This DPA is intended to form part of the KeyInOut Terms where a customer organisation uses KeyInOut to process personal data for which that customer is the controller. KeyInOut is a commercially available service operated by Alexander Arfs in Sweden.
01Parties and roles
The customer organisation using the KeyInOut workspace is the Controller. Alexander Arfs, Sweden, operating KeyInOut, is the Processor for Customer Personal Data processed on the Controller's behalf. Privacy contact: privacy@keyinout.com.
02Scope and instructions
The Processor will process Customer Personal Data only on documented instructions from the Controller, including instructions expressed through the Controller's use and configuration of KeyInOut, and only as necessary to provide, secure, maintain and support the service, unless processing is required by EU or Member State law. If legally permitted, the Processor will inform the Controller before processing required by such law.
If the Processor believes an instruction infringes applicable data-protection law, it will inform the Controller and may suspend the affected processing while the issue is resolved.
03Details of processing
- Subject matter
- Provision of the KeyInOut physical-key management service.
- Duration
- For the duration of the customer's use of KeyInOut and the limited period needed to complete deletion/return obligations.
- Nature and purpose
- Hosting, storing, organising, retrieving, displaying, exporting, emailing configured notifications about, and otherwise processing data needed to manage keys, holders, locations, users and activity.
- Data subjects
- Customer users, employees, contractors, key holders and other persons whose details the customer chooses to enter.
- Personal data
- Names, work/contact email addresses, phone numbers where supplied, account roles/status, key-holder relationships, check-out/return history, due dates, notes, audit records and related operational metadata.
- Special categories
- KeyInOut is not intended for special-category personal data. Customers should not enter such data unless they have independently determined that doing so is lawful and necessary.
04Confidentiality
The Processor will ensure that persons authorised to process Customer Personal Data are subject to an appropriate duty of confidentiality and access the data only as needed for their authorised duties.
05Security
Taking into account the state of the art, implementation costs, the nature and scope of processing and relevant risks, the Processor will maintain appropriate technical and organisational measures. Current measures include tenant-scoped access controls, role-based permissions, HTTPS, secure password hashing, hardened sessions, CSRF protection, prepared database statements, opaque QR identifiers, data-minimised public QR pages and administrative/activity logging where implemented. The current security overview is available on the Security page.
06Subprocessors
The Controller gives general written authorisation for the Processor to use subprocessors necessary to operate KeyInOut, subject to Article 28 GDPR. The Processor will impose data-protection obligations on subprocessors that are materially equivalent to those required for the relevant processing and remains responsible for its obligations under this DPA.
Current infrastructure subprocessor: Simply.com is used for hosting/infrastructure and transactional email services relevant to the current service. If a new subprocessor is introduced that materially processes Customer Personal Data, KeyInOut will update the published information and provide reasonable advance notice where required, giving the Controller an opportunity to raise a reasoned data-protection objection.
07International transfers
The Processor will not knowingly transfer Customer Personal Data outside the EU/EEA without ensuring that a lawful transfer mechanism and required safeguards are in place. Where a subprocessor's processing involves a restricted international transfer, the Processor will use an appropriate GDPR Chapter V mechanism as applicable.
08Data-subject requests
Taking into account the nature of the processing, the Processor will provide reasonable assistance to the Controller, through appropriate technical and organisational measures where possible, to respond to requests from data subjects exercising their GDPR rights. If a request relating to Customer Personal Data is received directly, the Processor will normally refer the requester to the Controller unless legally required to respond otherwise.
09Security incidents and compliance assistance
The Processor will notify the Controller without undue delay after becoming aware of a personal-data breach affecting Customer Personal Data and will provide information reasonably available to assist the Controller with its obligations under Articles 32–36 GDPR.
The Processor will also provide reasonable assistance, taking into account the nature of processing and information available, with security, breach notification, data-protection impact assessments and prior consultation obligations applicable to the Controller.
10Deletion and return
During the service, workspace owners can export available workspace data. On termination or workspace deletion, the Processor will delete Customer Personal Data from the live service, unless applicable law requires retention. Residual copies may remain temporarily in technical backups until overwritten or deleted according to the applicable backup cycle and will remain protected and unavailable for ordinary use during that period.
11Information and audits
The Processor will make available information reasonably necessary to demonstrate compliance with Article 28 obligations and will allow and contribute to reasonable audits or inspections by the Controller or an auditor mandated by it. Audits must be proportionate, protect other customers' confidentiality and security, and where possible first use available documentation rather than intrusive testing.
The parties will agree reasonable timing and scope in advance except where urgent action is required by a supervisory authority or serious incident.
12Controller obligations
The Controller is responsible for the lawfulness, fairness and transparency of its processing; the accuracy and necessity of data it enters; its legal bases; notices to data subjects; user permissions; and its instructions to the Processor. The Controller must not instruct the Processor to process personal data unlawfully.
13Order of precedence and changes
This DPA supplements the Terms of Service. For matters concerning processing of Customer Personal Data, this DPA prevails over conflicting general terms. We may update this DPA where needed to reflect changes in law or the service; material changes will be communicated where appropriate.
14Contact
Processor: Alexander Arfs, Sweden, operating KeyInOut. Privacy/DPA enquiries: privacy@keyinout.com. Security incidents: security@keyinout.com.