KeyInOut SIMPLE ACCESS. BETTER CONTROL
🌐 English ▾
English ✓ Svenska Deutsch Norsk Dansk Français Español Nederlands Suomi Italiano Polski Português
← Home

Legal

Privacy Notice

How personal data is handled when you visit or use KeyInOut.

Last updated: 12 September 2026

On this page
01Who is responsible for your data? 02Personal data we process 03Why we process data and our legal bases 04Emails and reminders 05Public QR return information 06Service providers and recipients 07International transfers 08Retention 09Your data-protection rights 10Cookies and analytics 11Security 12Changes and contact
Privacy and data use

KeyInOut is a commercially available subscription service operated by Alexander Arfs in Sweden. Paid subscriptions are processed through Stripe. Optional website analytics are provided through Google Analytics 4 only after the visitor has consented.

01Who is responsible for your data?

For account administration, service security, communications with KeyInOut and operation of the KeyInOut website, the controller is Alexander Arfs, Sweden, operating KeyInOut. Privacy enquiries can be sent to privacy@keyinout.com. General support enquiries can be sent to support@keyinout.com.

For personal data that a customer organisation enters into its workspace — for example employee or contractor details, key-holder records and key activity — the customer organisation normally determines why and how that data is used and is therefore the controller. KeyInOut processes that workspace data on the customer's behalf as a processor. The Data Processing Agreement describes that relationship.

02Personal data we process

  • Account and team data: name, email address, role, account status and verification information.
  • Workspace data: organisation/workspace name, locations, key records and settings.
  • People and key-holder data: names and, when supplied by the customer, email addresses and phone numbers.
  • Operational records: check-outs, returns, expected return times, notes, holder snapshots and audit/history records.
  • Security and technical data: authentication attempts, IP-related security records where recorded, timestamps, session/security information and administrative audit events.
  • Communications and billing-contact data: information supplied when contacting us and a billing email where configured. Payment-card processing is not currently enabled.

Passwords are not stored in readable form; password hashes are stored instead. Verification, reset and invitation secrets are stored as hashes where applicable.

03Why we process data and our legal bases

Where KeyInOut acts as controller, account and service data is processed to provide the requested service and administer accounts (performance of a contract or steps requested before entering one). Security logs, abuse prevention, service reliability and limited operational records are processed where necessary for our legitimate interests in protecting and operating KeyInOut. Data may also be processed where necessary to comply with a legal obligation.

Where KeyInOut acts as processor for a customer organisation, the customer determines the applicable purpose and legal basis. Customers are responsible for ensuring they have a lawful basis for personal data they enter into KeyInOut and for providing required information to their staff, contractors or other data subjects.

04Emails and reminders

KeyInOut sends transactional messages needed for account verification, password reset, invitations and service operation. A workspace may also configure overdue-key reminders. Reminder recipients and settings are controlled by the workspace. KeyInOut does not currently send third-party advertising through the service.

05Public QR return information

A workspace can optionally make selected return contact information public to a person who scans a KeyInOut label. This is disabled unless configured by the workspace. The public return page is designed not to expose the key name, current holder, location, hook position, due date or check-out status.

06Service providers and recipients

Personal data is disclosed only where needed to operate the service, comply with law, protect the service or follow a customer's instructions. KeyInOut currently relies on infrastructure providers for web/database hosting and transactional email delivery. Our current infrastructure is hosted through Simply.com. We use Google Analytics 4 only after the visitor has consented to optional analytics. Stripe is used for subscription payment processing.

Our list of processors may change as KeyInOut develops. Material changes affecting customer workspace data will be reflected in this notice and, where applicable, the DPA/subprocessor information.

07International transfers

KeyInOut is operated from Sweden. We aim to use service infrastructure appropriate for an EU/EEA service. If a provider requires personal data to be transferred outside the EU/EEA, an applicable GDPR transfer mechanism and safeguards must be used where required. We will update this notice when new providers materially change the transfer position.

08Retention

Account and workspace data is generally retained while the workspace exists. Workspace owners can export data and can delete the workspace using the controls provided in KeyInOut. Deletion removes workspace data from the live application subject to technical backup cycles, security records that must be retained for a limited period, and any retention required by law. Authentication, delivery and security logs are kept only for as long as reasonably needed for their operational or security purpose.

Operational logs and backups are retained according to the production hosting, security and backup configuration. Backup copies may remain for a limited period after data is removed from the live application and are not intended for normal application use.

09Your data-protection rights

Where KeyInOut/Alexander Arfs is the controller, you may have rights under the GDPR including access, rectification, erasure, restriction, data portability and objection, depending on the circumstances and legal basis. Contact privacy@keyinout.com to make a request.

If your request concerns data entered by your employer or another customer organisation, please contact that organisation first because it is normally the controller. KeyInOut will assist the customer as required by the DPA.

You also have the right to lodge a complaint with the Swedish Authority for Privacy Protection (Integritetsskyddsmyndigheten, IMY) or another competent supervisory authority.

10Cookies and analytics

KeyInOut uses technical browser/session mechanisms needed to keep users signed in securely and to operate the service. With consent, KeyInOut also uses Google Analytics 4 to understand website traffic and usage. Analytics is optional and the choice can be changed through Cookie settings.

11Security

We use technical and organisational measures intended to protect personal data. These include tenant-scoped access, role-based permissions, HTTPS, hardened sessions, CSRF protection, prepared database statements and minimised QR data. More information is available on the Security page. No online service can guarantee absolute security.

12Changes and contact

We may update this notice as KeyInOut develops, including when new infrastructure, analytics or payment providers are introduced. Material changes will be reflected by updating the date above. Questions about privacy can be sent to privacy@keyinout.com.

© 2026 KeyInOut
Security Terms DPA Cookies Create account