Log inJoin the waitlist

Search the help center, features, guides and more.

Legal

Data processing agreement

The terms under which Vallkey processes personal data for businesses using Vallkey for Business, as GDPR Article 28 requires.

Takes effect when Vallkey opens. The version in force is published here with its date.

This agreement applies when an organization uses Vallkey for Teams or Business, and Vallkey processes personal data on its behalf. It follows Article 28 of the GDPR.

Roles

The organization is the controller of its members’ account data. Vallkey is its processor. Vault contents are encrypted end to end: Vallkey can’t access them, and processes them only as encrypted data to store and sync.

What Vallkey processes

Members’ email addresses, encrypted vault data, device records, and administrative records such as audit logs, for as long as the organization’s subscription lasts.

Vallkey’s commitments

  • Process data only on the organization’s documented instructions.
  • Keep staff with access bound by confidentiality.
  • Apply the security measures described in the trust center.
  • Use only the subprocessors listed, telling the organization 30 days before adding one.
  • Help with data subject requests and with data protection impact assessments.
  • Report a personal data breach without undue delay, and within 48 hours of becoming aware of it.
  • Delete or return data when the subscription ends.
  • Make available the information needed to show compliance, and allow audits.

International transfers

Where data leaves the EEA, transfers rely on the European Commission’s Standard Contractual Clauses.

Signing

Business customers can ask for a signed copy at sales@vallkey.com.

Last updated October 3, 2026