, develop features, and evaluate business trends, provided that such data does not identify a customer or individual.

14. Data Subject Requests

If Paius receives a request from a data subject relating to Customer Personal Data controlled by Customer, Paius may direct the individual to Customer or assist Customer as reasonably required by applicable law.

Customer is responsible for responding to requests where Customer determines the purposes and means of processing.

15. Security Incidents

“Security Incident” means a confirmed breach of security leading to accidental or unlawful destruction, loss, alteration, unauthorized disclosure of, or access to Customer Personal Data processed by Paius.

Paius will notify Customer without undue delay after becoming aware of a Security Incident affecting Customer Personal Data. Notice may include information reasonably available to Paius, such as the nature of the incident, affected data, mitigation steps, and recommended actions.

Unsuccessful attacks, scans, pings, attempted logins, denial-of-service attempts, and events that do not compromise Customer Personal Data are not Security Incidents requiring notice under this DPA.

16. Deletion and Return

Upon verified account deletion, termination, or written request, Paius will delete or return Customer Personal Data within a reasonable period, generally within 30 days, unless retention is required or permitted for legal, tax, accounting, security, fraud prevention, dispute resolution, backup, or legitimate business purposes.

Workspace records and Customer Content may otherwise be retained for up to five years for history, receipts, analytics, and debugging unless deleted earlier under this DPA or the Privacy Policy.

In-app workflow prompt and output content follows the workspace retention setting: full, redacted, or none.

Billing, tax, and accounting records may be retained for up to seven years.

17. Audits and Information

Upon reasonable written request, Paius may provide information regarding its security and privacy practices to help Customer evaluate compliance with this DPA. Paius may satisfy audit requests by providing written responses, security documentation, policy summaries, or other appropriate information.

On-site audits are not available unless separately agreed in writing.

18. International Transfers

Paius is intended for U.S. users and U.S.-based processing at launch. Customer should not use the Service from outside the United States unless Paius expressly authorizes such use in writing.

If international transfer requirements apply, the parties will work in good faith to implement appropriate transfer mechanisms where required.

19. Conflicts

If there is a conflict between this DPA and the Terms of Service regarding processing of Customer Personal Data, this DPA controls to the extent of the conflict.

20. Contact

Questions about this DPA may be sent to:

Paius / Kinard Applied Solutions LLC
1795 Alysheba Way Ste 7203A
Lexington, KY 40509
support@getpaius.com

Paius wordmark

Built for the next generation of managers leading AI-powered work.

Product

  • Product
  • Integrations
  • Pricing
  • Start Assessment

Legal

  • Privacy Policy
  • Terms of Service
  • Cookie Policy
  • Acceptable Use Policy
  • Data Processing Agreement
  • Billing & Subscription Policy
  • Refund & Cancellation Policy
  • AI Disclaimer
  • Security & Trust Center
  • Subprocessor List
© 2026 Paius. All rights reserved.