Data Processing Agreement
Data Processing Agreement
Last updated 20 September 2026. This is Kryston's standard DPA template, published for review before an engagement begins. It's designed to be incorporated by reference into a signed agreement, or executed as its own signed document alongside one; it isn't in force on its own.
1. Roles
For the purposes of this Agreement, the client is the Controller and Ilija Stoev, trading as Kryston ("Kryston", the "Processor") processes personal data on the Controller's behalf and instructions, in connection with the marketing and search visibility services described in the underlying engagement (the "Services").
2. Subject matter and duration
This Agreement covers the processing of personal data Kryston performs while delivering the Services, for the duration of the engagement, plus any period needed to return or delete that data afterward under Section 7.
3. Nature and purpose of processing
Kryston processes personal data only as needed to deliver the Services: for example, contact and firmographic data used for buyer research, outreach lists, or content and account access the Controller provides for the engagement. The specific categories of data and data subjects for a given engagement are set out in that engagement's statement of work.
4. Processor obligations
In carrying out the Services, Kryston will:
- Process personal data only on the Controller's documented instructions, unless required otherwise by law.
- Keep personal data confidential, and ensure anyone processing it under Kryston's authority is bound to confidentiality.
- Implement the technical and organizational security measures described on Kryston's Trust Center, including multi-factor authentication, encrypted credential handling, and role-scoped access.
- Not engage a new subprocessor without giving the Controller reasonable notice; current subprocessors are listed on the Trust Center.
- Assist the Controller, on reasonable request, in responding to data subject access requests and in meeting its own obligations around security, breach notification and data protection impact assessments, to the extent Kryston's processing is involved.
- Notify the Controller without undue delay, and in any case within 72 hours of becoming aware, of any personal data breach affecting data processed under this Agreement.
- Make available the information reasonably necessary to demonstrate compliance with this Agreement, and allow for reasonable audits by the Controller or its auditor on reasonable notice.
5. International transfers
Where personal data is transferred to a subprocessor outside the Controller's jurisdiction, Kryston will rely on that subprocessor's own cross-border transfer safeguards (such as Standard Contractual Clauses, where applicable), and will make details available to the Controller on request.
6. Sub-processing
The Controller authorizes Kryston to engage the subprocessors listed on the Trust Center as of the effective date of the engagement. Kryston remains responsible for a subprocessor's compliance with obligations equivalent to those in this Agreement.
7. Deletion or return of data
On termination of the engagement, Kryston will, at the Controller's choice, delete or return all personal data processed under this Agreement within the duration of the engagement plus 12 months, unless a client agreement states otherwise, except where retention is required by law.
8. Liability
Liability under this Agreement is subject to any limitation of liability agreed in the underlying engagement.
9. Governing law
This Agreement is governed by the laws of North Macedonia, unless the underlying engagement specifies otherwise.
10. Contact
To execute a signed copy of this Agreement for your engagement, or to ask questions before you do: privacy@kryston.net.
This is a template drafted with AI assistance. It has not been reviewed by a lawyer and is not tailored to any specific engagement, jurisdiction, or regulatory regime your organization may be subject to. Have your own counsel review it, and Kryston's, before signing.