Data Processing Agreement
Overview and Incorporation
This Data Processing Agreement ("DPA") is incorporated into the Koffyr Terms of Service for all customers whose use of the Service involves processing personal data. A countersigned copy is available on request to legal@koffyr.com.
Processor: Valtio Inc., a Delaware corporation ("Processor" or "Valtio").
Controller / Customer: The agency, organization, or individual using the Koffyr platform ("Controller" or "Customer").
In the event of conflict between this DPA and the Terms of Service, this DPA governs with respect to data processing matters.
Effective Date: The date the Controller accepts the Terms of Service or executes this DPA, whichever is earlier.
Definitions
For purposes of this DPA:
- "Applicable Data Protection Law" means, as applicable: (a) the EU General Data Protection Regulation (GDPR); (b) the UK GDPR and the Data Protection Act 2018; (c) the California Consumer Privacy Act (CCPA/CPRA); and (d) any other data protection or privacy law applicable to a party's processing of Personal Data under this DPA.
- "Data Subject" means an identified or identifiable natural person whose Personal Data is processed under this DPA, including policyholders, insureds, certificate holders, employees, and principals of the Controller's insureds.
- "Personal Data" has the meaning given in Applicable Data Protection Law and, for purposes of this DPA, means personal data or personal information processed by the Processor on behalf of the Controller in connection with the Service.
- "Processing" has the meaning given in Applicable Data Protection Law (any operation performed on Personal Data, including collection, storage, use, disclosure, deletion).
- "Security Incident" means a confirmed breach of security leading to the accidental or unlawful destruction, loss, alteration, unauthorized disclosure of, or access to, Personal Data.
- "Sub-processor" means any third party engaged by the Processor to carry out processing activities on Personal Data on the Processor's behalf.
- "SCCs" means the Standard Contractual Clauses for the transfer of personal data to third countries pursuant to GDPR, as adopted by the European Commission Decision C(2021)3972.
Scope and Role
3.1 Controller is the Controller. The Controller determines the purposes and means of processing Personal Data in connection with the Service. The Controller instructs the Processor to process Personal Data on its behalf as described in Schedule 1.
3.2 Processor is the Processor. The Processor processes Personal Data on behalf of the Controller solely for the purposes described in this DPA and the Terms of Service.
3.3 Valtio as an Independent Controller. Notwithstanding Section 3.2, Valtio also acts as an independent controller for certain data it collects for its own purposes (e.g., account registration, billing, platform analytics). Such data is governed by Valtio's Privacy Policy, not this DPA.
Processor Obligations
The Processor agrees that it will:
4.1 Process only on instructions. Process Personal Data only on the documented instructions of the Controller, including as set out in this DPA, the Terms of Service, and any subsequent written instructions. If the Processor is required by applicable law to process Personal Data beyond those instructions, it will notify the Controller before processing (unless prohibited by law).
4.2 Confidentiality. Ensure that persons authorized to process Personal Data are under appropriate confidentiality obligations (contractual or statutory).
4.3 Security. Implement and maintain the technical and organizational security measures described in Schedule 2.
4.4 Sub-processors. Comply with Section 7 of this DPA regarding Sub-processors.
4.5 Data Subject Rights Assistance. Assist the Controller in fulfilling its obligations to respond to Data Subject requests to exercise their rights under Applicable Data Protection Law. The Processor will promptly (and in no event more than 5 business days) forward to the Controller any Data Subject requests it receives that relate to the Controller's data.
4.6 Security Assistance. Assist the Controller in ensuring compliance with its security, data breach notification, DPIA, and prior consultation obligations by providing information reasonably requested by the Controller.
4.7 Deletion / Return. At the Controller's choice, at the end of the provision of the Service, delete or return all Personal Data to the Controller, and delete existing copies, unless applicable law requires the Processor to retain the data. For insurance records, the Processor retains Personal Data for a minimum of 7 years from the date of issuance to comply with applicable insurance record-keeping laws.
4.8 Audit and Information. Make available to the Controller all information necessary to demonstrate compliance with GDPR Article 28 and allow for audits, including inspections, conducted by the Controller or a mandated auditor. The Processor may satisfy this obligation by providing SOC 2-style reports or security questionnaires. On-site audits may be conducted at the Controller's expense, no more than once per year (absent specific regulatory cause), upon 30 days' written notice during business hours.
4.9 Infringement Notification. The Processor will inform the Controller if, in its opinion, an instruction infringes Applicable Data Protection Law.
Controller Obligations
The Controller agrees that it will:
- Have a lawful basis for each category of Personal Data uploaded to the Service, including appropriate consent, contract, or other basis required under Applicable Data Protection Law.
- Have a valid basis for any transfer of Personal Data to the Processor (including, where applicable, for international transfers — see Section 8).
- Ensure accuracy of Personal Data provided to the Service and promptly instruct the Processor to correct or delete inaccurate data.
- Respond to Data Subject requests within the applicable legal timeframe, with reasonable assistance from the Processor as described in Section 4.5.
- Ensure that its use of the Service complies with applicable insurance regulations and data protection laws.
Security and Data Breach Notification
6.1 Security Measures. The Processor maintains the technical and organizational security measures set out in Schedule 2.
6.2 Security Incident Notification. Upon becoming aware of a confirmed Security Incident affecting Personal Data, the Processor will:
- Notify the Controller without undue delay, and in any event within 72 hours of becoming aware of a confirmed breach affecting Personal Data, to the email address on file for the Controller's account Owner. For Controllers whose Data Subjects include EU/EEA residents, this 72-hour window is also intended to support the Controller's own GDPR Article 33 notification obligations.
- Provide reasonable information about the nature of the incident, categories and approximate number of Data Subjects and records affected, likely consequences, and measures taken or proposed to address the incident.
- Cooperate with the Controller's investigation and remediation efforts.
6.3 Notification Responsibilities. The Controller is solely responsible for determining whether and when to notify regulatory authorities or Data Subjects. The Processor will provide reasonable assistance to the Controller in making such notifications.
Sub-processors
7.1 Authorized Sub-processors. The Controller provides general written authorization for the Processor to engage the Sub-processors listed in Schedule 3 (Authorized Sub-processors), which corresponds to the Koffyr Sub-processors page.
7.2 New Sub-processors. The Processor will notify workspace Owners by email at least 30 days in advance of adding a new Sub-processor that processes Customer Personal Data. If the Controller objects to the new Sub-processor on reasonable data protection grounds, the Controller may terminate the affected portion of the Service by providing written notice within the 30-day window.
7.3 Sub-processor Obligations. The Processor will enter into a written agreement with each Sub-processor that imposes data protection obligations no less protective than those set out in this DPA. The Processor remains responsible for the acts and omissions of its Sub-processors.
International Data Transfers
8.1 EEA/UK Transfers. To the extent Personal Data is transferred from the European Economic Area or United Kingdom to the Processor (located in the United States), the parties will rely on Module 2 (Controller-to-Processor) Standard Contractual Clauses as adopted by the European Commission in C(2021)3972. Where SCCs are used, the details in Schedule 1 satisfy the SCCs' Annex I requirements; the security measures in Schedule 2 satisfy the SCCs' Annex II requirements; Schedule 3 satisfies Annex III (Sub-processors).
Koffyr currently serves customers in the United States. GDPR/UK GDPR transfer provisions are included for completeness and future EU/UK expansion; no EU/EEA data subjects are actively served at this time.
8.2 Additional Safeguards. If the legal framework for transfers is invalidated or supplemented by a supervisory authority ruling, the parties will cooperate in good faith to implement alternative lawful transfer mechanisms.
CCPA Obligations (California Customers)
To the extent the CCPA applies, the Processor acknowledges that:
- It acts as a "Service Provider" under the CCPA with respect to Personal Information processed under this DPA.
- It will not sell, share, retain, use, or disclose Personal Information for any purpose other than the business purposes specified in this DPA and the Terms of Service, or as otherwise permitted under the CCPA for service providers.
- It will not retain, use, or disclose Personal Information outside of the direct business relationship between the parties.
- It will assist the Controller in responding to Consumer rights requests under the CCPA consistent with Section 4.5 of this DPA.
- It certifies that it understands and will comply with the foregoing restrictions.
Special Category Data
The Service is not intended for the processing of special category personal data as defined in GDPR Article 9 (including health data, biometric data, or data revealing racial or ethnic origin). The Controller agrees not to upload special category personal data to the Service unless the parties have entered into a written addendum expressly permitting such processing.
Where the Service is used in connection with workers' compensation or health insurance certificates, Customers are responsible for ensuring that any incidental special category data is handled in compliance with Applicable Data Protection Law.
Term and Termination
10.1 This DPA is effective for the duration of the Terms of Service.
10.2 Upon termination of the Terms of Service, Sections 4.7 (deletion/return), 6 (data breach notification for pre-termination incidents), 8 (international transfers), and the obligations that by their nature should survive termination will remain in effect.
Liability and Governing Law
11.1 Each party's liability under this DPA is subject to the limitations of liability in the Terms of Service, to the extent permitted by Applicable Data Protection Law.
11.2 Where both parties are liable for the same damage to a Data Subject, they are each responsible to the extent they caused the damage. If the Processor followed the Controller's documented instructions, the Controller bears primary responsibility.
11.3 Governing Law. This DPA is governed by the laws of the State of Delaware, without regard to conflict-of-law principles. In the event of conflict with the Terms of Service, this DPA takes precedence with respect to data protection matters.
11.4 Modifications. Valtio may update this DPA to reflect changes in law or sub-processor roster by providing 30 days' prior written notice to workspace Owners.
Schedule 1 — Description of Processing
Nature and Purpose of Processing. The Processor provides the Koffyr COI issuance and insurance management platform. Processing activities include: storing and managing insurance policy records, COI data, and related documents; facilitating e-signature workflows and generating Certificates of Completion; notifying insureds and certificate holders of COI requests and status updates; providing audit trails of certificate issuance and lifecycle events; and document storage and secure sharing.
Duration of Processing. As long as the Controller has an active account, plus applicable retention periods (minimum 7 years for insurance records and audit logs).
Categories of Data Subjects.
- Agency employees and members (users of the Koffyr platform)
- Policyholders and insureds (individuals or organization principals)
- Certificate holders / additional insureds (recipients of COI documents)
- Representatives and signatories of insured organizations
Categories of Personal Data.
| Category | Examples |
|---|---|
| Identifiers | Name, email address, phone number, organization name |
| Financial/insurance | Tax ID (TIN/EIN), policy numbers, carrier names, coverage limits |
| Professional | Insured organization name and address, line of business |
| E-signature data | IP address, user agent, signing timestamps |
| Document metadata | Document names, file extensions, upload timestamps |
| Communications | Email delivery status, opt-out preferences |
Schedule 2 — Technical and Organizational Security Measures
Access Control.
- Role-based access control (RBAC); least-privilege principle applied to all resources
- Passkeys (WebAuthn) as primary authentication — phishing-resistant; no static passwords stored
- Email magic links as a single-factor possession alternative; single-use tokens (argon2id hashed)
- Session tokens with short TTL
- Separate KMS key-admin and key-use roles (AWS IAM)
Encryption.
- At rest: Sensitive PII fields (Tax ID / EIN, email, phone, date of birth, home address) are AES-GCM-256 KMS-envelope-encrypted in PostgreSQL.
- In transit: TLS 1.2 minimum with TLS 1.3 negotiated for all data in transit; Cloudflare terminates public HTTPS traffic.
- E-signatures: RFC 3161 timestamps via Entrust TSA (AATL-listed).
Data Integrity and Availability.
- Daily SHA-256 audit digest (tamper-evident seal over audit event log)
- Continuous database backups with point-in-time recovery (PITR), plus immutable weekly recovery points retained 35 days; a documented restore runbook is in place and the first full restore drill is scheduled for Q4 2026
- S3 document vault with versioning
- Multi-AZ RDS deployment for production availability
Monitoring and Incident Detection.
- Sentry for real-time error monitoring and anomaly detection
- Better Stack for log aggregation and uptime monitoring
- Immutable audit log for all resource changes (7-year retention)
- AWS GuardDuty, SecurityHub, Inspector, and Config for infrastructure threat detection (organization-wide)
- AWS CloudTrail for API activity logging
Vulnerability Management.
- CI/CD security scanning: SAST (semgrep), secrets scanning (gitleaks), dependency scanning (trivy) on every merge request
- Dependency update management via Renovate
Organizational Measures.
- Confidentiality obligations for all Valtio personnel with access to Personal Data
- Incident response policy with defined SLAs (see Responsible Disclosure)
Schedule 3 — Authorized Sub-processors
The current authoritative list of authorized sub-processors is published at koffyr.com/sub-processors and constitutes Schedule 3 to this DPA. Sub-processor changes will be communicated in accordance with Section 7.2.
| Sub-processor | Service | Location |
|---|---|---|
| Amazon Web Services, Inc. | Cloud infrastructure (compute, database, storage, KMS, AppSync) | United States (us-east-2) |
| Cloudflare, Inc. | CDN, WAF, DDoS protection, frontend hosting | Global (HQ: United States) |
| Twilio Inc. (SendGrid) | Transactional email delivery | United States |
| Mixpanel, Inc. | Product analytics (anonymous IDs only) | United States |
| Functional Software, Inc. (Sentry) | Error monitoring | United States |
| Stripe, Inc. | Payment processing | United States |
| Entrust, Inc. (Timestamp Authority) | RFC 3161 timestamping for e-signatures (document hashes only) | United States |
| Better Stack, Inc. | Log aggregation and uptime monitoring | United States |