Skip to main content

    Data Processing Agreement

    Last updated: September 2026 (rev. 7)

    1. Parties and Scope

    This Data Processing Agreement ("DPA") is entered into between:

    • Controller: The Enterprise customer identified in the Order Form ("Customer").
    • Processor: Keypra OÜ, Sepapaja tn 6, 15551 Tallinn, Harju maakond, Estonia. Registry code: 17502390. ("Keypra").

    This DPA forms part of the Enterprise Agreement and governs Keypra's processing of Customer Personal Data in accordance with GDPR (Regulation EU 2016/679) and the Estonian Personal Data Protection Act.

    2. Definitions

    • "Customer Personal Data" — any personal data processed by Keypra on behalf of the Customer in the course of providing the Service, including employee names, email addresses, usage data, and AI prompt content.
    • "Processing" — has the meaning given in Art. 4(2) GDPR.
    • "Data Subject" — the individuals (typically Customer's employees or learners) whose personal data is processed.
    • "Sub-processor" — any third party engaged by Keypra to process Customer Personal Data.

    3. Subject Matter and Nature of Processing

    Keypra processes Customer Personal Data solely for the purpose of providing the Keypra AI prompt engineering training platform, including:

    • User authentication and account management
    • AI prompt analysis, coaching, and curriculum delivery
    • Organisation administration (member management, usage analytics)
    • Billing and subscription management

    Duration: For the term of the Agreement, plus any post-termination retention period specified in Section 8.

    Categories of data subjects: Customer's employees, contractors, and learners.

    Types of personal data: Name, work email, job title, usage metrics, AI prompt and response content (where entered by users).

    Email channel ("Keypra by Email"). Authorised Users may use the Services by writing to ask@in.keypra.com and receiving AI-generated replies. Where they do, Keypra additionally processes: the sender's work e-mail address (stored as a SHA-256 hash together with the domain in clear text), display name, subject line, message body, attachments, and the addresses of colleagues placed in CC. Customer acknowledges that inbound e-mail is a channel Keypra does not control end-to-end and that an Authorised User may therefore transmit Customer Personal Data that Customer did not intend to disclose, including data about third parties. Retention for this channel is fixed and short: inbound message bodies 7 days; archived copies of Keypra's replies 30 days; email projects (prompt text, revisions, scores) 30 days from last activity; thread and participant metadata for the life of the thread; message metadata 24 months. Keypra refuses generic role addresses (info@, hr@, legal@, support@ and similar) as senders and as invited participants. Where Customer operates in §203 StGB professional-secrecy mode, the email channel is outside the assured scope and is disabled — see /legal/berufsgeheimnis.

    3a. Customer Instructions Concerning the Email Channel

    By accepting this DPA, the Customer instructs Keypra to accept and process e-mail sent by the Customer's Authorised Users to ask@in.keypra.com, and to reply to it, on the terms described in Section 3.

    Customer remains controller. The Customer remains the controller for whatever its Authorised Users choose to write, attach, or forward through that channel, and for the addresses of any colleague they place in CC. Keypra has no means of pre-screening inbound content.

    Customer undertakings. The Customer shall (i) inform its Authorised Users that the email channel must not be used for special categories of personal data (Art. 9 GDPR), legally privileged material, or professional-secrecy material; (ii) ensure that Authorised Users have a lawful basis before inviting a colleague or a third party into a thread; and (iii) notify Keypra without undue delay at privacy@keypra.com if data was sent through the channel in error, so that Keypra can delete it ahead of the scheduled retention window.

    Disabling the channel. On written request to enterprise@keypra.com, Keypra will disable the email channel for all addresses on the Customer's verified domains. It is disabled by default where §203 StGB mode is active.

    4. Keypra's Obligations

    Keypra shall:

    1. Process Customer Personal Data only on documented instructions from the Customer (the Agreement and this DPA constitute such instructions).
    2. Ensure that personnel authorised to process Customer Personal Data are bound by confidentiality obligations.
    3. Implement appropriate technical and organisational measures (TOMs) as described in Section 5.
    4. Not engage sub-processors without the Customer's general authorisation (granted by accepting this DPA) and the measures in Section 6.
    5. Assist the Customer in fulfilling Data Subject rights requests (Art. 15–22 GDPR) within 30 days.
    6. Notify the Customer within 72 hours of becoming aware of a personal data breach affecting Customer Personal Data.
    7. Delete or return all Customer Personal Data upon termination of the Agreement, as specified in Section 8.

    4a. No AI Model Training on Customer Personal Data

    Keypra shall not, and shall procure that its sub-processors shall not, use Customer Personal Data — including prompts, AI responses, uploaded files, Behavioural Telemetry, classroom submissions, or any derivative thereof — to train, fine-tune, evaluate, validate, or otherwise improve any AI or machine-learning model, whether Keypra's own model or a third-party model.

    Sub-processor commitments. Keypra contracts with its AI sub-processors (currently Google for Gemini and OpenAI for GPT) on enterprise/API terms under which customer API content is not used to train the provider's foundation models by default. The current posture of each AI sub-processor is published at /legal/sub-processors §4b. Keypra reviews these commitments at least annually and promptly when a provider announces a material change, and will notify Customer under Section 6 (sub-processor change notice) if a sub-processor's training posture changes in a way that affects Customer Personal Data.

    Aggregated, anonymised statistics. Keypra may compute irreversibly aggregated and anonymised usage statistics (counts, percentages, error rates) that do not constitute personal data within the meaning of Recital 26 GDPR. Such statistics never include prompt or response content and never enable re-identification of an Authorised User or of Customer.

    Audit. On request, Keypra will furnish Customer with a written attestation describing (i) which AI sub-processors are in use for Customer's tenant, (ii) each provider's then-current training-data commitment, and (iii) the date of Keypra's most recent review.

    5. Technical and Organisational Measures (TOMs)

    MeasureImplementation
    Encryption at restAll Customer Personal Data is encrypted at rest using AES-256, managed by Keypra's infrastructure provider (Lovable Cloud / Supabase). Application-level Customer-Managed Key (CMK) encryption is available on request for regulated-industry customers under a separate Order Form. Contact enterprise@keypra.com.
    Encryption in transitTLS 1.3 for all connections
    Encryption of org API keysAES-256-GCM authenticated encryption. Master key stored in Supabase Edge Function secrets (isolated execution environment). Key never persisted to database. All key operations logged in immutable audit trail. FIPS 140-2 validated environments available on request.
    Access controlsRole-based (org_admin, manager, member); Row Level Security on all tables
    AuthenticationMulti-factor capable; OAuth SSO (Google Workspace) live; SAML 2.0 / OIDC available under separate Order Form
    Audit loggingAll material actions logged with user_id, timestamp, action type; retained per Section 8
    Data residencyPrimary database: EU Frankfurt region (Lovable Cloud / Supabase)
    Security certificationsLovable Cloud holds SOC 2 Type II and ISO 27001 (available on request)
    Vulnerability managementContinuous automated scanning; annual penetration testing via Lovable platform
    Email engagement processingTransactional emails sent via Resend (sub-processor) include open tracking (1×1 pixel) and click tracking (links rewritten through track.keypra.com). Engagement events stored in email_engagement_events for deliverability monitoring and feature-discovery analytics. Recipient email is hashed (SHA-256) for aggregation; raw email retained for admin-readable diagnostics only. Legal basis: legitimate interest (Art. 6(1)(f) GDPR); recipients may unsubscribe via the footer in every email. Tiered retention (Art. 5(1)(c)+(e) GDPR — data minimisation & storage limitation): (a) 0–90 days: full detail retained for live deliverability triage and per-recipient support; (b) 90 days – 13 months: rows pseudonymised — raw email, IP, user-agent, and full payload are nulled; only the SHA-256 hash, template, event type, link host, day, and country are kept; (c) over 13 months: rows are deleted from email_engagement_events after counts are folded into anonymous daily totals in email_engagement_daily (template × event × country × day). Users with active Marketing consent (user_consents.consent_type='marketing', not revoked, not expired) are exempt from step (b) for the duration of their consent. The schedule runs nightly at 03:30 UTC (apply_email_engagement_retention()), is auditable in email_engagement_retention_runs, and is triggered immediately when the matching account is deleted (BEFORE DELETE trigger on auth.users).
    Email channel integrityInbound mail is accepted only from the receiving sub-processor over a signed webhook whose signature is verified before any content is parsed. Generic role addresses are refused as senders and as invited participants. Per-sender rate limits and loop protection apply. Stored inbound bodies and archived replies are reachable only by the service role — no client role holds SELECT on those tables — and are hard-deleted by scheduled purge at the end of their fixed retention window. A colleague placed in CC receives their own consent request and is not enrolled until they confirm.
    Email channel transportE-mail reaching Keypra is protected by TLS where the sending mail server supports it; Keypra cannot guarantee end-to-end encryption of inbound mail. Customer is advised to instruct its Authorised Users not to send special-category, privileged, or professional-secrecy material through the email channel.

    5a. Data Isolation

    Customer Personal Data is logically isolated at the row level using PostgreSQL Row Level Security (RLS) enforced by Keypra's infrastructure provider (Lovable Cloud / Supabase). All multi-tenant tables carry an org_id or equivalent tenancy column, and access is restricted via SECURITY DEFINER functions that prevent cross-tenant reads or writes.

    Keypra does not offer physical database separation or dedicated database instances by default. Dedicated infrastructure arrangements (single-tenant database, isolated compute, dedicated EU region) are available under a separate Order Form. Contact enterprise@keypra.com.

    6. Sub-processors

    The Customer grants general authorisation to Keypra to engage sub-processors. The current list is published at /legal/sub-processors. Key sub-processors for Enterprise customers:

    Sub-processorServicesLocationLegal Basis
    Lovable Cloud (Supabase)Database, auth, storage, functionsEU (Frankfurt)DPA; EU hosting
    Google (Gemini)AI model processingEU/USEU-US DPF
    OpenAI (GPT)AI model processingUSSCCs
    StripePayment processingEU/USDPF + SCCs
    ResendTransactional emailUSSCCs
    Zoho MailInbound and internal emailEU (Netherlands)EU hosting
    Xolo OÜAccounting & invoicing (Estonian Accounting Act §12, 7-year retention)Estonia (EU)EU hosting

    Keypra will provide 30 days' written notice before engaging a new sub-processor that processes Customer Personal Data. The Customer may object within this period on reasonable grounds relating to data protection.

    Note on buyer billing data: Buyer billing details (legal company name, VAT/Tax ID, registered address, billing contact) supplied at checkout are processed exclusively by Stripe and, for Estonian statutory bookkeeping, by Xolo OÜ. Keypra does not mirror these fields in its own systems.

    7. International Data Transfers

    Where Customer Personal Data is transferred outside the EEA, such transfers are made pursuant to:

    • The EU-US Data Privacy Framework (DPF) where the sub-processor is a verified DPF participant (Google, Stripe); or
    • Standard Contractual Clauses (SCCs) — Commission Decision (EU) 2021/914 — for other transfers (OpenAI, Resend).

    The primary database and application infrastructure remain within the EU (Frankfurt). AI model processing involves EEA-to-US transfers as described above.

    8. Retention and Deletion

    Data TypeRetention Period
    Email channel — inbound message body7 days
    Email channel — archived copy of Keypra's reply30 days
    Email projects — prompt text, revisions, scores30 days from last activity
    Email channel — thread and participant recordsLife of the thread
    Email channel — message metadata24 months
    Active account dataDuration of Agreement
    Backups90-day rolling deletion
    Audit logs3 years (security and compliance; individual identifiers may be pseudonymised upon erasure request)
    Post-termination30-day grace period for data export; permanent deletion within 60 days of termination
    Payment records7 years (Stripe; financial regulatory requirement)

    Right to erasure (Art. 17 GDPR): Where a Data Subject exercises the right to erasure, Keypra will delete identifiable personal data within 30 days. Audit log entries referencing the Data Subject's user_id will be pseudonymised (replacing the user_id with an anonymised reference) rather than deleted, where deletion would conflict with legitimate security and compliance obligations under Art. 17(3)(b) and (e) GDPR. Keypra will inform the Customer of such cases.

    8e. Anonymisation and Pseudonymisation

    Keypra may produce anonymous statistical information from Customer Personal Data only where, assessed against all means reasonably likely to be used by Keypra or by any third party (having regard to cost, available technology and the time required), no data subject and no Customer can be identified, whether directly or indirectly, and where no key, mapping or other means permitting reversal is retained. Results are reported only at a level of aggregation at which no data subject can be singled out.

    Keypra shall not, and shall procure that its sub-processors shall not, attempt to re-identify such information or combine it with other datasets for that purpose.

    Pseudonymisation — including the replacement of identifiers in audit and security records following an erasure request under Section 8 — is a security measure within the meaning of Art. 32 GDPR and does not render the data anonymous. Such data remains Customer Personal Data under this DPA and is deleted at the end of the applicable retention period.

    Where a derived dataset does not meet the standard in this Section, Keypra treats it as Customer Personal Data and applies the retention and deletion terms of Section 8.

    8a. Data Minimisation Mode (Optional)

    Enterprise customers may request activation of Data Minimisation Mode under their Order Form. When activated, Keypra:

    • Disables persistence of AI prompt content and AI response bodies in the organisation's logs (token-count metadata is still retained for billing and abuse-prevention purposes).
    • Configures automatic deletion of user-generated content (drafts, prompts, workflow inputs, uploaded context files) after a Customer-configured retention period, with a minimum of 7 days.

    Activation is performed by Keypra's operations team and confirmed in writing. Contact enterprise@keypra.com to scope and activate this mode.

    8c. Cloud Switching Assistance (EU Data Act, B2B)

    This Section reflects Keypra's obligations toward Enterprise Customers under Regulation (EU) 2023/2854 (the EU Data Act), Articles 25 to 30, in force since 12 September 2025.

    Right to switch. The Customer may terminate this Agreement and switch to another data processing service or to an on-premises infrastructure at any time, subject to the standard notice period in the Order Form.

    Maximum transition window. Keypra will support a 30-day transition window from the Customer's notice of switching, during which the Service remains available for migration purposes, plus an extended assistance period of up to 6 months on request to help the Customer re-establish functional equivalence with the destination service.

    Switching charges. Keypra applies €0 switching charges and voluntarily applies the post-12-January-2027 zero-charge regime of Article 29 today. Standard usage fees for the Service during the transition window remain payable under the Order Form.

    No obstacles. Keypra will not impose technical, contractual or commercial obstacles that inhibit the Customer from terminating the Agreement, switching provider, or porting Customer Personal Data. Self-serve export tools, documented APIs and open export formats (JSON for structured data, plain Markdown for documents) are provided to that end.

    Assistance SLA. Keypra will acknowledge a switching request within 72 hours, agree on the migration plan within 7 business days, and execute the transition within the 30-day window. Extended-assistance support is delivered as commercially reasonable best-efforts during the 6-month extended period.

    Contact. Enterprise switching requests should be addressed to enterprise@keypra.com with subject tag [SWITCH].

    8d. Legal Hold

    Where Customer Personal Data is subject to a binding legal preservation order — including a court order, regulatory inquiry, ongoing dispute, or law-enforcement preservation request addressed to Keypra — that data is excluded from the deletion timelines in Section 8, the dormancy / inactivity-deletion routine in Privacy Policy §17, and any other automated cleanup routine, until the hold is released.

    Notification. Where lawful, Keypra will notify the Customer (and, for personal accounts, the Data Subject) that a Legal Hold has been placed and identify the affected records to the extent permitted by the order.

    Resumption. Normal deletion timelines resume within 30 days of the hold being released, and Keypra will confirm completion in writing on request.

    Implementation. Legal Hold is enforced technically via the profiles.legal_hold_until column on Keypra's user profile records and is honoured by the inactivity-cleanup and account-deletion routines.

    8b. Behavioural Telemetry — Purpose Limitation and EU AI Act

    Where Customer's Authorised Users have opted in to the Behavioural Telemetry consent category, Keypra processes typing-cadence statistics (pause counts, deletion ratios, session duration, "thinking ratio", "revision ratio") for the sole purpose of providing the member-private "Crafting Fluency" view in the user's own workspace. The full methodology is published at /compliance/behavioural-telemetry-methodology.

    Processor commitments. Keypra does not, and will not, expose to the Customer (acting as Controller) any per-person Behavioural Telemetry value, any per-person Crafting Fluency metric, any per-person ALI score, any per-person mastery status or tier label, or any equivalent classification of an Authorised User. No API, export route, edge function, RPC or report exposes such per-person data to the Customer. Aggregate outputs available to the Customer are k-anonymised at k≥3.

    Controller commitments. The Customer warrants that it shall not use the Service, or any data derived from it, as the basis for hiring, promotion, performance evaluation, disciplinary action, termination, or any other employment-related decision affecting any natural person, and that it shall not represent Behavioural Telemetry as an emotion-recognition or affect-inference system. This obligation mirrors the Prohibited Employment-Decision Use clause of the Terms of Service and binds the Customer in its capacity as Controller and as a deployer under Regulation (EU) 2024/1689 (the EU AI Act).

    EU AI Act allocation. Keypra is the provider of an AI literacy training tool. The Customer remains the deployer of its own internal AI literacy programme under Article 4 of the EU AI Act. Nothing in this Agreement transfers Keypra's provider obligations to the Customer or the Customer's deployer obligations to Keypra. The classification analysis under Articles 5 and 6 and Annex III of the EU AI Act is set out in Keypra's public note at /docs/compliance/eu-ai-act.

    Competence scoring transparency. The pass threshold, rubric weighting and contestability mechanism applied to AI-graded competence assessments are disclosed at /compliance/competence-methodology.

    9. Audit Rights

    The Customer may, once per calendar year and with 30 days' written notice, request a summary audit report covering Keypra's technical and organisational security measures relevant to the processing of Customer Personal Data. Keypra will provide:

    • Its current SOC 2 Type II report (subject to confidentiality agreement)
    • Answers to a reasonable written security questionnaire

    On-site audits require mutual agreement and will be conducted at the Customer's cost.

    9a. Personal Data Breach Notification (Art. 33 GDPR)

    Keypra (as Processor) shall notify the Customer (as Controller) of any personal-data breach affecting Customer Personal Data without undue delay after becoming aware of it, and in any event in time to allow the Customer to meet its own Art. 33 GDPR notification deadlines. The notification will include the nature of the breach, the categories and approximate number of data subjects affected, the likely consequences, the measures taken or proposed, and a designated contact for further information.

    Keypra maintains an internal breach register in line with Art. 33(5) GDPR and will provide reasonable assistance to the Customer in carrying out the Controller's notification obligations to supervisory authorities and to data subjects under Arts. 33 and 34 GDPR.

    Security-incident reports may be submitted to security@keypra.com with subject tag [SECURITY-INCIDENT]; acknowledgement is sent within 24 hours.

    10. Contact and Governing Law

    Privacy inquiries: privacy@keypra.com

    Enterprise DPA inquiries: enterprise@keypra.com

    This DPA is governed by the laws of the Republic of Estonia. For EU-based Customers, the supervisory authority is the Estonian Data Protection Inspectorate (Andmekaitse Inspektsioon).

    Entity: Keypra OÜ, Sepapaja tn 6, 15551 Tallinn, Harju maakond, Estonia. Registry code: 17502390. Court of registry: Tartu Maakohus, registriosakond.

    Email: enterprise@keypra.com
    Address: Keypra OÜ, Sepapaja tn 6, 15551 Tallinn, Harju maakond, Estonia