This Data Processing Agreement (DPA) forms part of the agreement between Brenkon Holdings Limited (trading as Keeval) and each client and sets out how Keeval processes personal data on the client's behalf under UK GDPR Article 28. Where Keeval handles personal data contained in your compliance records, site data, certificates and contacts, you are the controller and Keeval is the processor.
Roles and scope
The client is the data controller; Brenkon Holdings Limited (trading as Keeval) is the data processor. Keeval processes personal data only to provide the managed compliance and facilities service, and only on the client’s documented instructions (including those given through the portal), unless required otherwise by law.
Subject matter and details of processing (Art. 28(3))
Subject matter & duration: processing for the term of the client agreement and any period required to meet legal record-keeping obligations afterwards.
Nature & purpose: tracking statutory obligations, coordinating accredited engineers, collecting and storing certificates and evidence, reporting, and account administration.
Types of personal data: names, work contact details, and any personal data contained in site records, certificates, supplier documents and correspondence the client provides or generates in the service.
Categories of data subjects: the client’s staff and authorised contacts, and individuals named in compliance documents (e.g. responsible persons, engineers).
Keeval’s obligations as processor
Process personal data only on the client’s documented instructions; ensure personnel are bound by confidentiality; implement appropriate technical and organisational security measures (see below).
Assist the client, taking account of the nature of processing, with responding to data-subject rights requests and with the client’s own security, breach-notification and impact-assessment obligations.
Make available the information needed to demonstrate compliance with Article 28 and allow for and contribute to reasonable audits.
On termination, delete or return all personal data at the client’s choice, save where retention is required by law.
Security measures
Encryption of data in transit (TLS); access controls and least-privilege access for staff; tenant separation so a client’s data is not exposed to other clients; managed, access-controlled hosting and database services; and logging. Measures are reviewed as the service evolves.
Sub-processors
Keeval uses the following sub-processors to deliver the service. The client authorises their use; Keeval remains responsible for their compliance and will give notice of any intended changes so the client may object.
Clerk — authentication and user/identity management (US).
Stripe — subscription billing and payment processing (US/EU).
Resend — transactional and notification email delivery (US).
Vercel — application hosting and content delivery (US/global).
Neon — PostgreSQL database hosting (data hosted in the UK/EU region).
International transfers
Some sub-processors are based outside the UK (notably the US). Where personal data is transferred outside the UK, Keeval relies on an appropriate safeguard — the UK International Data Transfer Agreement or the EU Standard Contractual Clauses with the UK Addendum, and/or adequacy where it applies.
Personal data breaches
Keeval will notify the client without undue delay after becoming aware of a personal data breach affecting the client’s data, with the information the client reasonably needs to meet its own notification obligations.
Contact
Questions about this DPA or to request a signed copy: hello@keeval.co.uk.