Legal

Data Processing Agreement

Last updated: January 9, 2026

This Data Processing Agreement ("DPA") forms part of the agreement between KeyEnv ("Processor") and the Customer ("Controller") for the provision of secrets management services.

Enterprise Customers: To execute this DPA, please contact [email protected] with your company details. We will provide a countersigned copy for your records.

1. Definitions

  • "Personal Data" means any information relating to an identified or identifiable natural person.
  • "Processing" means any operation performed on Personal Data, including collection, storage, use, and deletion.
  • "Data Subject" means the individual to whom Personal Data relates.
  • "Sub-processor" means any third party engaged by KeyEnv to process Personal Data.
  • "Data Protection Laws" means GDPR, CCPA, and other applicable privacy regulations.
  • "Services" means the KeyEnv secrets management platform and related services.

2. Scope and Purpose

This DPA applies to the Processing of Personal Data by KeyEnv on behalf of the Customer in connection with the Services. The subject matter, duration, nature, and purpose of Processing are defined in the main service agreement.

KeyEnv processes Personal Data solely to provide the Services and as instructed by the Customer, except where required by applicable law.

3. Data Processing Details

3.1 Categories of Data Subjects

  • Customer employees and contractors
  • Customer's end users (if applicable)
  • Other individuals whose data is stored in Customer's secrets

3.2 Types of Personal Data

  • Account information (email, name)
  • Usage data and access logs
  • Any Personal Data contained in Customer's encrypted secrets

3.3 Processing Operations

  • Storage of encrypted secrets
  • Authentication and access control
  • Audit logging
  • Service analytics (anonymized)

4. Processor Obligations

KeyEnv agrees to:

  • Process Personal Data only on documented instructions from the Customer
  • Ensure persons authorized to process data are bound by confidentiality
  • Implement appropriate technical and organizational security measures
  • Assist the Customer in responding to Data Subject requests
  • Assist with data protection impact assessments when required
  • Delete or return all Personal Data upon termination of Services
  • Make available information necessary to demonstrate compliance
  • Allow for and contribute to audits conducted by the Customer

5. Security Measures

KeyEnv implements the following security measures:

  • Encryption: AES-256-GCM for data at rest, TLS 1.3 for data in transit
  • Access Control: Role-based access, MFA, principle of least privilege
  • Monitoring: Intrusion detection, audit logging, anomaly detection
  • Physical Security: SOC 2 compliant data centers with restricted access
  • Incident Response: Documented procedures for security incidents
  • Business Continuity: Regular backups, disaster recovery planning

6. Sub-processors

Customer authorizes KeyEnv to engage the following categories of Sub-processors:

Sub-processorPurposeLocation
RailwayCloud hosting infrastructureUnited States
VercelWeb application hostingUnited States
ClerkAuthentication servicesUnited States
StripePayment processingUnited States
SentryError monitoringUnited States

KeyEnv will notify the Customer of any intended changes to Sub-processors, giving the Customer an opportunity to object. Sub-processors are bound by data protection obligations equivalent to those in this DPA.

7. International Data Transfers

Where Personal Data is transferred outside the European Economic Area (EEA), KeyEnv ensures appropriate safeguards are in place:

  • Standard Contractual Clauses (SCCs) approved by the European Commission
  • Transfer to countries with adequate data protection (per EU Commission decisions)
  • Binding Corporate Rules where applicable

8. Data Subject Rights

KeyEnv will assist the Customer in fulfilling Data Subject rights requests, including:

  • Right of access
  • Right to rectification
  • Right to erasure ("right to be forgotten")
  • Right to restriction of processing
  • Right to data portability
  • Right to object

Requests received directly by KeyEnv will be forwarded to the Customer unless legally prohibited.

9. Data Breach Notification

In the event of a Personal Data breach, KeyEnv will:

  • Notify the Customer without undue delay (within 72 hours of becoming aware)
  • Provide information about the nature and consequences of the breach
  • Describe measures taken or proposed to address the breach
  • Cooperate with the Customer's investigation and remediation efforts

10. Audit Rights

KeyEnv will make available to the Customer:

  • Security certifications and audit reports (SOC 2, when available)
  • Documentation of security measures and policies
  • Results of penetration tests (summary form)

Upon reasonable notice, the Customer may conduct or commission an audit of KeyEnv's compliance with this DPA. Audits shall be conducted at the Customer's expense and shall not unreasonably interfere with KeyEnv's business operations.

11. Term and Termination

This DPA remains in effect for the duration of the main service agreement. Upon termination:

  • KeyEnv will delete all Personal Data within 30 days
  • Customer may request data export before deletion
  • KeyEnv will certify deletion upon request
  • Some data may be retained where required by law

12. Liability

Each party's liability under this DPA is subject to the limitations set forth in the main service agreement. KeyEnv shall be liable for damages caused by Processing that violates Data Protection Laws or this DPA.

13. Contact

For questions about this DPA or to execute a signed version: