Kevra
Documentation Login Sign Up

Privacy Policy

Last updated: July 24, 2026

1. Who we are

Kevra (“Kevra”, “we”, “us”) provides a managed hosting platform for open-source software, including our Identity (Keycloak), Security (Prowler), and Infrastructure (Terrakube) products. This policy applies to kevra.io, our customer dashboard at app.kevra.io, and the managed instances we operate for customers. Kevra is the controller for the personal data described in this policy. You can reach us at contact@kevra.io.

2. When we are a controller and when we are a processor

Kevra plays two different roles, and it matters which one applies:

If you are an end user whose data sits inside an instance we host (for example, an employee of a Kevra customer), that organization, not Kevra, is responsible for it. Please direct access or deletion requests to them; we will support them in responding.

3. Data we collect

Account and profile data

When you create an account we collect your work email address and a password, which we store only as a hash. You can optionally provide an organization name, and if you sign in through a single sign-on provider we receive the identifiers and basic profile details that provider returns. You can add details such as your name later. Administrators may invite team members, which means we hold their basic account details too.

Billing data

Subscriptions are billed through our payment processor, Stripe. We store your plan, billing contact, invoices, and the last four digits and card type. We do not store full card numbers; Stripe handles card data as a PCI-DSS compliant processor.

Usage, device, and log data

When you use the website or dashboard we automatically collect IP address, browser and device type, pages and features used, referring URLs, timestamps, and diagnostic logs. Our hosted instances also generate operational logs, such as sign-in and administration events, provisioning and directory sync jobs, security scan runs, and infrastructure plan and apply runs. We retain these to run, secure, and support the service.

Data inside the instances we host for you

The instances we operate hold whatever data customers and their users place or generate there. Because these are standard applications such as Keycloak, they record data about end users, including names, email addresses, and the IP addresses captured at sign-in. Depending on the products you use, the data can also include user directories, group memberships, credentials, sign-in records, cloud account metadata, security findings, infrastructure configuration, variables, and Terraform state. We hold this data as a processor, on the customer’s instructions (see section 2).

Connected cloud provider accounts

If you connect a cloud provider account, such as AWS or Azure, to our products, we store the access you grant (for example, roles or credentials) and the configuration metadata, findings, and run history generated from it. We use that access only to provide the service as you configure it.

Support and communications

If you contact us for support, sales, or via a form, we keep your messages and the contact details you provide so we can respond and keep a record.

4. How we use data

5. Legal bases (GDPR / UK GDPR)

Where the GDPR or UK GDPR applies, we rely on:

6. Cookies & analytics

We use a small number of cookies and third-party scripts:

You can accept or decline non-essential cookies in the banner we show on your first visit, change your choice at any time through the Cookie settings link in the footer, or use your browser settings. Blocking strictly necessary cookies may break parts of the service.

7. Sharing & sub-processors

We do not sell personal data and we do not share it for others’ independent marketing. We share it only with the service providers that help us run the service (cloud hosting, payment processing, analytics, bot protection, email delivery, error monitoring, and support tooling), and with professional advisers and authorities where required by law, to establish, exercise, or defend legal claims, or in connection with a merger, acquisition, or sale of assets.

Each provider processes data under a contract that limits use to the services it provides to us. A current list of sub-processors is available on request at contact@kevra.io.

8. International transfers

We and our providers may process data in countries other than your own. Where we transfer personal data out of the European Economic Area, the United Kingdom, or Switzerland, we rely on an adequacy decision or on Standard Contractual Clauses (and the UK Addendum where relevant), together with additional safeguards where needed. Where feasible, we host customer instances in the region you select.

9. Data retention

We keep personal data only as long as we need it for the purposes above. Account data is kept for the life of your subscription and for a limited period afterward to meet legal, accounting, and dispute-resolution needs. Operational logs are kept for a rolling window, typically 90 days, unless specific records are needed longer for security or support. Billing records are kept as long as tax and accounting law requires. When data is no longer needed we delete or anonymize it.

10. Security

We protect personal data with appropriate technical and organizational measures, including encryption in transit and at rest, access controls, and separation between customer environments. No system is perfectly secure, and we cannot guarantee absolute security. If we become aware of a breach affecting personal data we control, we will notify affected parties and the competent authority where and when the law requires. For personal data inside your instances we act as a processor and will inform you without undue delay so you can meet your own obligations as controller.

11. Your rights

Depending on where you live, you may have the right to access, correct, delete, or receive a portable copy of your personal data, to object to or restrict certain processing, and to withdraw consent. To exercise these rights for data we control, email contact@kevra.io; we will respond within the time the law allows and may need to verify your identity.

If you are in the EEA, the UK, or Switzerland, you may also lodge a complaint with your local data protection authority. If you are a California resident, you may exercise the rights available under the CCPA/CPRA, including the right to know and to delete. We do not sell personal information; to the extent any advertising measurement is considered “sharing” under California law, you can opt out through the Cookie settings link in the footer or by emailing contact@kevra.io.

12. Children

Kevra is a business product and is not directed to children. We do not knowingly collect personal data from anyone under 16. If you believe a child has provided us data, contact us and we will delete it.

13. Changes to this policy

We may update this policy at any time. We will post the updated version here with a revised “Last updated” date and, for material changes, give notice through the dashboard or by email before they take effect. Continued use of the service after the effective date means the updated policy applies.

14. Contact

Questions about this policy or our data practices? Email contact@kevra.io.