Data processing agreement

Last updated on

If you use SecretsMonkey within an organisation, you are the controller for the data your people share with it and we are the processor. This agreement records what we do and do not do in that role. It applies as soon as you use the service with an account and forms one whole with the privacy statement and the terms of use.

Parties and roles

The controller is the organisation holding the account. The processor is MonkeySoft, Eiland van Surya 23, 1705 SH Heerhugowaard, Chamber of Commerce 37133843.

We process solely on the instruction of the controller and never use the data for our own purposes, not for training models and not for building profiles.

Subject matter and duration

The subject matter of the processing is the encrypted, single-use transfer of confidential data between a sender and a recipient, and the requesting thereof.

The agreement runs for as long as the account exists and ends when it is deleted.

Data subjects and data

The processing concerns the following categories:

  • Data subjects: employees and users of the controller, and the recipients they send a link to.
  • Account holder data: name, email address, fingerprint of the password, and the details for two-factor authentication or passkeys.
  • Data inside the secrets themselves: unknown to us, because it is encrypted with a key we do not hold. What goes into it is determined by the controller.
  • Metadata: expiry times, counters, a fingerprint of the network block and a coarse device label per access attempt.

Processing on instruction

We process only on documented instruction from the controller. That instruction consists of the use of the service as described in the documentation and the terms of use.

Where Union or member state law obliges us to process beyond that, we report it in advance, unless that law forbids such notification.

Confidentiality

Everyone on our side with access to the systems is bound to confidentiality. Access to production systems is limited to the people who need it and runs through multi-factor authentication.

Security measures

The most important measure sits in the design: the content of a secret is encrypted with a key that exists only in the share link and that we do not store. A copy of our database therefore contains no readable secrets.

In addition, the following apply among others:

  • Encrypted traffic between browser and server, with strict security headers and a content policy that blocks third-party scripts.
  • Passwords are stored as a fingerprint using a deliberately slow algorithm; two-factor authentication and passkeys are available.
  • Rate limits on creating, opening, answering and signing in, to slow down guessing and overloading.
  • A contentless audit trail of security-relevant actions, into which no secret, password or token ever ends up.
  • Data minimisation on origin: network block instead of IP address, device kind instead of full browser string.
  • Separation between organisations, so nobody outside an organisation can see its secrets.
  • Encrypted backups, kept within the European Economic Area.

Sub-processors

We engage the following sub-processors:

  • Hetzner, Germany — servers and storage.
  • Lettermint, the Netherlands — sending of email.

Changes to sub-processors

If we add a sub-processor or replace one, we announce it at least thirty days in advance. The controller may object; if we cannot reach agreement, the agreement may be terminated at no cost.

Transfers outside the EEA

These do not take place. All processing, storage and backup happens within the European Economic Area.

Assistance with data subject rights

If the controller receives a request for access, correction, erasure or portability, we assist within a reasonable period and at cost price. If such a request reaches us directly, we forward it and do not answer it ourselves.

Data breaches

In the event of a personal data breach we notify the controller without undue delay and at the latest within forty-eight hours of discovery, with what we know about its nature, scope and the measures taken. Notification to the supervisory authority is made by the controller.

Return and deletion

On termination we erase the data. Deleting the account wipes the account data and the associated secrets immediately; the security logs lose their reference to the person in doing so and then expire within their own retention period.

An export of the data before deletion can be supplied on request.

Audit

The controller may verify once a year that we abide by this agreement, and more often where there is concrete cause. Notice at least thirty days in advance; the costs are for the controller, unless the audit reveals a shortcoming on our side.

Signing and contact

If you need a signed copy, or your own model instead of this one, send a message to hallo@monkeysoft.nl.