Data Processing Agreement
Last updated: July 24, 2026
1. Scope and roles
This Data Processing Agreement (the “DPA”) forms part of the Terms of Use between Kevra and the Customer and applies where Kevra processes personal data contained in Customer Data on the Customer’s behalf. For that data the Customer is the controller (or a processor acting for another controller) and Kevra is the processor. Capitalized terms not defined here have the meaning given in the Terms; “personal data”, “processing”, “controller”, “processor”, and “personal data breach” have the meanings given in the GDPR.
2. Details of processing
| Subject matter | Hosting and management of software instances as described in the Terms. |
| Duration | The subscription term plus the export window described in the Terms. |
| Nature and purpose | Storage, transmission, backup, display, and related technical operations needed to provide, secure, and support the service. |
| Data subjects | End Users and other individuals whose personal data the Customer or its End Users submit to the service. |
| Categories of data | Identification and contact details, credentials, group and role memberships, sign-in and usage records, cloud account metadata, security findings, infrastructure configuration and state, and any other personal data the Customer chooses to submit. |
The service is not intended for special categories of personal data. Do not submit them without our prior written agreement.
3. Instructions
We process personal data in Customer Data only on the Customer’s documented instructions, which are the Terms, this DPA, and the configuration choices you make in the service, unless processing is required by law, in which case we will inform you unless the law prevents it. We will inform you if, in our view, an instruction infringes data protection law; we are not obliged to monitor your instructions for compliance. You are responsible for ensuring that your instructions comply with data protection law.
4. Confidentiality and personnel
We ensure that the people we authorize to process personal data are bound by confidentiality obligations and access it only as needed to provide the service.
5. Security
We implement appropriate technical and organizational measures for the risk, including encryption in transit and at rest, access controls, separation between customer environments, backups, and the update and patching practices described in the Terms. We may update these measures over time, provided the overall level of protection is not materially reduced.
6. Sub-processors
You authorize us to use sub-processors to provide the service, such as our hosting and email providers. We impose data protection obligations on sub-processors consistent with this DPA and remain responsible for their performance. A current list is available on request at contact@kevra.io. We will give notice through the dashboard or by email before adding or replacing a sub-processor that processes personal data in Customer Data. If, within 30 days of the notice, you raise a data protection objection that we cannot reasonably resolve, you may cancel the affected service before the change applies to your Instances, and we will refund any prepaid fees for the unused part of the term of that service. This is your sole and exclusive remedy for a sub-processor change.
7. Assistance
Taking into account the nature of the processing, we assist you in meeting your obligations to respond to data subject requests and, where relevant, with security, breach notification, data protection impact assessments, and prior consultations with supervisory authorities. The administration and export tools built into the service are the primary means of assistance. If a data subject contacts us directly about data in your instances, we will redirect them to you. We may charge a reasonable fee for assistance that goes materially beyond the tools of the service.
8. Personal data breach
If we become aware of a personal data breach affecting personal data in Customer Data, we will notify you without undue delay and provide the information reasonably available to us to support your own notification obligations. Notifying supervisory authorities and data subjects for that data is your responsibility as controller. A notification by us is not an admission of fault.
9. International transfers
Where processing involves a transfer of personal data out of the European Economic Area, the United Kingdom, or Switzerland, you authorize the transfer and we rely on an adequacy decision or on Standard Contractual Clauses (and the UK Addendum where relevant), together with additional safeguards where needed.
10. Audits and information
On request, we make available the information reasonably necessary to demonstrate compliance with this DPA, including summaries of third-party audit reports or certifications where available. Where the law grants you an audit right that this information does not satisfy, an audit may take place at most once in any 12-month period, on at least 30 days’ notice, during business hours, without access to other customers’ data, and at your cost. The audit must not unreasonably disrupt our operations, any third-party auditor must be bound by confidentiality and must not be a competitor of Kevra, and the results are our confidential information under the Terms.
11. Return and deletion
During the subscription and for the export window described in the Terms, you can export your Customer Data in the standard formats of the hosted software. After that window we delete personal data in Customer Data from active systems and let residual copies expire from backups on our normal backup cycle, unless the law requires us to keep it.
12. Liability and precedence
This DPA is subject to the limitations of liability in the Terms. If this DPA conflicts with the Terms, this DPA prevails for the subject matter of data protection.
13. Changes
We may update this DPA at any time as the service or the law changes, following the change process in the Terms. The version posted on this page is the current version.
14. Contact
Questions about this DPA? Email contact@kevra.io.