Dual Login
← Trust Center

Data Processing Addendum (DPA)

Last updated: August 9, 2026

This Data Processing Addendum ("DPA") applies where Keyback Systems Ltd. processes personal data on behalf of a business customer ("Customer") in providing the Services, and where data protection law (such as the GDPR or UK GDPR) requires such terms. It forms part of our Terms of Service. To request a signed copy, email legal@duallogin.com.

In plain English

A policy has to be precise, which makes it hard to read. Here is the same document answered as the questions people usually arrive with. It is a summary: where the two could be read differently, the numbered sections below govern.

Do I need this document?

Only if you are a business putting other people's personal data through the Services and your own data protection obligations require terms with your vendors — typically GDPR or UK GDPR. If you are one person managing your own accounts, the Privacy Policy is the document that describes your relationship with us, and this one does not add anything you need.

Who is responsible for what?

Section 1 sets the roles. For the data you decide to put through the platform, you are the controller and we are the processor: you determine why it is being processed and we act on your instructions. For our own relationship with you — your account, your billing, the emails we send you — we are the controller and the Privacy Policy governs.

Who else touches the data?

Subprocessors, under section 6: infrastructure and payment providers, each engaged for a specific job and bound to terms no weaker than these. They are not a hidden set of hands. If you need the current list for your own records, ask.

What happens if there is a breach?

Section 9. We notify you without undue delay, with enough detail for you to meet your own notification deadlines — which are short and start running whether or not your vendor has been in touch. A breach notice that arrives without the facts you need to file your own is a formality; the point of this clause is to give you the substance in time to use it.

Can I get my data back, or have it deleted?

Both, under section 10, on termination and on request during the term. Deletion means deletion, allowing for the backup cycles to age out, and section 11 covers the audit rights that let you verify it rather than take our word.

Can I get a signed copy for our vendor file?

Yes. Email legal@duallogin.com and say which entity should be named. This is a routine request and it does not require a call, a sales process, or a plan upgrade.

Which parts of the platform involve us as your processor?

The parts where you decide what goes in. Profile data you sync, team member records you create, and anything your own work puts through the Services. Our own relationship with you -- your account, your billing, our emails to you -- is not processing on your behalf, and the Privacy Policy governs it instead. Section 1 draws that line, and it is worth reading carefully because it determines which document answers a given question.

Do you use standard contractual clauses?

Where a transfer needs a lawful basis, yes -- section 7 covers the transfer mechanisms. The relevant point for a reviewer is that transfers are addressed explicitly rather than left to be discovered, and the safeguards travel with the subprocessors under section 6.

How long does deletion actually take?

Live systems immediately on request; backups age out on their normal cycle rather than being surgically edited, which is the honest answer every provider should give and not all do. Section 10 sets this out. A vendor claiming instantaneous deletion from immutable backups is describing an architecture that does not exist.

A data subject has come to us with a request. What do you do?

Assist, under section 8. You hold the relationship with that person and you make the decision; we provide what is needed to act on it within your deadline. If a request reaches us directly for data we hold on your behalf, we route it to you rather than answering it ourselves, because answering it ourselves would be acting outside your instructions.

1. Roles

For personal data processed on the Customer's behalf, the Customer is the controller and Dual Login is the processor. Each party will comply with its obligations under applicable data protection law.

2. Scope and instructions

Dual Login processes personal data only to provide and support the Services, and following the Customer's documented instructions (including these Terms), unless the law requires otherwise. If we believe an instruction breaks the law, we will tell the Customer.

3. Nature of processing

The subject matter is the provision of the Services. Data may include account and team contact details and any personal data contained in browser profiles the Customer chooses to sync. Data subjects may include the Customer's staff and its own contacts.

4. Confidentiality

We ensure that personnel authorised to process personal data are bound by confidentiality obligations.

5. Security

We implement appropriate technical and organisational measures to protect personal data, as described in our Security Policy, taking into account the state of the art and the risks involved.

6. Subprocessors

The Customer authorises Dual Login to engage subprocessors (such as hosting, payment and email providers) to help deliver the Services. We impose data protection obligations on subprocessors that are no less protective than this DPA, and we remain responsible for their performance. We will inform Customers of material changes to our subprocessors on request.

7. International transfers

Where we transfer personal data across borders, we use appropriate safeguards such as the Standard Contractual Clauses.

8. Data subject rights and assistance

Taking into account the nature of the processing, we will assist the Customer with reasonable measures to help it respond to data subject requests and to meet its obligations for security, breach notification and impact assessments.

9. Breach notification

We will notify the Customer without undue delay after becoming aware of a personal data breach affecting the Customer's data, with the information reasonably available to us.

10. Deletion and return

On termination, we will delete or return the Customer's personal data as described in our Privacy Policy, subject to legal retention requirements.

11. Audits

We will make available information reasonably necessary to demonstrate compliance and allow for audits, subject to reasonable notice, confidentiality and frequency limits.

This document is provided for transparency and does not constitute legal advice. If you have questions, contact us at legal@duallogin.com.