Data Processing Agreement
Version 1.0. Effective 29 July 2026.
This Data Processing Agreement (“DPA”) forms part of, and is incorporated into, the Terms of Service between you (the “Customer”) and Keystone HSE Ltd (the “Provider”). It applies whenever the Provider processes Customer Personal Data on the Customer’s behalf. The Provider is registered with the Jersey Data Protection Authority as a controller and processor, registration number 104029. Where this DPA conflicts with the Terms of Service, this DPA prevails in respect of the processing of personal data.
1. Definitions
Data Protection Law means all legislation applicable to the processing of personal data under this DPA, including the Data Protection (Jersey) Law 2018 and, where it applies to the Customer or to the processing, the UK GDPR and the Data Protection Act 2018.
Customer Personal Data means personal data contained within Customer Data, as defined in the Terms of Service, which the Provider processes on the Customer’s behalf. Annex 1 describes it.
Controller, processor, data subject, personal data, special category data, processing and personal data breach have the meanings given to them in Data Protection Law.
2. Roles of the parties
The Customer is the controller of Customer Personal Data. The Provider is the processor, acting on the Customer’s behalf.
The Customer is responsible for establishing a lawful basis for the processing, for the accuracy of the personal data it uploads or enters, and for issuing any privacy information required to the individuals concerned. The Provider does not determine the purposes of the processing.
The Provider is a separate controller in respect of the Customer’s own account and billing data, and of data processed to secure and operate the platform. That processing is described in the Privacy Policy and is outside the scope of this DPA.
3. Scope and details of processing
The subject matter, duration, nature and purpose of the processing, the types of personal data and the categories of data subject are set out in Annex 1.
The Customer acknowledges that the service is designed to record health and safety information, and that in normal use it will contain special category data, in particular data concerning health arising from accident, injury, near miss and hand-arm vibration exposure records. The Customer is responsible for identifying the condition it relies on for processing such data.
4. Processing on documented instructions
The Provider shall process Customer Personal Data only on the Customer’s documented instructions, including in relation to transfers to a third country, unless required to do otherwise by law to which the Provider is subject. Where the Provider is required by law to process otherwise, it shall inform the Customer of that legal requirement before processing, unless the law prohibits it from doing so on important grounds of public interest.
The Terms of Service, this DPA, and the Customer’s use of the features of the service constitute the Customer’s complete documented instructions.
The Provider shall inform the Customer if, in its opinion, an instruction infringes Data Protection Law.
5. Confidentiality
The Provider shall ensure that persons authorised to process Customer Personal Data are subject to an appropriate duty of confidentiality, and shall limit access to those persons who need it in order to provide, secure or support the service.
6. Security
The Provider shall implement appropriate technical and organisational measures to ensure a level of security appropriate to the risk. The measures in place at the effective date of this DPA are set out in Annex 2.
The Provider may update those measures over time provided the level of protection is not reduced.
7. Sub-processors
The Customer gives the Provider general written authorisation to engage sub-processors. The sub-processors engaged at the effective date of this DPA are listed in Annex 3.
The Provider shall impose on each sub-processor data protection obligations no less protective than those in this DPA, and remains fully liable to the Customer for the performance of each sub-processor’s obligations.
The Provider shall give the Customer at least 30 days’ notice by email of any intended addition or replacement of a sub-processor. The Customer may object on reasonable data protection grounds within that period. If the parties cannot resolve the objection, the Customer may terminate the affected subscription without penalty and receive a pro-rata refund of any prepaid fees for the unused period.
8. Assistance with data subject rights
Taking into account the nature of the processing, the Provider shall assist the Customer by appropriate technical and organisational measures, insofar as this is possible, in fulfilling the Customer’s obligation to respond to requests to exercise data subject rights.
The service provides the Customer with direct access to Customer Personal Data through the application, including the ability to view, correct, export and delete records. Where the Customer can act on a request itself using those features, that is the Provider’s assistance. Where it cannot, the Provider shall provide reasonable additional assistance on request.
If the Provider receives a request directly from a data subject in relation to Customer Personal Data, it shall not respond to the substance of the request and shall refer the data subject to the Customer without undue delay.
9. Personal data breaches and impact assessments
The Provider shall notify the Customer without undue delay, and in any event within 48 hours, after becoming aware of a personal data breach affecting Customer Personal Data. The notification shall describe, to the extent known, the nature of the breach, the categories and approximate number of data subjects and records concerned, the likely consequences, and the measures taken or proposed.
The Provider shall provide reasonable assistance to the Customer with data protection impact assessments and any prior consultation with a supervisory authority, taking into account the nature of the processing and the information available to the Provider.
10. Deletion and return
On termination or expiry of the Customer’s subscription, the Provider shall, at the Customer’s choice, delete or return Customer Personal Data, save to the extent it is required to retain a copy by law.
In practice this operates as follows. The Customer may export its records at any time, including after cancellation, using the export feature in the application. Customer Personal Data is retained for 90 days after cancellation takes effect so that the account can be reactivated without loss, and is then deleted from the live service. Because encrypted offsite backups are retained on a rolling 30-day cycle, a copy may persist in those backups for up to 30 days beyond the 90-day period, after which it is overwritten. Backups are not accessible to the Customer and are used only for disaster recovery.
The Customer may request earlier deletion from the live service by contacting privacy@keystonehse.com.
11. Audits and information
The Provider shall make available to the Customer all information reasonably necessary to demonstrate compliance with this DPA, and shall allow for and contribute to audits, including inspections, conducted by the Customer or an auditor it mandates.
Audits shall be conducted on at least 30 days’ written notice, no more than once in any 12-month period unless required by a supervisory authority or following a personal data breach, during normal business hours, and subject to reasonable confidentiality undertakings. The parties shall each bear their own costs. The Provider may satisfy an audit request by providing written responses and supporting documentation where these reasonably address the Customer’s enquiry.
12. International transfers
Customer Personal Data is hosted within the European Economic Area. Certain sub-processors listed in Annex 3 are established outside the EEA and the United Kingdom. Where personal data is transferred to such a sub-processor, the Provider shall ensure an appropriate transfer mechanism is in place, such as the UK International Data Transfer Addendum, the EU Standard Contractual Clauses, or a finding of adequacy.
Jersey is recognised by the European Commission as providing an adequate level of data protection.
13. Liability
Each party’s liability arising out of or in connection with this DPA is subject to the limitations and exclusions of liability set out in the Terms of Service. Nothing in this DPA limits either party’s liability to a data subject, or in respect of any fine or claim to the extent it cannot lawfully be limited.
14. Term and changes
This DPA takes effect when the Customer accepts the Terms of Service and continues for as long as the Provider processes Customer Personal Data.
The Provider may update this DPA where required by a change in Data Protection Law, in the service, or in its sub-processors. Material changes will be notified in accordance with the change process in the Terms of Service. The current version and its effective date are shown at the top of this page.
15. Governing law
This DPA is governed by the law of Jersey, and the parties submit to the exclusive jurisdiction of the courts of Jersey, consistent with the Terms of Service.
Annex 1 — Details of the processing
Subject matter
Provision of the Keystone HSE platform: the generation, storage, issue and record-keeping of health and safety documentation on the Customer’s behalf.
Duration
The term of the Customer’s subscription, plus the retention periods described in clause 10.
Nature and purpose
Hosting, storage, structuring, retrieval, generation of documents, rendering to PDF, transmission of notifications by email and push message, and backup. Content is submitted to an artificial intelligence sub-processor in order to draft and tailor documentation. That content is not used to train the sub-processor’s models.
Categories of data subject
- The Customer’s employees, operatives and crew members;
- The Customer’s administrative and office users;
- Individuals named in the Customer’s health and safety records, including site contacts, witnesses to incidents, and injured persons who may not be employed by the Customer.
Types of personal data
- Name, job role and employer;
- Contact details, where the Customer records them;
- Training, competency and medical-surveillance certificates, and their expiry dates;
- Digital signatures captured on briefing records, permits and site documents;
- Photographs taken on site and attached to submissions;
- Hand-arm vibration exposure records and calculated exposure points;
- Accident, injury and near-miss records, including body part affected, apparent cause, first aid given and investigation findings;
- Account identifiers, hashed credentials, and authentication and session metadata;
- IP addresses and technical metadata recorded in application logs.
Special category data
Data concerning health, arising from accident, injury and near-miss records, hand-arm vibration exposure records, and any medical-surveillance or fitness certificates the Customer chooses to upload.
Annex 2 — Technical and organisational measures
The Provider maintains technical and organisational measures appropriate to the risk. At the effective date of this DPA these include:
- Encryption in transit. All traffic to the service is served over TLS, with HTTP Strict Transport Security enabled.
- Credential protection. Account passwords are stored as salted one-way hashes, never in plain text. Tenant-specific API credentials are held encrypted.
- Tenant isolation. Every request is scoped to a single customer, derived from the authenticated session rather than from any value supplied by the client, and each customer’s documents, libraries and database are held separately. Isolation is tested independently of the application code.
- Authentication and access control. Sessions use signed tokens. Administrative functions, and access to the accident and incident register, are restricted to the Customer’s own administrator users. Crew accounts are confined to the mobile application and cannot reach desktop functions.
- Infrastructure security. Remote administrative access requires cryptographic keys; password-based and direct root access are disabled. Security updates are applied automatically. A content security policy, security response headers and rate limiting are in force.
- Personnel. Access to production systems is limited to those who require it in order to operate the service, subject to the confidentiality duty in clause 5.
- Backup and recovery. Encrypted offsite backups are taken nightly and retained on a rolling 30-day cycle. A documented recovery procedure exists, including restoration of a single customer’s data in isolation, and is tested.
- Logging and retention. Application logs are retained for 30 days and then purged.
- AI processing. Content submitted to the artificial intelligence sub-processor is processed under terms that prohibit its use for model training.
A fuller description of these measures is available to Customers on request, subject to a reasonable confidentiality undertaking, and to auditors under clause 11. The Provider does not publish detailed configuration information, as doing so would itself weaken the security of the service.
Annex 3 — Authorised sub-processors
| Sub-processor | Purpose | Location |
|---|---|---|
| Hetzner Online GmbH | Hosting infrastructure: application servers and databases | Germany |
| Anthropic PBC | Large-language-model API used to draft, polish, suggest and analyse documentation | United States |
| Paddle.com Market Limited | Payment processing as Merchant of Record | United Kingdom |
| Resend, Inc. | Transactional email delivery | United States |
| Backblaze, Inc. | Encrypted offsite backup storage | United States |
| Namecheap, Inc. | Inbound email hosting for the Provider’s mail accounts | United States / European Union |
Website analytics are self-hosted by the Provider and involve no third-party analytics processor, no third-party cookies and no cross-site tracking.
Questions about this DPA: privacy@keystonehse.com. Legal contact: legal@keystonehse.com.