Effective July 21, 2026
Data Processing Addendum
Terms for Keyfolio's processing of personal data on behalf of a workspace customer.
Scope and roles
This Data Processing Addendum (DPA) forms part of the Terms between the customer using Keyfolio (Customer) and Keyfolio (Keyfolio). To the extent Keyfolio processes personal data on Customer's behalf in providing the service, Customer is the controller or processor and Keyfolio is the processor or subprocessor, as applicable.
Documented instructions
Keyfolio will process personal data only on Customer's documented instructions, including these Terms and the normal use of the service, unless required by applicable law. If required by law to process data differently, Keyfolio will notify Customer unless prohibited from doing so.
Processing details
The subject matter is provision of the Keyfolio billing workspace. The duration is the term of the customer relationship plus retention required for legal, security, backup, and dispute purposes. The nature and purpose are hosting, authentication, reconciliation, invoicing, payment-link facilitation, support, security, and service maintenance. Data subjects may include Customer users, Customer clients and contacts, and authorized provider users. Data may include identity, contact, account, usage, invoice, payment-status, and security information.
Confidentiality and security
Keyfolio will ensure personnel authorized to process personal data are subject to appropriate confidentiality obligations. Keyfolio will maintain appropriate technical and organizational measures, taking account of the nature of the processing and risks involved, including authenticated access controls, encrypted storage for provider management credentials, and security monitoring. Customer is responsible for configuring its workspace, managing authorized users, and protecting credentials it controls.
Subprocessors
Customer authorizes Keyfolio to use subprocessors needed to provide the service, including the categories and providers described on the Subprocessors page. Keyfolio will impose data-protection obligations on subprocessors that are materially consistent with this DPA. Keyfolio will provide notice of material new subprocessors by updating that page; Customer may object on reasonable data-protection grounds by contacting us within 30 days. If the objection cannot reasonably be resolved, Customer may stop using the affected service.
Assistance and incidents
Taking account of the nature of processing and information available, Keyfolio will provide reasonable assistance for data-subject requests, security obligations, impact assessments, and regulator consultations. Keyfolio will notify Customer without undue delay after becoming aware of a personal-data breach affecting Customer data and will provide available information needed for Customer's response.
Transfers, audit, and deletion
Where a cross-border transfer requires a transfer mechanism, the parties will use an appropriate legally recognized mechanism. On termination, Customer may export its available data before access ends. Keyfolio will delete or return personal data within a reasonable period, unless retention is required by law or needed for security, backup, or legal claims. On reasonable written request no more than once annually, Keyfolio will make available information reasonably necessary to demonstrate compliance, subject to confidentiality, security, and cost protections.
Contact
For DPA or subprocessor questions, contact privacy@keyfolio.ai.
