Data Processing Addendum
Draft for review · September 2026. This addendum forms part of the Kovern terms for business customers once countersigned.
1. Roles
The customer is the controller of personal data about its personnel that it enters into Kovern. Vibe Code Beast Inc. (“Kovern”) is the processor and processes that data only to provide the service described in the terms.
2. Scope of processing
- Subjects: the customer's employees and contractors who are issued a Kovern card, and the customer's administrators.
- Data: name, work email, job title, optional phone number, monthly budget, card authorizations and transactions as reported by the card network, detected subscriptions, and administrative actions.
- Purpose: issuing and controlling virtual cards, applying the customer's policies, reporting, notifications the customer configures, and support the customer requests.
- Duration: the term of the agreement, plus the retention periods on the trust page.
3. Kovern's obligations
- Process personal data only on the customer's documented instructions, which include the service configuration the customer sets in the product.
- Ensure people authorized to process the data are bound by confidentiality.
- Maintain the technical and organizational measures described on the trust page, including encryption in transit, private networking for the database, role-based access, and per-company audit logging.
- Engage subprocessors only under written terms that impose equivalent obligations, publish the current list on the trust page, and give at least 30 days' notice before adding one that processes personal data. The customer may object on reasonable grounds and terminate the affected service if the objection cannot be resolved.
- Assist the customer with data-subject requests, security assessments, and impact assessments to the extent the information is available to Kovern.
- Notify the customer without undue delay, and in any case within 72 hours of confirmation, of a personal data breach affecting the customer's data.
- On termination, delete or return the personal data within 30 days, except records Kovern must keep under financial regulations, which are kept only for that purpose and for the required period.
- Make available the information needed to demonstrate compliance and allow audits by the customer or an independent auditor it appoints, no more than once a year unless required by a supervisory authority or following a breach, on 30 days' notice.
4. Customer's obligations
The customer is responsible for the lawfulness of the data it enters, for giving its personnel any notices the law requires, and for keeping administrator credentials secure, including the two-step verification Kovern offers.
5. International transfers
Kovern and its subprocessors process data in the United States. Where a customer is subject to laws that restrict transfers, the parties will rely on standard contractual clauses or another lawful mechanism, which the customer can request at hello@kovern.ai.
6. Liability and precedence
Liability under this addendum is subject to the limitations in the terms. If this addendum conflicts with the terms on the processing of personal data, this addendum controls.
Requesting a signed copy
Email hello@kovern.ai from your company domain. We return a countersigned PDF within two business days.