Data/engineering: data ingestion, API integrations, event schemas
Best practices and playbooks
Pre-built templates for common use cases (cart abandonment, product recommendations, win-back campaigns)
Experiment design, KPI definition, and success criteria
Training accessibility and cadence
Self-serve training library plus periodic live training sessions
Regular update briefings when features change
Security Measures
Data protection
Data encryption at rest and in transit (TLS for in-transit, AES-256 at rest)
Tokenization or pseudonymization for sensitive attributes where applicable
Access control
Role-based access control (RBAC) with least-privilege permissions
Multi-factor authentication (MFA) for admin access
IP allowlists or VPN-only access for admin interfaces
Data governance
Data lineage and auditing of data flows and changes
Data retention policies with configurable purge windows
Privacy controls for opt-outs, data deletion requests, and data residency options
Updates
Update cadence
Typically monthly or quarterly minor releases
Major releases on a scheduled cycle (e.g., quarterly or biannually) with feature freezes during critical periods
Change management
Detailed release notes highlighting new features, changes, deprecations, and potential impact
Compatibility guidance for APIs, data schemas, and integration points
Optional staged rollout (pilot in a non-production environment or a subset of tenants) before full deployment
Deployment and delivery
Seamless in-app updates or cockpit-based enablement of features
Backward-compatible defaults with opt-in for new capabilities to minimize disruption
Versioned APIs and clear deprecation timelines for any breaking changes
Testing and validation
Sandbox or staging environments for pre-release testing
Guidance and tooling for validating data mappings and experiment integrity post-update
Communication
Regular release webinars or internal notes to customers
Post-release support guidance if issues arise after deployment
Data Ownership and Portability
Data ownership
Explicit statement that your organization retains ownership of all data you provide or generate in the platform (customer data, event data, product data, analytics outputs).
Clarification that Kahuna does not claim ownership or use your data beyond providing the service.
Data usage rights
Permission for Kahuna to process data solely for the purpose of delivering the service per DPA (data processing agreement) and compliant with applicable laws.
Prohibition on using your data for advertising or other purposes without explicit consent.
Data access and export
Availability of data export in standard, machine-readable formats (CSV, JSON, Parquet) and via API.
Ability to retrieve full data set, including raw event data, audience definitions, segments, experiments, and performance metrics, upon request.
Data portability timeline: how quickly data can be exported after termination or upon request.
Data retention and deletion
Clear data retention policy (how long Kahuna keeps your data after you terminate, and any backup copies).
Procedures for secure data deletion (including deletion from backups, if applicable) with verification.
Options for data anonymization or privatization for analytics post-termination, if offered.
Scaling Up / Down
Scaling options
How pricing, quotas (events, users, data volume), and feature access adjust when you scale up.
Availability of flexible tiers or usage-based pricing to match growth or downsizing.
Minimums and commitments
Any minimum contract term, minimum spend, or annual commitment required to access certain features.
Upgrade/downgrade processes
How easy it is to upgrade to higher tiers or downgrade during a term without penalties.
Propagation time for changes to take effect (billing, data handling, support levels).
Data and load considerations
Limits on simultaneous experiments, audience size, data ingestion rates, and latency guarantees when scaling.
Performance SLAs and how they adapt with scale.
Exit ramps
Provisions for reducing usage (and associated pricing) without penalties.
Notice periods for scale changes.
The terms & conditions for contract renewal and cancellation
Renewal cadence
Automatic renewal terms (auto-renewal vs. opt-in) and renewal notice period.
Price adjustment
How pricing changes at renewal (annual increases, CPI, or tier-based changes).
Any caps on price increases or grandfathering options for existing customers.
Termination rights
Termination for convenience vs. for cause (with or without penalty).
Required notice period to cancel (60/90/180 days, etc.).
Data handover at termination
Deadline and format for providing data export upon termination.
Access to the platform during wind-down (limited access, full access, or no access) and for how long.
Post-termination obligations
Continuation of support during wind-down, if any.
Obligation to delete or return data within a defined timeframe.
Insolvency/exit
Provisions if either party enters bankruptcy or insolvency.
SLA continuity
How support levels and SLAs are affected during notice period and wind-down.
Non-disparagement and transition assistance
Any assistance Kahuna provides to migrate to another vendor or to in-house solutions.
Renewal exclusions
Specific terms or conditions that void renewal offers (e.g., breaches, non-payment).
Compliance
Data protection laws covered
Explicit alignment with GDPR, CCPA/CPRA, and any other jurisdiction-specific privacy laws.
Mechanisms for handling data subject access requests (DSARs), erasure requests, and data portability under GDPR.
Security certifications
Independent attestations such as SOC 2 (Type II), SOC 1, ISO 27001, ISO 27017, ISO 27018.
PCI DSS applicability if processing payment data (usually not used for personalization platforms, but good to confirm).
Data processing agreements
A DPA that codifies roles (controller vs. processor), data handling, subprocessors, and breach notification timelines.
Data residency and cross-border data transfers
Options for data localization or regional data storage.
Mechanisms for international data transfers (SCCs, UK IDTA, EU/US data transfer frameworks, etc.).
Privacy by design
Evidence of secure development practices, vulnerability management, and regular third-party security testing.
Incident response
Defined breach notification timelines (e.g., 72 hours), contact points, and escalation procedures.
Employee and vendor management
Background checks, access controls, and minimum security training for staff handling data.
Audit rights
Right to perform or request security audits, assessments, or third-party audits (scope, frequency, and cost).
Data minimization and retention
Policies to minimize data collection to what is necessary and to purge data per retention schedules.