Draft — not yet reviewed by a lawyer, and not in force.
This wording was prepared to describe what the product actually does, so that a solicitor has something concrete to work from. It is not legal advice and it does not bind anybody. Do not rely on it, publish it, or send it to a client until it has been reviewed and this banner has gone.
Data processing agreement
This describes how KVAi processes material on an agency's behalf. It is written to be attached to the terms of use, and its factual annexes are generated from the product itself so they cannot drift out of date.
Roles
The agency is the controller. KVAi is the processor. Where the agency is itself processing on behalf of a pharmaceutical client, KVAi is a subprocessor to that arrangement — which is usually the shape of the relationship in practice, and is why the annex below matters to the client's own legal team.
Annex 1 — subject matter and duration
Drafting, editorial checking and reference work on promotional and educational material for medicines, for as long as the agency holds a workspace.
Annex 2 — nature and purpose
- Storing documents the agency uploads to a client space.
- Indexing those documents so passages in them can be retrieved and cited.
- Sending a brief, with retrieved passages, to a large language model to produce a draft.
- Checking every claim in that draft against the retrieved passages, and flagging any that has no support.
- Recording who approved what, and when.
Annex 3 — categories of data
Predominantly commercial and scientific material rather than personal data: summaries of product characteristics, clinical publications, claim matrices, house style guides and draft copy. Personal data is limited to the names, work email addresses and actions of the agency's own staff.
KVAi is not intended for patient data. The product has no clinical or patient record function, and material of that kind should not be uploaded.
Annex 4 — subprocessors
The current list, with what each receives and where, is published and kept current at https://kvai.co.uk/legal/subprocessors.
Annex 5 — security measures
These are the measures actually implemented, not aspirations:
- Separation between agencies is enforced at the database layer, and fails closed: a query that cannot establish which agency it belongs to raises an error rather than returning data. Scope is taken from the signed-in session and never from a request.
- An agent reads only the shared library and the one client space it was briefed in. Nothing crosses between an agency's own clients.
- Encryption in transit throughout, including to the mail provider.
- Two-factor authentication available, and enforced once enrolled.
- Passwords stored only as hashes, checked against known breach corpora on being set.
- A content security policy with per-request nonces.
- Error reports have confidential fields removed before they leave the server, and identify a workspace and person by identifier only. Session recording and AI tracing are deliberately switched off.
- Removing somebody's access ends their existing sessions immediately.
Annex 6 — return and deletion
An owner can request deletion of a workspace, which removes everything in it after a grace period. Documents withdrawn from a client space are excluded from retrieval immediately, so they can no longer be cited.
Stated plainly because it has to be: the knowledge service that indexes uploaded documents exposes only ingest and retrieval operations, and no deletion. Withdrawing a document in KVAi therefore stops it being retrieved or cited, but the indexed text remains held by that service. Complete deletion requires a change to that interface, which is outstanding. An agency's client should be told this in these words rather than reassured loosely.
Assistance and audit
We will help with data subject requests, and provide the information needed for a controller's own impact assessment. What is left after an erasure is documented in the product so it can be answered consistently.
Not drafted here, and needed:
The operative clauses: instructions and confidentiality, breach notification periods, audit rights and their limits, liability as between the parties, the international transfer mechanism and the UK addendum, and the contracting entity. The annexes above are factual and can be relied on as descriptions of the product; the clauses that turn them into obligations are a solicitor's work.