Skip to content
Regsta

Legal

Data processing agreement

Regsta's standard data processing agreement under Article 28 of the GDPR. Your company is the controller and Keyton ApS is the processor. We offer it for review and signature.

Draft version 2.0 · Last updated 29 September 2026

Draft, awaiting legal review. This agreement has not yet been reviewed by a lawyer against the Danish standard clauses. It is offered for review and signature and is not a signed agreement until both parties have signed it.

1. Parties and purpose

This agreement governs how Keyton ApS (the Processor) processes personal data on behalf of the Customer (the Controller) when it provides Regsta, a service for recording working time.

The processing covers recording working time, approvals, the audit trail, checks against working-time rules, support and exports.

2. Duration

The agreement runs for as long as the Customer's Regsta agreement, plus any period needed afterwards for export, retention, deletion or legal preservation.

3. Nature of the processing and categories of data

Data subjects

  • employees;
  • Admins, Planners, Payroll and Auditor users;
  • the Customer's support contacts.

Personal data

  • name, email address and employee number;
  • role and access data;
  • time entries, including clock times and breaks;
  • approval and rejection decisions, and reasons for manual entries and corrections;
  • audit trail events and export history;
  • security metadata such as IP address and browser details (user agent).

No special categories of personal data (sensitive data) and no GPS location data are processed.

Sign-in uses a verified email address, with a sign-in link or with email and password. Phone numbers are optional contact details and are not used to sign in.

4. The Processor's obligations

The Processor processes personal data only on documented instructions from the Controller. It processes Customer data only to provide and secure the service, to support the Customer, to comply with this agreement and the law, and to carry out the Controller's documented instructions.

The Processor makes sure that everyone with access to the data is bound by confidentiality, has access only to what they need, and has received relevant security instructions.

5. Technical and organisational measures

The measures include PostgreSQL Row Level Security to keep each company's data apart, TLS encryption in transit with HSTS, encrypted webhook secrets (AES-256-GCM), and an audit trail that the database does not allow to be changed or deleted during the retention period.

Hosting in the EU: the database and sign-in in Falkenstein, Germany (Hetzner), and the application in Frankfurt, Germany (Vercel).

6. Subprocessors

The Processor uses these subprocessors: Hetzner Online GmbH (database and sign-in, Falkenstein, Germany), Vercel Inc. (application hosting, Frankfurt, Germany), Upstash, Inc. (rate limiting; region not yet recorded), Resend (email delivery) and Expo, 650 Industries, Inc. (push notifications to the mobile app, USA, delivered onward through Apple and Google; transfer mechanism not yet recorded).

Changes to subprocessors are notified in writing to the Customer's Admin before they take effect.

See the subprocessor list, including services not in use today

7. Assistance and data subjects' rights

The Processor assists the Controller with technical tools so that data subjects can exercise their rights of access, rectification, erasure and data portability. Employees can see their own time entries in Regsta and correct a shift themselves with a reason. The employer provides an export of an employee's own hours from the export page.

The Processor also assists the Controller with:

  • handling personal data breaches;
  • audits;
  • deletion and export;
  • information for the record of processing activities;
  • security documentation.

8. Deletion and return when the agreement ends

When the agreement ends, the Controller can export all historical time and audit data with the export function. Data is kept for the Customer's configured retention period (at least five years after the reference period; default 1,946 days) and is then deleted automatically.

The detailed procedure for return and deletion at the end of the agreement, and the assistance terms that go with it, have not been drafted yet.

9. Audits

The Controller may ask for documentation of the relevant technical and organisational measures. On-site audits, or audits by a third party, need prior written agreement.

10. Contact

Ask for the DPA for review and signature: hej@regsta.com