Back to Keywindow

Data-processing terms

Effective 20 August 2026. Beta version 2.

These terms apply when a host or organisation uses Keywindow to process guest, cleaner, contractor or visitor data. The host is the controller and Keywindow is the processor.

Instructions and purpose

We process names, optional recipient email addresses, access windows, encrypted PINs, lock identifiers and lock events only to provide, secure and support Keywindow, on your documented instructions expressed through the service and support requests.

Confidentiality and security

People authorised to process customer data must keep it confidential. We use access controls, HTTPS, encryption of stored SmartThings tokens and PINs, secret redaction, operational monitoring and controlled backups appropriate to the beta service.

Subprocessors

You authorise the providers listed on the subprocessors page. We remain responsible for imposing appropriate data-protection obligations on subprocessors. We will give reasonable notice of a material new subprocessor.

Requests, incidents and deletion

We will provide reasonable assistance with data-subject requests, security incidents and compliance information. We will notify affected controllers without undue delay after confirming a personal-data breach. On account deletion we remove live account data, subject to limited backup retention and legal obligations.

International transfers

Where data leaves the UK or EEA, we rely on an adequacy decision, approved contractual safeguards or another lawful transfer mechanism provided by the relevant subprocessor.

Audit information

We will make reasonable security and compliance information available. Formal on-site audits are not included in the free beta but mandatory legal rights remain unaffected.

Questions should be sent to the contact address in your beta invitation.