Data processing addendum
This addendum (the “DPA”) describes how Keel processes personal data on your
behalf when you use the service. It is written in plain language and is designed to meet the
requirements of the GDPR, the UK GDPR, and the CCPA/CPRA. It is a starting version; for an
executed or countersigned copy, email [email protected].
Last updated: July 2026.
This DPA supplements the Terms of Service between you (“Customer”) and Keel GRC LLC, headquartered in Buford, Georgia, USA (“Keel”). Terms not defined here have the meaning given in the Terms or in applicable data-protection law.
Roles of the parties
For personal data contained in customer content, the Customer is the controller (or business), and Keel is the processor (or service provider) that processes such data on the Customer’s behalf. Keel acts as an independent controller only for the limited account, billing, and site-analytics data described in our Privacy & Cookies policy.
Scope of this addendum
This DPA applies to Keel’s processing of personal data on the Customer’s behalf. It supplements the Terms. If there is a conflict between this DPA and the Terms specifically regarding the processing of personal data, this DPA governs.
Subject matter, duration, nature & purpose
The subject matter of the processing is the provision of the Keel GRC service. Keel processes personal data for the duration of the Customer’s subscription and for the limited period afterward described under “Return and deletion” below. The nature and purpose of the processing is to host, store, secure, display, and otherwise handle customer content so that the Customer can use the service, and to provide related support.
Categories of data subjects & personal data
Data subjects may include the Customer’s personnel, users, and other individuals whose information the Customer chooses to store in Keel. Personal data may include names, business contact details, account identifiers, and whatever compliance-related information the Customer decides to enter. The Customer controls what personal data it puts into the service and should avoid uploading special-category data unless necessary and lawful.
Keel’s obligations as processor
- Process personal data only on the Customer’s documented instructions, including as set out in the Terms and this DPA, unless required by law (in which case Keel will inform the Customer where permitted).
- Ensure that personnel authorized to process personal data are bound by appropriate confidentiality obligations.
- Implement and maintain appropriate technical and organizational security measures, summarized at our trust center. In particular, each workspace’s data is isolated at the database level using PostgreSQL row-level security (RLS), so one workspace cannot reach another’s data.
- Assist the Customer, taking into account the nature of the processing, in responding to data-subject requests and in carrying out data protection impact assessments and related consultations with supervisory authorities.
Sub-processors
The Customer authorizes Keel to engage the sub-processors listed and kept current at our sub-processors page, which is the maintained source of truth. Keel will give notice of intended changes to its sub-processors so the Customer has an opportunity to object on reasonable data-protection grounds. Keel imposes data-protection obligations on its sub-processors and remains responsible for their performance of the tasks delegated to them.
International transfers
Where the provision of the service involves transferring personal data outside the European Economic Area or the United Kingdom, the parties will rely on an appropriate transfer mechanism, such as the European Commission’s Standard Contractual Clauses together with the UK Addendum or International Data Transfer Agreement (IDTA), or another lawful safeguard, as applicable to the transfer.
Personal-data breaches
Keel will notify the Customer without undue delay after becoming aware of a personal-data
breach affecting the Customer’s personal data, and will provide information reasonably
available to help the Customer meet its own notification obligations. Report suspected
security issues to [email protected].
Data-subject requests
If Keel receives a request from an individual to exercise their rights (such as access, correction, or deletion) regarding customer content, Keel will, where legally permitted, direct the individual to the Customer and assist the Customer in responding, taking into account the nature of the processing.
Audits
Keel will make available to the Customer the information reasonably necessary to demonstrate
compliance with this DPA, primarily through the documentation at
our trust center and its security
overview. Where the Customer reasonably needs further information, it may submit a
written request to [email protected], and the parties will agree on scope and
timing consistent with confidentiality and security.
Return & deletion
On termination or expiry of the subscription, the Customer may export its data during a defined window. After that window, Keel will delete or anonymize the Customer’s personal data within a standard period, such as 30 days, except where retention is required by law. Backup copies are deleted in the ordinary course of Keel’s backup cycle.
CCPA & CPRA terms
Where the CCPA/CPRA applies, Keel acts as a “service provider” and processes personal information only to perform the service and for the business purposes described in the Terms and this DPA. Keel does not sell or share personal information, does not retain, use, or disclose it outside the direct business relationship, and does not combine it with data from other sources except as permitted by law.
Contact & signature
To execute a countersigned DPA, or for any question about how Keel processes personal data,
email [email protected].