Data Processing Agreement
Last updated: September 28, 2026
This Data Processing Agreement (“DPA”) forms part of the agreement between Regentic (“Keepsake”, “we”, “us” or “our”) and the customer using the Keepsake service (“Customer”, “you” or “your”). It applies where we process personal data on your behalf in connection with your use of Keepsake.
For the purposes of UK data protection law, the Customer will generally act as the controller and Keepsake will generally act as the processor. This DPA should be read together with the Keepsake Terms of Service and Privacy Policy.
1. Definitions
In this DPA, “Data Protection Laws” means applicable data protection and privacy laws, including the UK General Data Protection Regulation (“UK GDPR”) and the Data Protection Act 2018.“Personal Data” means personal data processed by Keepsake on behalf of the Customer in connection with the Service. “Processing” has the meaning given under applicable Data Protection Laws.“Sub-processor” means a third party engaged by Keepsake to process Personal Data. “Service” means the Keepsake platform and related services provided by Regentic.2. Roles of the parties
The Customer determines the purposes for which Personal Data is processed through its use of Keepsake. Keepsake processes Personal Data on behalf of the Customer to provide, secure and maintain the Service.Where applicable, the Customer acts as controller and Keepsake acts as processor. Keepsake will process Personal Data only in accordance with the Customer’s documented instructions, including those contained in the Terms of Service and the Customer’s use of the Service. Keepsake may process Personal Data where necessary to comply with applicable law or protect the security and integrity of the Service.3. Subject matter and duration
The subject matter is the provision of the Keepsake Service, including creating and managing handover vaults, storing project information and deliverables, client review and comments, change requests, approvals and sign-offs, certificates, audit records, transactional communications, account and subscription functionality, and securing and maintaining the Service.Processing continues for the duration of the Customer’s use of the Service and any additional period required by law or legitimate security, backup or record-keeping requirements.4. Categories of Personal Data
Depending on use of Keepsake, Personal Data may include:- Names, email addresses, and company or organisation names
- Account information and client contact information
- Project, handover, comment, review, approval and sign-off information
- Digital signature representations, timestamps, audit and security information
- Files or information within uploaded deliverables where they contain Personal Data
- Subscription and billing-related information necessary to administer the account
5. Categories of Data Subjects
- Customer account holders, employees and team members
- Customer clients and client representatives
- Collaborators and other persons identified in project materials
- Persons whose information appears within uploaded deliverables
6. Customer responsibilities
The Customer is responsible for having an appropriate lawful basis, providing required privacy information, ensuring instructions are lawful, ensuring uploaded content is appropriate, configuring access controls, managing client links and passwords responsibly, and responding to Data Subject requests where the Customer is responsible.The Customer must not use Keepsake to process Personal Data in violation of applicable law.7. Keepsake’s processing obligations
- Process Personal Data only as necessary to provide the Service and in accordance with documented instructions
- Ensure authorised persons are subject to appropriate confidentiality obligations
- Implement appropriate technical and organisational security measures
- Reasonably assist with Data Subject rights, security incidents, breaches, DPIAs and regulatory obligations
- Maintain appropriate processing records where required by law
- Make information reasonably necessary to demonstrate compliance available, subject to confidentiality and security restrictions
8. Security measures
Keepsake implements technical and organisational measures designed to protect Personal Data against unauthorised access, accidental loss, destruction, alteration or disclosure.- Encryption in transit and at rest
- Server-side authorisation and database access controls
- Private object storage and controlled access to uploaded files
- Secure authentication, access tokens and short-lived signed URLs where appropriate
- Audit logging, input validation and least-privilege access controls
- Security monitoring, vulnerability management, backup and recovery measures
9. Sub-processors
The Customer authorises Keepsake to use third-party providers that process Personal Data where necessary to provide the Service. Current providers may include:- Supabase — database, authentication and application infrastructure
- Cloudflare — file storage and related infrastructure
- Vercel — application hosting and infrastructure
- Resend — transactional email delivery
- Stripe — subscription billing and payment processing
10. International transfers
Where Personal Data is transferred outside the United Kingdom, Keepsake will use an appropriate lawful transfer mechanism where required, including an adequacy decision, contractual safeguards, or another recognised mechanism.11. Data Subject rights
Taking into account the nature of processing, Keepsake will reasonably assist the Customer with Data Subject requests relating to access, rectification, erasure, restriction, objection, data portability and other applicable rights. Where a Data Subject contacts Keepsake directly regarding Personal Data controlled by the Customer, Keepsake may direct the request to the Customer.12. Personal Data breaches
Keepsake maintains procedures designed to identify, investigate and respond to Personal Data breaches. Where Keepsake becomes aware of a breach affecting Personal Data processed for the Customer, it will notify the Customer without undue delay where required by law and, where reasonably possible, provide information about the incident, affected data, likely consequences and response measures.13. Assistance with regulatory obligations
Taking into account the nature of processing and information available, Keepsake will reasonably assist the Customer with security measures, Personal Data breaches, Data Subject rights, data protection impact assessments and consultations with regulators where required.14. Deletion and return of Personal Data
When the Customer’s use ends, Keepsake will delete or return Personal Data where required by law and subject to the Customer’s instructions. Keepsake may retain limited information to comply with legal obligations, establish or defend legal claims, maintain security records, prevent fraud or abuse, or maintain backups for a limited disaster-recovery period. Backup data remains protected and is deleted under applicable retention procedures.15. Audits and compliance information
Keepsake will make available information reasonably necessary to demonstrate compliance with applicable processor obligations. Any audit must be reasonable, confidential, secure, non-disruptive and take account of available reports or assessments. Reasonable costs for extensive or unusual audit requests may apply where permitted by law and agreed in advance.16. Confidentiality
Keepsake will ensure authorised persons are subject to confidentiality obligations and will not disclose Personal Data except as necessary to provide the Service, authorised by the Customer, required by law, or necessary to protect the security, rights or integrity of the Service.17. Data retention
Keepsake retains Personal Data only as reasonably necessary for this DPA, the Terms of Service and applicable law. Retention may vary with account status, vault status, expiry settings, legal requirements, security and audit requirements, and backup systems.18. Order of precedence
If this DPA conflicts with the Terms of Service regarding processing of Personal Data, this DPA takes precedence to the extent of that conflict.19. Changes to this DPA
Keepsake may update this DPA to reflect changes to the Service, technology, legal requirements or Sub-processors. Material changes will be communicated where required by law or the agreement between the parties.20. Contact
Questions about this DPA or data protection matters can be directed to: