Legal · Data Processing Addendum
Data Processing Addendum
This Data Processing Addendum ("DPA") forms part of the Terms of Service between XNOR Group Pte. Ltd. ("Processor", "we") and the customer organisation ("Controller", "you"). It applies where we process personal data on your behalf. It is accepted together with the Terms of Service in the application, and no signature is required for it to take effect.
What makes this DPA unusual
The great majority of the data you place in Keyvaci is encrypted with keys we never hold. For that data we are a custodian of ciphertext: we cannot read it, cannot search it, cannot classify it, and cannot act on a data subject request about its contents. Our processing obligations below are therefore split between the operational data we can read and the ciphertext we cannot. Please read Annex I with that split in mind, because it changes what you can realistically ask us to do.
1. Roles and scope
- You are the Controller of personal data relating to your members. We are your Processor. Where the law of a jurisdiction uses different terms, such as "business" and "service provider" under the CCPA, the equivalent roles apply.
- We process personal data only on your documented instructions. Your use of the service, and the Terms of Service, constitute those instructions. Additional instructions outside them require written agreement and may be chargeable.
- We will inform you if, in our opinion, an instruction infringes applicable data protection law, unless prohibited from doing so.
- We remain an independent controller for our own billing records, our correspondence with you, and the security logs we keep to defend the service. Our Privacy Policy governs that processing.
2. Confidentiality and personnel
We ensure that personnel authorised to process personal data are bound by confidentiality obligations, receive appropriate training, and are granted access on a least-privilege basis. No member of our personnel is able to read vault contents, and this is a property of the system's design rather than an access control that could be varied.
3. Security
We implement the technical and organisational measures set out in Annex II. We may update them as the service evolves, provided the level of protection is not reduced.
4. Sub-processors
- You give general authorisation for the sub-processors listed in Annex III.
- We will give at least 30 days' notice before adding or replacing a sub-processor, by email to your administrators. You may object on reasonable data protection grounds within that period. If we cannot resolve the objection, you may terminate the affected part of the service and receive a refund of fees prepaid for the unused remainder of the term, which is an exception to the no-refund rule in the Terms of Service.
- We impose data protection obligations on each sub-processor no less protective than those in this DPA, and we remain liable to you for their performance.
5. Assistance to the Controller
- Data subject requests. Taking into account the nature of the processing, we will assist you by appropriate technical and organisational measures in responding to requests to exercise data subject rights. For operational data, the application itself provides the means to read, correct and delete. Where you need more, we will help within 10 business days.
- Requests received by us. If a data subject contacts us directly about data we process for you, we will not respond substantively except to confirm that we have referred the request to you, unless legally required to do so.
- Impact assessments. We will provide reasonable assistance with data protection impact assessments and prior consultations, including the information in the Annexes, which is written to be usable directly in such an assessment. For Vietnamese personal data, we will supply what you need for the dossier required by Decree 13/2023/ND-CP.
- Limits. We cannot assist with requests concerning the contents of vault entries, for the reason given at the top of this DPA. You retain the ability to decrypt and act on that content yourself, and you are best placed to do so.
6. Personal data breach
We will notify you without undue delay, and in any event within 48 hours of becoming aware of a personal data breach affecting data we process for you. The notification will describe the nature of the breach, the categories and approximate number of data subjects and records concerned, the likely consequences, the measures taken or proposed, and a contact point. Where the full picture is not yet available, we will provide information in phases rather than delay the first notification.
We will not make public statements identifying you in connection with a breach without your prior written consent, unless legally required.
7. Deletion and return
On termination, you may export your data for 30 days. After that we delete it from live systems and it ages out of backups within a further 35 days as the point-in-time recovery window rolls forward. We will certify deletion on written request. We may retain data where required by law, in which case we continue to protect it and process it only for that purpose.
8. Audit
- We will make available the information necessary to demonstrate compliance with this DPA, including the Annexes, our current security documentation, and the results of any independent assessment we hold.
- You may audit no more than once in any twelve-month period, on 30 days' written notice, at your cost, during business hours, without unreasonably disrupting our operations, and subject to confidentiality. A regulator exercising a statutory power is not subject to these limits. An additional audit may be conducted following a personal data breach affecting your data.
9. International transfers
Where we transfer personal data protected by EU or UK law outside an adequate jurisdiction, the Standard Contractual Clauses (Commission Implementing Decision (EU) 2021/914), Module Two (controller to processor), are incorporated into this DPA by reference and are completed as follows: the data exporter is you, the data importer is us; Clause 7 (docking) applies; under Clause 9, Option 2 general written authorisation applies with the 30-day notice period in section 4; under Clause 11, the optional independent dispute resolution body is not used; under Clause 17, the governing law is that of Ireland; under Clause 18(b), the forum is the courts of Ireland. Annexes I, II and III below serve as the Annexes to the Clauses. For UK transfers, the UK International Data Transfer Addendum applies to the same Clauses.
For transfers out of Singapore, we satisfy the transfer limitation obligation under section 26 of the PDPA by binding recipients contractually to a comparable standard of protection.
10. Liability
Each party's liability under this DPA is subject to the limitations and exclusions in the Terms of Service. Nothing in this DPA limits any right of a data subject under applicable law.
11. Precedence and term
This DPA prevails over the Terms of Service in the event of conflict on matters of personal data. It remains in force for as long as we process personal data for you.
Annex I: Description of processing
A. Parties
Data exporter / Controller: the customer organisation that created the tenant, as
identified by its Microsoft Entra directory and the administrator contact details held in the
application.
Data importer / Processor: XNOR Group Pte. Ltd., Singapore.
Contact: keyvaci@xnorgroup.com.
B. Categories of data subjects
- Employees, contractors and other personnel of the Controller who are members of the tenant.
- Individuals invited to become members but who have not yet joined.
- Any individual whose personal data the Controller chooses to place inside an encrypted vault entry. We have no knowledge of who these individuals are.
C. Categories of personal data
| Visible to us | Not visible to us |
|---|---|
| Directory object identifier; work email address; display name; role and status within the tenant; which vaults a person can access and at what level; audit records of a person's actions in the service, including vault access, revealing entries and use of recovery; billing contact email; IP address and user agent in edge logs; records of terms acceptance. Where email sign-in is used, additionally: the state and time of address confirmation, a session-invalidation counter, the digests of outstanding one-time links, and, where a second factor is enrolled, an encrypted authenticator secret with the digests of unused recovery codes. No sign-in password is received or stored, in any form. | The contents of every vault entry, including any credential, note or personal data placed inside it; the name of every vault; the member's private keys, which we hold only in a form encrypted under their own passphrase and under the organisation's recovery key. |
Special category data. The service is not designed for special category data as defined by GDPR Article 9. Because we cannot read vault contents, we cannot detect or prevent it being placed there. If the Controller chooses to store such data in a vault entry, it does so as controller, on its own legal basis, and the encryption described in Annex II is the relevant safeguard.
D. Nature and purpose
Storage, transmission and access control of encrypted credentials on behalf of the Controller; identity and membership management within the tenant; recording of security-relevant events; provision of the recovery workflow initiated by a member and completed by the Controller's own administrator; billing.
E. Frequency and duration
Continuous for the duration of the subscription, and as set out in section 7 and in the retention table of the Privacy Policy thereafter.
Annex II: Technical and organisational measures
| Area | Measure |
|---|---|
| Encryption of user content | End-to-end encryption. Vault entries are encrypted in the browser with XChaCha20-Poly1305 under a per-vault key; the vault key is delivered to each member sealed to their personal public key. Keys are derived from the member's passphrase with Argon2id. No key capable of decrypting content is ever transmitted to or stored by us |
| Authenticity | Each entry carries an author signature and each grant of access carries a signature binding the recipient, the role, the key version and the wrapped key. Recipients verify these before use and fail closed |
| Encryption in transit and at rest | TLS 1.2 or above enforced at the edge with HSTS. Data at rest encrypted with a customer-managed key held in AWS KMS, separate per environment, with automatic rotation enabled |
| Tenant isolation | Tenant identity is taken only from the verified authentication token, never from a request parameter. A single module constructs every database partition key, enforced by an automated lint rule, and a cross-tenant test matrix blocks deployment on failure |
| Access control | Authentication either delegated to the Controller's Microsoft Entra directory, or performed by us by sending a single-use link to a confirmed email address, stored only as a SHA-256 digest and valid for five minutes. No sign-in password is received or stored. Session tokens are signed with Ed25519, the private half readable only by the sign-in component, and expire absolutely twelve hours after the original authentication. Enrolling or removing a second factor ends every existing session. A second factor is available as a time-based one-time code, its secret encrypted under the environment key rather than stored in the clear, with each code period accepted at most once; an organisation may require one before a credential is revealed. Role checks on every administrative route. Members receive vault access only after an administrator has countersigned their identity keys |
| Auditability | Append-only audit trail enforced by infrastructure permissions rather than application code, so no application defect can alter history. Security-relevant events written synchronously before the response is returned |
| Application hardening | Content security policy forbidding inline script and permitting third-party script from one named origin only, Cloudflare Turnstile on the contact form; no third-party analytics or advertising code; strict schema validation on every request body; generic error responses that do not disclose internal detail |
| Abuse resistance | Web application firewall with managed rule sets and per-IP rate limiting at the edge; origin cloaking so the API cannot be reached bypassing the firewall; per-user rate limits on revealing entries and on retrieving encrypted vault contents |
| Client-side key hygiene | Decryption keys held in memory only, erased on sign-out, after 15 minutes of inactivity, and 5 minutes after the browser tab is hidden |
| Resilience | Managed multi-availability-zone database with point-in-time recovery over a 35-day window; infrastructure defined as code and reproducible |
| Governance | Least-privilege roles with no wildcard permissions; secrets held in a managed secret store and read at runtime rather than embedded in configuration; independent security review of the design and of the implementation, with findings tracked to closure |
Annex III: Approved sub-processors
| Sub-processor | Purpose | Processing location |
|---|---|---|
| Amazon Web Services, Inc. | Hosting, database, key management, content delivery, logging, and outbound email through Amazon SES where the Controller's organisation uses email sign-in or invitations | Singapore (primary). Edge delivery, certificate and firewall services operate from AWS facilities in the United States and from globally distributed edge locations |
| Stripe, Inc. and Stripe Payments Europe, Ltd. | Payment processing, invoicing, subscription management | United States, Ireland |
| Cloudflare, Inc. | Bot protection on the marketing site's contact form only, through Cloudflare Turnstile. It receives the visitor's IP address and a challenge token; it never receives vault content, and it is not present anywhere in the application | United States, and globally distributed edge locations |
Microsoft is not listed as a sub-processor because authentication takes place in the Controller's own Microsoft Entra directory under the Controller's own agreement with Microsoft. We receive the resulting token; we do not engage Microsoft to process data on our behalf.