Kong Konnect Cloud Addendum

Last Revised: September 8, 2022


This Kong Konnect Cloud Addendum (“Addendum”) is an addendum to the master agreement entered into by and between Kong Inc. and the Customer for the purchase of subscriptions to Kong Software from time to time by Customer, or Affiliates of Customer (the “Agreement”). This Addendum is effective as of the date Customer accepts its terms (“Addendum Effective Date”) and applies to the use of the Konnect Cloud Services (as defined below).

Except as otherwise modified in this Addendum, all other terms and conditions of the Agreement will remain in full force and effect. All capitalized terms not defined in this Addendum will have the meaning given to them in the Agreement. On and after the Addendum Effective Date, any reference to the Agreement means the Agreement as modified by this Addendum. In the event of a conflict between the terms of this Addendum and the terms of the Agreement less this Addendum, the terms of this Addendum will prevail for the purposes of the Konnect Cloud Services.

  1.  Definitions:

Account Information” means information about Customer provided by or for Customer or its Authorized Users to Kong in connection with the creation, administration or support of Customer’s account with Kong. For example, Account Information includes names, usernames, phone numbers, email addresses and billing information associated with Customer’s account with Kong.

API Service” means an API (application programming interface) for a discrete unit of programmatic functionality that is exposed for remote consumption and managed through the Software or the Konnect Cloud Services. Examples of API Services include a data transformation microservice or a billing API.  

Customer Content” means data and information submitted by or for Customer to the Konnect Cloud Service. For example, Customer Content includes configuration files for Customer’s Konnect Runtimes. Customer Content does not include Account Information or Usage Data.

Customer Network Environment” means the Customer-controlled network on which Customer deploys and operates the Software. This network may include the Customer’s own servers, servers of third party cloud provider services (such as Amazon Web Services, Microsoft Azure or Google Cloud) or some combination of on-premises and cloud provider deployment.

Customer Payload Data” means the actual Customer data (and not metadata or header data) contained within a packet or message that is processed by the Software. An analogy is the contents of an envelope as distinct from the address on the envelope; Customer Payload Data in this analogy is the contents of the envelope.

Konnect Cloud Services” means the Kong-hosted software-as-a service products and services purchased by Customer for use under an Order Form or used by Customer under a free trial or free subscription tier.

“Konnect Platform” means Kong’s end-to-end API Service connectivity platform for the configuration, deployment, management and securing of API Services, including the Konnect Cloud Services and the Software.

Konnect Runtime” means Kong’s proprietary API gateway, version 2.7 and subsequent releases.

Software” means Kong’s software that Kong makes generally available as part of the Konnect Platform that is ordered by Customer as set forth in the Order Form, or that Kong makes available to the Customer for a free trial together with any Updates. “Software” does not include plug-ins to the Software identified as provided by or originating from third parties.

Usage Data” means usage data, telemetry and any other data (other than Customer Content and Customer Payload Data) relating to the operation, support and/or about use of the Konnect Platform by Customer and its Authorized Users.

Further, (i) the terms “Order Form” and “Order” in the Agreement may be used interchangeably, and have the same meaning, (ii) the terms “Subscription Term” and “License Term” may be used interchangeably, with each referring to the purchased term of access to the Konnect Cloud Services and/or license to the Software under the applicable Order Form, (iii) the terms “User” and “Authorized User” in the Agreement may be used interchangeably, and have the same meaning, (iv) the terms “License Parameter(s)” and “usage limits” may be used interchangeably and have the same meaning.

  1. Access and License to Konnect Platform. If Customer purchases a subscription to the Konnect Platform, then subject to the terms and conditions of the Agreement and the applicable Order Form, during the Subscription Term, Kong (a) will make the Konnect Cloud Services available to Customer and (b) grants to Customer a non-exclusive, non-transferable, worldwide, limited-term license to install and use the Software in the Customer Network Environment. Customer may maintain a reasonable number of copies of the Software on its systems for backup and recovery purposes, provided use of the copies is strictly limited to back up or disaster recovery purposes.

  1. User ID and Password Protection. Customer will require that all Authorized Users keep user ID and password information for Konnect Cloud Services strictly confidential and not share such information between Authorized Users and/or with any unauthorized person. Kong will have no liability for actions taken using Customer’s user IDs and passwords, including any unauthorized use or access caused by misuse or misappropriation of such user IDs and passwords. Customer will be responsible for restricting access by any Authorized User who is no longer authorized to access or use the Konnect Cloud Service.

  1. Acceptable Use. Customer must not use the Konnect Cloud Service in any jurisdiction for unlawful, obscene, offensive or fraudulent content or activity, such as advocating or causing harm, interfering with or violating the integrity or security of a network or system, evading filters, sending unsolicited, abusive, or deceptive messages, viruses or harmful code, or violating third party rights.

  1. Restrictions. In additions to the restrictions included in the Agreement, Customer and its Affiliates must not and must not allow any third party to (i) interfere with, disrupt, alter, or modify the Konnect Cloud Services or any part thereof, or create an undue burden on the Konnect Cloud Services or the networks or services connected to the Konnect Cloud Services; (ii) introduce software or automated agents or scripts into the Konnect Cloud Services so as to produce multiple accounts, generate automated searches, requests or queries, or to strip or mine data from the Konnect Cloud Services; or (iii) store or transmit any malicious code through the Konnect Cloud Services.

  1. Rights in Customer Content. As between the parties, Customer or its licensors retain all right, title and interest (including any and all intellectual property rights) in and to the Customer Content, and any modifications made thereto in the course of the operation of Konnect Cloud Services as provided to Kong. Subject to the terms of the Agreement, Customer hereby grants to Kong a non-exclusive, worldwide, royalty-free right to process the Customer Content solely to the extent necessary to provide the services to Customer, or as may be required by law.

  1. Kong’s Security Measures. Kong will take reasonable and appropriate technical and organizational measures designed to protect Customer Content against unauthorized access, accidental loss or unauthorized disclosure while being processed by the Konnect Cloud Service. However, the use of the Konnect Cloud Service necessarily involves transmission of Customer Content over networks that are not owned, operated or controlled by Kong, and Kong is not responsible for any Customer Content that is lost, altered, intercepted or stored across such networks.

  1. Customer’s Security Measures. Customer acknowledges that Kong does not host the Software or control the Customer Network Environment, and the Customer acknowledges and agrees that Customer must undertake technical and organizational measures to protect the Software, the Customer Network Environment and Customer Payload Data. Customer is responsible for properly configuring and using the Konnect Platform and taking its own steps to maintain appropriate security, protection and backup of its data, including Customer Payload Data.

  1. Customer Security Contact. Customer is responsible for ensuring Kong at all times has updated and accurate Customer contact information for the appropriate person for Kong to notify regarding data security issues relating to the Konnect Platform, with each such Customer current contact’s information to be provided by Customer in the Customer account page for Konnect Cloud Services or Kong’s support portal, if applicable. 

  1. Usage Data. For the avoidance of doubt, Customer may choose to disable the self-reporting feature in the Software which permits transmission of the Usage Data to Kong only if Customer has subscribed for a purely self-hosted deployment of the Konnect Platform.

  1. Termination. With respect to the Konnect Cloud Services, Customer will have up to 30 calendar days from the effective date of termination or expiration of the Agreement or an Order Form (if not renewed), if it has paid all amounts due under the Agreement, to access the Konnect Cloud Service solely to retrieve available Customer Content, but may not use the Konnect Cloud Service to manage Software or for any other purposes, and for such retrieval purposes only the Agreement and the applicable Order Form will survive for such period. Thereafter, (i) Kong will have no further obligation to make the Konnect Cloud Service available or to retain Customer Content, (ii) Customer will have no further access to Customer Content held through the Konnect Cloud Service, and (iii) Customer will cease use of and access to Konnect Cloud Service for all purposes whatsoever and will delete all copies of Documentation, Konnect Cloud Services passwords or access codes, and any other Kong Confidential Information in its possession.

In addition to any of its other rights or remedies (including, without limitation, any termination rights set forth in the Agreement), Kong reserves the right to suspend Customer’s access to the Konnect Cloud Service if: (a) Customer (or Customer’s Authorized Reseller, if applicable) is 30 days or more overdue on a payment, (b) Kong reasonably determines that Customer’s use of the Konnect Cloud Service is in violation of Section “Acceptable Use” above, (c) Kong reasonably determines that Customer’s use of the Konnect Cloud Services may be unlawful, (d) Kong reasonably determines suspension is necessary to avoid material harm to Kong or its other customers, including if the Konnect Cloud Services are experiencing denial of service attacks, mail flooding, or other attacks or disruptions outside of Kong’s control, or (e) required by law or at the request of governmental entities.

  1. Indemnification by Kong. The parties agree that Kong will have no indemnification obligations under the Agreement or otherwise if the claim is attributable to the Customer Content.

Last updated: March 16, 2022