Data Processing Agreement
Last updated: September 26, 2026 · Version 2026-09-26
On this page
This Data Processing Agreement ("DPA") forms part of the Terms of Service between Keyleads and the customer that owns a workspace ("you"). It applies automatically when you accept the Terms; you do not need to sign anything. If you need a countersigned copy, email hello@keyleads.app.
Punnawich Vanadilok, trading as Keyleads
43/196 Soi Mu Ban Pho Kaew Soi 1, Thailand
Email: hello@keyleads.app
1. Scope and roles
Workspace data. For personal data you and your team put into a workspace (members' names and emails, notes, statuses, replies you write, notification settings), you are the controller and Keyleads is your processor.
Indexed public posts. Keyleads is an independent controller for the indexed public-post dataset: the public posts we collect, their authors' handles and the AI scores we attach. We decide what to collect and how long to keep it, and we answer authors' requests directly under our notice for post authors. Once you copy, export or act on a post outside Keyleads, you are an independent controller of what you do with it.
Keyleads is also an independent controller of account, billing and security data, as described in our Privacy Policy.
2. Instructions
We process workspace data only on your documented instructions, which are the Terms, this DPA and your use and configuration of Keyleads, unless the law requires otherwise; in that case we will tell you first unless the law forbids it. We will tell you if we think an instruction breaks data protection law.
3. Confidentiality
Everyone at Keyleads who can access workspace data is bound by confidentiality.
4. Security
We apply the technical and organisational measures in Annex II and keep them appropriate to the risk.
5. Subprocessors
You authorise the subprocessors on our Subprocessors page. We give at least 30 days' notice of a new subprocessor by updating that page and emailing owners who asked for notice. You may object on reasonable data protection grounds within those 30 days; if we cannot address the objection, you may terminate the affected service and we will refund prepaid fees for the unused period. We impose data protection terms on each subprocessor that are at least as protective as this DPA and remain responsible for them.
6. Assistance with requests
Taking into account the nature of the processing, we help you respond to requests from people exercising their data protection rights, mostly through self-serve tools (export and deletion in Settings), and with security, breach notification, data protection impact assessments and prior consultation where required. If a person contacts us directly about workspace data, we will pass the request to you.
7. Personal data breaches
We will notify you of a personal data breach affecting workspace data without undue delay and in any case within 48 hours of confirming it, with the information we have and updates as we learn more.
8. Deletion and return
You can export workspace data and delete the workspace at any time in Settings. When a workspace is deleted, we delete its workspace data from our live systems straight away and from backups within their normal rotation, except where the law requires us to keep it (for example invoices).
9. Information and audits
We will make available the information reasonably needed to show compliance with this DPA, including answers to security questionnaires. If that is not enough, you may audit us, at your cost, no more than once a year, with 30 days' notice, during business hours, and under confidentiality.
10. International transfers
Keyleads is established in Thailand. For transfers of personal data from the EU/EEA, the Standard Contractual Clauses adopted by Commission Implementing Decision (EU) 2021/914 are incorporated by reference: Module 2 (controller to processor) where you are a controller, and Module 3 (processor to processor) where you are a processor. Clause 7 (docking) applies, clause 9 option 2 (general authorisation) applies with the notice period in section 5, clause 11 optional language does not apply, and clauses 17 and 18 select the law and courts of Ireland. For transfers from the UK, the UK International Data Transfer Addendum is incorporated by reference. Annexes I and II below complete the clauses.
11. Liability and precedence
Each party's liability under this DPA is subject to the limitation of liability in the Terms, to the extent the law allows. If this DPA conflicts with the Terms, this DPA controls for the processing of personal data; if it conflicts with the Standard Contractual Clauses, the clauses control.
Annex I: Details of processing
| Item | Details |
|---|---|
| Parties | Data exporter: the customer. Data importer: Keyleads (contact above). |
| Data subjects | The customer's workspace members and invitees. |
| Categories of data | Names, email addresses, roles, notes, lead statuses and replies written in Keyleads, notification settings (Telegram chat ID, push endpoint, quiet hours), activity events. |
| Sensitive data | None intended. |
| Nature and purpose | Hosting, storage, AI-assisted scoring and suggestions, alerts, collaboration and support for the customer's use of Keyleads. |
| Frequency | Continuous while the workspace exists. |
| Duration and retention | For the life of the workspace. Leads are kept for the plan's retention period (Free 7 days, Starter 90 days, Pro 365 days). |
| Competent supervisory authority | As determined by clause 13 of the Standard Contractual Clauses. |
Annex II: Security measures
- Encryption in transit (TLS) for all traffic; encryption at rest by our database and hosting providers.
- Workspace isolation enforced in the database with row-level security on every workspace table.
- Plan limits, roles and seats checked on the server for every action.
- Service credentials held in environment configuration, never in code; least-privilege access to production.
- Sign-in by email link or Google; no passwords stored for customers.
- Automatic deletion of data at the end of each retention period.
- Backups by our database provider; logging and alerting on collector and job failures.
- Personal data minimised in analytics (no email addresses, post content or reply text) and in AI prompts.