1. Scope & Parties
This Data Processing Agreement regulates Keyton ApS (Processor) processing of personal data on behalf of the Customer (Controller) in providing the Regsta SaaS workforce platform.
Compliance
GDPR Article 28 Data Processing Agreement for Regsta workforce compliance platform.
This Data Processing Agreement regulates Keyton ApS (Processor) processing of personal data on behalf of the Customer (Controller) in providing the Regsta SaaS workforce platform.
Data processed includes standard personal data: name, email, employee ID, shift timestamps, breaks, shift approvals, correction reasons, and audit logs. Zero sensitive personal data (special categories) and zero GPS tracking data are processed.
The Processor processes personal data solely on documented instructions from the Controller and ensures personnel authorized to process personal data have committed themselves to confidentiality.
Measures include PostgreSQL Row-Level Security (RLS) for tenant isolation, TLS 1.3 transit encryption, AES-256 rest encryption, immutable audit ledgers, and hosting within the European Union (Germany/Frankfurt).
Approved EU sub-processors include Supabase Inc. (Database & Auth, EU Frankfurt), Vercel Inc. (Edge deployment, EU), and Upstash Inc. (Rate limiting, EU).
The Processor provides self-service features for access, rectification, export, and deletion. Employees have direct access to view and export their own work-time data.
Upon contract termination, the Controller may export all historical time and audit data. Data is retained for the customer's configured statutory period (5 years by law) and purged automatically thereafter.