This document was approved for publication following qualified Irish/EU and Brazilian legal review. Customer-specific Order Forms and negotiated agreements control where expressly stated.
This Data Processing Agreement (“DPA”) forms part of the agreement between the Customer as controller or processor and the kubbeevault supplier named in the Order Form as processor or subprocessor. It applies to Customer Personal Data processed by kubbeevault to provide the Services.
1. Definitions and scope
“Applicable Data Protection Law” means data-protection and privacy law applicable to the processing, including the EU General Data Protection Regulation 2016/679 (“GDPR”), the Brazilian Law 13,709/2018 (“LGPD”), and implementing or successor laws. “Customer Personal Data” means personal data processed by kubbeevault on behalf of the Customer. Controller, processor, data subject, processing, personal data breach, and supervisory authority have the meanings given by applicable law.
The applicable kubbeevault contracting entity is KUBBEE TECH LIMITED for Customers in Europe and KUBBEEVAULT INOVA SIMPLES (I.S.) for Customers in Brazil and all other locations outside Europe. The Customer determines the purposes and means of processing Customer Personal Data. kubbeevault processes it only to provide, secure, maintain, and support the Services and on the Customer’s documented instructions, including the agreement, authorised product configuration, support requests, and other written instructions consistent with the Services.
2. Details of processing
- Subject matter: operation and support of a company credential and secrets-management platform and purchased integrations or professional services.
- Duration: the subscription term plus the limited export, backup, deletion, and legally required retention periods in the agreement.
- Nature and purpose: collection, recording, organisation, encryption, storage, retrieval, access control, sharing at the Customer’s direction, audit logging, transmission, backup, support, security monitoring, deletion, and other processing needed to provide the Services.
- Data subjects: Customer users, administrators, personnel, contractors, business partners, and other people whose personal data the Customer submits or records in the Services.
- Personal data: names, business contact data, identifiers, account and authentication metadata, organisation and role information, IP and device data, audit events, support data, and personal data contained in Customer-selected credential records or metadata.
- Special or high-risk data: not intentionally required by kubbeevault. The Customer must not submit it unless permitted by the agreement and supported by an appropriate risk assessment and lawful instruction.
3. Instructions and compliance
kubbeevault will process Customer Personal Data only on documented instructions unless required by law. Where legally permitted, kubbeevault will inform the Customer before legally required processing. kubbeevault will promptly inform the Customer if it believes an instruction violates Applicable Data Protection Law and may suspend the affected processing while the parties resolve the issue.
The Customer is responsible for the lawfulness, accuracy, and quality of Customer Personal Data; providing notices; responding as controller to data subjects; configuring the Services; and ensuring that its instructions comply with law. The Customer will not instruct kubbeevault to process data in a manner inconsistent with the Services or agreement.
4. Confidentiality and security
kubbeevault will ensure that personnel authorised to process Customer Personal Data are bound by confidentiality obligations and receive access only as needed. kubbeevault will maintain appropriate technical and organisational measures designed to protect confidentiality, integrity, availability, and resilience, considering the state of the art, implementation costs, scope and context, and risks to people.
- Encryption in transit and at rest for supported hosted components.
- Identity, authentication, role-based access, least-privilege, tenant and resource authorisation controls.
- Audit and security logging, monitoring, alerting, and investigation processes appropriate to the service and selected plan.
- Secure change, patch, dependency, vulnerability, backup, recovery, and incident-management practices appropriate to the deployment.
- Access reviews, confidentiality commitments, secure administration, and controlled production access.
- Periodic testing and review of relevant safeguards, with remediation prioritised by risk.
5. Subprocessors
The Customer gives general written authorisation for the subprocessors on the Subprocessor List. kubbeevault will impose data-protection duties that provide materially equivalent protection for the relevant processing and remains responsible for each subprocessor’s performance to the extent required by applicable law.
kubbeevault will publish or provide notice of a new subprocessor before it begins processing Customer Personal Data, using the advance-notice period stated in the applicable lawyer-reviewed Order Form or DPA. A Customer may make a reasonable written objection based on documented data-protection grounds during that period. The parties will work in good faith on a commercially reasonable solution; if none is available, either party may terminate only the affected Service, subject to the agreement.
6. Data-subject and compliance assistance
Taking into account the nature of processing, kubbeevault will provide reasonable assistance through available product features and support so the Customer can respond to data-subject requests. If kubbeevault receives a request relating to Customer Personal Data, it will direct the requester to the Customer and will not respond substantively unless instructed or legally required.
kubbeevault will provide reasonable information and assistance for the Customer’s security obligations, data-protection impact assessments, prior consultations, and regulator enquiries, taking into account the processing and information available to kubbeevault. Material assistance beyond standard documentation and product functionality may be charged at agreed professional-services rates unless caused by kubbeevault’s breach.
7. Personal data breach
kubbeevault will notify the Customer without undue delay after becoming aware of a confirmed Personal Data Breach affecting Customer Personal Data and, where practicable, within 48 hours. Notification will include information reasonably available about the nature of the breach, likely consequences, affected data and people, measures taken or proposed, and a contact for follow-up. Information may be provided in phases as the investigation progresses.
kubbeevault will take reasonable steps to contain, investigate, mitigate, and remediate the breach and will preserve appropriate records. Notification is not an admission of fault. The Customer is responsible for determining whether and how to notify authorities and data subjects, including the GDPR 72-hour requirement where applicable and the LGPD/ANPD deadline applicable to the controller.
8. International transfers
Processing locations depend on the Order Form, deployment, support, and authorised subprocessors. The Customer authorises transfers necessary to provide the Services subject to an applicable lawful transfer mechanism.
For a restricted transfer of EEA personal data to a recipient not covered by an adequacy decision, the parties incorporate the controller-to-processor or processor-to-processor module, as applicable, of the EU Standard Contractual Clauses adopted by Commission Implementing Decision (EU) 2021/914. The docking clause applies; optional independent dispute resolution does not apply; the supervisory authority and governing-law selections follow the exporter’s establishment where legally permitted; and Annexes I–III are completed by this DPA, the Order Form, Security Policy, and Subprocessor List. The parties will add the UK Addendum or another required local mechanism when applicable.
9. Return, deletion, and retention
On termination and at the Customer’s choice where technically available, kubbeevault will return or permit export of Customer Personal Data and delete remaining copies within the periods in the agreement, unless law requires retention. Data in backups will be isolated from ordinary use and deleted through the applicable backup cycle. kubbeevault may retain minimal records needed for legal compliance, dispute resolution, security, and proof of deletion, subject to continued protection.
10. Information and audits
kubbeevault will make available information reasonably necessary to demonstrate compliance, beginning with current security documentation, independent reports if available, and written responses. No certification or audit report exists unless expressly listed in the Security Policy or Order Form.
If that information is insufficient, the Customer may request one audit per year by an independent qualified auditor, or more after a material breach or regulator request. The audit requires reasonable notice, a confidentiality agreement, minimal operational disruption, no access to another customer’s data, and reimbursement of reasonable costs unless the audit identifies a material kubbeevault breach. Results are kubbeevault confidential information.
11. Order, liability, and termination
This DPA controls over conflicting data-protection terms in the main agreement. The EU Standard Contractual Clauses control for a conflict concerning a restricted transfer. Liability under this DPA is subject to the agreement’s liability framework except where applicable law or the Standard Contractual Clauses prohibit a limitation.
This DPA ends when kubbeevault no longer processes Customer Personal Data, but provisions that protect retained data or allocate continuing duties survive. It may be accepted through the same auditable electronic click-to-accept process as the Customer agreement. The controller and processor roles, applicable governing-law terms, subprocessor notice period, and definitive deletion schedule must be completed in the lawyer-reviewed Customer agreement before acceptance.