Procurement schedule
Data Processing Addendum
Version 1.0 · 27 July 2026
These are the processor terms offered by Kinane Labs Ltd, operator of SetupPasskeys, for personal data an organisation directs the service to place in, store for or deliver through its Passkey Rollout Kit. The schedule follows the required elements of Article 28 GDPR.
How to execute this Addendum
- Email privacy@setuppasskeys.com with the customer’s legal name, registered or service address, order reference, signatory name/title, and whether the customer acts as controller or processor.
- Kinane Labs Ltd will return a durable PDF identifying both legal parties and any agreed changes. Procurement may request the current provider regions and transfer documents at the same time.
- The Addendum takes effect on the later signature date, or on the order date if an order expressly incorporates a completed version accepted by both parties.
Do not submit personal data that requires an executed DPA until this process is complete. A customer-specific addendum may be considered, but no amendment is effective unless accepted in writing by both parties.
1. Parties, roles and scope
“Customer” means the legal person identified in the executed cover sheet or order. “Supplier” means Kinane Labs Ltd, operator of SetupPasskeys. “Customer Personal Data” means personal data processed by Supplier on Customer’s behalf in providing the kit service.
Customer is controller, or a processor authorised by its controller. Supplier is processor or subprocessor for Customer Personal Data. Supplier is a separate controller for its own order administration, payment reconciliation, fraud prevention, legal compliance, enquiries and business communications; those activities are governed by the Privacy notice, not this Addendum.
This Addendum forms part of the applicable order and Terms of sale and use. If there is a conflict about processing Customer Personal Data, this Addendum prevails over the general terms; applicable Standard Contractual Clauses prevail over this Addendum.
2. Customer instructions and responsibilities
Supplier will process Customer Personal Data only on documented instructions from Customer, including the order, use of builder controls, support requests and this Addendum, unless Union or Member State law requires otherwise. Where legally permitted, Supplier will inform Customer before processing required by law.
Supplier will promptly tell Customer if, in its opinion, an instruction infringes applicable data-protection law and may pause the affected processing while the parties resolve it. Customer is responsible for the lawfulness, fairness, transparency, accuracy and minimisation of the data and instructions it supplies, and for giving any required notices to data subjects.
The service is not intended for special-category or criminal-offence data, identity documents, credentials, PINs, Temporary Access Pass values, recovery codes, authentication tokens, live enrolment QR codes or confidential incident evidence. Customer must not submit them.
3. Confidentiality and personnel
Supplier will ensure that people authorised to process Customer Personal Data are bound by confidentiality obligations, receive access only where required for their role and process the data only under Supplier’s instructions, except where law requires otherwise. Access will be removed when no longer required.
4. Security
Taking account of the state of the art, implementation cost, nature and context of the processing and risks to people, Supplier will maintain appropriate technical and organisational measures under Article 32 GDPR. The current measures are described in Schedule 2. No internet or storage system can be guaranteed absolutely secure.
5. Personal-data breaches
Supplier will notify Customer without undue delay after becoming aware of a personal-data breach affecting Customer Personal Data. As information becomes available, the notice will describe the nature of the breach, likely consequences, affected categories and approximate volumes, measures taken or proposed and a contact point. Supplier will reasonably assist Customer with investigation, mitigation and legally required notifications. Customer remains responsible for deciding whether and how to notify a supervisory authority or data subjects.
6. Data-subject requests
Taking account of the nature of the processing, Supplier will reasonably assist Customer through appropriate technical and organisational measures with requests to exercise data subject rights. If Supplier receives a request relating to Customer Personal Data, it will refer the requester to Customer and will not respond substantively except on Customer’s instruction or where required by law.
7. Regulatory and risk-assessment assistance
Supplier will provide information reasonably available to assist Customer with Articles 32–36 obligations, including security assessments, breach response, data-protection impact assessments and prior consultation, taking account of the nature of the processing and information available to Supplier.
8. Subprocessors
Customer gives general written authorisation for the subprocessors in Schedule 3. Supplier will impose materially equivalent data-protection obligations on each subprocessor and remains responsible to Customer for the subprocessor’s performance of those obligations.
Supplier will give the purchase contact reasonable prior written notice of an intended addition or replacement that processes Customer Personal Data. Customer may object on reasonable data-protection grounds before the change takes effect. The parties will try in good faith to find a reasonable alternative; if none is available, either party may end the affected processing without penalty, subject to payment for services already delivered.
9. International transfers
Supplier will not transfer Customer Personal Data outside the EEA, or permit such a transfer by a subprocessor, unless Chapter V GDPR is satisfied. Depending on the recipient and destination, safeguards may include an adequacy decision or the then-current European Commission Standard Contractual Clauses with the appropriate module and supplementary measures. Customer authorises those safeguards through this Addendum and may request a copy, subject to redaction of unrelated confidential information.
If the completed party details require controller-to-processor or processor-to-processor Standard Contractual Clauses directly between Customer and Supplier, the appropriate 2021/914 module must be attached to the signed copy; this page does not silently create incomplete SCC annexes.
10. Return and deletion
On Customer’s written request or termination of the affected service, Supplier will, at Customer’s choice, return an available copy of Customer Personal Data and delete it, unless applicable law requires retention. Existing customer downloads are already under Customer’s control and are not remotely deleted. Residual encrypted backups will be isolated from ordinary use and will age out under the applicable provider cycle; if restored for disaster recovery, the deletion instruction will be reapplied.
Order, invoice, fraud-prevention and legal-claims records for which Supplier is controller are retained under the Privacy notice and are not Customer Personal Data under this Addendum.
11. Information and audits
Supplier will make information reasonably necessary to demonstrate compliance with Article 28 available to Customer. Audits should first use current policies, security information, provider reports and written responses. If that is insufficient, Customer may request one proportionate audit in a 12-month period on at least 30 days’ notice, during normal business hours, subject to confidentiality and without access to other customers’ data or systems.
Customer bears reasonable audit costs unless the audit identifies a material breach by Supplier, or an audit is required by a competent supervisory authority or following a substantiated personal-data breach. Supplier will inform Customer if an audit instruction would infringe law or compromise another person’s security.
12. Government requests
Unless prohibited by law, Supplier will notify Customer of a legally binding request for Customer Personal Data and will assess whether the request is valid and proportionate. Supplier will disclose only the data legally required and document the response.
13. Liability and term
The liability provisions in the applicable order and Terms apply to this Addendum only to the extent permitted by data-protection law and without reducing data subjects’ enforceable rights. This Addendum continues while Supplier processes Customer Personal Data and its protection, deletion, audit, transfer and confidentiality clauses survive for as long as relevant data remains.
14. Governing law
Unless mandatory data-protection law or attached SCCs require otherwise, this Addendum is governed by Irish law and disputes are subject to the courts specified in the applicable order. Data subjects retain their rights to complain to and seek remedies from competent supervisory authorities and courts.
Schedule 1 — Details of processing
| Subject matter | Generating, storing, editing, delivering and recovering Customer’s branded Passkey Rollout Kit. |
|---|---|
| Duration | From Customer’s submission of Customer Personal Data until deletion or return under section 10. Unpaid drafts expire seven days after their last save. |
| Nature and purpose | Collection, validation, storage, retrieval, organisation, rendering into documents, packaging, transmission by download or email, support and deletion, solely to provide the ordered kit. |
| Data subjects | Customer personnel and contractors identified in branding, example-account, helpdesk, approval, communication or custom-note fields; authorised purchaser contacts where included in Customer-directed content. |
| Personal-data types | Names, work email addresses or formats, job/function references, organisation and support contact details, logos that identify an individual, rollout dates and Customer-authored text. No special-category data is intended. |
| Frequency | Intermittent: when Customer saves, edits, generates, downloads, recovers or asks Supplier to deliver the kit. |
| Customer rights and duties | As controller or authorised processor under applicable law, the order, the Terms and this Addendum, including deciding content, lawful basis, recipients, accuracy and retention. |
Schedule 2 — Technical and organisational measures
- Data minimisation and separation No customer account, Microsoft tenant connection or Graph permission is required. Kit content is separated by high-entropy private capability tokens.
- Transmission protection Public service traffic and provider API calls use HTTPS/TLS. Card data is entered on Stripe-hosted checkout and is not stored by the kit application.
- Storage access control Order tables use row-level security with no anonymous or ordinary authenticated policies. Server-side service credentials are kept in managed environment settings and are not sent to the browser.
- Private-link protection Edit tokens are generated with Web Crypto randomness. Recovery requires both the recovery code and purchase email and only resends the private link to that address.
- Payment integrity Payment is checked server-side. Stripe webhooks are signature-verified and fulfilment operations use stable idempotency controls to reduce duplicate or conflicting delivery.
- Abuse prevention and lifecycle Anonymous saves are subject to atomic per-IP quotas using short-lived keyed hashes. Unpaid drafts expire after seven days and quota events after approximately 25 hours.
- Availability and recovery Managed hosting and database providers supply platform resilience and backup capabilities. Buyers are instructed to retain the downloaded package rather than rely on perpetual hosted access.
- Secure development and response Changes are linted and tested; access is restricted to authorised administrators; and suspected incidents are triaged through privacy@setuppasskeys.com.
Schedule 3 — Current subprocessors
This list applies where a provider processes Customer Personal Data on Supplier’s behalf. Exact data location depends on the configured provider region and current provider architecture; procurement teams should request confirmation for their order if location is material.
| Provider | Service | Customer Personal Data |
|---|---|---|
| Vercel, Inc. | Website hosting, edge/server execution and network delivery | Request data and kit content processed during save, render, download or support operations |
| Supabase, Inc. | Managed database and related infrastructure | Saved kit configuration, private token/code, order linkage and delivery state |
| Plus Five Five, Inc. (Resend) | Transactional email delivery | Recipient address and purchase/recovery email content when delivery is requested |
Stripe processes payment and billing data under the roles described in its own terms and is disclosed in the Privacy notice. It is not treated here as a subprocessor for editable kit content merely because it processes the purchase.
Execution cover sheet
The signed PDF will complete the following fields; the blank template is not evidence of execution.
Customer
Legal name: ____________________
Address: _______________________
Signatory/title: ________________
Signature/date: _________________
Supplier
Legal name: Kinane Labs Ltd
Address: _______________________
Signatory/title: ________________
Signature/date: _________________