Data Processing Addendum
- Version: 2026-07-15
- Effective with Terms release: 2026-07-15
LAUNCH BLOCKER: replace every bracketed Operator identity field in the Legal Notice before this Addendum is used.
This Data Processing Addendum (DPA) forms part of the Terms of Service between the Account holder or organisation using Kepeink (Customer) and [FULL LEGAL NAME] e.v. (Operator) when the Operator processes personal data on the Customer's behalf. It may apply to a consumer who is a controller, but does not apply where the Customer's processing is outside the GDPR under the personal or household exemption. Capitalised terms not defined here have the meaning in the Terms. If this DPA conflicts with the Terms about processing Customer Personal Data, this DPA prevails.
1. Scope and roles
Customer Personal Data means personal data contained in Customer Content that the Operator processes as processor to provide the Service. The Customer is controller or a processor authorised by another controller. The Operator is processor or subprocessor, respectively.
This DPA does not govern data for which the Operator is an independent controller, including Account authentication, contract evidence, the Operator's billing reconciliation, network security, abuse handling, legal compliance, and legal claims. That processing is described in the Privacy Notice.
Processing begins when Customer Personal Data enters the Service and continues until deletion under this DPA. The nature is receiving, transmitting, routing, transiently buffering, securing, troubleshooting, backing up where applicable, and deleting data for authenticated reverse connectivity.
2. Processing details
| Item | Description |
|---|---|
| Subject matter | Reverse routing between a public Tunnel endpoint and the Customer-controlled Agent/origin; related support and security operations |
| Duration | The Service term plus deletion and backup-expiry periods in §10 |
| Purpose | Provide, secure, maintain and support the Service on documented Customer instructions |
| Data subjects | Customer personnel and users; visitors, users, employees, contractors, customers or other persons whose data the Customer makes accessible through a Tunnel |
| Data types | Network identifiers, request/response data, application content, account identifiers, communications, files, database responses, and any other data selected by the Customer |
| Sensitive data | Not intended. The Customer must not deliberately route special-category, criminal-offence, payment-card, health, biometric, child, or similarly high-risk data without first completing a documented risk assessment and obtaining the Operator's written approval |
| Frequency | Continuous or intermittent, as initiated by the Customer and its users |
3. Customer instructions and duties
The Terms, Workspace/Tunnel configuration, documented API calls, and written support instructions are the Customer's documented instructions. The Operator will process Customer Personal Data only on those instructions, including for transfers, unless EU or Member-State law requires other processing. If legally permitted, the Operator will notify the Customer before legally required processing.
Where data-protection law applies to the Customer, the Customer is responsible for ensuring that its instructions comply with that law, that it has the necessary lawful bases, notices, permissions, and controller-to-processor authority, and that its configuration implements proportionate data minimisation, authentication, encryption, retention, and data-subject controls. The Customer decides whether the Service is appropriate for the data and risk. This allocation does not remove mandatory consumer rights or impose professional compliance duties on a purely household activity outside GDPR scope.
If the Operator reasonably believes an instruction infringes the GDPR or other applicable data-protection law, it will inform the Customer and may suspend the affected processing while the parties resolve it. The Operator does not provide legal advice to the Customer.
4. Confidentiality and personnel
The Operator ensures that persons authorised to process Customer Personal Data are bound by confidentiality and access it only as needed for assigned duties. Initially, privileged human access is limited to the founder. Access must be individually attributable, use multi-factor authentication, follow least privilege, and be logged. The confidentiality duty continues after access or engagement ends.
5. Security
The Operator will maintain measures appropriate to the risk under GDPR Article 32, taking account of the beta Service, state of the art, implementation cost, and processing context. Current measures include:
- TLS for service connections and passthrough encryption where selected;
- high-entropy session, API, and Agent credentials, with server-side hash storage for bearer secrets;
- encryption of designated recoverable secrets and encrypted backups;
- tenant/workspace scoping, role checks, and least-privilege service identities;
- separated management and router functions, firewalling, authenticated configuration, and controlled operator access;
- signed Agent release manifests, dependency/build controls, patching and credential rotation procedures;
- rate limits, abuse controls, monitoring, alerting, audit events, and incident-response procedures;
- backup, restore, continuity, and emergency-revocation procedures tested on a risk-based schedule; and
- deletion, pseudonymisation, and bounded operational-log retention.
The Operator may improve or replace a measure without notice if overall protection is not materially reduced. No security measure makes an internet service risk-free. Customer remains responsible for endpoint security, application access control, data-level encryption, backups, and an alternative access path.
6. Subprocessors
The Customer gives general written authorisation for the subprocessors listed in the Privacy Notice and the Operator's dated subprocessor register. The Operator will contractually require each subprocessor to protect Customer Personal Data to the extent required by GDPR Article 28 and remains responsible for its subprocessor obligations under that Article.
The Operator will provide at least 15 days' prior notice of a new subprocessor where reasonably practicable. The Customer may object during that period on specific, documented data-protection grounds. The parties will try to find a reasonable alternative. If none is reasonably available, either party may terminate only the affected Service; any refund follows the Terms and merchant-of-record process. Emergency security replacement may occur sooner with notice as soon as practicable.
7. International transfers
The Operator intends to process core Service data in the EEA. A subprocessor may process elsewhere only with a valid GDPR Chapter V mechanism. The Operator will verify the mechanism applicable to the contracted entity and processing, perform or obtain an appropriate transfer assessment, and apply supplementary measures where required.
If the Operator itself makes a restricted controller-to-processor transfer not otherwise covered by adequacy, the parties will complete the applicable module of the European Commission's 2021 Standard Contractual Clauses and required annexes. This DPA does not falsely represent that every recipient is certified under an adequacy framework.
8. Assistance
Taking account of the processing and information available to it, the Operator will reasonably assist the Customer with:
- data-subject requests under GDPR Chapter III;
- security of processing and personal-data-breach duties;
- data-protection impact assessments and prior consultation; and
- information needed to demonstrate the Customer's compliance with Article 28.
The Customer should first use self-service export, deletion, logs, and configuration controls. If a data subject contacts the Operator about Customer Personal Data, the Operator will ordinarily refer the request to the Customer and not respond substantively unless instructed or legally required. Assistance outside standard product functionality may be charged at a reasonable disclosed rate where law permits.
9. Personal-data breaches
After becoming aware of a confirmed personal-data breach affecting Customer Personal Data, the Operator will notify the Customer without undue delay at the Account's security contact and provide information available to it about nature, likely consequences, affected categories/approximate numbers, mitigation, and contact. Information may be supplied in phases. Notification is not an admission of fault or liability.
The Operator will contain, investigate, document, and remediate the incident and preserve relevant evidence. The Customer decides whether it must notify a supervisory authority or data subjects unless law assigns that duty to the Operator for its independent-controller processing.
10. Return and deletion
During the term the Customer can retrieve its configuration and data exposed by product export functions. On valid Account/Workspace deletion or termination, the Operator will stop serving affected Tunnels, revoke credentials, and delete or anonymise Customer Personal Data according to the Privacy Notice, normally after a 30-day operational grace period.
Encrypted rolling backups may retain a residual copy for up to 90 days. Backups are isolated from ordinary use, restored only for disaster recovery, and any deletion due is re-applied after restoration. The Operator may retain a restricted record where EU or Member-State law requires it or where necessary for legal claims; it will not use that record for another purpose.
11. Audits
On reasonable written request no more than once per year, the Operator will provide information reasonably necessary to demonstrate Article 28 compliance, such as current policies, architecture/security summaries, subprocessor information, and relevant independent reports when available.
If that information is insufficient and the Customer has a specific credible concern, the Customer may request a proportionate remote audit by an independent qualified auditor bound by confidentiality. On-site access requires a legal or supervisory-authority requirement or a material unresolved risk, at least 30 days' notice where possible, no access to another tenant's data or security secrets, and coordination to avoid disruption. The requesting Customer bears reasonable costs unless the audit finds a material breach by the Operator.
12. Government requests
The Operator will review demands for Customer Personal Data, verify authority and scope, challenge unlawful or disproportionate demands where reasonable, disclose only what is legally required, and notify the Customer unless prohibited. Nothing requires the Operator to violate law or compromise another person.
13. Liability, term, and law
The Terms' liability exclusions, cap, indemnity, governing law, and dispute provisions apply to this DPA as part of one agreement, to the extent permitted by data-protection law. This DPA terminates when the Operator no longer processes Customer Personal Data, except provisions that must survive for confidentiality, deletion, audit, liability, or law.
Privacy and DPA questions: support@kepeink.hu.