Data Processing Agreement
This DPA forms part of the Terms of Service between the customer ("you", the Controller) and Fergus Richards trading as Kept ("Kept", the Processor), contactable at [email protected]. It applies wherever Kept processes personal data on your behalf under UK GDPR or EU GDPR.
Last updated: 9 September 2026 (v4)
1. What is processed
| Subject matter | Monitoring whether your automated workflows ran |
| Duration | While you have an account, plus retention periods below |
| Nature and purpose | Storing client and promise names, ping timestamps and statuses, short scrubbed messages, and alert history, in order to detect late, missing or failed runs and alert you |
| Types of personal data | Names or identifiers you choose to enter (e.g. a sole-trader client name, a person named in a task title); anything that survives scrubbing in an error message. No payload data is accepted |
| Data subjects | Your clients, staff or contacts, to the extent you name them |
| Retention | Pings 90 days; alerts 180 days; names while the account exists; all deleted on account deletion |
2. Your obligations
You confirm you have a lawful basis for any personal data you send, that you will minimise it (describe the task, not the person, unless needed), and that you are responsible for what appears on any public status page you enable. Alerts are delivered to channels you configure and control; once delivered, their content is held in those tools under your own retention settings, and enabling "Include error details in alerts" is your instruction to send that additional content there.
3. Our obligations
Kept will:
- process personal data only to provide the Service and on your documented instructions (these terms and your use of the app), unless the law requires otherwise, in which case we'll tell you if permitted;
- ensure staff and contractors with access are bound by confidentiality;
- apply the security measures in Section 5;
- assist you, so far as reasonable, with data-subject requests and with your security, breach-notification and impact-assessment obligations;
- notify you without undue delay, and within 48 hours of becoming aware, of any personal data breach affecting your data, with what we know and what we're doing;
- delete or return your personal data when the Service ends, at your choice, and delete remaining copies within 30 days unless the law requires retention;
- make available the information needed to show compliance, and allow audits at reasonable notice no more than once a year (a written questionnaire first; on-site only if that is insufficient), at your cost.
4. Sub-processors
You authorise the sub-processors listed in the Privacy Policy. We'll give at least 14 days' notice by email before adding one; if you object on reasonable data-protection grounds and we can't resolve it, you may terminate. We remain responsible for our sub-processors.
5. Security measures
Encryption in transit and at rest; API keys stored as hashes only; automatic scrubbing of emails, phone numbers and tokens from names, descriptions and messages; 2 KB ping size limit; role-based access and two-factor authentication on infrastructure accounts; automated retention and deletion; rate limiting; logging; backups with point-in-time recovery; hosting in the EU.
6. International transfers
Where a sub-processor processes data outside the UK/EU, transfers are covered by the UK International Data Transfer Addendum or EU Standard Contractual Clauses, as applicable.
7. Liability
Liability under this DPA is subject to the limits in the Terms of Service.
8. Precedence
If this DPA conflicts with the Terms, this DPA prevails for data-protection matters.
Accepted electronically at sign-up. A signed copy is available on request from [email protected].