Legal
Data Processing Agreement
This Data Processing Agreement ("DPA") forms part of the agreement between KeyEnv ("Processor") and the Customer ("Controller") for the provision of secrets management services.
Enterprise Customers: To execute this DPA, please contact [email protected] with your company details. We will provide a countersigned copy for your records.
1. Definitions
- "Personal Data" means any information relating to an identified or identifiable natural person.
- "Processing" means any operation performed on Personal Data, including collection, storage, use, and deletion.
- "Data Subject" means the individual to whom Personal Data relates.
- "Sub-processor" means any third party engaged by KeyEnv to process Personal Data.
- "Data Protection Laws" means GDPR, CCPA, and other applicable privacy regulations.
- "Services" means the KeyEnv secrets management platform and related services.
2. Scope and Purpose
This DPA applies to the Processing of Personal Data by KeyEnv on behalf of the Customer in connection with the Services. The subject matter, duration, nature, and purpose of Processing are defined in the main service agreement.
KeyEnv processes Personal Data solely to provide the Services and as instructed by the Customer, except where required by applicable law.
3. Data Processing Details
3.1 Categories of Data Subjects
- Customer employees and contractors
- Customer's end users (if applicable)
- Other individuals whose data is stored in Customer's secrets
3.2 Types of Personal Data
- Account information (email, name)
- Usage data and access logs
- Any Personal Data contained in Customer's encrypted secrets
3.3 Processing Operations
- Storage of encrypted secrets
- Authentication and access control
- Audit logging
- Service analytics (anonymized)
4. Processor Obligations
KeyEnv agrees to:
- Process Personal Data only on documented instructions from the Customer
- Ensure persons authorized to process data are bound by confidentiality
- Implement appropriate technical and organizational security measures
- Assist the Customer in responding to Data Subject requests
- Assist with data protection impact assessments when required
- Delete or return all Personal Data upon termination of Services
- Make available information necessary to demonstrate compliance
- Allow for and contribute to audits conducted by the Customer
5. Security Measures
KeyEnv implements the following security measures:
- Encryption: AES-256-GCM for data at rest, TLS 1.3 for data in transit
- Access Control: Role-based access, MFA, principle of least privilege
- Monitoring: Intrusion detection, audit logging, anomaly detection
- Physical Security: SOC 2 compliant data centers with restricted access
- Incident Response: Documented procedures for security incidents
- Business Continuity: Regular backups, disaster recovery planning
6. Sub-processors
Customer authorizes KeyEnv to engage the following categories of Sub-processors:
| Sub-processor | Purpose | Location |
|---|---|---|
| Railway | Cloud hosting infrastructure | United States |
| Vercel | Web application hosting | United States |
| Clerk | Authentication services | United States |
| Stripe | Payment processing | United States |
| Sentry | Error monitoring | United States |
KeyEnv will notify the Customer of any intended changes to Sub-processors, giving the Customer an opportunity to object. Sub-processors are bound by data protection obligations equivalent to those in this DPA.
7. International Data Transfers
Where Personal Data is transferred outside the European Economic Area (EEA), KeyEnv ensures appropriate safeguards are in place:
- Standard Contractual Clauses (SCCs) approved by the European Commission
- Transfer to countries with adequate data protection (per EU Commission decisions)
- Binding Corporate Rules where applicable
8. Data Subject Rights
KeyEnv will assist the Customer in fulfilling Data Subject rights requests, including:
- Right of access
- Right to rectification
- Right to erasure ("right to be forgotten")
- Right to restriction of processing
- Right to data portability
- Right to object
Requests received directly by KeyEnv will be forwarded to the Customer unless legally prohibited.
9. Data Breach Notification
In the event of a Personal Data breach, KeyEnv will:
- Notify the Customer without undue delay (within 72 hours of becoming aware)
- Provide information about the nature and consequences of the breach
- Describe measures taken or proposed to address the breach
- Cooperate with the Customer's investigation and remediation efforts
10. Audit Rights
KeyEnv will make available to the Customer:
- Security certifications and audit reports (SOC 2, when available)
- Documentation of security measures and policies
- Results of penetration tests (summary form)
Upon reasonable notice, the Customer may conduct or commission an audit of KeyEnv's compliance with this DPA. Audits shall be conducted at the Customer's expense and shall not unreasonably interfere with KeyEnv's business operations.
11. Term and Termination
This DPA remains in effect for the duration of the main service agreement. Upon termination:
- KeyEnv will delete all Personal Data within 30 days
- Customer may request data export before deletion
- KeyEnv will certify deletion upon request
- Some data may be retained where required by law
12. Liability
Each party's liability under this DPA is subject to the limitations set forth in the main service agreement. KeyEnv shall be liable for damages caused by Processing that violates Data Protection Laws or this DPA.
13. Contact
For questions about this DPA or to execute a signed version:
- Email: [email protected]