Privacy Policy
Last updated: July 24, 2026
1. Who we are
Kevra (“Kevra”, “we”, “us”) provides a managed hosting platform for open-source software, including our Identity (Keycloak), Security (Prowler), and Infrastructure (Terrakube) products. This policy applies to kevra.io, our customer dashboard at app.kevra.io, and the managed instances we operate for customers. Kevra is the controller for the personal data described in this policy. You can reach us at contact@kevra.io.
2. When we are a controller and when we are a processor
Kevra plays two different roles, and it matters which one applies:
- Controller. For data about our customers, the individuals who administer their accounts, our website visitors, and billing, we decide why and how the data is processed. This policy governs that processing.
- Processor. For the content you and your end users place inside the services we host for you, you are the controller and Kevra is a processor. We process that data only on your documented instructions, under our Terms of Use and Data Processing Agreement, not this policy.
If you are an end user whose data sits inside an instance we host (for example, an employee of a Kevra customer), that organization, not Kevra, is responsible for it. Please direct access or deletion requests to them; we will support them in responding.
3. Data we collect
Account and profile data
When you create an account we collect your work email address and a password, which we store only as a hash. You can optionally provide an organization name, and if you sign in through a single sign-on provider we receive the identifiers and basic profile details that provider returns. You can add details such as your name later. Administrators may invite team members, which means we hold their basic account details too.
Billing data
Subscriptions are billed through our payment processor, Stripe. We store your plan, billing contact, invoices, and the last four digits and card type. We do not store full card numbers; Stripe handles card data as a PCI-DSS compliant processor.
Usage, device, and log data
When you use the website or dashboard we automatically collect IP address, browser and device type, pages and features used, referring URLs, timestamps, and diagnostic logs. Our hosted instances also generate operational logs, such as sign-in and administration events, provisioning and directory sync jobs, security scan runs, and infrastructure plan and apply runs. We retain these to run, secure, and support the service.
Data inside the instances we host for you
The instances we operate hold whatever data customers and their users place or generate there. Because these are standard applications such as Keycloak, they record data about end users, including names, email addresses, and the IP addresses captured at sign-in. Depending on the products you use, the data can also include user directories, group memberships, credentials, sign-in records, cloud account metadata, security findings, infrastructure configuration, variables, and Terraform state. We hold this data as a processor, on the customer’s instructions (see section 2).
Connected cloud provider accounts
If you connect a cloud provider account, such as AWS or Azure, to our products, we store the access you grant (for example, roles or credentials) and the configuration metadata, findings, and run history generated from it. We use that access only to provide the service as you configure it.
Support and communications
If you contact us for support, sales, or via a form, we keep your messages and the contact details you provide so we can respond and keep a record.
4. How we use data
- Provide the service. Create and authenticate accounts, provision and operate your instances, apply patches, upgrades, and backups, and deliver the features you subscribe to.
- Billing. Process subscriptions, invoices, and taxes, and prevent payment fraud.
- Support and communication. Respond to requests and send service and security notices you cannot opt out of (for example, downtime, breaches, or material changes).
- Security and integrity. Monitor for abuse, detect and investigate incidents, enforce our terms, and keep the platform available.
- Improve the service. Understand how features are used and diagnose problems, using aggregated or minimized data where we can.
- Legal and compliance. Meet legal obligations and respond to lawful requests.
- Marketing. Send product updates or offers where you have consented or where we have a legitimate interest; every marketing message includes an unsubscribe link.
5. Legal bases (GDPR / UK GDPR)
Where the GDPR or UK GDPR applies, we rely on:
- Performance of a contract. To provide the service you signed up for and to bill for it.
- Legitimate interests. To secure and improve the platform, prevent fraud and abuse, and carry out limited business communications, balanced against your rights.
- Consent. For non-essential cookies and certain marketing, which you can withdraw at any time.
- Legal obligation. To keep accounting records and respond to lawful requests.
6. Cookies & analytics
We use a small number of cookies and third-party scripts:
- Strictly necessary. Session, authentication, and security cookies required for the site and dashboard to work.
- Analytics and advertising. Analytics tags help us measure traffic and the performance of our own campaigns.
- Bot protection. An automated check protects our sign-up and contact forms from abuse.
- Third-party content. Some pages load fonts and open-source JavaScript libraries from public content delivery networks; those providers receive your IP address and browser details when your browser fetches the files.
You can accept or decline non-essential cookies in the banner we show on your first visit, change your choice at any time through the Cookie settings link in the footer, or use your browser settings. Blocking strictly necessary cookies may break parts of the service.
7. Sharing & sub-processors
We do not sell personal data and we do not share it for others’ independent marketing. We share it only with the service providers that help us run the service (cloud hosting, payment processing, analytics, bot protection, email delivery, error monitoring, and support tooling), and with professional advisers and authorities where required by law, to establish, exercise, or defend legal claims, or in connection with a merger, acquisition, or sale of assets.
Each provider processes data under a contract that limits use to the services it provides to us. A current list of sub-processors is available on request at contact@kevra.io.
8. International transfers
We and our providers may process data in countries other than your own. Where we transfer personal data out of the European Economic Area, the United Kingdom, or Switzerland, we rely on an adequacy decision or on Standard Contractual Clauses (and the UK Addendum where relevant), together with additional safeguards where needed. Where feasible, we host customer instances in the region you select.
9. Data retention
We keep personal data only as long as we need it for the purposes above. Account data is kept for the life of your subscription and for a limited period afterward to meet legal, accounting, and dispute-resolution needs. Operational logs are kept for a rolling window, typically 90 days, unless specific records are needed longer for security or support. Billing records are kept as long as tax and accounting law requires. When data is no longer needed we delete or anonymize it.
10. Security
We protect personal data with appropriate technical and organizational measures, including encryption in transit and at rest, access controls, and separation between customer environments. No system is perfectly secure, and we cannot guarantee absolute security. If we become aware of a breach affecting personal data we control, we will notify affected parties and the competent authority where and when the law requires. For personal data inside your instances we act as a processor and will inform you without undue delay so you can meet your own obligations as controller.
11. Your rights
Depending on where you live, you may have the right to access, correct, delete, or receive a portable copy of your personal data, to object to or restrict certain processing, and to withdraw consent. To exercise these rights for data we control, email contact@kevra.io; we will respond within the time the law allows and may need to verify your identity.
If you are in the EEA, the UK, or Switzerland, you may also lodge a complaint with your local data protection authority. If you are a California resident, you may exercise the rights available under the CCPA/CPRA, including the right to know and to delete. We do not sell personal information; to the extent any advertising measurement is considered “sharing” under California law, you can opt out through the Cookie settings link in the footer or by emailing contact@kevra.io.
12. Children
Kevra is a business product and is not directed to children. We do not knowingly collect personal data from anyone under 16. If you believe a child has provided us data, contact us and we will delete it.
13. Changes to this policy
We may update this policy at any time. We will post the updated version here with a revised “Last updated” date and, for material changes, give notice through the dashboard or by email before they take effect. Continued use of the service after the effective date means the updated policy applies.
14. Contact
Questions about this policy or our data practices? Email contact@kevra.io.