Back to Sign In

Data Processing Addendum (DPA)

logKeet · Effective June 6, 2026

This Data Processing Addendum ("DPA") governs the processing of personal data by logKeet on behalf of our clients in accordance with GDPR, India's DPDP Act 2023, and CCPA.

1. Scope & Definitions

This DPA applies when logKeet processes Customer Personal Data (defined below) as a Data Processor on behalf of the customer who acts as the Data Controller.

  • Customer Personal Data: Any personal data processed by our SDK or API during your use of our logging services.
  • Data Protection Laws: GDPR (EU 2016/679), India's Digital Personal Data Protection (DPDP) Act 2023, and CCPA/CPRA.
  • Data Processor: logKeet (we process data solely on your instructions).
  • Data Controller: Your organization (you control the data and determine what telemetry/logs are collected).

2. Processing Instructions

We will only process Customer Personal Data in accordance with:

  • Your written instructions, including the main Terms of Service.
  • To provide, secure, and debug the Software Insights Logger services.
  • To fulfill our legal obligations under applicable Data Protection Laws.
  • We will immediately inform you if, in our opinion, your instruction infringes data protection regulations.

3. Technical & Organizational Measures (TOMs)

We implement and maintain industry-standard security measures (Article 32 GDPR) to protect Customer Personal Data:

  • Data Transit: Enforced HTTPS/TLS 1.2+ encryption for all SDK event collection and dashboard traffic.
  • Data Encryption: Sensitive integration credentials (OAuth client secrets, API keys) encrypted at rest using AES-256-GCM.
  • Access Controls: Access to databases restricted to authorized operations personnel using multi-factor authentication (MFA).
  • Log Auditing: Full audit logs tracked for all administrative changes, credentials rotations, and project settings modifications.
  • System Integrity: Automated backups created daily and stored encrypted in offsite locations.

4. Approved Sub-processors

The Customer consents to our engagement of the following sub-processors to host customer log data and send notifications:

Sub-processorService ProvidedLocation
Hetzner Online GmbHPrimary Cloud Infrastructure, Databases & VMsHelsinki, Finland (EU)
Cloudflare, Inc.CDN, DDoS Protection & R2 Backup StorageEU region (GDPR-compliant)
Hetzner Object StorageEncrypted Backup StorageEU (Falkenstein, Germany)
Msg91 (Sinch)OTP SMS Verification ServicesIndia (Noida)

* We will notify you by email at least 30 days prior to adding or changing any sub-processor, giving you the right to object on reasonable privacy grounds.

5. Data Subject Requests Assistance

We provide tooling in your dashboard (Dashboard → GDPR & Privacy) to assist you in complying with requests from your end-users:

  • Right to Access & Portability: Generate a complete JSON export of all logged actions and events associated with a specific User ID.
  • Right to Erasure (Right to be Forgotten): Permanently purge a User ID's records from ClickHouse and PostgreSQL in a single action.
  • If we receive a data subject request directly from one of your users, we will redirect them to contact your organization.

6. Personal Data Breach Notification

In the event of a confirmed security incident affecting Customer Personal Data:

  • We will notify your administrator by email within 48 hours of confirmation.
  • We will provide details of the nature of the breach, affected data categories, and immediate mitigation steps taken.
  • We will cooperate with your team to remediate the incident and comply with regulatory notification requirements.

7. Deletion or Return of Data

Upon termination of your subscription or request from your administrator:

  • All telemetry, log files, crash reports, and workspaces will be deleted from active servers within 30 days.
  • Offline backup archives containing Customer Personal Data will automatically rotate and purge within 30 days.

8. DPA Contact Information

For any queries regarding this DPA, or to request a signed PDF copy of this addendum with Standard Contractual Clauses (SCCs), please contact us at:

  • Data Protection Officer Email: privacy@logkeet.com
  • Legal Inquiries: privacy@logkeet.com

logKeet · Data Processing Addendum · Effective June 6, 2026

← Back to Sign In