Privacy notice
How kubbeevault handles personal data
This notice explains the personal data processed through the kubbeevault website and services, why it is used, the providers involved, and the rights available to individuals.
1. Who we are
kubbeevault is a secure secrets and credentials management platform. KUBBEE TECH LIMITED, CRO number 811108, with its registered office at 2nd Floor, 57 Mary Street, Dublin 1, D01 C6X5, Ireland, is the operator and contracting company for customers in Europe. KUBBEEVAULT INOVA SIMPLES (I.S.), CNPJ 63.450.016/0001-16, with its address at Av. Direitos Humanos 1201, 114/4, Imirim, São Paulo - SP, 02475-000, Brazil, is the operator and contracting company for customers in Brazil and all other locations outside Europe, as well as the platform company.
For website enquiries, demonstrations, sales, subscriptions, and commercial relationships involving customers in Europe, KUBBEE TECH LIMITED acts as the relevant data controller. For customers in Brazil and all other locations outside Europe, KUBBEEVAULT INOVA SIMPLES (I.S.) acts as the relevant data controller. For platform and customer-service processing, the responsible entity and its role as controller or processor depend on the applicable customer agreement and processing activity.
The platform supports the secure storage, management, access, auditing, and protection of credentials, secrets, keys, and related organisational data.
2. Personal data we collect
The personal data collected depends on how an individual interacts with kubbeevault. We apply data-minimisation principles and ask people not to submit passwords, API keys, tokens, or other secrets through website forms.
- Account and profile information, such as name, business email address, authentication identifiers, and account preferences.
- Organisation and service information, such as company, team, workspace, role, permission, subscription, and support details.
- Sales and demonstration enquiry information, including name, work email, company, company size, country, expected users, use case, current credential-management process, and any optional message.
- Security and technical information, such as IP address, device and browser information, authentication events, audit records, and indicators of suspicious or abusive activity.
- Customer-provided service data where kubbeevault processes information on behalf of a business customer under the customer agreement and applicable Data Processing Agreement.
3. Why we process personal data
kubbeevault does not use customer secrets for advertising and does not automatically add website-form contacts to marketing lists.
- Creating and managing user accounts and authenticating users.
- Operating kubbeevault services and managing organisations, workspaces, users, permissions, subscriptions, and support.
- Providing security controls, audit logging, monitoring, and fraud or abuse prevention.
- Responding to contact, sales, demonstration, support, and service enquiries.
- Managing contractual and commercial relationships with customers.
- Maintaining and improving platform security, reliability, performance, and availability.
- Meeting applicable legal, regulatory, accounting, contractual, and security obligations.
4. Legal bases for processing
- Performance of a contract: where processing is required to provide services, administer accounts, manage subscriptions, authenticate users, or provide customer support.
- Legitimate interests: where processing is necessary to operate and secure the platform, respond to business enquiries, prevent fraud and abuse, protect systems and customers, and improve reliability. We assess these interests against the rights and freedoms of affected individuals.
- Legal obligation: where processing is required by applicable law, regulation, tax or accounting rules, or a lawful request from a competent authority.
- Consent: where consent is the appropriate basis for an optional communication or activity. Consent can be withdrawn at any time without affecting earlier lawful processing.
6. Data retention
Personal data is kept only for as long as necessary for the purpose for which it was collected. The applicable period is determined by the duration of the customer or user relationship, the status of an enquiry, contractual requirements, security and audit needs, legal and regulatory obligations, and the need to establish, exercise, or defend legal claims.
Account and service information may be retained while an account is active and for an appropriate period after termination. Security and audit records are retained for periods defined by security, contractual, and compliance requirements. Information that is no longer required is securely deleted or anonymised under kubbeevault retention procedures.
7. Individual data-protection rights
Subject to applicable law and its conditions, individuals may request access, rectification, erasure, restriction, data portability, or withdrawal of consent, and may object to certain processing based on legitimate interests.
We may need to verify the requester’s identity before completing a request. Individuals may also lodge a complaint with the supervisory authority responsible for their location. In Ireland, this is the Data Protection Commission.
8. Data Protection Officer
If KUBBEE TECH LIMITED or KUBBEEVAULT INOVA SIMPLES (I.S.) is required to appoint a Data Protection Officer, the DPO’s contact information will be published here. Unless and until a separate DPO contact is published, privacy and data-protection enquiries for both entities are handled through the privacy contact identified in this notice.
9. Legitimate interests
We consider the potential impact on individuals before relying on legitimate interests as a lawful basis.
- Protecting kubbeevault infrastructure and customers from security threats.
- Preventing fraud, abuse, unauthorised access, and malicious activity.
- Monitoring service availability, security, and reliability.
- Maintaining appropriate audit and security records.
- Improving platform performance and operational reliability.
- Protecting the legal and commercial interests of KUBBEE TECH LIMITED, KUBBEEVAULT INOVA SIMPLES (I.S.), and their customers.
10. International data transfers
Some technology providers supporting kubbeevault may process information outside the country where an individual or customer is located, including outside the European Economic Area.
Where GDPR-protected personal data is transferred outside the European Economic Area, an appropriate transfer mechanism is used where required, such as an adequacy decision or Standard Contractual Clauses, together with additional safeguards where appropriate. Information about applicable safeguards can be requested through the privacy contact.
11. Withdrawal of consent
Where processing relies on consent, consent can be withdrawn at any time through the relevant account preference, unsubscribe mechanism, or by contacting the privacy address below. Withdrawal does not affect processing that was lawful before consent was withdrawn.
12. Mandatory information
Certain information may be required to create an account, provide contracted services, meet security requirements, process payments, or comply with legal obligations. Required website-form fields are needed so the team can understand and respond to the request. Where information is mandatory, the requirement and relevant consequences of not providing it will be explained.
13. Automated decision-making
kubbeevault does not currently use personal data to make solely automated decisions that produce legal or similarly significant effects on individuals.
Security systems, including reCAPTCHA on website forms, may automatically detect suspicious behaviour, authentication anomalies, or potential threats. These mechanisms protect the platform and its users and are not intended to make legal or similarly significant decisions. If Article 22 GDPR decision-making is introduced, affected individuals will receive the information and safeguards required by law.
14. Updates to this notice
This notice may be updated when services, processing activities, technology, providers, or legal obligations change. Where a change materially affects how personal data is processed, appropriate notice will be provided to affected individuals.