Skip to content

Data Processing Addendum

How to execute this Addendum

  1. Email privacy@setuppasskeys.com with the customer’s legal name, registered or service address, order reference, signatory name/title, and whether the customer acts as controller or processor.
  2. Kinane Labs Ltd will return a durable PDF identifying both legal parties and any agreed changes. Procurement may request the current provider regions and transfer documents at the same time.
  3. The Addendum takes effect on the later signature date, or on the order date if an order expressly incorporates a completed version accepted by both parties.

Do not submit personal data that requires an executed DPA until this process is complete. A customer-specific addendum may be considered, but no amendment is effective unless accepted in writing by both parties.

1. Parties, roles and scope

“Customer” means the legal person identified in the executed cover sheet or order. “Supplier” means Kinane Labs Ltd, operator of SetupPasskeys. “Customer Personal Data” means personal data processed by Supplier on Customer’s behalf in providing the kit service.

Customer is controller, or a processor authorised by its controller. Supplier is processor or subprocessor for Customer Personal Data. Supplier is a separate controller for its own order administration, payment reconciliation, fraud prevention, legal compliance, enquiries and business communications; those activities are governed by the Privacy notice, not this Addendum.

This Addendum forms part of the applicable order and Terms of sale and use. If there is a conflict about processing Customer Personal Data, this Addendum prevails over the general terms; applicable Standard Contractual Clauses prevail over this Addendum.

2. Customer instructions and responsibilities

Supplier will process Customer Personal Data only on documented instructions from Customer, including the order, use of builder controls, support requests and this Addendum, unless Union or Member State law requires otherwise. Where legally permitted, Supplier will inform Customer before processing required by law.

Supplier will promptly tell Customer if, in its opinion, an instruction infringes applicable data-protection law and may pause the affected processing while the parties resolve it. Customer is responsible for the lawfulness, fairness, transparency, accuracy and minimisation of the data and instructions it supplies, and for giving any required notices to data subjects.

The service is not intended for special-category or criminal-offence data, identity documents, credentials, PINs, Temporary Access Pass values, recovery codes, authentication tokens, live enrolment QR codes or confidential incident evidence. Customer must not submit them.

3. Confidentiality and personnel

Supplier will ensure that people authorised to process Customer Personal Data are bound by confidentiality obligations, receive access only where required for their role and process the data only under Supplier’s instructions, except where law requires otherwise. Access will be removed when no longer required.

4. Security

Taking account of the state of the art, implementation cost, nature and context of the processing and risks to people, Supplier will maintain appropriate technical and organisational measures under Article 32 GDPR. The current measures are described in Schedule 2. No internet or storage system can be guaranteed absolutely secure.

5. Personal-data breaches

Supplier will notify Customer without undue delay after becoming aware of a personal-data breach affecting Customer Personal Data. As information becomes available, the notice will describe the nature of the breach, likely consequences, affected categories and approximate volumes, measures taken or proposed and a contact point. Supplier will reasonably assist Customer with investigation, mitigation and legally required notifications. Customer remains responsible for deciding whether and how to notify a supervisory authority or data subjects.

6. Data-subject requests

Taking account of the nature of the processing, Supplier will reasonably assist Customer through appropriate technical and organisational measures with requests to exercise data subject rights. If Supplier receives a request relating to Customer Personal Data, it will refer the requester to Customer and will not respond substantively except on Customer’s instruction or where required by law.

7. Regulatory and risk-assessment assistance

Supplier will provide information reasonably available to assist Customer with Articles 32–36 obligations, including security assessments, breach response, data-protection impact assessments and prior consultation, taking account of the nature of the processing and information available to Supplier.

8. Subprocessors

Customer gives general written authorisation for the subprocessors in Schedule 3. Supplier will impose materially equivalent data-protection obligations on each subprocessor and remains responsible to Customer for the subprocessor’s performance of those obligations.

Supplier will give the purchase contact reasonable prior written notice of an intended addition or replacement that processes Customer Personal Data. Customer may object on reasonable data-protection grounds before the change takes effect. The parties will try in good faith to find a reasonable alternative; if none is available, either party may end the affected processing without penalty, subject to payment for services already delivered.

9. International transfers

Supplier will not transfer Customer Personal Data outside the EEA, or permit such a transfer by a subprocessor, unless Chapter V GDPR is satisfied. Depending on the recipient and destination, safeguards may include an adequacy decision or the then-current European Commission Standard Contractual Clauses with the appropriate module and supplementary measures. Customer authorises those safeguards through this Addendum and may request a copy, subject to redaction of unrelated confidential information.

If the completed party details require controller-to-processor or processor-to-processor Standard Contractual Clauses directly between Customer and Supplier, the appropriate 2021/914 module must be attached to the signed copy; this page does not silently create incomplete SCC annexes.

10. Return and deletion

On Customer’s written request or termination of the affected service, Supplier will, at Customer’s choice, return an available copy of Customer Personal Data and delete it, unless applicable law requires retention. Existing customer downloads are already under Customer’s control and are not remotely deleted. Residual encrypted backups will be isolated from ordinary use and will age out under the applicable provider cycle; if restored for disaster recovery, the deletion instruction will be reapplied.

Order, invoice, fraud-prevention and legal-claims records for which Supplier is controller are retained under the Privacy notice and are not Customer Personal Data under this Addendum.

11. Information and audits

Supplier will make information reasonably necessary to demonstrate compliance with Article 28 available to Customer. Audits should first use current policies, security information, provider reports and written responses. If that is insufficient, Customer may request one proportionate audit in a 12-month period on at least 30 days’ notice, during normal business hours, subject to confidentiality and without access to other customers’ data or systems.

Customer bears reasonable audit costs unless the audit identifies a material breach by Supplier, or an audit is required by a competent supervisory authority or following a substantiated personal-data breach. Supplier will inform Customer if an audit instruction would infringe law or compromise another person’s security.

12. Government requests

Unless prohibited by law, Supplier will notify Customer of a legally binding request for Customer Personal Data and will assess whether the request is valid and proportionate. Supplier will disclose only the data legally required and document the response.

13. Liability and term

The liability provisions in the applicable order and Terms apply to this Addendum only to the extent permitted by data-protection law and without reducing data subjects’ enforceable rights. This Addendum continues while Supplier processes Customer Personal Data and its protection, deletion, audit, transfer and confidentiality clauses survive for as long as relevant data remains.

14. Governing law

Unless mandatory data-protection law or attached SCCs require otherwise, this Addendum is governed by Irish law and disputes are subject to the courts specified in the applicable order. Data subjects retain their rights to complain to and seek remedies from competent supervisory authorities and courts.

Schedule 1 — Details of processing

Schedule 2 — Technical and organisational measures

Schedule 3 — Current subprocessors

This list applies where a provider processes Customer Personal Data on Supplier’s behalf. Exact data location depends on the configured provider region and current provider architecture; procurement teams should request confirmation for their order if location is material.

Stripe processes payment and billing data under the roles described in its own terms and is disclosed in the Privacy notice. It is not treated here as a subprocessor for editable kit content merely because it processes the purchase.