Last updated 2026-07-01
Roles
Where you use the service to process personal data of your employees, customers, or other individuals, you act as controller and we act as processor. This agreement forms part of the Terms of Service for such customers.
Processing instructions
We process personal data only on your documented instructions, which are given through your configuration and use of the service, unless required otherwise by law — in which case we will inform you before processing unless the law prohibits it.
Confidentiality and security
Personnel with access to personal data are bound by confidentiality obligations. We maintain technical and organisational measures appropriate to the risk, including encryption in transit and at rest, client-side encryption for vault content, role-based access control, least-privilege administrative access, and logging of administrative actions.
Subprocessors
You give general authorisation for the subprocessors listed in our Third-Party Services page. We will give at least 30 days' notice before adding or replacing a subprocessor, and you may object on reasonable data protection grounds.
Assistance and breach notification
We assist you with data subject requests, data protection impact assessments, and consultations with supervisory authorities, taking into account the nature of processing. We notify you without undue delay and in any case within 72 hours of becoming aware of a personal data breach affecting your data.
Deletion and audit
On termination we delete or return personal data at your choice, subject to legal retention requirements. We make available the information necessary to demonstrate compliance and will accommodate audits, ordinarily by providing documentation and completing questionnaires.