Data Processing Addendum
This DPA forms part of the LifeKeep Terms of Service for customers who require one for procurement, vendor risk, or data protection compliance purposes.
This Data Processing Addendum ("DPA") forms part of the Terms of Service between Empowered Dynamics FZ-LLC ("Processor", "LifeKeep", "we", "our", or "us") and the customer using LifeKeep ("Controller", "Customer", or "you"). This DPA applies where LifeKeep processes Personal Data on behalf of the Customer in connection with the Services.
1. Definitions
Unless otherwise defined in this DPA:
- Applicable Data Protection Laws means all laws relating to the protection of Personal Data, including the UK GDPR, EU GDPR, the UK Data Protection Act 2018, and any other applicable privacy legislation.
- Controller, Processor, Data Subject, Processing, Personal Data, Special Category Data, and Supervisory Authority have the meanings given in the GDPR.
2. Scope
This DPA applies whenever LifeKeep processes Personal Data on behalf of a Customer. This includes Personal Data stored, transmitted or otherwise processed through LifeKeep mobile applications, LifeKeep web services, APIs, and support services.
3. Roles
The parties agree that the Customer acts as the Data Controller and LifeKeep acts as the Data Processor.
LifeKeep processes Personal Data only on documented instructions from the Customer unless otherwise required by law.
4. Nature and purpose of processing
LifeKeep processes Personal Data solely for the purpose of providing the Services. Processing activities may include:
- Storing information
- Organising information
- Retrieving information
- Encrypting information
- Synchronising information
- Backing up information
- Securely sharing information through Trusted Access
- Maintaining account functionality
- Providing customer support
- Improving platform reliability and security
5. Categories of data
Depending on how Customers use LifeKeep, Personal Data may include:
Account information — names, email addresses, profile photographs.
Household information — documents, household records, contacts, service providers, notes, maintenance records, insurance information, financial information, legal information, and health-related information voluntarily uploaded by users.
Trusted Access information — trusted contacts, invitation details, permissions, access history.
Technical information — device identifiers, application version, diagnostic logs, IP addresses, authentication records.
6. Categories of data subjects
Personal Data may relate to Customers, household members, family members, trusted contacts, contractors, service providers, advisers, support contacts, and other individuals whose information Customers choose to store.
7. Processing instructions
LifeKeep shall process Personal Data only to provide the Services, in accordance with Customer instructions, and as required by law.
If applicable law requires processing beyond Customer instructions, LifeKeep will notify the Customer unless prohibited by law.
8. Confidentiality
LifeKeep ensures that all personnel authorised to process Personal Data are subject to confidentiality obligations, receive appropriate privacy and security training, and access Personal Data only where necessary.
9. Security measures
LifeKeep maintains appropriate technical and organisational measures designed to protect Personal Data, including encryption of data in transit, encryption of data at rest, role-based access controls, least-privilege access, multi-factor authentication for administrative access, logging and monitoring, secure software development practices, regular security updates, vulnerability management, business continuity planning, and disaster recovery procedures.
Security measures may evolve to reflect technological developments and emerging risks.
10. Subprocessors
LifeKeep may engage carefully selected subprocessors to assist in providing the Services, including providers of cloud hosting, email delivery, payment processing, customer support tools, analytics, monitoring and security services.
LifeKeep remains responsible for ensuring subprocessors provide appropriate safeguards. A current list of subprocessors will be made available upon request or published on the LifeKeep website.
11. International transfers
Where Personal Data is transferred outside the UK, EEA or another jurisdiction requiring safeguards, LifeKeep will ensure appropriate transfer mechanisms are implemented, including where applicable the UK International Data Transfer Agreement (IDTA), the UK Addendum to the EU SCCs, European Commission Standard Contractual Clauses, adequacy decisions, or other legally recognised transfer mechanisms.
12. Assistance to the Controller
LifeKeep will provide reasonable assistance to Customers in responding to access requests, rectification requests, deletion requests, restriction requests, portability requests, and objection requests, where such assistance is reasonably required and technically feasible.
13. Security incidents
If LifeKeep becomes aware of a Personal Data Breach affecting Customer Personal Data, LifeKeep will notify the Customer without undue delay, provide available information regarding the incident, investigate the incident, take reasonable steps to mitigate its effects, and cooperate with the Customer where required.
Notification does not constitute an admission of liability.
14. Data subject requests
Where LifeKeep receives a request directly from a Data Subject relating to Personal Data processed on behalf of a Customer, LifeKeep will promptly notify the Customer where legally permitted, and will not respond directly except where required by law or authorised by the Customer.
15. Audits
Upon reasonable written notice, Customers may request information demonstrating LifeKeep's compliance with this DPA. Where necessary, LifeKeep may satisfy audit obligations by providing independent audit reports, certifications, security documentation, compliance reports, or responses to reasonable security questionnaires.
Physical audits may be permitted only where legally required, subject to confidentiality obligations and reasonable notice.
16. Return or deletion of data
Upon termination of the Services, and subject to applicable law, Customers may export their Personal Data or request deletion of Personal Data.
LifeKeep will securely delete Customer Personal Data after any applicable retention period unless required by law to retain it.
17. Records of processing
LifeKeep will maintain records of processing activities where required by Applicable Data Protection Laws.
18. Liability
Liability under this DPA shall be governed by the liability provisions contained within the LifeKeep Terms of Service, except where Applicable Data Protection Laws require otherwise.
19. Governing law
This DPA shall be governed by the same governing law specified in the LifeKeep Terms of Service unless otherwise agreed in writing.
A. Annex A — Processing details
Subject matter — provision of the LifeKeep household continuity platform.
Duration — for the duration of the Customer's use of the Services.
Nature of processing — collection, storage, organisation, encryption, retrieval, sharing through Trusted Access, synchronisation, backup, and deletion.
Purpose — providing secure household organisation, continuity, trusted access and account management services.
Types of Personal Data — as described in Section 5.
Categories of data subjects — as described in Section 6.
B. Annex B — Technical & organisational measures
LifeKeep maintains measures including:
- Encryption in transit (TLS)
- Encryption at rest
- Secure authentication
- Multi-factor authentication for privileged access
- Role-based access control
- Logging and monitoring
- Security event management
- Backup and recovery procedures
- Secure software development lifecycle
- Vulnerability management
- Infrastructure security monitoring
- Staff confidentiality agreements
- Security awareness training
- Incident response procedures
- Business continuity planning
- Disaster recovery procedures
- Periodic security reviews
Future enhancements
- Subprocessor List
- Security Overview (Trust Centre)
- Data Retention Policy
- Law Enforcement Request Policy
- Vulnerability Disclosure Policy
- ISO 27001 / SOC 2 status (once certified)