1. Scope and roles
Customer is the controller and Keystone is the processor for Customer Personal Data. This DPA is incorporated into the SaaS Agreement. It prevails over the agreement where they conflict on processing Customer Personal Data. Terms such as controller, processor, personal data and personal data breach have the meanings in applicable data-protection law.
2. Documented instructions
Keystone will process Customer Personal Data only on Customer’s documented instructions: to provide, secure, support and improve the service; as set out in the SaaS Agreement and this DPA; or as required by applicable law. If law requires processing, Keystone will inform Customer before doing so unless prohibited by law.
3. Confidentiality and security
Keystone will ensure that people authorised to process Customer Personal Data are bound by confidentiality obligations and will implement appropriate technical and organisational measures taking account of Article 32 UK GDPR. The current measures and known limitations are described in the Security Pack; Customer remains responsible for its user access, passwords and the lawful use of the service.
4. Subprocessors
Customer gives general written authorisation for the subprocessors listed in the Security Pack and for replacements or additional subprocessors that provide substantially similar services. Keystone will maintain that list and give at least 14 days’ notice of a material new subprocessor where practicable. Customer may object on reasonable data-protection grounds during that period; the parties will work in good faith on a solution, and Customer may terminate the affected service if none is available. Keystone will impose written data-protection obligations on subprocessors no less protective than this DPA and remains responsible for their performance to the extent required by law.
5. International transfers
Keystone will not transfer Customer Personal Data outside the UK except on Customer’s instructions or where a lawful transfer mechanism applies. Where a transfer is restricted, Keystone will use an adequacy regulation, the UK International Data Transfer Agreement, the UK Addendum to EU standard contractual clauses, or another valid safeguard, and provide relevant transfer information on reasonable request.
6. Assistance
Taking account of the nature of processing and information available, Keystone will provide reasonable assistance for data-subject requests, security obligations, data-protection impact assessments, prior consultation, breach investigation and regulatory enquiries. Keystone may charge reasonable professional-services fees for assistance outside normal service support where permitted by law.
7. Personal data breaches
Keystone will notify Customer without undue delay after becoming aware of a Personal Data Breach affecting Customer Personal Data and provide information reasonably available to help Customer meet its notification obligations. Customer is responsible for deciding whether to notify a regulator or individuals, unless law requires Keystone to do so directly.
8. Audit and information
On reasonable written request no more than once a year, Keystone will make available information reasonably necessary to demonstrate compliance with this DPA. If that is insufficient, Customer may conduct an audit through an independent auditor bound by confidentiality, on at least 30 days’ notice, during normal business hours, without unreasonable disruption and at Customer’s expense. Audits must not expose other customers’ data or Keystone confidential information.
9. Return and deletion
During the subscription term, Customer can export Customer Data using available product functions or request reasonable assistance. Following termination, Keystone will delete or return Customer Personal Data on Customer’s written instruction unless retention is required by law. Our service does not yet provide an automated, workspace-wide deletion workflow or a published backup-retention period; deletion requests are handled through support and may be subject to reasonable identity, authority and legal-retention checks. Data held in backups is isolated from active use and deleted in accordance with the underlying provider’s retention cycle.
10. Processing details
Subject matter and duration: delivery and support of Keystone Site for the subscription term and deletion/return period. Nature and purpose: hosting, storage, authentication, communication, support, security, analytics and optional AI or transcription features requested through the service. Categories of data subjects: Customer’s staff, installers, prospects, customers, suppliers and other people whose data Customer enters. Types of data: identity, contact, job, property, communication, photo, document, location-event, account and other Customer Data chosen by Customer. Customer’s rights and obligations are those under applicable data-protection law.
11. Contact
Send DPA questions, instructions and subprocessor objections to
site@keystoneai.uk.