Kendagor TechLegal centre Back to app →

Data Processing Agreement

Our duties when we process your customers' data on your behalf.

Version 1.0 · Effective 9 October 2026

1. Scope and roles

This Data Processing Agreement ("DPA") forms part of the Terms of Service. It applies when Kendagor Tech processes personal data of an ISP's end customers and staff ("Customer Personal Data") on the ISP's behalf. The ISP is the data controller and Kendagor Tech is the data processor within the meaning of the Data Protection Act, 2019.

2. Details of processing

Subject matterProviding the ISP billing, RADIUS and network-management Service
DurationFor as long as the ISP's account exists, then deletion as set out below
Data subjectsThe ISP's Hotspot and PPPoE customers, payers and staff users
Data typesNames, phone numbers, emails, device MAC and IP addresses, session and usage records, payment references, vouchers, support messages
OperationsStorage, authentication, accounting, billing, messaging the ISP initiates, reporting, backup and deletion

3. Our obligations as processor

Kendagor Tech will:

  • process Customer Personal Data only on the ISP's documented instructions, which are given through the Service's settings and these Terms, unless the law requires otherwise (in which case we will tell the ISP unless the law forbids it);
  • ensure that people authorised to process the data are bound by confidentiality;
  • implement appropriate technical and organisational security measures, as described in the Privacy Policy;
  • use sub-processors (such as our hosting, payment, email and messaging providers) only under written terms that protect the data at least as well as this DPA, and remain responsible for them; we will tell ISPs of material changes to our sub-processors;
  • help the ISP respond to data-subject requests and meet its obligations on security, breach notification and data-protection impact assessments, taking into account the information available to us;
  • notify the ISP without undue delay after becoming aware of a personal-data breach affecting Customer Personal Data;
  • at the end of the Service, delete Customer Personal Data, unless the law requires us to keep it; the ISP should export what it needs first;
  • make available information reasonably necessary to show compliance with this DPA.

4. The ISP's obligations as controller

  • have a lawful basis for the processing and give end customers a privacy notice explaining it, including on the captive portal;
  • register with the Office of the Data Protection Commissioner where the law requires the ISP to do so;
  • collect only the data needed, keep it accurate, and respond to its customers' requests;
  • keep its dashboard accounts, staff access and router credentials secure.

5. International transfers

Customer Personal Data is hosted in Sydney, Australia, and may be processed by sub-processors in other countries. Transfers are made in line with Part VI of the Act, with appropriate safeguards as described in the Privacy Policy.