Last updated: July 9, 2026
This Data Processing Addendum ("DPA") is incorporated into the Korent Terms of Serviceby reference and forms part of the agreement between Korent and each operator ("the Agreement"). It is also available for countersignature on request at legal@korent.app. This document is provided in English; translations may be offered for convenience, but the English version controls.
Subject matter:Korent's processing of Customer Data in the course of providing the Service. Duration: the term of the Agreement plus the deletion period in Section 10. Nature: hosting, storage, transmission, display, backup, and related technical operations, including sending communications the operator initiates or configures. Purpose: providing, securing, and supporting the Service as described in the Agreement and as further instructed by the operator through its use of the Service's features. Korent does not sell Customer Data and does not use it for its own marketing.
Data subjects:the operator's customers and prospective customers (renters), their delivery and event contacts, and signatories of documents the operator sends.
Categories of personal data: names; email addresses; phone numbers; billing, delivery, and event addresses; order, quote, and payment records; electronic signatures, including drawn signature images; IP address and user-agent details captured when a document is signed; logs of email, SMS, and WhatsApp messages sent through the Service; and photos the operator or its customers upload (for example event or equipment photos). The Service is not intended for special categories of data (e.g. health data) and the operator agrees not to submit them.
Korent will process Customer Data only on the operator's documented instructions, including as documented in the Agreement, this DPA, and the operator's configuration and use of the Service — unless required to do otherwise by law, in which case Korent will inform the operator of that legal requirement before processing (unless the law prohibits it). Korent will inform the operator if, in its opinion, an instruction infringes applicable data protection law.
Korent ensures that persons authorized to process Customer Data are bound by contractual or statutory confidentiality obligations, and limits access to personnel who need it to provide, secure, or support the Service.
Korent implements appropriate technical and organizational measures to protect Customer Data, including:
Korent may update these measures from time to time, provided the updates do not materially reduce the overall level of protection.
The operator provides general written authorization for Korent to engage sub-processors to provide the Service. The current list is published at korent.app/subprocessors. Korent will (a) impose data protection obligations on each sub-processor that are materially no less protective than this DPA, (b) remain responsible for each sub-processor's performance, and (c) give the operator notice — by updating that page and by email or in-app notice — at least 30 days before a new sub-processor processes Customer Data. If the operator has a reasonable, data-protection-related objection that Korent cannot resolve, the operator may terminate the affected services and receive a pro-rata refund of prepaid fees for the terminated period.
Taking into account the nature of the processing, Korent will assist the operator by appropriate technical and organizational measures — including in-app access, correction, export, and deletion tools — in fulfilling the operator's obligation to respond to data subject requests (access, rectification, erasure, restriction, portability, objection). If a data subject contacts Korent directly about Customer Data, Korent will refer them to the operator without responding substantively, unless required by law.
Korent will notify the operator without undue delayafter becoming aware of a personal data breach affecting Customer Data, and will provide information reasonably required for the operator to meet its own breach notification obligations, including the nature of the breach, the categories and approximate volume of data and data subjects concerned, likely consequences, and measures taken or proposed. Korent's notification is not an acknowledgement of fault.
Upon termination of the Agreement, Customer Data enters a 30-day soft-delete grace period during which the operator may request an export (self-service CSV export is also available in-app during the term). After the grace period, Korent deletes Customer Data from production systems, and residual copies age out of backups on the backup provider's rotation schedule, unless retention is required by law — in which case the data remains protected by this DPA and is deleted when the requirement ends.
Korent will make available information reasonably necessary to demonstrate compliance with this DPA — including its security documentation and SOC-style summaries of its own and its infrastructure providers' controls — and will allow for and contribute to audits, which the parties agree are satisfied in the first instance by review of that documentation. Where a supervisory authority or applicable law requires more, Korent will cooperate with a mutually agreed, confidential audit at the operator's expense, no more than once per year absent a breach or regulatory demand. Taking into account the nature of the processing and the information available to it, Korent will also provide reasonable assistance with the operator's data protection impact assessments and prior consultations.
Customer Data is processed in the United States and in the regions used by the sub-processors listed at korent.app/subprocessors. For transfers of personal data from the European Economic Area, the United Kingdom, or Switzerland: (a) where Korent or the relevant sub-processor is certified under the EU–U.S. Data Privacy Framework (and its UK and Swiss extensions), the transfer relies on that certification; and (b) otherwise, the parties incorporate the European Commission's Standard Contractual Clauses (2021/914), Module Two (controller to processor), with the operator as data exporter, Korent as data importer, the annexes deemed completed by Sections 2, 3, 6, and 7 of this DPA, option 2 of Clause 9 with the notice period in Section 7, and the law and courts of Ireland for Clauses 17 and 18.
For transfers subject to the UK GDPR, the parties incorporate the UK Information Commissioner's International Data Transfer Addendum to the EU Standard Contractual Clauses (version B1.0), with Tables 1–3 deemed completed by the information in this DPA and the SCCs as incorporated above, and with neither party able to end the Addendum under its Table 4 except as the Addendum mandates.
Where the operator is subject to Quebec's Act respecting the protection of personal information in the private sector (as amended by Law 25): this DPA constitutes the written mandate required by section 18.3; Korent will process personal information only for the purposes in Section 2, will notify the operator without undue delay of any confidentiality incident involving that information and cooperate in its assessment and mitigation, will not communicate the information outside Quebec except under Section 12 (and will assist the operator with any required privacy impact assessment for such communication), and will destroy or return the information per Section 10.
Where the operator is subject to the Australian Privacy Act 1988 (Cth) and its Australian Privacy Principles (APPs), the operator discloses personal information to Korent as an overseas recipient. Korent will handle that information consistently with the APPs; will use and disclose it only for the purposes in Section 2 and to sub-processors bound to substantially the same obligations; will notify the operator without undue delay of any data breach affecting that information so the operator can meet its Notifiable Data Breaches obligations, and will reasonably assist with the operator's complaint handling. The operator may rely on this DPA as the enforceable arrangement it is expected to put in place before an overseas disclosure under APP 8.1.
Where the operator is subject to the New Zealand Privacy Act 2020, Korent processes the operator's customer personal information solely as the operator's agent for storage and processing, and does not use it for its own purposes — so that, under section 11 of that Act, the information is treated as held by the operator and its transfer to Korent is not a "disclosure" under Information Privacy Principle 12. Korent will protect that information with safeguards comparable to those required by the New Zealand Information Privacy Principles and will notify the operator without undue delay of any notifiable privacy breach.
Each party's liability under this DPA is subject to the limitations of liability in the Agreement, except where applicable data protection law does not permit that. If this DPA conflicts with the Agreement on the processing of Customer Data, this DPA controls; if the Standard Contractual Clauses or the UK Addendum conflict with this DPA, they control.
Questions about this DPA, requests for a countersigned copy, and legal notices: legal@korent.app. Privacy requests: privacy@korent.app.