Data Processing Agreement (DPA)

KohaSupport
KohaSupport Services

Last updated: January 11, 2022

Structure

This DPA is structured as follows:

Section Content
Section A Key Terms
Section B Processing Instructions
Section C Security Measures
Section D Sub-Processors
Section E Data Subject Rights
Section F Audit and Compliance

Section A: Key Terms

Parties

Data Controller: The Client (library or organization using KohaSupport services)
Data Processor: KohaSupport

Definitions

Personal Data: Any information relating to library patrons, staff, or other identifiable individuals processed through the Koha library system.

Processing: Any operation performed on personal data, including collection, storage, retrieval, use, transmission, and deletion.

Sub-Processor: Third-party service providers engaged by KohaSupport to assist in providing services.

Scope of Processing

Subject Matter: Provision of Koha library management system hosting and support services

Duration: For the term of the service agreement

Nature and Purpose:

Types of Personal Data:

Categories of Data Subjects:


Section B: Processing Instructions

General Instructions

  1. KohaSupport shall process personal data only on documented instructions from the Client
  2. Instructions may be provided through:
    • The service agreement
    • Email communications
    • Service dashboard controls
    • Technical support tickets

Prohibited Processing

KohaSupport shall NOT:

Data Location

Primary Data Center: AWS US-East-1 (Virginia)
Backup Location: AWS US-West-2 (Oregon)
Geographic Restriction: United States only (unless otherwise agreed)


Section C: Security Measures

Technical Measures

  1. Encryption
    • TLS 1.3 for data in transit
    • AES-256 encryption for data at rest
    • Encrypted database backups
  2. Access Control
    • Multi-factor authentication
    • Role-based access controls
    • Audit logging of all access
  3. Network Security
    • Firewall protection
    • DDoS mitigation
    • Regular security scanning
  4. Backup and Recovery
    • Daily automated backups
    • 30-day retention period
    • Tested recovery procedures

Organizational Measures

  1. Staff Training
    • Annual GDPR and privacy training
    • Security awareness programs
    • Confidentiality agreements
  2. Incident Response
    • 24/7 monitoring
    • Incident response procedures
    • Breach notification protocol
  3. Vendor Management
    • Sub-processor due diligence
    • Contractual data protection obligations
    • Regular vendor assessments

Section D: Sub-Processors

Authorized Sub-Processors

KohaSupport uses the following sub-processors:

Sub-Processor Service Location Purpose
Amazon Web Services (AWS) Cloud Infrastructure United States Hosting and storage
Stripe Payment Processing United States Billing services
SendGrid Email Delivery United States Transactional emails

Sub-Processor Changes

  1. KohaSupport will notify the Client of any intended changes to sub-processors
  2. Client has 30 days to object to new sub-processors
  3. If Client objects, parties will work together to find alternative solution

Section E: Data Subject Rights

Assistance with Rights Requests

KohaSupport will assist the Client in responding to data subject requests:

  1. Access Requests: Provide data exports in common formats
  2. Rectification: Enable data correction through system interfaces
  3. Erasure: Delete data upon instruction (subject to legal retention)
  4. Portability: Provide data in machine-readable format
  5. Restriction: Implement processing restrictions as instructed

Response Time

KohaSupport will respond to rights assistance requests within:


Section F: Audit and Compliance

Audit Rights

The Client may:

  1. Request information demonstrating compliance
  2. Conduct audits (with reasonable notice)
  3. Engage third-party auditors (subject to confidentiality)

Compliance Documentation

KohaSupport maintains:

Audit Process

  1. Client provides 30 days written notice
  2. Audits conducted during business hours
  3. KohaSupport provides reasonable assistance
  4. Audit findings shared within 15 days
  5. Remediation plan for any issues identified

Section G: Data Breach Notification

Notification Procedure

In the event of a personal data breach, KohaSupport will:

  1. Immediate Actions (within 24 hours)
    • Contain and investigate the breach
    • Notify internal security team
    • Begin evidence preservation
  2. Client Notification (within 72 hours)
    • Description of the breach
    • Categories and approximate number of affected records
    • Likely consequences
    • Measures taken or proposed
  3. Ongoing Communication
    • Regular updates during investigation
    • Final incident report
    • Lessons learned and improvements

Section H: Data Deletion and Return

Upon Termination

Within 30 days of service termination, KohaSupport will:

  1. Client Choice:
    • Return all personal data in agreed format, OR
    • Securely delete all personal data
  2. Deletion Process:
    • Remove from production systems
    • Delete from all backups
    • Provide certificate of deletion
  3. Retention Exceptions:
    • Legal or regulatory requirements
    • Anonymized data for statistical purposes
    • Data necessary for dispute resolution

Section I: Liability and Indemnification

Liability

Each party is liable for damages caused by breach of this DPA, subject to:

Indemnification

KohaSupport will indemnify the Client for:

Resulting from KohaSupport’s breach of this DPA.


Section J: Governing Law and Dispute Resolution

Governing Law: Laws of the State of Delaware, United States

Dispute Resolution:

  1. Good faith negotiations
  2. Mediation
  3. Binding arbitration
  4. Courts of competent jurisdiction

Section K: Amendments

This DPA may be amended:


Contact Information

For DPA-related inquiries:

KohaSupport
KohaSupport Data Protection Team
Email: support@kohasupport.com
Website: https://kohasupport.com/contact/


Execution

This DPA is incorporated into and forms part of the service agreement between the parties.

Effective Date: Date of service agreement execution


KohaSupport
Committed to Data Protection and Privacy

Cookie Consent Banner -->