Public BetaJoin as a Founding User and lock in 50% off while the offer is active. Register and create AI agents

Data Processing Agreement

Version 0.2 · Last updated: August 11, 2026

Draft for legal review before production use.This Data Processing Agreement ("DPA") is published as a draft to support transparency and vendor assessment. It is not yet a binding agreement. Contact [email protected] to review or execute a DPA for your organization.

This DPA forms part of the agreement between Klicco Pte. Ltd. ("KlicForge") and the customer ("Customer") and governs the processing of Customer Personal Data in connection with the KlicForge services.

1. Definitions

"Applicable Data Protection Law" means the data-protection laws applying to the processing of Customer Personal Data, including as applicable the Singapore Personal Data Protection Act 2012 ("PDPA"), the EU/EEA General Data Protection Regulation ("GDPR"), the UK GDPR, and the California Consumer Privacy Act as amended ("CCPA").

"Customer Personal Data" means personal data that the Customer (or its end users) submits to the services and that KlicForge processes on the Customer's behalf.

Under the GDPR/CCPA, the Customer is the controller (or a processor acting for its own controllers) and KlicForge the processor / service provider. Under the PDPA, the Customer is the organisation and KlicForge a data intermediaryprocessing Customer Personal Data on the Customer's behalf pursuant to a contract evidenced in writing. These terms describe the same relationship and are used interchangeably in this DPA.

2. Roles & scope of processing

KlicForge processes Customer Personal Data only on the Customer's documented instructions — as set out in the agreement, this DPA, and the Customer's configuration of the services — and not for any other purpose. KlicForge acts as an independent organisation (controller) only for the account, billing, and usage data of the Customer's own personnel, as described in the Privacy Policy.

Schedule 1 — Processing details. Subject matter: provision of the KlicForge AI agent platform (agent runtime, dashboard, messaging channels, knowledge and data storage, notifications). Duration: the subscription term plus the deletion window in Section 10. Nature and purposes: hosting and storage; processing conversations and generating AI agent responses; retrieval from Customer-provided knowledge; execution of Customer-configured tools and integrations; channel delivery; support. Categories of individuals: the Customer's end users and contacts, and the Customer's personnel using the services. Categories of data: contact and identification details, conversation content, and any personal data the Customer chooses to include in uploaded knowledge, connected tools, or data tables.

The Customer instructs KlicForge to process Customer Personal Data using the AI model providers and other subprocessors disclosed under Section 6, as configured by the Customer.

3. Customer obligations

The Customer warrants that it has the lawful authority to provide Customer Personal Data to KlicForge for processing — including any consent, notification, or other basis required by Applicable Data Protection Law — and that its instructions are lawful. The Customer is responsible for the accuracy and lawfulness of the data it submits, for managing its authorised users and access, and for responding to its own data subjects.

4. KlicForge obligations

  • Instructions. Process Customer Personal Data only on documented instructions, and inform the Customer if an instruction appears to infringe Applicable Data Protection Law.
  • Confidentiality. Ensure persons authorised to process Customer Personal Data are bound by confidentiality.
  • Security. Maintain reasonable security arrangements as required by section 24 of the PDPA and Article 32 GDPR, as described in Section 5.
  • Retention limitation. Not retain Customer Personal Data longer than necessary to provide the services, per the retention schedule on the Singapore PDPA page and Section 10.
  • Assistance. Provide reasonable assistance with data-subject requests (Section 9), security, breach assessment and notification, and data protection impact assessments, taking into account the nature of the processing.
  • No training. Not use Customer Personal Data to train AI models, and not opt in to third-party AI provider training programmes (Section 7).

5. Security measures

KlicForge maintains technical and organisational measures designed to protect Customer Personal Data, including: field-level AES-256-GCM encryption with versioned, rotatable keys; database-level tenant isolation enforced by PostgreSQL row-level security; TLS for data in transit; role-based access control with multi-factor authentication available to all users and mandatory for KlicForge platform administrators; append-only security and data audit logging with enforced retention; a default-on PII-redaction guardrail applied before AI model requests; automated security scanning of each release; and automated daily database backups with a 7-day retention window.

These measures (Schedule 2) are further described on the Trust Hub and the Singapore PDPA page, which form the security exhibit to this DPA. KlicForge may update the measures provided the overall level of protection is not reduced.

6. Subprocessors

The Customer provides general authorization for KlicForge to engage the subprocessors listed on the Subprocessor List, including AI model providers. KlicForge imposes data-protection obligations on subprocessors consistent with this DPA and remains responsible for their performance.

KlicForge will give at least 30 days advance notice before a new subprocessor begins processing Customer Personal Data. To receive that notice, register an address with [email protected]; changes are also published to the Subprocessor List. The Customer may object on reasonable data-protection grounds within the notice period, in which case the parties will work in good faith to find an alternative. If none is available, the Customer may terminate the affected service.

7. AI & model training

KlicForge does not use Customer Personal Data to train its own AI models, and does not opt in to third-party AI provider training programmes. When an agent uses an AI model, content is processed by the selected model provider; KlicForge routes platform model requests through an aggregator account with Zero Data Retention enabled. Provider-specific handling depends on the chosen model and its terms, as disclosed per provider on the Subprocessor List. Where the Customer connects its own model provider credentials (bring-your-own-key), requests to that provider run under the Customer's own account and terms.

8. International transfers

KlicForge is operated by Klicco Pte. Ltd., established in Singapore. Application compute and the primary database are hosted in Singapore; certain subprocessors listed on the Subprocessor List process personal data in the United States and other countries.

Singapore (PDPA). For Customer Personal Data transferred out of Singapore, KlicForge will ensure the recipient is bound by legally enforceable obligations to provide the transferred data a standard of protection comparable to the PDPA, in accordance with the Transfer Limitation Obligation (section 26 of the PDPA and its regulations). KlicForge maintains contractual data-protection terms with each subprocessor for this purpose.

EEA / Switzerland / UK. Where personal data originating in the EEA or Switzerland is transferred to a country without an adequacy decision, the parties rely on the Standard Contractual Clauses adopted in Commission Implementing Decision (EU) 2021/914, incorporated by reference. For personal data originating in the United Kingdom, the UK International Data Transfer Addendum applies.

9. Personal data breaches & data subject requests

Where KlicForge has reason to believe that a personal data breach has occurred affecting Customer Personal Data, KlicForge will notify the Customer without undue delay, and in any case within 72 hours of confirming the breach, providing the information reasonably available at the time (nature of the breach, categories and approximate volume of data affected, measures taken) and supplementing it as more becomes known. The Customer remains responsible for assessing whether the breach is notifiable under Applicable Data Protection Law and for notifications to regulators (including the PDPC) and to individuals, except where the law requires KlicForge to notify directly. KlicForge will provide reasonable cooperation with the Customer's assessment and notifications.

If KlicForge receives a request from the Customer's data subject directly, it will redirect the individual to the Customer where appropriate. The services provide tools for access, export, correction, and deletion; beyond those tools, KlicForge provides reasonable assistance under Section 4.

10. Return & deletion

The Customer can delete Customer Personal Data through the services at any time. Upon termination or account closure, KlicForge will delete Customer Personal Data across its stores — including uploaded files and search indexes — within 30 days, except where retention is required by law (for example, billing records). Deleted data ages out of encrypted database backups within the 7-day backup rotation.

11. Audit & information rights

KlicForge makes information demonstrating compliance with this DPA available through: the Trust Hub and Singapore PDPA pages; the Subprocessor List; and written responses to reasonable information requests and vendor-assessment questionnaires addressed to [email protected]. Where Applicable Data Protection Law grants the Customer a mandatory audit right that cannot be satisfied by the above, an audit may be conducted no more than once per year, on reasonable notice, during business hours, at the Customer's cost, and without access to other customers' data or KlicForge's security- sensitive configurations.

12. Precedence, liability & governing law

This DPA forms part of, and is subject to, the agreement between the parties (including its limitations of liability). In case of conflict regarding the processing of Customer Personal Data, this DPA prevails. Governing law and jurisdiction follow the agreement.

13. Contact

To request a signed DPA or for any data-protection question, contact [email protected] — this address reaches KlicForge's designated Data Protection Officer function.

Version history

0.2 (August 11, 2026) — restructured with PDPA data-intermediary definitions, Singapore transfer module, breach-notification clause, processing details schedule, and audit ladder. · 0.1 (June 18, 2026) — initial draft.