Kyndrava Customer-Managed Operations Addendum
A public addendum-style draft for linking customer-managed responsibilities to the Usage Rules, Terms, Order Form or individual agreement. It is not legal advice.
1. Role of this addendum
This addendum is intended to supplement the Usage Rules, Terms, Order Form, quotation or individual agreement. A different individual written agreement prevails.
2. Definitions
- Product: Kyndrava software, documentation, updates and licence information.
- Customer Administrator: the customer-appointed person managing users, devices, invitations, QR codes, licence assignment and backups.
- End User: a person authorised by the Customer Administrator to use the Product.
3. Customer-managed operation
The Customer Administrator performs user and device registration, QR issuance, invitation distribution, suspension, deletion, backups, recovery and other post-purchase operations.
4. Vendor-no-touch boundary
Unless separately agreed, the vendor does not acquire, store or manage end-user rosters, device lists, individual usage logs, personal data or backup data.
5. QR codes and invitations
QR codes and invitation links must not contain passwords, private keys, persistent API keys or personal information. Tokens should be short-lived, limited-use and revocable.
6. Installation and distribution
The Customer Administrator distributes the Product using vendor-provided instructions, installers, QR codes or invite links. The vendor does not normally distribute to individual end users or register devices for them.
7. Licence scope
Use is limited to the period, device count, user count and organisational scope in the Order Form or licence certificate. Resale, lending, third-party provision, reverse engineering, modification and circumvention are prohibited.
8. Administrator responsibility
The Customer Administrator is responsible for user changes, device registration and revocation, access control, backups, restore tests, log review, internal-policy alignment and legal compliance.
9. Backups and recovery
The customer must regularly back up settings, data, certificates, logs and Kyndrava-related data and verify restorability. The vendor has no backup-retention obligation without a separate agreement.
10. Support materials
Before submitting logs, configurations or screenshots, the Customer Administrator must remove or mask personal data, confidential information, credentials and certificate private keys.
11. Telemetry and logs
Without express customer consent, the Product does not automatically transmit end-user rosters, device content, individual usage logs or personal data. Any anonymous statistics require disclosure of content, purpose and opt-out method.
12. Privacy and personal data
The vendor handles only minimum information needed for contracting, billing, licence issuance and support. Processing personal data requires a separate data-processing agreement.
13. Security and updates
The customer manages administrator credentials, MFA, devices, access control, backups, anti-malware and network protection. The vendor will use reasonable efforts to provide security improvements and updates.
14. Sales representations and warranty
The vendor discloses price, payment, delivery, cancellation, renewal, support scope, recommended environment and limitations, and avoids unsupported absolute claims such as perfect protection.
15. Suspension, termination and exit handling
For breach, abuse or urgent security risk, the vendor may take minimum necessary suspension or termination measures. After termination, the Customer Administrator handles deletion, backup deletion and uninstall. Temporarily received support materials are deleted within a reasonable period after support ends.
16. Mandatory legal-review issues
- B2B-only or consumer sales
- Vendor cloud and personal-data receipt
- Receipt of logs, configurations or screenshots
- E-commerce, subscriptions, international sales, export controls, tax, governing law and jurisdiction
- Validity of liability limits under consumer-protection rules