This page explains how a Business Customer can request a data processing agreement (DPA) when KEYVERA processes personal data on the customer's behalf and applicable data-protection law requires one.
This page is a request process, not the DPA itself. A DPA applies only after the appropriate document has been executed or otherwise validly accepted by KEYVERA and the Business Customer.
DPA request summary
- DPAs are intended for Business Customers acting as controllers or processors.
- Request the DPA before sending personal data that requires processor terms.
- Identify the models, data categories, data subjects, countries, and intended use.
- Provider and upstream subprocessors may differ by model or route.
- International-transfer provisions are assessed for the applicable processing.
- A request does not create an SLA or approve regulated data by itself.
1. When a DPA may apply
A DPA may apply where a Business Customer determines the purposes and means of processing personal data and instructs KEYVERA to process that data through the Services on its behalf. Depending on the processing chain, KEYVERA may act as a processor or subprocessor for Customer Content while acting as an independent controller for account, billing, security, fraud-prevention, and legal-compliance data.
Consumers do not normally need a business DPA. Their personal data is governed by the Privacy Policy and mandatory data-protection law.
2. Information required
To assess and prepare a DPA, email KEYVERA with:
- the legal name, registered address, and registration number of the Business Customer;
- the authorised signatory and privacy or security contact;
- whether the customer acts as controller, processor, or both;
- the categories of personal data and data subjects;
- the processing purpose, expected volume, and duration;
- the models, features, or provider families expected to be used;
- the countries from which data will be submitted and any required data-location restrictions;
- whether special-category, criminal-offence, children's, health, biometric, financial, or other regulated data is involved; and
- any sector-specific requirement, security schedule, or transfer assessment that must be considered.
Do not include live personal data, API Keys, passwords, production prompts, medical records, or other sensitive Customer Content in the initial request.
3. DPA coverage
Where applicable, the DPA may address documented instructions, confidentiality, security measures, subprocessors, assistance with individual rights and incidents, deletion or return, audits, international transfers, and the allocation of responsibilities required by applicable law.
The final scope depends on the Services and processing approved for the Business Customer. A DPA does not make every model suitable for every data type and does not override provider restrictions, the Acceptable Use Policy, or applicable law.
4. Providers, subprocessors, and transfers
Selected model requests may require processing by model providers, upstream channels, hosting, security, communications, or other service providers. The relevant chain may vary by model and configuration.
KEYVERA will evaluate the applicable providers and transfer mechanism for the requested scope. If Standard Contractual Clauses or another transfer mechanism is required, the relevant provisions will be addressed in the executed documentation.
5. Request and review process
- Send the information in Section 2 to KEYVERA.
- KEYVERA reviews the proposed processing, model routes, and legal roles.
- KEYVERA may request clarification, recommend a different configuration, or determine that a proposed data category is not supported.
- The parties execute or otherwise validly accept the applicable DPA.
- The Business Customer implements its own notices, lawful basis, access controls, retention settings, and end-user safeguards before processing begins.
6. Request a DPA
Email legal@keyvera.cloud with the subject “KEYVERA DPA request”. KEYVERA may require the request to come from the Account owner or an authorised representative.