1. Parties and taking effect
The processor is Bröderna Saxin AB, operating as PineCore Systems, company no. 559379-4364, Lindesby 152, 713 94 Nora, Sweden. The controller is the organisation identified in the written confirmation. If that organisation acts as a processor, these terms apply to PineKey as its subprocessor within the documented processing chain.
This DPA takes effect when both parties confirm in writing the customer’s identity, authorised contact, this version and the processing scope below. Publishing or reading this page alone does not create an executed agreement. Request confirmation at [email protected]. No paid subscription is required. Do not include vault secrets in the request.
The confirmation records the relevant provider contracts and international-transfer safeguards before covered processing begins. Any unresolved hosting or transfer requirement must be settled in that confirmation. Mandatory data-protection law prevails; this DPA prevails over conflicting service terms about processing.
2. Processing schedule
| Subject | Agreed default scope, completed in the written confirmation |
|---|---|
| Service and purpose | Providing an encrypted organisation vault, collection access, membership, synchronisation, security events and related service/support operations. |
| Nature of processing | Receipt, encrypted storage, transmission, retrieval by authorised clients, access administration, backup, recovery and deletion. No independent advertising or AI-training use of customer content. |
| Duration | For the covered service relationship, followed by the restricted return/deletion and backup period below. |
| Data subjects | The controller’s staff, contractors, invited collaborators and people whose data the controller lawfully places in vault items. |
| Data categories | Contact and account identifiers, organisation membership/permissions, activity metadata, and encrypted credentials, notes and other fields selected by the controller. |
| Sensitive data | The controller must assess whether special-category, criminal-record or otherwise high-risk data is appropriate. Requirements beyond this documented beta must be agreed before such processing. |
| Locations and contacts | Primary hosting in Helsinki, Finland; support from Sweden. The provider register identifies international supporting services. Each party’s authorised privacy/security contact is recorded in the confirmation. |
3. Instructions and confidentiality
We process covered data only on the controller’s documented instructions, including instructions concerning transfers, unless applicable law requires otherwise. We inform the controller of that requirement unless prohibited. We notify the controller if an instruction appears to infringe data-protection law. People authorised to access covered information must be bound by confidentiality and receive access only as necessary. The controller remains responsible for a lawful purpose, legal basis, member permissions and the information given to data subjects.
4. Technical and organisational measures
- Vault content encryption in the client; protected account and organisation keys; TLS for service connections.
- Authenticated sessions, same-origin checks, device revocation and role/collection access controls.
- Restricted host access, isolated service containers and encrypted routine server backups.
- Service updates, activity records and restore checks supporting operational security.
- Local key locking and optional two-factor sign-in; users and controllers must configure the controls appropriate for them.
The current security description is part of the processing schedule. The beta has no independent security certification and no automated offsite backup. These limitations must be assessed by the controller before use. Material reductions in agreed protection require notification and resolution, not a silent change to this schedule.
5. Subprocessors and international transfers
The controller gives general written authorisation for the providers recorded with the confirmation. We bind subprocessors to equivalent applicable processing obligations and remain responsible for their performance of those obligations. We give at least 30 days’ notice before adding or replacing a subprocessor for covered processing, allowing a reasoned objection. We work to resolve it; if no suitable alternative is available, the controller may end the affected processing without a termination penalty. Transfers outside the EEA require a valid Chapter V mechanism and any necessary supplementary measures; a sending-region or server-location setting alone is insufficient.
6. Assistance and incidents
Taking account of the nature of the processing and information available to us, we assist the controller with data-subject requests, security obligations, impact assessments and prior consultation. We forward a request concerning controller data to its authorised contact unless legally required to act directly. We notify that contact without undue delay after becoming aware of a personal-data breach, providing available details about its nature, affected data, likely consequences and mitigation, with updates as facts become known. The controller handles required notifications to authorities and data subjects, with our assistance.
7. Information and audit
We make information reasonably necessary to demonstrate compliance available and allow and contribute to audits, including inspections by the controller or its mandated auditor. The parties coordinate timing, confidentiality and scope to protect other customers and avoid unnecessary disruption; these arrangements must not prevent a legally required or incident-driven audit. We notify the controller promptly if we believe an audit instruction infringes data-protection law.
8. Return and deletion
At the controller’s choice, covered data is returned through available export facilities or deleted when processing ends, unless law requires storage. The controller must perform content export while it retains its decryption keys; we cannot supply decrypted content. Active copies are removed without undue delay following the verified instruction. Historical encrypted backups remain restricted to recovery until the published rotation of 30 daily, 8 weekly and 12 monthly restore points removes them. They are not used for ordinary processing; any restoration must reapply deletion instructions. The parties agree any stricter deletion requirement before processing begins. We confirm completion on request and describe any legally required exception.