Data Processing Addendum
1. Introduction and Scope
This Data Processing Addendum ("DPA") forms part of the agreement between Zachary Cardoza, doing business as Kaweah Tech ("Kaweah Tech," "we," "us," or "our"), and the organization that subscribes to an Organization plan for Licentio ("the Service") as described in Terms of Service § 6.2 (the "Organization," "you," or "your"). Together, the Terms of Service, the plan terms referenced in them, and this DPA are the "Agreement."
This DPA applies automatically to every Organization plan subscription and does not require signature. If your procurement process requires a countersigned copy, contact legal@licent.io and we will execute one. If a vendor form your organization provides conflicts with this DPA, the two documents must be reconciled in writing before the conflicting terms bind either party; neither submitting a form to us nor referencing it in a purchase order amends the Agreement by itself.
This DPA governs our processing of Organization Personal Data, defined in Section 2. It does not replace or modify our Privacy Policy, which describes our practices for all personal information we process, or the direct agreements between Kaweah Tech and the individual users in your organization, described in Section 3.
2. Organization Personal Data
"Organization Personal Data" means personal information that we process on your behalf in connection with your organization's use of the Service, consisting of:
- Roster and membership data: the names, email addresses, roles, and membership dates of the people you invite to or manage within your organization, including pending invitations
- Reporting views: the dashboards, aggregate metrics, and report exports the Service produces for your organization, to the extent they contain personal information about your members, within the visibility limits of Terms of Service § 5.2
- Audit records: the log of actions taken within your organization (membership changes, role changes, report exports, billing events) described in Data Retention Policy § 4.1
- Billing contact data: the names and email addresses of your administrators and billing contacts
"Processing" means any operation performed on personal information, such as collection, storage, use, disclosure, or deletion. Terms such as "business," "service provider," "contractor," "consumer," "sell," and "share" have the meanings given by the California Consumer Privacy Act, Cal. Civ. Code § 1798.100 et seq. ("CCPA"); where the privacy law of another US state applies, "business" should be read to include "controller" and "service provider" to include "processor."
3. Roles and Relationship to Individual Agreements
With respect to Organization Personal Data, you are the business and we are your service provider: we process that data on your behalf and on your instructions as set out in this DPA and the Agreement.
Every associate, supervisor, and administrator in your organization also holds an individual Licentio account under their own direct agreement with Kaweah Tech, including our Terms of Service and Privacy Policy. Associates own their individual licensure records; your organization administers access and reporting but does not own those records (Terms of Service § 5.2). For personal information that individuals provide under their own accounts — their licensure records, supervision data, profile information, and account activity — we act as the business collecting that information directly, as described in the Privacy Policy. This DPA does not give your organization rights over that data, and nothing in this DPA reduces the rights of individual users under their own agreements with us.
4. Details of Processing
| Aspect | Description |
|---|---|
| Purpose of processing | Providing the Organization plan features: membership and invitation management, role administration, organization dashboards and aggregate reporting, report exports, audit logging, and subscription billing |
| Duration | The term of your organization subscription, plus the retention periods described in Data Retention Policy § 4 |
| Categories of data subjects | Your administrators, supervisors, associates, invitees, and billing contacts |
| Categories of personal information | Identifiers (name, email address); professional information (role, membership dates, and the aggregate progress figures described in Terms of Service § 5.2); audit log entries; billing metadata |
| Sensitive personal information | None intended. The Service prohibits protected health information and client-identifying data (see Section 10) |
5. Our Obligations as Your Service Provider
With respect to Organization Personal Data, we will:
- Process it only for the limited and specified purposes described in Section 4 and as otherwise permitted for service providers by the CCPA, and not for any other purpose
- Not sell it or share it for cross-context behavioral advertising
- Not retain, use, or disclose it outside of our direct business relationship with you, except as permitted by the CCPA and its regulations
- Not combine it with personal information we receive from other sources, except as permitted for service providers by the CCPA regulations
- Comply with the obligations the CCPA places on service providers and provide the same level of privacy protection the CCPA requires of businesses, and comply with the equivalent processor obligations of any other applicable US state privacy law
- Not use it to train artificial intelligence or machine learning models, consistent with the commitment in Privacy Policy § 2.3
- Notify you without unreasonable delay if we determine that we can no longer meet our obligations under the CCPA or this DPA
- Upon reasonable notice, permit you to take reasonable and appropriate steps to stop and remediate any unauthorized use of Organization Personal Data, as provided by Cal. Civ. Code § 1798.100(d)
We certify that we understand the restrictions above and will comply with them.
6. Confidentiality and Security
We ensure that every person we authorize to process Organization Personal Data is bound by a duty of confidentiality.
We maintain the technical and organizational security measures described on our Security page, including encryption in transit (TLS 1.2 or higher), encryption at rest for structured data and backups, Argon2id password hashing, capability-based authorization, and audit logging of authentication events, record modifications, role changes, and administrative actions. Those measures are incorporated into this DPA by reference. We may improve or update them over time, but we will not materially reduce the overall protection of Organization Personal Data during your subscription term.
As stated on the Security page, we do not currently hold SOC 2, HIPAA, or HITRUST attestations. We plan to pursue a SOC 2 Type II audit as the platform matures, and the Security page will be updated when that process begins.
7. Subprocessors
You provide general written authorization for us to engage the subprocessors that support the Service. The canonical, current list of subprocessors — including the data each processes and the purpose of each engagement — is Privacy Policy § 4.2, which is incorporated into this DPA by reference and maintained as the single source of truth, as described on our Security page, Section 3.
Each subprocessor that processes personal information is engaged under a written agreement with data protection obligations consistent with those in this DPA, as described in Privacy Policy § 4.2. We remain responsible to you for our subprocessors' performance of those obligations.
Before a new subprocessor processes Organization Personal Data, we will update the Privacy Policy and notify your organization's administrators by email at least 30 days in advance, consistent with the notice commitment in Privacy Policy § 10. If you have a reasonable, data-protection-related objection to the new subprocessor, contact legal@licent.io within that notice period and we will work with you in good faith to resolve the objection. If we cannot resolve it, you may cancel your organization subscription as described in Terms of Service § 6.4 before the change takes effect.
8. Breach Notification
"Breach" has the meaning given in Privacy Policy § 5.1: the unauthorized acquisition of unencrypted personal information, or of encrypted personal information together with the key or credential necessary to decrypt it, consistent with Cal. Civ. Code § 1798.82.
If we confirm a breach affecting Organization Personal Data, we will notify your organization's administrators without undue delay, and in any event within 72 hours of confirmation. Because the initial notice is prompt, it may be preliminary: it will describe the nature of the breach, the categories and approximate volume of Organization Personal Data involved, and the measures we have taken or plan to take, to the extent known at the time, and we will supplement it as the investigation progresses. Individual users affected by a breach are notified separately under Privacy Policy § 5.1.
We will reasonably cooperate with your organization's own legal notification obligations arising from the breach. Our notification is not an acknowledgement of fault or liability.
9. Assistance with Privacy Rights Requests
Because every member of your organization is also our direct consumer under the Privacy Policy, individuals exercise their privacy rights (access, correction, deletion, export) directly with us, using the mechanisms in Privacy Policy § 7. We respond to those requests ourselves; you do not need to relay them.
If your organization receives a privacy rights request that concerns Organization Personal Data, we will provide reasonable assistance so you can respond, including confirming what Organization Personal Data we hold. If we receive a request that is properly directed to your organization as the business, we will forward it to your administrators without unreasonable delay.
10. No PHI; No Business Associate Agreement
The Service must not be used to store protected health information (PHI) or client-identifying data (Terms of Service § 5.1). As an Organization plan subscriber, you are responsible for communicating this prohibition to the associates and supervisors in your organization (Terms of Service § 5.2).
We are not a HIPAA Business Associate, no Business Associate Agreement exists between Kaweah Tech and any user or organization, and nothing in this DPA creates one or makes Kaweah Tech a Business Associate (Privacy Policy § 5.3).
11. Data Location
Organization Personal Data is stored and processed in the United States (Privacy Policy § 5). The Service is offered exclusively to users in the United States, and we do not transfer Organization Personal Data outside the United States.
12. Audits and Security Reviews
We support your vendor due diligence through documentation: this DPA, the Privacy Policy, the Data Retention Policy, and the Security page are our standing description of what we process, how long we keep it, and how we protect it.
In addition, no more than once in any 12-month period, you may submit a written security questionnaire or information request to legal@licent.io, and we will respond within 30 days. Kaweah Tech is a small operation and does not accommodate on-site or third-party audits; written responses and the documentation above are how we satisfy audit and verification requests, and you agree they are sufficient to meet any audit right under applicable US state privacy law, to the extent that law allows an assessment to be satisfied this way.
13. Return and Deletion
During your subscription, your organization can retrieve Organization Personal Data at any time through its dashboards and report exports, and each individual member can export their own records under Terms of Service § 7.4.
When your organization plan ends, the organization is archived, as described in Data Retention Policy § 4.3 and Terms of Service § 5.2: your organization's reporting access to member records is removed and pending invitations are revoked.
Two categories of data are deliberately not deleted at plan end, and this DPA is your instruction to us to retain them:
- Members' own licensure records are not Organization Personal Data. They belong to the individual members, remain under their individual accounts, and follow the retention and deletion timelines of the members' own agreements with us (Data Retention Policy §§ 2–3).
- Membership and audit records are retained as described in Data Retention Policy § 4.1. They are the record of who held access to what and when; both your organization and its members may later need to rely on that record, and removing it would destroy the audit trail that documents past access.
Administrator and billing contact information held under an individual account is deleted on that account's own deletion schedule (Data Retention Policy § 3).
14. Term, Precedence, and General Terms
This DPA takes effect when your organization subscription begins and continues for as long as we process Organization Personal Data, including the retention periods in Section 13.
If this DPA conflicts with the Terms of Service with respect to the processing of Organization Personal Data, this DPA controls. In all other respects the Terms of Service govern, and this DPA is subject to the disclaimers, limitations of liability, and dispute resolution provisions of the Terms of Service, Sections 9, 10, and 16. This DPA is governed by the laws of the State of California, consistent with Terms of Service § 16.
We may update this DPA as described in Terms of Service § 14: material changes will be notified to your organization's administrators at least 30 days in advance, and non-material clarifications take effect on posting.
15. Contact
For questions about this DPA, to request a countersigned copy, or to submit a security questionnaire, contact us at:
| Inquiry Type | Contact |
|---|---|
| DPA execution, subprocessor objections, security questionnaires, privacy inquiries | legal@licent.io |
| Security vulnerabilities | security@licent.io |
| General support (login, billing, account operations) | support@licent.io |