Last updated: April 28, 2026
This Data Processing Addendum ("DPA") supplements the Terms of Service between KCENAV.AI, operating as AISupplyNav ("Processor," "we"), and the subscribing entity ("Controller," "you"). This DPA addresses the requirements of GDPR Article 28 and applicable data protection legislation.
For B2B subscribers: This DPA is automatically incorporated into your subscription agreement. To request a countersigned copy for your records, email legal@kcenav.ai.
"Personal Data" means any information relating to an identified or identifiable natural person provided by Controller to Processor through the AISupplyNav platform.
"Processing" means any operation performed on Personal Data, including collection, storage, analysis by AI models, retrieval, and deletion.
"Sub-processor" means any third party engaged by Processor to process Personal Data on behalf of Controller.
"Data Protection Laws" means GDPR (EU Regulation 2016/679), UK GDPR, CCPA/CPRA, and any other applicable data protection legislation.
| Element | Details |
|---|---|
| Subject matter | Provision of AI-powered supply chain intelligence services |
| Duration | For the term of the subscription agreement plus 30 days for deletion |
| Nature & purpose | Storage, AI analysis, report generation, and advisory services for supply chain data |
| Categories of data subjects | Controller's employees, authorized users, and supply chain contacts referenced in uploaded data |
| Types of Personal Data | Email addresses, names, job titles, company information, supply chain data containing business contact details |
The Processor shall:
The Controller provides general authorization for the Processor to engage Sub-processors. Current Sub-processors:
| Sub-processor | Purpose | Location |
|---|---|---|
| Neon Tech, Inc. | PostgreSQL database hosting | United States |
| Render Services, Inc. | Application hosting & infrastructure | United States |
| Stripe, Inc. | Payment processing | United States |
| AI model providers (multi-model) | Natural language processing for supply chain analysis | United States |
The Processor shall:
If the Controller objects to a new Sub-processor, the Controller may terminate the affected services within 30 days of notification.
All data is processed and stored in the United States. For transfers of Personal Data from the EEA/UK to the US, the parties agree to rely on the EU Standard Contractual Clauses (Module Two: Controller to Processor, Commission Implementing Decision 2021/914) incorporated by reference.
The Processor shall, taking into account the nature of the processing, assist the Controller by appropriate technical and organizational measures for the fulfillment of data subject requests including:
The Processor shall respond to Controller requests for assistance within 10 business days.
The Processor shall notify the Controller without undue delay (and in any event within 72 hours) after becoming aware of a Personal Data breach. Notification shall include:
The Processor shall make available to the Controller all information necessary to demonstrate compliance with this DPA. The Controller may conduct audits, including inspections, subject to:
Given that AISupplyNav uses AI models to process data:
See our AI Use Policy for detailed practices.
This DPA is effective for the duration of the subscription agreement. Upon termination:
This DPA is governed by the laws of the State of Delaware, United States. For Controller's located in the EEA, the GDPR shall apply in addition.
To request a countersigned DPA, report a data issue, or exercise audit rights: