Skip to content
Kalma
Back to home

Data Processing Agreement (DPA)

Last updated: 24 September 2026

This Data Processing Agreement (DPA) is provided in English, its authoritative version, which prevails in case of discrepancy.

This Data Processing Agreement (the “DPA”) forms part of the Terms and Conditions (the “Agreement”) between Tekio Consulting and Engineering Ltd, a company registered in Israel under number 516402492, with its registered office at Dr. Abraham Elihau Harkavy 3, Tel Aviv-Yafo 6732921, Israel (the “Processor”), and the customer that has accepted the Agreement (the “Controller”). It governs the Processing of Personal Data carried out by the Processor on behalf of the Controller in connection with Kalma (the “Service”), in accordance with the General Data Protection Regulation (EU) 2016/679 (“GDPR”) and, where applicable, the UK GDPR. In case of conflict, this DPA prevails over the Agreement with respect to the Processing of Personal Data.

1. Definitions

Capitalized terms not defined herein have the meaning given in the GDPR. “Controller”, “Processor”, “Personal Data”, “Processing”, “Data Subject”, “Personal Data Breach” and “Supervisory Authority” have the meanings set out in Article 4 GDPR. “Sub-processor” means any processor engaged by the Processor. “SCCs” means the Standard Contractual Clauses approved by the European Commission.

2. Roles and scope of Processing

With respect to the Personal Data that the Controller and its users enter into the Service as project content (including the names and email addresses of project members and discipline leads), the Controller is the controller and the Processor is the processor. The Processor shall Process such Personal Data only on the documented instructions of the Controller, including with regard to international transfers, unless required to do otherwise by applicable law. The Agreement and the Controller’s use of the Service’s features constitute the Controller’s documented instructions.

The Processor acts as an independent controller for the account, billing, security, product-analytics and communication data it processes to operate its own business, as described in its Privacy Policy; that Processing is outside the scope of this DPA.

The subject matter, duration, nature and purpose of the Processing, the types of Personal Data and the categories of Data Subjects are set out in Annex I.

3. Processor obligations

The Processor shall: (a) Process Personal Data only on documented instructions; (b) ensure that persons authorized to Process Personal Data are bound by confidentiality; (c) not Process the Personal Data for its own purposes; and (d) inform the Controller if, in its opinion, an instruction infringes the GDPR.

4. Security

The Processor shall implement appropriate technical and organizational measures to ensure a level of security appropriate to the risk, in accordance with Article 32 GDPR. A description of those measures is set out in Annex II.

5. Sub-processors

The Controller grants the Processor general authorization to engage the Sub-processors listed on the Processor’s Subprocessors page. The Processor shall impose on each Sub-processor data-protection obligations substantially equivalent to those set out in this DPA and remains responsible for the performance of its Sub-processors.

The Processor shall inform the Controller by email at least fifteen (15) days before adding or replacing a Sub-processor, giving the Controller the opportunity to object on reasonable data-protection grounds. If the parties cannot resolve the objection, the Controller may terminate the Agreement.

6. Data Subject rights

Taking into account the nature of the Processing, the Processor shall assist the Controller by appropriate technical and organizational measures, insofar as possible, in responding to requests from Data Subjects exercising their rights under the GDPR. If the Processor receives such a request directly, it shall refer the Data Subject to the Controller without responding on the merits, unless instructed otherwise.

7. Assistance to the Controller

The Processor shall assist the Controller in ensuring compliance with its obligations under Articles 32 to 36 GDPR, including security of Processing, notification of Personal Data Breaches, data protection impact assessments and prior consultation, taking into account the nature of Processing and the information available to the Processor.

8. Personal Data Breach

The Processor shall notify the Controller without undue delay, and in any event within forty-eight (48) hours, after becoming aware of a Personal Data Breach affecting the Controller’s Personal Data, and shall provide the information reasonably available to enable the Controller to meet its notification obligations.

9. International transfers

The Processor is established in Israel, which benefits from an adequacy decision of the European Commission and is recognized as adequate by the United Kingdom. The Service’s database and application servers are hosted in the European Union. Where a Sub-processor Processes Personal Data in a country without an adequacy decision, the transfer is subject to appropriate safeguards under the GDPR, such as the EU-U.S. Data Privacy Framework or the SCCs, which are incorporated into this DPA by reference where applicable.

10. Audits

The Processor shall make available to the Controller information necessary to demonstrate compliance with this DPA and shall allow for and contribute to audits, including inspections, conducted by the Controller or an auditor mandated by it, subject to reasonable prior notice, confidentiality obligations and no more than one audit per year unless required by a Supervisory Authority or following a Personal Data Breach.

11. Return or deletion of data

Upon termination of the Service, the Processor shall, at the choice of the Controller, return the Personal Data in a commonly used format or delete it, and shall delete existing copies within thirty (30) days, unless applicable law requires further storage. Backups are overwritten in the ordinary course of the Sub-processors’ backup cycles.

12. Liability and term

The liability of each party under this DPA is subject to the limitations and exclusions of liability set out in the Agreement, to the extent permitted by the GDPR. This DPA shall remain in effect for as long as the Processor Processes Personal Data on behalf of the Controller.

13. Governing law

This DPA is governed by the laws of the State of Israel, consistent with the Agreement, without prejudice to the provisions of the GDPR, the UK GDPR and the SCCs, which prevail where applicable.

Annex I — Details of Processing

Subject matter: provision of the Service. Duration: the term of the Agreement, plus the deletion period in Section 11. Nature and purpose: hosting, storage, organization and display of Personal Data to provide ISO 19650 deliverable-management features, including notifications to project members and the optional Autodesk Construction Cloud integration.

Types of Personal Data: names and email addresses of project members and discipline leads, their role and assignments, deliverable data and history attributed to them, and Autodesk Construction Cloud file metadata. Categories of Data Subjects: the Controller’s authorized users and the individuals participating in the Controller’s projects (employees, consultants and contractors). No special categories of Personal Data are intended to be Processed.

Processor contact for data protection: info@kalma.build.

Annex II — Technical and organizational measures

Encryption in transit (TLS/HTTPS) for all connections to the Service; encryption at rest provided by the hosting database; passwords stored only as salted one-way hashes (bcrypt); single-use verification and reset tokens stored as hashes.

Object-level access control: every request for project data checks that the user is a member of the project and holds the required role; role-based permissions (editor / viewer).

Hosting of the database and application servers in the European Union (Frankfurt) with reputable cloud providers; rate limiting of authentication and public endpoints; security headers; separation of production and test environments.

Access by the Processor’s personnel limited to what is necessary for support and operations, bound by confidentiality; error tracking without personal content; regular review of dependencies and security practices.

Annex III — Sub-processors

The current list of Sub-processors is available on the Processor’s Subprocessors page and forms part of this DPA.