Data Processing Agreement
Last updated: 04-04-2026
Parties
This Data Processing Agreement ("Agreement") is entered into between the customer ("Data Controller") and KeySafe ApS, CVR: 20404078, Møllevej 9 F1, 2990 Nivå, Denmark ("Data Processor").
Scope of processing
The Data Processor processes personal data on behalf of the Data Controller in connection with the provision of the KeySafe service. This includes finder information (name, phone, email, message, photo) submitted via the contact form when a person finds a key belonging to the Data Controller.
Obligations of the Data Processor
The Data Processor undertakes to:
- Only process personal data in accordance with documented instructions from the Data Controller
- Ensure that persons authorised to process personal data are bound by confidentiality
- Implement all necessary technical and organisational security measures in accordance with GDPR Article 32
- Assist the Data Controller in fulfilling its obligations under GDPR Articles 32-36
Sub-processors
The Data Processor uses the following sub-processors:
- Simply.com (hosting) — Denmark
- Postmark/ActiveCampaign (email) — USA (EU Standard Contractual Clauses)
- Stripe (payments) — USA (EU Standard Contractual Clauses)
Security measures
The Data Processor implements appropriate technical and organisational measures, including encryption of data in transit (TLS), access control, logging and regular security assessments.
Data breach
The Data Processor shall notify the Data Controller of any personal data breach without undue delay and no later than 48 hours after becoming aware of the breach.
Deletion
Upon termination of the agreement, personal data is retained for an additional 12 months, after which the Data Processor shall delete all personal data processed on behalf of the Data Controller, with the exception of data that must be retained under Danish bookkeeping legislation (up to 5 years).
Contact
Questions regarding this agreement can be directed to KeySafe ApS at hej@keysafe.dk.