Skip to content
Kifas
PlatformMCPPricingDocsChangelogSign inStart free
Sign inStart free

Legal

Terms of ServicePrivacy PolicyData Processing AddendumSecuritySubprocessorsRefund Policy

Kifas Data Processing Addendum

Effective Date: 13 September 2026 | Last Updated: 13 September 2026

This Data Processing Addendum ("DPA") forms part of the agreement between the customer identified in the applicable Kifas Terms of Service, Order Form, or Master Services Agreement ("Customer") and Kifas Labs Ltd, Israeli Company Number 517267134, with its registered office at Shikma 2, Dvira 8533000, Israel ("Kifas").

This DPA applies when Kifas processes Customer Personal Data on Customer's behalf in connection with the Services. It is incorporated into the Kifas Terms of Service and takes effect when Customer accepts the Terms, signs an Order Form or Master Services Agreement that refers to this DPA, or uses the Services to process Customer Personal Data.

1. Definitions

"Applicable Data Protection Law" means a privacy, data protection, or data security law that applies to Kifas's processing of Customer Personal Data under the Agreement.

"Customer Personal Data" means personal data, personal information, or an equivalent term under Applicable Data Protection Law that Kifas processes on Customer's behalf through the Services. It does not include personal data for which Kifas independently determines the purposes and means of processing, such as Kifas account administration, billing, security, fraud prevention, and direct customer communications described in the Privacy Policy.

"De-identified Data" means data that cannot reasonably be linked to an identified or identifiable individual or household. Kifas will maintain technical safeguards and business processes designed to prevent reidentification, will not attempt to reidentify De-identified Data except to test those safeguards where permitted by law, and will contractually require any recipient to follow the same restrictions.

"Data Subject Request" means a request by an individual to exercise a right under Applicable Data Protection Law.

"Security Incident" means a breach of security that results in the accidental or unlawful destruction, loss, alteration, unauthorized disclosure of, or access to Customer Personal Data. Security Incident does not include unsuccessful attempts or activity that does not compromise Customer Personal Data, such as scans, pings, failed login attempts, or denial-of-service attacks.

"Subprocessor" means a third party engaged by Kifas to process Customer Personal Data on Customer's behalf.

Capitalized terms not defined in this DPA have the meanings given in the Agreement.

2. Roles and instructions

Customer is the controller or business and Kifas is the processor, service provider, or contractor for Customer Personal Data, as those terms are defined by Applicable Data Protection Law. Customer appoints Kifas to process Customer Personal Data only:

  • to provide, maintain, secure, and support the Services;
  • as described in the Agreement and Schedule 1;
  • on Customer's documented instructions, including instructions given through Customer's use and configuration of the Services; and
  • as required by law.

If law requires Kifas to process Customer Personal Data other than on Customer's instructions, Kifas will inform Customer before that processing unless the law prohibits notice. Kifas will notify Customer if, in its reasonable opinion, an instruction violates Applicable Data Protection Law. Kifas is not responsible for deciding whether Customer's instructions comply with law.

Notwithstanding Section 11 of the Terms, Kifas will not use Customer Personal Data to train, fine-tune, evaluate, or improve AI models.

Customer is responsible for the lawfulness, accuracy, and quality of Customer Personal Data and for providing all notices and obtaining all rights, consents, and authorizations needed for Kifas to process it under this DPA. Customer will not instruct Kifas to process data in violation of the Agreement or Applicable Data Protection Law.

3. Confidentiality and access

Kifas will ensure that people authorized to process Customer Personal Data are bound by confidentiality obligations and receive access only as needed to perform their duties. Kifas will maintain access controls designed to prevent unauthorized processing.

4. Security

Kifas will maintain reasonable administrative, technical, and organizational measures appropriate to the nature of Customer Personal Data and the risk of processing. These measures include the controls described in Schedule 2 and on the Kifas Security page.

Customer is responsible for configuring the Services appropriately, protecting its credentials and endpoints, and using available security controls. Customer acknowledges that no system can guarantee absolute security.

5. Security Incidents

Kifas will notify Customer without undue delay after becoming aware of a Security Incident. An initial notice may contain the information then available and does not constitute a final determination that a breach occurred. The notice will include information reasonably available to Kifas about the nature of the incident, affected data, likely consequences, and remediation steps. Kifas may provide information in phases as its investigation progresses.

Kifas will take reasonable steps to contain, investigate, and remediate a Security Incident and will reasonably assist Customer with legally required notifications. Kifas's notice or response is not an admission of fault or liability.

6. Data Subject Requests and compliance assistance

Taking into account the nature of the processing, Kifas will provide reasonable assistance to help Customer respond to Data Subject Requests. If Kifas receives a request concerning Customer Personal Data directly from an individual, Kifas will direct the requester to Customer unless Kifas is legally required to respond.

Taking into account the nature of processing and information available to Kifas, Kifas will provide reasonable assistance with Customer's obligations concerning security, breach notification, and data protection assessments under Applicable Data Protection Law. Customer is responsible for its own compliance decisions and regulatory communications.

7. Subprocessors

Customer gives Kifas general authorization to use the Subprocessors listed at kifas.io/subprocessors. Kifas will impose on each Subprocessor the same data protection obligations imposed on Kifas by this DPA, to the extent applicable to the services performed. Kifas remains responsible under this DPA for each Subprocessor's compliance with those obligations.

Kifas will give Customer at least 15 days' advance notice at the primary email address on Customer's account before a new Subprocessor begins processing Customer Personal Data. Customer may also request notice by emailing legal@kifas.io. Customer may object on reasonable data protection grounds within 15 days after notice. The parties will work in good faith to resolve the objection. If no reasonable alternative is available, either party may terminate the affected part of the Services, and Kifas will refund prepaid fees for the terminated period.

8. Return and deletion

During the term, Customer may access or export Customer Personal Data through available Service features. At Customer's choice, Kifas will return or delete all Customer Personal Data after termination or expiration, unless law requires retention. Customer may exercise that choice by emailing legal@kifas.io before the applicable deletion deadline in the Privacy Policy. If Customer gives no direction, Kifas will delete Customer Personal Data according to those deadlines.

For Kifas for Jira, access stops immediately when a Jira site is unlinked or the app is uninstalled. App credentials are deleted immediately, and retained Jira data and data derived from it are permanently purged within 30 days. Other retention periods are described in the Privacy Policy.

If law requires retention, Kifas will isolate and protect the retained data and process it only for the legally required purpose.

9. Reviews and audits

On reasonable written request, Kifas will provide information necessary to demonstrate its compliance with this DPA. Customer may request a remote review no more than once in any 12-month period, unless a Security Incident or regulator requires an additional review.

If the provided information is not reasonably sufficient, Customer may request an audit by an independent auditor bound by confidentiality. The audit must occur during normal business hours, avoid disruption, protect other customers' data, and be limited to systems relevant to Customer Personal Data. Customer will pay its audit costs and Kifas's reasonable assistance costs unless the audit identifies a material breach of this DPA by Kifas.

10. U.S. state privacy terms

To the extent a U.S. state privacy law applies and Customer is a business or controller, Kifas acts as Customer's service provider, contractor, or processor for Customer Personal Data. Kifas will:

  • process Customer Personal Data only for the purposes in Section 2 and Schedule 1 and on Customer's instructions;
  • not sell or share Customer Personal Data, including for cross-context behavioral advertising or targeted advertising;
  • not retain, use, or disclose Customer Personal Data outside the direct business relationship with Customer or for a commercial purpose other than providing the Services;
  • not combine Customer Personal Data with personal information received from another person or collected from Kifas's own interaction with an individual, except as permitted by law to provide the Services;
  • provide the same level of privacy protection required of Customer to the extent required by applicable law;
  • notify Customer if Kifas determines it can no longer meet these obligations; and
  • allow Customer to take reasonable and appropriate steps to verify, stop, and remediate unauthorized use of Customer Personal Data.

The parties acknowledge that Customer provides Customer Personal Data to Kifas only for the limited and specified purposes in Section 2 and Schedule 1. Kifas certifies that it understands and will comply with the restrictions in this Section.

11. International transfers and geographic scope

Customer Personal Data is processed in the United States, Israel, and the locations disclosed on the Subprocessors page. Customer authorizes those transfers subject to this DPA and Applicable Data Protection Law.

The Services are not offered to residents of the European Union, European Economic Area, United Kingdom, or Switzerland. This DPA does not change that restriction. Customer must not use the Services to process personal data subject to the laws of those regions without Kifas's prior written agreement and an approved transfer mechanism. This DPA does not incorporate the European Commission Standard Contractual Clauses, the UK International Data Transfer Addendum, or the Swiss equivalent.

12. Liability, conflict, and term

This DPA remains in effect while Kifas processes Customer Personal Data. The limitations of liability, governing law, dispute resolution, and other terms of the Agreement apply to this DPA.

If this DPA conflicts with the Agreement on the processing of Customer Personal Data, this DPA controls. An Order Form or signed Master Services Agreement controls over this DPA only if it specifically identifies the section of this DPA that it overrides.

13. Contact

Questions, notices, and requests concerning this DPA should be sent to legal@kifas.io.

Schedule 1: Details of processing

Subject matter and purpose: Providing, maintaining, securing, and supporting the Kifas cloud testing platform and customer-selected integrations, including Kifas for Jira.

Duration: The term of the Agreement plus the retention and deletion periods described in Section 8.

Nature of processing: Collection, receipt, access, organization, storage, retrieval, consultation, analysis, transmission, synchronization, display, modification at Customer's direction, support, security monitoring, deletion, and other processing needed to provide the Services.

Categories of individuals: Customer's users, personnel, contractors, customers, website or application users represented in Customer test data, Jira users represented in synchronized issues, and other individuals whose personal data Customer submits to the Services.

Types of Customer Personal Data: Names, business contact details, account and technical identifiers, IP addresses, Jira account IDs and display names, Jira issue content and metadata, code and pull-request metadata, test inputs and outputs, workflows, prompts, screenshots, recordings, logs, support content, and other Customer Content submitted through the Services.

Sensitive data: The Services are not designed to process government identifiers, payment-card data, health data, biometric data, precise geolocation, or other sensitive personal data. Customer must not submit sensitive personal data unless Kifas has agreed in writing and appropriate safeguards are in place. Customer must not include Customer Personal Data in a Published Workflow.

Processing instructions: The Agreement, this DPA, Customer's configuration and use of the Services, and other documented instructions accepted by Kifas.

Schedule 2: Security measures

Kifas maintains measures designed to protect Customer Personal Data, including:

  • TLS 1.2 or newer for network traffic and AES-256 or equivalent provider-managed encryption at rest;
  • role-based and least-privilege access and multi-factor authentication for administrative access;
  • tenant authorization controls, including database row-level security;
  • secrets management that keeps credentials out of source control;
  • secure development practices, code review, dependency and static analysis, patching, and vulnerability management;
  • request validation, parameterized database access, output escaping, logging, monitoring, backups, and incident response;
  • short-lived Jira user tokens that are not stored, and short-lived app credentials protected with AWS KMS envelope encryption;
  • restrictions designed to keep passwords, API keys, Forge tokens, Jira ticket bodies, and Atlassian account IDs out of application logs; and
  • deletion processes for expired or terminated Customer Personal Data.
Kifas ยท Testing built for agents.
PlatformMCPPricingDocsChangelogSecurityPrivacyDPATermsRefundCookie preferences