This Data Processing Addendum (“DPA”) supplements the Terms of Service between Knolink (Pty) Ltd (“Entropy”, “Processor”, or “Service Provider”), located in Midrand, Gauteng, South Africa, and the Customer (“Controller” or “Responsible Party”) agreeing to these terms.
This DPA applies where and to the extent that Entropy processes Customer Personal Data in the course of providing the Service under South Africa's Protection of Personal Information Act (POPIA), the General Data Protection Regulation (GDPR), and applicable international data privacy laws.
1. Definitions & Scope
“Customer Personal Data” means any personal information processed by Entropy on behalf of Customer in connection with the Service. “Applicable Privacy Law” means POPIA, Regulation (EU) 2016/679 (GDPR), UK Data Protection Act 2018, and California Consumer Privacy Act (CCPA).
2. Roles of the Parties
The parties acknowledge and agree that with respect to Customer Personal Data processed within developer workspaces and collaborative sessions, Customer is the Controller (or Responsible Party) and Entropy is the Processor (or Operator).
3. Processor Obligations
Entropy agrees to process Customer Personal Data only on documented instructions from Customer, including regarding transfers of personal data, unless required to do so by applicable statutory law.
Entropy guarantees that all personnel authorized to process Customer Personal Data have committed themselves to confidentiality or are under an appropriate statutory obligation of confidentiality.
4. Subprocessors & Transfers
Customer provides general authorization for Entropy to engage third-party subprocessors (including AI infrastructure providers Anthropic, OpenAI, and Google) subject to equivalent data protection obligations.
Entropy maintains an up-to-date schedule of all authorized subprocessors at entropy.knolink.co.za/acceptable-use-policies.
5. Technical & Organizational Measures (TOMs)
Entropy implements and maintains appropriate technical and organizational measures to ensure a level of security appropriate to the risk, including:
- End-to-end encryption in transit (TLS 1.3) and at rest (AES-256).
- Hardware security keys and role-based access control (RBAC).
- Continuous vulnerability scanning and automated container isolation.
- Regular backup verification and zero-retention AI inference pipelines.
6. Security Incident Notification
Entropy will notify Customer without undue delay (and in any event within 72 hours) upon becoming aware of a confirmed Security Incident affecting Customer Personal Data.
7. Deletion & Return of Data
Upon termination of the Services or upon Customer’s written request, Entropy will delete or return all Customer Personal Data within 30 days, unless applicable statutory law requires ongoing retention.
8. Execution & Inquiries
Enterprise customers requiring a countersigned copy of this Data Processing Addendum or custom Standard Contractual Clauses (SCCs) may contact our legal counsel: