01Parties and roles
You, the customer, decide why and how personal data in your workspace is processed: you are the controller ("responsable"). wiredfor processes it only on your behalf to provide Kirky: we are the processor ("encargado").
02Subject matter and duration
This agreement covers the processing needed to provide Kirky under your subscription, for as long as the subscription lasts and until the data is deleted as section 12 describes.
03Nature and purpose
We process personal data to:
- Answer your users’ questions from your documents and systems, and run the actions they confirm
- Run Centinela checks on the records your admin selects
- Keep conversations and the audit log for the periods your admin sets
- Secure, support and bill the service
04Data and data subjects
Data subjects are your users and the people named in the documents and records you connect. Categories are whatever you choose to load or connect: typically names, work contact details, roles, questions asked and business records. You don’t send us sensitive personal data unless you have the legal basis and safeguards for it.
05Your instructions
We process personal data only on your documented instructions: this agreement, your configuration in the portal and your users’ requests through the widget. If we believe an instruction breaks the law, we will tell you.
06Confidentiality of our team
Everyone at wiredfor who can access personal data is bound by confidentiality. Staff can only act inside your workspace through a support session that is time-limited and recorded in your audit log.
07Security measures and model use
7.1 We apply the technical and organizational measures described on the security page, including workspace isolation, encryption in transit and at rest, signed short-lived sessions, least-privilege access and an audit log.
7.2 Customer data is not used to train or improve any model.
7.3 The AI model provider is configured not to retain requests, and model invocation logs are kept in our own storage.
08Subprocessors
You authorize the subprocessors listed on the subprocessors page. We will tell you before a new subprocessor starts processing your data, and you can object on reasonable grounds. Each subprocessor is bound by data protection obligations at least as protective as these.
09Where data is processed
Your workspace data is stored and processed in the United States. Where the law requires safeguards for transfers, we put them in place.
10Helping you meet your obligations
We help you answer requests from data subjects (such as access, rectification, cancellation and opposition), and with assessments and consultations with authorities, as far as the service allows. The portal lets your admin export and delete data directly.
11Personal data breaches
If we become aware of a breach affecting your personal data, we notify you without undue delay, with what happened, the data involved, the likely consequences and the measures taken, and keep you informed until it is resolved.
12Deletion and return
When your subscription ends, you can export your data during a transition window. After it, we delete the personal data in your workspace, including backups on their normal rotation, unless the law requires us to keep it.
13Information and audits
We make available the information needed to show we meet this agreement, such as this page, the security model and answers to your security questionnaire. Where that is not enough, you can audit us with reasonable notice, at a reasonable frequency and under confidentiality.
14Order of precedence
This agreement is part of the terms of service. On personal data, it prevails over the terms. A signed DPA with different terms prevails over this page.