Data Processing Agreement
Effective September 25, 2026
1. Parties and subject matter
This agreement governs the processing of personal data that Tripticode S.L. (Tax ID B05654819, C/ Jucar 36B, 41012 Seville, Spain), owner of Keyio (the “Processor”), carries out on behalf of the customer holding the Keyio account (the “Controller”), pursuant to Article 28 of Regulation (EU) 2016/679 (GDPR) and Spanish Organic Law 3/2018 (LOPDGDD).
It forms an integral part of the Terms of Service and is accepted together with them. For the data of the customer's own account (name, email, billing), Keyio acts as controller, as described in the Privacy Policy.
2. Nature, purpose and duration
The Processor processes the data solely to provide the contracted Keyio service: storage, organisation, consultation, submission to authorities when instructed by the Controller (e.g. SES.HOSPEDAJES), communication with data subjects by email or WhatsApp, document generation and, if the Controller enables it, automatic extraction of data from identity documents.
Processing lasts for as long as the Controller's account is active, and until the data is deleted or returned as set out in clause 9.
3. Categories of data subjects and data
- Guests and companions (traveller register, Royal Decree 933/2021): identification, document type and number, document image if scanning is used, nationality, date of birth, sex, address, contact details, relationship, stay and payment details.
- Tenants and rental candidates: identification, contact details, contract data, payments and supporting documents.
- External contacts (cleaning, maintenance staff), co-owners and signers: identification, contact details and, for signatures, IP address and user agent.
The Controller must not enter special categories of data (Art. 9 GDPR) unless required by law; free-text fields are not intended for them.
4. Processor obligations
The Processor shall:
- Process the data only on the Controller's documented instructions — this agreement, the Terms and the configuration the Controller sets in the application — including with regard to international transfers, unless required by law, in which case it will inform the Controller beforehand unless the law prohibits it. It will immediately inform the Controller if it considers an instruction infringes data protection law.
- Ensure that persons authorised to process the data have committed to confidentiality or are under a statutory obligation of confidentiality.
- Implement the security measures in clause 5.
- Engage sub-processors only as set out in clause 6.
- Assist the Controller, through appropriate technical and organisational measures, in responding to data subject requests (access, rectification, erasure, objection, restriction and portability). If a data subject contacts the Processor directly, the request will be forwarded to the Controller without delay.
- Assist the Controller in complying with Articles 32 to 36 GDPR (security, breach notification, impact assessments and prior consultation), taking into account the information available to it.
- Make available to the Controller the information necessary to demonstrate compliance with this agreement and allow audits under clause 8.
5. Security measures
The Processor applies the Article 32 GDPR measures described on the Security page and in the Privacy Policy, including: encryption in transit (TLS) and field-level encryption (AES-256-GCM) of identity documents, dates of birth, addresses, phone numbers, third-party emails and credentials; hosting of the database in the European Union; role-based access control; rate limiting and anti-abuse protection on public forms; security event logging; and daily backups.
6. Sub-processors
The Controller gives general authorisation for the Processor to engage the following sub-processors, which are contractually bound by data protection obligations equivalent to those in this agreement:
- Google Cloud / Firebase (Google Ireland Ltd.): hosting, database, authentication and file storage — European Union (Madrid and the Netherlands).
- Google (Gemini API, paid tier): document data extraction and AI features, only if the Controller uses them.
- Resend: transactional email delivery.
- Twilio: WhatsApp messaging, only if the Controller uses that feature.
- Google reCAPTCHA: anti-abuse protection for public forms.
The Processor will notify the Controller, by email or in-app notice, of any addition or replacement of sub-processors at least 30 days in advance. The Controller may object on reasonable data protection grounds by writing to info@gokeyio.com; if no solution is reached, the Controller may terminate the contract without penalty.
7. International transfers
Some sub-processors (Google for the Gemini API and reCAPTCHA, Resend, Twilio) may process data outside the European Economic Area. In those cases the transfer relies on an adequacy decision (including the EU-US Data Privacy Framework for certified entities) or on the standard contractual clauses approved by the European Commission.
8. Security breaches and audits
The Processor will notify the Controller without undue delay, and no later than 48 hours after becoming aware of it, of any personal data breach affecting data processed on its behalf, with the information available so the Controller can comply with Articles 33 and 34 GDPR.
The Controller may request from info@gokeyio.com the information necessary to verify compliance. If that information is insufficient, the Controller may carry out, directly or through an auditor bound by confidentiality, one audit per year with 30 days' notice, during business hours and without compromising the security of other customers, at its own cost.
9. End of processing
While the account is active, the Controller can export its data from the account settings and delete individual records or the whole account.
On termination of the service, at the Controller's choice, the Processor will return (via export) or delete the personal data. Deleting the account removes the data from live systems immediately; backups are overwritten on their ordinary cycle (7 days). Data that must be retained by law is kept blocked for the required period.
10. Controller obligations
The Controller warrants that it has a legal basis for the processing and for disclosing the data to the Processor, that it has informed data subjects under Articles 13 and 14 GDPR, and that its instructions comply with the law. It supervises the processing and is responsible for the data it enters into the platform.
11. Final provisions
With regard to data protection, this agreement prevails over any other provision of the Terms. The parties' liability is governed by the Terms, without prejudice to Article 82 GDPR. This agreement is governed by Spanish law.
Material changes will be notified to the Controller, who must accept them to continue using the service.