Skip to content

Compliance

Data Processing Agreement (DPA)

GDPR Article 28 Data Processing Agreement for Regsta workforce compliance platform.

01

1. Scope & Parties

This Data Processing Agreement regulates Keyton ApS (Processor) processing of personal data on behalf of the Customer (Controller) in providing the Regsta SaaS workforce platform.

02

2. Scope of Processing & Categories

Data processed includes standard personal data: name, email, employee ID, shift timestamps, breaks, shift approvals, correction reasons, and audit logs. Zero sensitive personal data (special categories) and zero GPS tracking data are processed.

03

3. Processor Obligations

The Processor processes personal data solely on documented instructions from the Controller and ensures personnel authorized to process personal data have committed themselves to confidentiality.

04

4. Technical & Organizational Measures

Measures include PostgreSQL Row-Level Security (RLS) for tenant isolation, TLS 1.3 transit encryption, AES-256 rest encryption, immutable audit ledgers, and hosting within the European Union (Germany/Frankfurt).

05

5. Sub-processors

Approved EU sub-processors include Supabase Inc. (Database & Auth, EU Frankfurt), Vercel Inc. (Edge deployment, EU), and Upstash Inc. (Rate limiting, EU).

06

6. Data Subject Rights

The Processor provides self-service features for access, rectification, export, and deletion. Employees have direct access to view and export their own work-time data.

07

7. Termination & Data Portability

Upon contract termination, the Controller may export all historical time and audit data. Data is retained for the customer's configured statutory period (5 years by law) and purged automatically thereafter.