Procurement schedule
Data Processing Addendum
Version 1.3 · 16 August 2026
These are the processor terms offered by Kinane Labs Ltd, operator of SetupPasskeys, for Customer Personal Data an organisation directs the service to publish or otherwise process in an ordered hosted branded guide, including optional connected Microsoft Entra personalisation, or separately to place in a legacy Passkey Rollout Kit. This template is structured around the processor topics in Article 28 GDPR; viewing it is not a certification of compliance or legal advice.
How to execute this Addendum
- Email privacy@setuppasskeys.com with the customer’s legal name, registered or service address, quote or order reference, signatory name/title, the service in scope, and whether the customer acts as controller or processor.
- Kinane Labs Ltd will return a durable PDF identifying both legal parties and any agreed changes. Procurement may request the current provider regions and transfer documents at the same time.
- The Addendum takes effect on the later signature date, or on the order date if an order expressly incorporates a completed version accepted by both parties.
Do not submit personal data that requires an executed DPA until this process is complete. A customer-specific addendum may be considered, but no amendment is effective unless accepted in writing by both parties.
1. Parties, roles and scope
“Customer” means the legal person identified in the executed cover sheet or order. “Supplier” means Kinane Labs Ltd, operator of SetupPasskeys. “Customer Personal Data” means personal data processed by Supplier on Customer’s behalf in providing the ordered hosted-guide or legacy-kit service.
Customer is controller, or a processor authorised by its controller. Supplier is processor or subprocessor for Customer Personal Data. Supplier is a separate controller for its own order administration, payment reconciliation, fraud prevention, legal compliance, enquiries and business communications; those activities are governed by the Privacy notice, not this Addendum.
This Addendum forms part of the applicable order and Terms of service and sale. If there is a conflict about processing Customer Personal Data, this Addendum prevails over the general terms; applicable Standard Contractual Clauses prevail over this Addendum.
2. Customer instructions and responsibilities
Supplier will process Customer Personal Data only on documented instructions from Customer, including the order, approved hosted-guide route matrix and content, any connected-tenant scope and retention settings, use of legacy builder controls, support requests and this Addendum, unless Union or Member State law requires otherwise. Where legally permitted, Supplier will inform Customer before processing required by law.
Supplier will promptly tell Customer if, in its opinion, an instruction infringes applicable data-protection law and may pause the affected processing while the parties resolve it. Customer is responsible for the lawfulness, fairness, transparency, accuracy and minimisation of the data and instructions it supplies, and for giving any required notices to data subjects.
The service is not intended for special-category or criminal-offence data, employee directory exports, identity documents, credentials, PINs, Temporary Access Pass values, recovery codes, authentication tokens, live enrolment QR codes or confidential incident evidence. Customer must not manually submit them. Where connected personalisation is ordered, Microsoft issues short-lived access and refresh tokens directly through the authorised protocol; Supplier may process those encrypted tokens only to provide the connection. Hosted-guide content is presented to visitors and must contain only information Customer is authorised to publish to the intended audience.
3. Confidentiality and personnel
Supplier will ensure that people authorised to process Customer Personal Data are bound by confidentiality obligations, receive access only where required for their role and process the data only under Supplier’s instructions, except where law requires otherwise. Access will be removed when no longer required.
4. Security
Taking account of the state of the art, implementation cost, nature and context of the processing and risks to people, Supplier will maintain appropriate technical and organisational measures under Article 32 GDPR. The current measures are described in Schedule 2. No internet or storage system can be guaranteed absolutely secure.
5. Personal-data breaches
Supplier will notify Customer without undue delay after becoming aware of a personal-data breach affecting Customer Personal Data. As information becomes available, the notice will describe the nature of the breach, likely consequences, affected categories and approximate volumes, measures taken or proposed and a contact point. Supplier will reasonably assist Customer with investigation, mitigation and legally required notifications. Customer remains responsible for deciding whether and how to notify a supervisory authority or data subjects.
6. Data-subject requests
Taking account of the nature of the processing, Supplier will reasonably assist Customer through appropriate technical and organisational measures with requests to exercise data subject rights. If Supplier receives a request relating to Customer Personal Data, it will refer the requester to Customer and will not respond substantively except on Customer’s instruction or where required by law.
7. Regulatory and risk-assessment assistance
Supplier will provide information reasonably available to assist Customer with Articles 32–36 obligations, including security assessments, breach response, data-protection impact assessments and prior consultation, taking account of the nature of the processing and information available to Supplier.
8. Subprocessors
Customer gives general written authorisation for the subprocessors in Schedule 3. Supplier will impose materially equivalent data-protection obligations on each subprocessor and remains responsible to Customer for the subprocessor’s performance of those obligations.
Supplier will give the Customer contact reasonable prior written notice of an intended addition or replacement that processes Customer Personal Data. Customer may object on reasonable data-protection grounds before the change takes effect. The parties will try in good faith to find a reasonable alternative; if none is available, either party may end the affected processing without penalty, subject to payment for services already delivered.
9. International transfers
Supplier will not transfer Customer Personal Data outside the EEA, or permit such a transfer by a subprocessor, unless Chapter V GDPR is satisfied. Depending on the recipient and destination, safeguards may include an adequacy decision or the then-current European Commission Standard Contractual Clauses with the appropriate module and supplementary measures. Customer authorises those safeguards through this Addendum and may request a copy, subject to redaction of unrelated confidential information.
If the completed party details require controller-to-processor or processor-to-processor Standard Contractual Clauses directly between Customer and Supplier, the appropriate 2021/914 module must be attached to the signed copy; this page does not silently create incomplete SCC annexes.
10. Return and deletion
On Customer’s written request or termination of the affected service, Supplier will, at Customer’s choice, return an available copy of Customer Personal Data and delete it, unless applicable law requires retention. A hosted guide can be withdrawn from ordinary public delivery, but copies already cached, downloaded or retained by third parties are outside Supplier’s control. Existing legacy-kit downloads are also under Customer’s control and are not remotely deleted. Residual encrypted backups will be isolated from ordinary use and will age out under the applicable provider cycle; if restored for disaster recovery, the deletion instruction will be reapplied.
Disconnecting an optional Microsoft connection invalidates connected employee sessions and schedules its pseudonymous session data and Customer-approved route mapping for deletion. The live Microsoft policy response is reduced in memory and is not retained as a policy snapshot. An inconclusive connected check, including detected consent revocation, invalidates that employee session; operator connection validation can then disable the connection. Supplier does not retain connected passkey results as an employee method-history record.
Order, invoice, fraud-prevention and legal-claims records for which Supplier is controller are retained under the Privacy notice and are not Customer Personal Data under this Addendum.
11. Information and audits
Supplier will make information reasonably necessary to demonstrate compliance with Article 28 available to Customer. Audits should first use current policies, security information, provider reports and written responses. If that is insufficient, Customer may request one proportionate audit in a 12-month period on at least 30 days’ notice, during normal business hours, subject to confidentiality and without access to other customers’ data or systems.
Customer bears reasonable audit costs unless the audit identifies a material breach by Supplier, or an audit is required by a competent supervisory authority or following a substantiated personal-data breach. Supplier will inform Customer if an audit instruction would infringe law or compromise another person’s security.
12. Government requests
Unless prohibited by law, Supplier will notify Customer of a legally binding request for Customer Personal Data and will assess whether the request is valid and proportionate. Supplier will disclose only the data legally required and document the response.
13. Liability and term
The liability provisions in the applicable order and Terms apply to this Addendum only to the extent permitted by data-protection law and without reducing data subjects’ enforceable rights. This Addendum continues while Supplier processes Customer Personal Data and its protection, deletion, audit, transfer and confidentiality clauses survive for as long as relevant data remains.
14. Governing law
Unless mandatory data-protection law or attached SCCs require otherwise, this Addendum is governed by Irish law and disputes are subject to the courts specified in the applicable order. Data subjects retain their rights to complain to and seek remedies from competent supervisory authorities and courts.
Schedule 1 — Details of processing
| Subject matter | Preparing, reviewing, hosting, maintaining and withdrawing Customer’s branded employee passkey guide; where expressly ordered, matching signed-in employees to Customer-approved routes through a read-only Microsoft Entra connection; and, only if separately ordered, generating, storing, editing, delivering and recovering Customer’s legacy Passkey Rollout Kit. |
|---|---|
| Duration | From Customer’s submission of Customer Personal Data until deletion or return under section 10. Hosted-guide processing normally continues for the service period in the order. Legacy unpaid drafts expire seven days after their last save. |
| Nature and purpose | Collection, validation, storage, retrieval, organisation, rendering into a hosted guide or legacy documents, publication or transmission, support, maintenance, return and deletion, solely to provide the service identified in the order. For connected personalisation this includes Microsoft authentication, tenant-policy retrieval, target-group match checks, reduction of registered-passkey metadata and selection of an allow-listed guide route. |
| Data subjects | Public, generic and unconnected guide visitors are not required to identify themselves. Customer personnel and contractors identified in branding, support, approval, example-account, communication or custom-note fields; authorised customer contacts where included in Customer-directed content; and employees or contractors who open an identity-enabled direct paid-org guide. After Customer authorisation, that direct guide can make one automatic non-interactive Microsoft session check; connected account data is supplied only when Microsoft can satisfy it or the visitor separately chooses the explicit Microsoft sign-in action. |
| Personal-data types |
Names, work email addresses or formats, job/function references, organisation and
support contact details, logos that identify an individual, rollout dates and
Customer-authored text. Approved passkey methods, provider rules and device routes
are normally organisation data rather than personal data. Connected
personalisation can additionally process Microsoft tenant and user object
identifiers (tid and oid), a match against only the
policy target groups and registered-passkey type and count. Authenticator model,
AAGUID, credential identifier and raw Graph response data are reduced away before
the browser response. No passkey private key, PIN, biometric or recovery secret
and no special-category data is intended.
|
| Frequency | Hosted guide: continuous delivery while the ordered guide is available, with intermittent review and updates. Connected personalisation: when an employee starts or resumes an authorised session and when the tenant policy is refreshed. Legacy kit: intermittent when Customer saves, edits, generates, downloads, recovers or asks Supplier to deliver it. |
| Customer rights and duties | As controller or authorised processor under applicable law, the order, the Terms and this Addendum, including deciding content, lawful basis, recipients, accuracy and retention. For a connected service, Customer also controls tenant consent, target audience, approved route mapping, employee transparency and disconnection. |
Schedule 2 — Technical and organisational measures
- Data minimisation and separation The public website, generic guide, public branding preview and unconnected hosted guide require no employee account, Microsoft tenant connection or Graph permission. A separately ordered connection processes only the tenant and user identifiers, target-group match and reduced passkey metadata needed for the approved route. It does not request a general group list or retain an employee passkey history. Legacy kit content is separated by high-entropy private capability tokens.
- Connected-session protection Microsoft authorisation uses an authorisation-code flow with PKCE, one-use state and nonce values, exact redirect destinations and server-side exchange. Microsoft access and refresh tokens are encrypted server-side and are not returned to browser scripts or placed in guide URLs or browser storage. The browser receives an opaque, secure, HTTP-only session cookie. Sessions expire and are invalidated on sign-out, Customer disconnection or detected consent revocation.
- Approved-route scoping Hosted-guide routes are manually configured from Customer’s approved method, provider, device, platform, version and sign-in matrix. Where connected personalisation is ordered, the server-side group and passkey result can narrow but never expand that matrix. Missing, unavailable, invalid or partial connected data fails closed. This presentation control does not replace Customer’s tenant policy enforcement.
- Published-content boundary Unless the order states otherwise, a hosted guide URL is not an authentication boundary. Customer Personal Data placed in the guide is limited to content Customer instructs Supplier to publish. Connected group identifiers, credential identifiers, raw Graph responses and Microsoft tokens are not published. Secrets and employee directory exports are prohibited.
- Transmission protection Public service traffic and provider API calls use HTTPS/TLS. Card data is entered on Stripe-hosted checkout and is not stored by the legacy kit application.
- Storage access control Legacy order and enquiry tables use row-level security with no anonymous or ordinary authenticated policies. Connected policy and session records are private server-side records rather than public guide configuration. Server-side service credentials are kept in managed environment settings and are not sent to the browser.
- Legacy private-link protection Edit tokens are generated with Web Crypto randomness. Recovery requires both the recovery code and purchase email and only resends the private link to that address.
- Legacy payment integrity Payment is checked server-side. Stripe webhooks are signature-verified and fulfilment operations use stable idempotency controls to reduce duplicate or conflicting delivery.
- Abuse prevention and lifecycle Anonymous saves, enquiries, paid-link recovery attempts, purchase verification and document downloads are subject to atomic quotas using short-lived, daily server-keyed hashes. Short database leases prevent duplicate verification and document generation. Raw IP addresses, email addresses, recovery codes, Stripe session IDs and private kit tokens are not stored in the quota or lease records. Unpaid drafts expire after seven days and those abuse-control records after approximately 25 hours. Connected identity starts use a daily server-keyed network/browser hash solely for a ten-minute quota; raw IP and user-agent values are not stored in that ledger. The hash stops counting after ten minutes; rows older than twenty minutes are removed on a later organisation start or by the daily purge, normally within approximately 24 hours. Connected authorisation transactions are one-use and short-lived; employee sessions end on sign-out or their configured idle or absolute expiry; connected records are deleted or minimised when the connection or ordered service ends, subject to legal records and provider backup cycles.
- Availability and recovery Managed hosting and database providers supply platform resilience and backup capabilities. Hosted-guide availability is subject to the applicable order. Legacy-kit buyers are instructed to retain the downloaded package rather than rely on perpetual hosted access.
- Secure development and response Changes are linted and tested; access is restricted to authorised administrators; and suspected incidents are triaged through privacy@setuppasskeys.com.
Schedule 3 — Current subprocessors
This list applies where a provider processes Customer Personal Data on Supplier’s behalf. Exact data location depends on the configured provider region and current provider architecture; procurement teams should request confirmation for their order if location is material.
| Provider | Service | Customer Personal Data |
|---|---|---|
| Vercel, Inc. | Website hosting, edge/server execution and network delivery | Hosted-guide content and visitor request data; where connected personalisation is ordered, Microsoft authorisation and reduced Graph results processed in transit; legacy kit content processed during save, render, download or support operations |
| GitHub, Inc. | Source control and deployment integration | Customer-supplied hosted-guide configuration or assets when they form part of the deployed site source; only content approved for publication may be included |
| Supabase, Inc. | Managed database and related infrastructure | Customer-approved connected-guide route configuration and encrypted session records where that feature is ordered; live Microsoft policy responses are not retained. Legacy saved-kit configuration, private token/code, order linkage and delivery state when the legacy kit is ordered |
| Plus Five Five, Inc. (Resend) | Transactional email delivery | Recipient address and Customer-directed delivery content when email delivery is requested; enquiry notifications are separate controller processing |
Stripe processes payment and billing data under the roles described in its own terms and is disclosed in the Privacy notice. It is not treated here as a subprocessor for editable kit content merely because it processes the purchase.
Where connected personalisation is ordered, Microsoft authenticates Customer work accounts and Microsoft Graph answers Customer-tenant requests. Microsoft’s role and terms arise principally from Customer’s Microsoft tenant and Customer’s administrator consent; the executed order and Addendum must record the applicable Microsoft environment, roles and transfer position rather than assuming that this public template settles them.
Execution cover sheet
The signed PDF will complete the following fields; the blank template is not evidence of execution.
Customer
Legal name: ____________________
Address: _______________________
Signatory/title: ________________
Signature/date: _________________
Supplier
Legal name: Kinane Labs Ltd
Address: _______________________
Signatory/title: ________________
Signature/date: _________________