KeyInOut SIMPLE ACCESS. BETTER CONTROL
🌐 English ▾
English ✓ Svenska Deutsch Norsk Dansk Français Español Nederlands Suomi Italiano Polski Português
← Home

Data protection

Data Processing Agreement

Article 28 terms for customer personal data processed through KeyInOut.

Version 1.0 · 9 September 2026

On this page
01Parties and roles 02Scope and instructions 03Details of processing 04Confidentiality 05Security 06Subprocessors 07International transfers 08Data-subject requests 09Security incidents and compliance assistance 10Deletion and return 11Information and audits 12Controller obligations 13Order of precedence and changes 14Contact
How this DPA applies

This DPA is intended to form part of the KeyInOut Terms where a customer organisation uses KeyInOut to process personal data for which that customer is the controller. KeyInOut is a commercially available service operated by Alexander Arfs in Sweden.

01Parties and roles

The customer organisation using the KeyInOut workspace is the Controller. Alexander Arfs, Sweden, operating KeyInOut, is the Processor for Customer Personal Data processed on the Controller's behalf. Privacy contact: privacy@keyinout.com.

02Scope and instructions

The Processor will process Customer Personal Data only on documented instructions from the Controller, including instructions expressed through the Controller's use and configuration of KeyInOut, and only as necessary to provide, secure, maintain and support the service, unless processing is required by EU or Member State law. If legally permitted, the Processor will inform the Controller before processing required by such law.

If the Processor believes an instruction infringes applicable data-protection law, it will inform the Controller and may suspend the affected processing while the issue is resolved.

03Details of processing

Subject matter
Provision of the KeyInOut physical-key management service.
Duration
For the duration of the customer's use of KeyInOut and the limited period needed to complete deletion/return obligations.
Nature and purpose
Hosting, storing, organising, retrieving, displaying, exporting, emailing configured notifications about, and otherwise processing data needed to manage keys, holders, locations, users and activity.
Data subjects
Customer users, employees, contractors, key holders and other persons whose details the customer chooses to enter.
Personal data
Names, work/contact email addresses, phone numbers where supplied, account roles/status, key-holder relationships, check-out/return history, due dates, notes, audit records and related operational metadata.
Special categories
KeyInOut is not intended for special-category personal data. Customers should not enter such data unless they have independently determined that doing so is lawful and necessary.

04Confidentiality

The Processor will ensure that persons authorised to process Customer Personal Data are subject to an appropriate duty of confidentiality and access the data only as needed for their authorised duties.

05Security

Taking into account the state of the art, implementation costs, the nature and scope of processing and relevant risks, the Processor will maintain appropriate technical and organisational measures. Current measures include tenant-scoped access controls, role-based permissions, HTTPS, secure password hashing, hardened sessions, CSRF protection, prepared database statements, opaque QR identifiers, data-minimised public QR pages and administrative/activity logging where implemented. The current security overview is available on the Security page.

06Subprocessors

The Controller gives general written authorisation for the Processor to use subprocessors necessary to operate KeyInOut, subject to Article 28 GDPR. The Processor will impose data-protection obligations on subprocessors that are materially equivalent to those required for the relevant processing and remains responsible for its obligations under this DPA.

Current infrastructure subprocessor: Simply.com is used for hosting/infrastructure and transactional email services relevant to the current service. If a new subprocessor is introduced that materially processes Customer Personal Data, KeyInOut will update the published information and provide reasonable advance notice where required, giving the Controller an opportunity to raise a reasoned data-protection objection.

07International transfers

The Processor will not knowingly transfer Customer Personal Data outside the EU/EEA without ensuring that a lawful transfer mechanism and required safeguards are in place. Where a subprocessor's processing involves a restricted international transfer, the Processor will use an appropriate GDPR Chapter V mechanism as applicable.

08Data-subject requests

Taking into account the nature of the processing, the Processor will provide reasonable assistance to the Controller, through appropriate technical and organisational measures where possible, to respond to requests from data subjects exercising their GDPR rights. If a request relating to Customer Personal Data is received directly, the Processor will normally refer the requester to the Controller unless legally required to respond otherwise.

09Security incidents and compliance assistance

The Processor will notify the Controller without undue delay after becoming aware of a personal-data breach affecting Customer Personal Data and will provide information reasonably available to assist the Controller with its obligations under Articles 32–36 GDPR.

The Processor will also provide reasonable assistance, taking into account the nature of processing and information available, with security, breach notification, data-protection impact assessments and prior consultation obligations applicable to the Controller.

10Deletion and return

During the service, workspace owners can export available workspace data. On termination or workspace deletion, the Processor will delete Customer Personal Data from the live service, unless applicable law requires retention. Residual copies may remain temporarily in technical backups until overwritten or deleted according to the applicable backup cycle and will remain protected and unavailable for ordinary use during that period.

11Information and audits

The Processor will make available information reasonably necessary to demonstrate compliance with Article 28 obligations and will allow and contribute to reasonable audits or inspections by the Controller or an auditor mandated by it. Audits must be proportionate, protect other customers' confidentiality and security, and where possible first use available documentation rather than intrusive testing.

The parties will agree reasonable timing and scope in advance except where urgent action is required by a supervisory authority or serious incident.

12Controller obligations

The Controller is responsible for the lawfulness, fairness and transparency of its processing; the accuracy and necessity of data it enters; its legal bases; notices to data subjects; user permissions; and its instructions to the Processor. The Controller must not instruct the Processor to process personal data unlawfully.

13Order of precedence and changes

This DPA supplements the Terms of Service. For matters concerning processing of Customer Personal Data, this DPA prevails over conflicting general terms. We may update this DPA where needed to reflect changes in law or the service; material changes will be communicated where appropriate.

14Contact

Processor: Alexander Arfs, Sweden, operating KeyInOut. Privacy/DPA enquiries: privacy@keyinout.com. Security incidents: security@keyinout.com.

© 2026 KeyInOut
Privacy Security Terms Cookies Create account