Privacy notice

How kubbeevault handles personal data

This notice explains the personal data processed through the kubbeevault website and services, why it is used, the providers involved, and the rights available to individuals.

1. Who we are

kubbeevault is a secure secrets and credentials management platform. KUBBEE TECH LIMITED, CRO number 811108, with its registered office at 2nd Floor, 57 Mary Street, Dublin 1, D01 C6X5, Ireland, is the operator and contracting company for customers in Europe. KUBBEEVAULT INOVA SIMPLES (I.S.), CNPJ 63.450.016/0001-16, with its address at Av. Direitos Humanos 1201, 114/4, Imirim, São Paulo - SP, 02475-000, Brazil, is the operator and contracting company for customers in Brazil and all other locations outside Europe, as well as the platform company.

For website enquiries, demonstrations, sales, subscriptions, and commercial relationships involving customers in Europe, KUBBEE TECH LIMITED acts as the relevant data controller. For customers in Brazil and all other locations outside Europe, KUBBEEVAULT INOVA SIMPLES (I.S.) acts as the relevant data controller. For platform and customer-service processing, the responsible entity and its role as controller or processor depend on the applicable customer agreement and processing activity.

The platform supports the secure storage, management, access, auditing, and protection of credentials, secrets, keys, and related organisational data.

2. Personal data we collect

The personal data collected depends on how an individual interacts with kubbeevault. We apply data-minimisation principles and ask people not to submit passwords, API keys, tokens, or other secrets through website forms.

  • Account and profile information, such as name, business email address, authentication identifiers, and account preferences.
  • Organisation and service information, such as company, team, workspace, role, permission, subscription, and support details.
  • Sales and demonstration enquiry information, including name, work email, company, company size, country, expected users, use case, current credential-management process, and any optional message.
  • Security and technical information, such as IP address, device and browser information, authentication events, audit records, and indicators of suspicious or abusive activity.
  • Customer-provided service data where kubbeevault processes information on behalf of a business customer under the customer agreement and applicable Data Processing Agreement.

3. Why we process personal data

kubbeevault does not use customer secrets for advertising and does not automatically add website-form contacts to marketing lists.

  • Creating and managing user accounts and authenticating users.
  • Operating kubbeevault services and managing organisations, workspaces, users, permissions, subscriptions, and support.
  • Providing security controls, audit logging, monitoring, and fraud or abuse prevention.
  • Responding to contact, sales, demonstration, support, and service enquiries.
  • Managing contractual and commercial relationships with customers.
  • Maintaining and improving platform security, reliability, performance, and availability.
  • Meeting applicable legal, regulatory, accounting, contractual, and security obligations.

5. Sharing personal data

kubbeevault does not sell personal data. Access is limited to authorised personnel and service providers where necessary to operate, secure, and support the service.

Website enquiry data is delivered through EmailJS and the configured email provider. Google reCAPTCHA processes technical and interaction data to help prevent automated abuse. Other providers may support cloud infrastructure, authentication, monitoring, security, billing, and customer operations.

Service providers are expected to process personal data only for the relevant service and under appropriate contractual and security requirements. Where kubbeevault acts as a processor for a business customer, customer data is processed according to that customer’s instructions and the applicable Data Processing Agreement.

6. Data retention

Personal data is kept only for as long as necessary for the purpose for which it was collected. The applicable period is determined by the duration of the customer or user relationship, the status of an enquiry, contractual requirements, security and audit needs, legal and regulatory obligations, and the need to establish, exercise, or defend legal claims.

Account and service information may be retained while an account is active and for an appropriate period after termination. Security and audit records are retained for periods defined by security, contractual, and compliance requirements. Information that is no longer required is securely deleted or anonymised under kubbeevault retention procedures.

7. Individual data-protection rights

Subject to applicable law and its conditions, individuals may request access, rectification, erasure, restriction, data portability, or withdrawal of consent, and may object to certain processing based on legitimate interests.

We may need to verify the requester’s identity before completing a request. Individuals may also lodge a complaint with the supervisory authority responsible for their location. In Ireland, this is the Data Protection Commission.

8. Data Protection Officer

If KUBBEE TECH LIMITED or KUBBEEVAULT INOVA SIMPLES (I.S.) is required to appoint a Data Protection Officer, the DPO’s contact information will be published here. Unless and until a separate DPO contact is published, privacy and data-protection enquiries for both entities are handled through the privacy contact identified in this notice.

9. Legitimate interests

We consider the potential impact on individuals before relying on legitimate interests as a lawful basis.

  • Protecting kubbeevault infrastructure and customers from security threats.
  • Preventing fraud, abuse, unauthorised access, and malicious activity.
  • Monitoring service availability, security, and reliability.
  • Maintaining appropriate audit and security records.
  • Improving platform performance and operational reliability.
  • Protecting the legal and commercial interests of KUBBEE TECH LIMITED, KUBBEEVAULT INOVA SIMPLES (I.S.), and their customers.

10. International data transfers

Some technology providers supporting kubbeevault may process information outside the country where an individual or customer is located, including outside the European Economic Area.

Where GDPR-protected personal data is transferred outside the European Economic Area, an appropriate transfer mechanism is used where required, such as an adequacy decision or Standard Contractual Clauses, together with additional safeguards where appropriate. Information about applicable safeguards can be requested through the privacy contact.

12. Mandatory information

Certain information may be required to create an account, provide contracted services, meet security requirements, process payments, or comply with legal obligations. Required website-form fields are needed so the team can understand and respond to the request. Where information is mandatory, the requirement and relevant consequences of not providing it will be explained.

13. Automated decision-making

kubbeevault does not currently use personal data to make solely automated decisions that produce legal or similarly significant effects on individuals.

Security systems, including reCAPTCHA on website forms, may automatically detect suspicious behaviour, authentication anomalies, or potential threats. These mechanisms protect the platform and its users and are not intended to make legal or similarly significant decisions. If Article 22 GDPR decision-making is introduced, affected individuals will receive the information and safeguards required by law.

14. Updates to this notice

This notice may be updated when services, processing activities, technology, providers, or legal obligations change. Where a change materially affects how personal data is processed, appropriate notice will be provided to affected individuals.