---
title: "Data Protection Addendum"
url: "http://35.223.47.52/dpa/"
date: "2026-08-13T14:43:13+00:00"
modified: "2026-08-24T09:24:44+00:00"
type: "page"
---

# Data Protection Addendum

Data Protection Addendum
========================

Version 1.3 · Dated 14/06/2023 · Last Updated 13/01/2026



This Data Protection Addendum (“Addendum”), dated 14/06/2023, and effective as of the Addendum Effective Date (as defined below), forms part of the Terms of Service (“Terms”) between (i) KNIT API Pvt Ltd. (“Knit”) and (ii) the counterparty entering into the Terms, each being a “Party” and together the “Parties”.

The Parties hereby agree that the terms and conditions set out below shall be added as an Addendum to the Terms and references in this Addendum to the Terms are to the Terms as amended by, and including, this Addendum.

1. Definitions
--------------

In this Addendum, the following terms shall have the meanings set out below and cognate terms shall be construed accordingly:

- **“Addendum Effective Date”** has the meaning given to it in section 2;
- **“Affiliate”** means an entity that owns or controls, is owned or controlled by or is or under common control or ownership with either Client or Knit (as the context allows), where control is defined as the possession, directly or indirectly, of the power to direct or cause the direction of the management and policies of an entity, whether through ownership of voting securities, by contract or otherwise;
- **“Client Personal Data”** means any Personal Data Processed by Knit (i) on behalf of Client (including for the sake of clarity, any Client Affiliate), or (ii) otherwise Processed by Knit, in each case pursuant to or in connection with instructions given by Client in writing, consistent with the Terms;
- **“Standard Contractual Clauses (SCCs)”** means the contractual clauses for the transfer of personal data to third countries pursuant to Regulation (EU) 2016/679 of the European Parliament and of the Council, as set out in Commission Implementing Decision (EU) 2021/914 of 4 June 2021, and as may be amended or replaced from time to time.
- **“Data Protection Laws”** means (i) Directive 95/46/EC and, from May 25, 2018, Regulation (EU) 2016/679 (“GDPR”) together with applicable legislation implementing or supplementing the same or otherwise relating to the processing of Personal Data of natural persons, and (ii) to the extent not included in sub-clause (i), the Data Protection Act 1998 of the United Kingdom, as amended from time to time, and including any substantially similar legislation that replaces the DPA 1998;
- **“Privacy Shield”** means the EU-US Privacy Shield Framework; and
- **“Services”** means the services to be supplied by Knit to Client or Client Affiliates pursuant to the Terms.

The terms “Controller”, “Data Subject”, “Personal Data”, “Personal Data Breach”, “Process”, “Processor” and “Supervisory Authority” have the same meanings as described in applicable Data Protection Laws and cognate terms shall be construed accordingly. Capitalized terms not otherwise defined in this Addendum shall have the meanings ascribed to them in the Terms.

2. Formation of this Addendum
-----------------------------

This Addendum is deemed agreed by the Parties, and comes into effect, on the “Addendum Effective Date”, being the later of (i) the date that this Addendum is accepted by Client; and (ii) Knit.

3. Roles of the Parties
-----------------------

The Parties acknowledge and agree that with regard to the Processing of Client Personal Data, and as more fully described in Annex 1 hereto, Client acts as a Controller and Knit acts as a Processor.

The Parties expressly agree that Client shall be solely responsible for ensuring timely communications to Client’s Affiliates or the relevant Controller(s) who receive the Services, insofar as such communications may be required or useful in light of applicable Data Protection Laws to enable Client’s Affiliates or the relevant Controller(s) to comply with such Laws.

4. Description of Personal Data Processing
------------------------------------------

In Annex 1 to this Addendum, the Parties have mutually set out their understanding of the details of the Processing of the Client Personal Data to be Processed by Knit pursuant to this Addendum, as required by Article 28(3) of the GDPR. Either Party may make reasonable amendments to Annex 1 by written notice to the other Party and as reasonably necessary to meet those requirements. Annex 1 does not create any obligation or rights for any Party.

5. Data Processing Terms
------------------------

5.1 Client shall comply with all applicable Data Protection Laws in connection with the performance of this Addendum. As between the Parties, Client shall be solely responsible for compliance with applicable Data Protection Laws regarding the collection of and transfer to Knit of Client Personal Data. Client agrees not to provide Knit with any data concerning a natural person’s health, religion or any special categories of data as defined in Article 9 of the GDPR.

5.2 Knit shall comply with all applicable Data Protection Laws in the Processing of Client Personal Data and Knit shall:

- 5.2.1 process the Client Personal Data relating to the categories of Data Subjects for the purposes of the Terms and for the specific purposes in each case as set out in Annex 1 to this Addendum and otherwise solely on the documented instructions of Client, for the purposes of providing the Services and as otherwise necessary to perform its obligations under the Terms including with regard to transfers of Client Personal Data to a third country or an international organization; Knit shall immediately inform Client if, in Knit’s opinion, an instruction infringes applicable Data Protection Laws;
- 5.2.2 ensure that persons authorized to process the Client Personal Data have committed themselves to confidentiality or are under an appropriate statutory obligation of confidentiality;
- 5.2.3 implement and maintain appropriate technical and organizational measures, including pseudonymization and encryption of Client Personal Data; ensuring ongoing confidentiality, integrity, availability and resilience of processing systems; restoring availability and access to Client Personal Data in a timely manner in the event of a physical or technical incident; and regularly testing, assessing and evaluating the effectiveness of such measures. Any amendment to such agreed measures that is necessitated by Client shall be dealt with via an agreed change control process between Knit and Client;
- 5.2.4 only engage another Processor to Process the Client Personal Data (“Other Processor”) as listed in Annex 2, subject to Knit notifying Client of any intended changes to its use of Other Processors, including materially equivalent data protection obligations in its contract with each Other Processor, and remaining liable to Client for any failure by each Other Processor. The Client shall have 30 days from notice to object to a new Other Processor, with a further 30-day good-faith period to find a solution; either Party may otherwise terminate the relevant Services on written notice without damages, penalty or indemnification;
- 5.2.5 to the extent legally permissible, promptly notify Client of any communication from a Data Subject or Supervisory Authority relating to the Client Personal Data, and assist Client with its obligations to respond to data subject rights requests under Chapter III GDPR (Client agrees to pay Knit for time and expenses incurred);
- 5.2.6 notify Client without undue delay upon becoming aware of a Personal Data Breach involving Client Personal Data, with all information reasonably required for Client to comply with its obligations;
- 5.2.7 provide reasonable assistance to Client with its obligations under Articles 32 to 36 of the GDPR (Client agrees to pay Knit for time and expenses incurred in connection with Articles 35 and 36);
- 5.2.8 cease Processing the Client Personal Data upon termination or expiry of the Terms, and at Client’s option either return or delete all copies of the Client Personal Data, unless applicable law requires continued storage; retained data remains subject to confidentiality obligations; and
- 5.2.9 make available to Client all information necessary to demonstrate compliance with this Addendum and allow for and contribute to audits, including providing annual responses to cybersecurity and other assessments on reasonable notice (Client agrees to pay Knit for time and expenses incurred).

6. Transfers
------------

Knit is certified to Information Security Management as per ISO 27001:2013. Knit shall notify Client in writing without undue delay if it can no longer comply with its privacy compliance obligations, and will either promptly remediate or engage in good-faith dialogue to determine a new data transfer mechanism. Knit acts as a Processor with respect to Personal Data received pursuant to a data transfer.

If the relevant privacy compliance mechanism is invalidated, Client and each Client Affiliate (“data exporter”) and Knit (“data importer”) shall enter into the Controller to Processor SCCs in respect of any transfer that would otherwise be prohibited by applicable Data Protection Laws, with Appendix 1 and Appendix 2 of the SCCs deemed prepopulated by the relevant sections of Annex 1 and the technical/organizational measures set forth in this Addendum.

7. Precedence
-------------

The provisions of this Addendum are supplemental to the provisions of the Terms. In the event of any inconsistency between the provisions of this Addendum and the provisions of the Terms, the provisions of this Addendum shall prevail.

8. Indemnity
------------

To the extent permissible by law, Client shall indemnify and hold harmless Knit against all losses, third-party claims, administrative fines, and reasonably incurred costs and expenses (including legal, investigatory and consultancy fees) that arise from any breach by Client of this Addendum or of its obligations under applicable Data Protection Laws.

9. Severability
---------------

The Parties agree that, if any section or sub-section of this Addendum is held by any court or competent authority to be unlawful or unenforceable, it shall not invalidate or render unenforceable any other section of this Addendum.

10. Other Commitments
---------------------

Knit’s data processing contract addresses Knit’s role in assisting the customer’s obligations, and follows: Privacy by Design and default; Achieving Security of Processing; Notification of breaches involving PII to a Supervisory Authority; Notification of breaches involving PII to Customers and PII Principals; Conducting Privacy Impact Assessments; Assurance of Assistance by Knit if prior consultations with relevant PII Protection authorities are needed; informing the customer if in Knit’s opinion a processing instruction infringes applicable legislation; not using PII processed under a contract for Marketing and Advertising; coordinating with Clients to help audit systems and providing information so Clients can demonstrate compliance; using AWS and PIPL as sub-processors with Security and Privacy requirements fulfilled; complying with all statutory and regulatory requirements, ISO 27001:2013, ISO 27701:2019 and EU GDPR requirements; deleting or de-identifying Data after processing/retention is complete; and informing clients 24 hours in advance of any legally binding disclosure requests.

For Access, Correction and/or Erasure of PII, or to raise concerns/complaints, contact the Data Protection Officer: **Kunal Mishra**, kunal@getknit.dev, +91 94310 14180.

Annex 1: Description of Processing of Client Personal Data
----------------------------------------------------------

**Subject matter and duration:** set out in Section 2 of the Terms.

**Nature and purpose of Processing:** Due diligence and background verification of organizations and individuals.

**Categories of Data Subjects:** Employees and contractors of Clients.

**Types of Client Personal Data:** Name, address, date of birth, age, education, email, gender, image, job, language, phone, related person, related URL, user ID, username.

**Special categories of data:** None.

**Data exporter:** Client of Knit that uses the Services. **Data importer:** Knit, which provides services to the client and requires receiving the Client’s query data.

**Processing operations:** Knit provides due diligence and background verification services per Client requirements.

Annex 2: Authorized Other Processors
------------------------------------

ProcessorDescription of ProcessingLocationAWSHosting the production environmentMumbai, India &amp; Stockholm, Sweden (for EU)Brevo (formerly SendInBlue)Email vendorEuropean UnionSentryApplication performance monitoringUSAMS ClarityCustomer data segmentation for Knit’s frontendUSAHubSpotLead management and CRM toolUSAAnnex 3: Jurisdiction-Specific Terms
------------------------------------

This Annex applies solely to the extent Client Personal Data includes data relating to data subjects in Canada, Australia, or India.

### 1. Canada (Federal and Quebec)

Applies to Personal Data subject to PIPEDA or Quebec’s Law 25. The Parties agree Knit’s adherence to ISO 27001, ISO 27701, and the technical measures in this DPA constitute “appropriate security safeguards” under PIPEDA Principle 7 and Law 25 Section 10. For Law 25 Section 17, Client acknowledges the transfer of Personal Data outside Quebec is necessary for the Services, that this DPA provides protection equivalent to generally accepted data protection principles, and serves as the written agreement required to mitigate risks identified in any PIA. In the event of a breach, Knit’s notification will include information reasonably necessary for Client to determine “real risk of significant harm” (RROSH) under PIPEDA.

### 2. Australia

Applies to Personal Data subject to the Privacy Act 1988 (Cth) and the Australian Privacy Principles (APPs). Client agrees Knit’s compliance with ISO 27001 and Section 5.2.3 satisfies “reasonable steps” under APP 11. The Parties acknowledge Knit processes Personal Data in India, the EU, and the USA; Knit agrees to process Personal Information in accordance with the GDPR, and Client agrees this constitutes a “law or binding scheme” satisfying the APP 8.2(a) exception. If Knit becomes aware of a breach, it will assist Client in assessing “serious harm” under the Notifiable Data Breaches scheme.

### 3. India

Applies to processing of Digital Personal Data within India, or related to offering goods or services to Data Principals within India, subject to the Digital Personal Data Protection Act, 2023 (“DPDP Act”). “Controller” means “Data Fiduciary” and “Data Subject” means “Data Principal” under the DPDP Act. Knit agrees to implement appropriate technical and organizational measures to comply with the DPDP Act, protect the confidentiality of personal data in its possession, and assist the Client in responding to grievances and Data Principal rights requests. The Data Protection Officer listed in this DPA also serves as the “Grievance Officer” for DPDP Act purposes.
