Data Processing Agreement
Effective date: 24 August 2026
Applies to all Keystone Operating Systems app versions, modules and workspaces.
This Data Processing Agreement ("DPA") forms part of the agreement between the customer using Keystone Operating Systems ("Customer", "you") and Keystone Strategic Ltd ("Keystone Strategic", "we", "us" or "our"). Keystone Strategic Ltd is registered in England and Wales under company number 17047166. Our trading address is 4 Benwick Road, Whittlesey, PE7 2HD.
1. Purpose and Scope
This DPA applies whenever Keystone Strategic processes personal data on behalf of a Customer through Keystone Operating Systems. It is intended to meet the requirements of Article 28 of the UK GDPR and, where applicable, equivalent requirements under the EU GDPR.
Keystone Operating Systems includes all OS app versions and modules, including CoreOS, RooferOS, TechOS, TransportOS, and future industry-specific operating system products or modules released under the Keystone Operating Systems brand.
This DPA applies to personal data entered, uploaded, generated, stored, synced, exported or otherwise processed inside a Customer workspace. It does not replace our Privacy Policy for account, support, billing, security, product analytics or service administration data where Keystone Strategic acts as controller.
2. Definitions
"Data Protection Laws" means the UK GDPR, the Data Protection Act 2018, the Privacy and Electronic Communications Regulations, and any other UK data protection law that applies to the processing. Where EU data protection law applies, it also includes the EU GDPR.
"Customer Personal Data" means personal data processed by Keystone Strategic on behalf of the Customer through Keystone Operating Systems.
"Sub-processor" means another processor engaged by Keystone Strategic to process Customer Personal Data for the service.
Terms such as controller, processor, personal data, processing, data subject, personal data breach and supervisory authority have the meanings given in applicable Data Protection Laws.
3. Roles
The Customer is the controller of Customer Personal Data. The Customer decides what personal data is entered into Keystone Operating Systems, the purpose of that processing, who can access the workspace, and how long records should be kept unless a legal or contractual retention rule applies.
Keystone Strategic is the processor of Customer Personal Data. We process Customer Personal Data only to provide, maintain, secure and support Keystone Operating Systems, or as otherwise instructed by the Customer in writing.
Keystone Strategic acts as controller for personal data about its own users, prospects, account administrators, billing contacts and support contacts where we decide the purposes and means of processing. That controller processing is covered by our Privacy Policy.
4. Subject Matter, Duration, Nature and Purpose
| Subject matter | Processing Customer Personal Data for the provision of Keystone Operating Systems and related support, hosting, security, synchronisation, storage, reporting, document, email, map, QR-code, export and integration features. |
|---|---|
| Duration | For the term of the Customer's subscription, trial, licence or service relationship, plus any post-termination retention period described in this DPA or required by law. |
| Nature of processing | Collection, recording, organisation, structuring, storage, hosting, retrieval, consultation, use, transmission, disclosure to authorised users, alignment, restriction, export, deletion, backup, restoration and security monitoring. |
| Purpose | To operate Keystone Operating Systems for the Customer, make workspace data available to authorised users, generate operational records and reports, support Customer workflows, secure the service, troubleshoot issues and comply with documented Customer instructions. |
| Controller obligations and rights | The Customer remains responsible for lawful collection and use of Customer Personal Data, transparency to data subjects, responding to rights requests, setting access permissions, keeping workspace data accurate, and issuing lawful documented instructions. |
5. Customer Instructions
The Customer instructs Keystone Strategic to process Customer Personal Data as necessary to provide Keystone Operating Systems and related support. Use of app features, workspace settings, support requests, exports, integrations and written instructions from authorised Customer representatives are documented instructions.
Keystone Strategic will not process Customer Personal Data for its own independent purposes unless required by law. If we believe an instruction infringes Data Protection Laws, we will inform the Customer where legally permitted.
6. Types of Personal Data
- Identity and contact data: names, emails, phone numbers, addresses, job titles, company names and user identifiers.
- Employment and workforce data: staff, subcontractor, visitor, attendance, induction, declaration, training, role and permission records.
- Project and site data: project contacts, site addresses, schedules, job notes, maps, site photos, signatures, inspection records and document metadata.
- Commercial and operational data: client records, supplier records, quotations, invoices, costs, payment terms, stock movements, asset records, vehicle records, delivery and collection logs.
- Compliance and health and safety data: forms, inspections, accreditations, method statements, risk assessments, incidents, evidence, sign-offs and uploaded documents.
- Technical data: audit logs, access logs, timestamps, device/browser data, security events, file metadata and sync records.
- Any other personal data the Customer or authorised users choose to enter into a workspace.
7. Categories of Data Subjects
- Customer staff, directors, managers, administrators and app users.
- Customer clients, prospects, client representatives and site contacts.
- Subcontractors, suppliers, consultants, visitors, delivery drivers and other site attendees.
- Employees, workers, trainees, inspectors, supervisors and other individuals recorded in operational or compliance workflows.
- Any other identifiable individuals whose data is entered by the Customer.
8. Special Category and Criminal-Offence Data
Keystone Operating Systems is not primarily designed for special category data or criminal-offence data. Some Customer workflows, such as health and safety, incident, attendance, compliance or employment records, may include sensitive information if entered by the Customer.
The Customer must ensure it has a lawful basis, and where required an Article 9 or Article 10 condition, before entering special category or criminal-offence data. Keystone Strategic will process that data only as processor and only as required to provide, secure and support the service.
9. Keystone Strategic Processor Obligations
Keystone Strategic will:
- Process Customer Personal Data only on documented Customer instructions, unless required by law.
- Ensure people authorised to process Customer Personal Data are subject to confidentiality obligations.
- Apply appropriate technical and organisational security measures.
- Assist the Customer, taking into account the nature of processing, with data subject rights requests where possible.
- Assist the Customer with security, breach notification, data protection impact assessment and supervisory authority consultation obligations where relevant and reasonably possible.
- Keep appropriate records of processing where required by Data Protection Laws.
- Make available information reasonably necessary to demonstrate compliance with Article 28 obligations.
- Notify the Customer without undue delay after becoming aware of a personal data breach affecting Customer Personal Data.
- Delete or return Customer Personal Data at the end of the service as described in this DPA, unless retention is required by law.
10. Customer Obligations
The Customer will:
- Comply with Data Protection Laws when using Keystone Operating Systems.
- Provide required privacy information to staff, clients, visitors, suppliers and other data subjects whose data is entered into the app.
- Ensure Customer Personal Data is collected lawfully, fairly and transparently.
- Ensure Customer Personal Data is accurate, relevant and limited to what is necessary.
- Manage authorised users, roles, workspace permissions and device access responsibly.
- Avoid entering special category or criminal-offence data unless legally permitted and necessary.
- Respond to data subject requests where the Customer is controller.
- Maintain its own backups or exports where required for its business continuity or legal retention obligations.
11. Technical and Organisational Measures
Keystone Strategic applies measures designed to protect Customer Personal Data, including:
- HTTPS/TLS encryption for data in transit.
- Managed database and storage security through Supabase or equivalent hosting providers.
- Workspace-level tenant separation using workspace identifiers.
- Database Row-Level Security and controlled save/load functions in Supabase-backed deployments.
- Authentication, user roles, module permissions and access controls.
- Audit logs and security event monitoring where supported by the app version.
- Private storage buckets or access-controlled document storage for workspace files where supported.
- Restricted production access for authorised personnel and service providers.
- Backup, restoration and resilience measures appropriate to the deployment environment.
- Sub-processor due diligence and contractual data protection obligations.
- Security headers and browser controls for hosted app versions where supported.
12. Sub-Processors
The Customer gives Keystone Strategic general written authorisation to use sub-processors needed to provide Keystone Operating Systems. Keystone Strategic remains responsible for requiring sub-processors to protect Customer Personal Data to a standard consistent with this DPA.
Current or likely sub-processors and third-party service providers include:
- Supabase: database, authentication, storage, row-level security and realtime workspace sync.
- Hosting and content delivery providers, such as Vercel, Netlify or Cloudflare Pages, depending on the deployment used for the relevant app version.
- Resend and/or Amazon SES: outbound service email delivery where enabled.
- Microsoft: optional Outlook, Microsoft 365, Microsoft Graph authentication, document preview and email draft features where configured or selected by a user.
- Google: Google Fonts, Google Maps and Google Places address, location and map display features where used.
- jsDelivr: delivery of app libraries used by the browser version of the service.
- QR code image providers, such as api.qrserver.com, when the app generates QR-code images.
We will give notice of material sub-processor changes by email, in-app notice, website notice or an updated policy page. The Customer may object on reasonable data protection grounds within 30 days of notice. If the objection cannot be resolved, the Customer may stop using the affected feature or terminate the affected service.
13. International Transfers
Where reasonably possible, Keystone Strategic uses UK, EEA or adequacy-approved processing locations. Some providers may process or access Customer Personal Data from outside the UK or EEA.
Where an international transfer is required, Keystone Strategic will use appropriate safeguards such as UK-approved international data transfer agreements, the UK Addendum to EU Standard Contractual Clauses, adequacy regulations, or another lawful transfer mechanism.
14. Personal Data Breaches
Keystone Strategic will notify the Customer without undue delay after becoming aware of a personal data breach affecting Customer Personal Data. The notice will include information reasonably available to us, such as the nature of the breach, affected data categories, likely consequences, mitigation steps taken or proposed, and a contact point for follow-up.
The Customer is responsible for deciding whether notification to a supervisory authority or data subjects is required where the Customer is controller. Keystone Strategic will reasonably assist with that assessment where possible.
15. Data Subject Requests
Where Keystone Strategic receives a request from a data subject about Customer Personal Data, we will either direct the person to the Customer or notify the Customer where appropriate, unless legally prohibited. Keystone Strategic will not independently respond to the substance of a request about Customer Personal Data unless instructed by the Customer or required by law.
Where possible, Keystone Operating Systems may provide tools to help Customers access, correct, export, restrict or delete Customer Personal Data.
16. Return and Deletion
During the subscription, the Customer may export or delete Customer Personal Data using available app tools, subject to user permissions and app functionality.
After termination, Keystone Strategic will delete or anonymise Customer Personal Data within 90 days unless the Customer requests return or export during any available post-termination access period, or unless a longer retention period is required by law, contract, backup lifecycle, dispute management, tax, accounting or legitimate security purposes.
Backups may remain for a limited period until overwritten or deleted in the normal backup cycle. Any retained data will remain subject to confidentiality and security obligations.
17. Audits and Compliance Information
Keystone Strategic will make available information reasonably necessary to demonstrate compliance with this DPA and Article 28 of the UK GDPR. The Customer may request an audit no more than once in any 12-month period unless required by a supervisory authority or following a confirmed personal data breach affecting Customer Personal Data.
Audits must be conducted on reasonable written notice, during normal business hours, in a way that protects the confidentiality, security and availability of Keystone Strategic systems and other customers' data. The Customer is responsible for its own audit costs unless otherwise agreed.
18. Confidentiality
Keystone Strategic will ensure that employees, contractors and other authorised personnel who may access Customer Personal Data are subject to appropriate confidentiality obligations. Customer Personal Data will be accessed only where needed to provide, secure, maintain or support the service, or where required by law.
19. Liability
Each party's liability under this DPA is subject to any limitation of liability in the main agreement between the parties, except where liability cannot be limited by law. Nothing in this DPA limits liability for fraud, fraudulent misrepresentation, death or personal injury caused by negligence, or liability that cannot be excluded under Data Protection Laws.
20. Order of Precedence
If there is a conflict between this DPA and another agreement between Keystone Strategic and the Customer, this DPA will take precedence for the processing of Customer Personal Data to the extent of the conflict. The main agreement continues to apply to commercial terms, payment, service scope and general liability unless expressly changed by this DPA.
21. Governing Law and Jurisdiction
This DPA is governed by the laws of England and Wales. The courts of England and Wales have exclusive jurisdiction, unless applicable Data Protection Laws require otherwise.
22. Acceptance and Contact
By using Keystone Operating Systems to process personal data about identifiable individuals, the Customer accepts this DPA. If a counter-signed copy is required, contact us and we will provide one within a reasonable time.
- Email: privacy@keystoneoperationsystems.com
- Support: support@keystoneoperationsystems.com
- Trading address: 4 Benwick Road, Whittlesey, PE7 2HD.
- Company number: 17047166.