Takes effect when Vallkey opens. The version in force is published here with its date.
This agreement applies when an organization uses Vallkey for Teams or Business, and Vallkey processes personal data on its behalf. It follows Article 28 of the GDPR.
Roles
The organization is the controller of its members’ account data. Vallkey is its processor. Vault contents are encrypted end to end: Vallkey can’t access them, and processes them only as encrypted data to store and sync.
What Vallkey processes
Members’ email addresses, encrypted vault data, device records, and administrative records such as audit logs, for as long as the organization’s subscription lasts.
Vallkey’s commitments
- Process data only on the organization’s documented instructions.
- Keep staff with access bound by confidentiality.
- Apply the security measures described in the trust center.
- Use only the subprocessors listed, telling the organization 30 days before adding one.
- Help with data subject requests and with data protection impact assessments.
- Report a personal data breach without undue delay, and within 48 hours of becoming aware of it.
- Delete or return data when the subscription ends.
- Make available the information needed to show compliance, and allow audits.
International transfers
Where data leaves the EEA, transfers rely on the European Commission’s Standard Contractual Clauses.
Signing
Business customers can ask for a signed copy at sales@vallkey.com.
Last updated October 3, 2026