Last Revised: July 22, 2026
First Light Holdings LLC abides by relevant data privacy laws and makes efforts to comply with applicable aspects of regulations such as the General Data Protection Regulation (GDPR) and the California Consumer Privacy Act (CCPA).
This Data Processing Agreement (the “DPA”) forms part of the overall Terms & Conditions of Use (the “Terms”) governing your use of KBD Systems (“KBD”, the “Platform”, or the “Services”) at kbdsystems.com. It is made and entered into by and between First Light Holdings LLC, a North Carolina limited liability company, on behalf of itself and its subsidiaries (“First Light Holdings”, “KBD”, “we”, “us”, “our”), and the client using the Services (the “Customer”, “Client”, “you”, “your”).
KBD is an all-in-one marketing-automation platform. The Client uses it to store contacts, generate marketing content, and send the Client’s own email campaigns and automations to the Client’s audience. This DPA sets out how personal data is handled under two distinct roles:
The subject matter of the processing is the operation of a marketing-automation platform on the Client’s behalf: storing the Client’s contacts, generating marketing content from the Client’s brand inputs, providing CRM functionality, and sending the Client’s email campaigns and automations.
The Client and KBD shall each comply with their respective Data Protection Requirements, including, to the extent applicable, the GDPR, the CCPA, and other applicable Privacy Laws. In the course of using the Services, the Client will upload or otherwise provide KBD with Customer Personal Data as required by the nature of the Services. The Client warrants that it has all necessary rights, consents, and legal bases to collect, process, and transfer Customer Personal Data to KBD for processing in accordance with this DPA and the Services, and that its email lists were lawfully collected with the required consent.
The Client shall have sole responsibility for the lawfulness, accuracy, quality, and secure collection of the Customer Personal Data it provides to KBD. KBD shall not access, use, or process Customer Personal Data except as necessary to:
in each case in accordance with the Client’s documented instructions (including through use of the Platform’s features), unless otherwise required by applicable law. The Client, as Data Controller, determines the nature and purpose of the Customer Personal Data and the categories of data subjects. KBD does not sell Customer Personal Data and does not use it to build independent profiles.
While Customer Personal Data is processed by KBD, the Client may access, modify, export, or delete such data directly through the self-serve account dashboard on the Platform, where such features are available. Requests relating to data not manageable through the dashboard may be submitted by contacting KBD at privacy@kbdsystems.com. Upon termination or expiry of the Services and, where requested, upon written request by the Client, KBD will delete or return (at the Client’s option, where feasible) Customer Personal Data in its possession or control relating to that Client’s account, subject to the retention and backup provisions below.
KBD shall provide reasonable and timely assistance to the Client (at the Client’s expense where such assistance requires significant effort beyond standard service provision) to enable the Client to respond to requests from data subjects exercising their rights under the GDPR or other applicable Privacy Laws — including rights of access, correction, objection, erasure, restriction of processing, and data portability — and to any correspondence, enquiry, or complaint received from a data subject, regulator, or other third party in connection with KBD’s processing of Customer Personal Data on the Client’s behalf. If any such request is made directly to KBD regarding data for which the Client is the Data Controller, KBD shall, to the extent permitted by law, promptly inform the Client and shall not otherwise respond except on the Client’s documented instructions or as required by law.
Where required by Data Protection Requirements, KBD shall provide the Client with reasonable assistance and available information (at the Client’s expense for significant efforts) in support of any data protection impact assessment (DPIA) conducted by the Client, solely in relation to KBD’s processing of Customer Personal Data as a Data Processor under this DPA, and where the Client would not otherwise have access to the relevant information.
KBD shall ensure that its personnel authorized to process Customer Personal Data have committed themselves to confidentiality or are under an appropriate statutory obligation of confidentiality. These obligations shall survive the termination of their engagement with KBD.
KBD implements and maintains appropriate technical and organizational measures designed to protect Customer Personal Data against accidental or unlawful destruction, loss, alteration, unauthorized disclosure, or access. These measures include, as appropriate:
If KBD becomes aware of a confirmed Personal Data Breach affecting Customer Personal Data for which the Client is the Data Controller and KBD is the Data Processor, KBD shall notify the Client without undue delay after becoming aware of the breach. Where possible, such notification shall include the information available to KBD regarding the nature of the breach, the categories and approximate number of data subjects and records concerned, and the measures taken or proposed to address the breach and mitigate its effects. KBD shall provide reasonable cooperation to the Client in investigating and remediating the breach. The Client is solely responsible for complying with its own breach-notification obligations under applicable Data Protection Requirements.
The Client authorizes KBD to engage subprocessors to process Customer Personal Data in connection with the Services. KBD imposes data-protection obligations on each subprocessor that are no less protective than those in this DPA, and remains responsible for its subprocessors’ performance of those obligations. KBD currently engages the following subprocessors:
| Subprocessor | Purpose |
|---|---|
| Supabase, Inc. | Database and file storage hosting (customer data at rest) |
| Vercel Inc. | Application hosting and content delivery (CDN) |
| Postmark (Wildbit / ActiveCampaign) | Transactional and broadcast email delivery |
| Authorize.Net (a Visa solution) | Payment processing |
| Stripe, Inc. | Payment processing (alternative) |
| Anthropic, PBC | AI generation of marketing content (Claude); API inputs are not used to train its models |
| Google LLC | Analytics (GA4) and Search Console — only if enabled by the Client |
| Keap | Read-only CRM integration — only when the Client connects their own Keap account; KBD reads, never writes |
Two subprocessors warrant specific note. Anthropicprovides the AI models that generate marketing copy and assets from the Client’s brand inputs; the inputs KBD sends to Anthropic’s API are not used to train Anthropic’s models. Keap is a read-only integration that operates only if the Client chooses to connect their own Keap account; KBD reads data from Keap and never writes to it.
KBD will give the Client advance notice of any intended addition or replacement of a subprocessor. The Client may object to a new subprocessor on reasonable, data-protection-related grounds; if the parties cannot resolve the objection, the Client may terminate the affected Services in accordance with the Terms.
KBD and its subprocessors may process Customer Personal Data in the United States and other countries. Where Customer Personal Data originating in the European Economic Area, the United Kingdom, or Switzerland is transferred to a country that has not received an adequacy decision, such transfers are carried out under an appropriate transfer mechanism, including the European Commission’s Standard Contractual Clauses (SCCs) where applicable, together with any supplementary measures reasonably required.
Upon termination or expiry of the Services, KBD will, at the Client’s option and where feasible, return or delete the Customer Personal Data in its possession or control relating to that Client’s account. This obligation does not apply to the extent KBD is required by applicable law to retain some or all of the Customer Personal Data, or to data retained in backup archives, which are protected from further processing until they are overwritten in the ordinary course or restored, at which point deletion can be applied.
The Client, as Data Controller for the Customer Personal Data, warrants that it has all necessary rights, consents, and legal bases to collect, process, and transfer that data to KBD for processing under this DPA. The Client shall maintain a procedure for individuals to exercise their rights, process only data that has been lawfully and validly collected, ensure such data is relevant and proportionate to its use, honor unsubscribe requests (KBD provides an unsubscribe mechanism), and not upload purchased lists or send email without the required consent.
Upon reasonable written request from the Client (not more than once annually, unless a confirmed security incident necessitates more frequent review), KBD shall provide the Client with information reasonably necessary to demonstrate compliance with its obligations under this DPA. If such information is insufficient, the Client may request an audit, to be conducted at the Client’s expense by the Client or an independent, qualified third-party auditor mutually agreed by the parties, during normal business hours, on reasonable advance notice, and subject to confidentiality. Any such audit shall be limited in scope to KBD’s processing of Customer Personal Data on the Client’s behalf and its compliance with this DPA.
KBD takes precautions to safeguard data and abide by relevant privacy laws. Any customized Data Processing Agreement mutually agreed in writing between KBD and the Client will supersede this DPA with respect to the subject matter of that custom agreement. This DPA may be updated from time to time to reflect changes in regulations, standards, or the Services; we will provide notice of material changes as required by law or as set out in the Terms. This DPA is governed by the laws of the State of North Carolina, consistent with the main Terms.
If you require more details or have any questions concerning this Data Processing Agreement, please contact us at privacy@kbdsystems.com.