Subprocessors and DPA

Arctickey uses a small set of infrastructure and business service providers to operate the service. This page is generated from the same public trust API used by the Trust Center.

Data Processing Agreement

A Data Processing Agreement is available on request for customers that process personal data with Arctickey.

Logged-in customers can request a DPA from the dashboard compliance page. You can also contact hello@arctickey.com with your company name, billing email, and whether you need the agreement before starting a paid subscription.

The dashboard EU Evidence Pack includes a DPA schedule starter with processing details, TOMs, subprocessors, transfer notes, retention prompts, and customer review actions for Article 28 annex review.

Active Material Change Notices

Loading current notices...

Current Subprocessors

Loading current subprocessor list...

Arctickey does not store card details directly. Card data is processed by the payment provider.

Vendor Inventory Use

Use this page with the EU Evidence Pack when recording Arctickey in a vendor inventory, Article 30 processing record, DPIA, or procurement ticket.

  • Treat Arctickey as processor for customer Valkey instance data and controller for account, billing, and service communication data.
  • Use the table below to document current recipients, processing purposes, region notes, and material-change status.
  • Attach active material-change notices and review them before regulated production use.
  • Download the EU Evidence Pack from the dashboard compliance page for a machine-readable copy of the current vendor inventory and RoPA prompts.

Customer Instance Data

Customer Valkey instance data is hosted in EU regions. The default production region is EU East.

Customer instance data is not transferred outside the EU/EEA for normal service operation.

Transfer Review Notes

Customer instance data is designed to stay in EU regions during normal service operation, but customers should still review subprocessors for account metadata, billing metadata, support workflows, and any future material changes.

  • Review each provider's region notes, privacy URL, and DPA URL where available.
  • Record whether a provider processes only business metadata or can access customer personal data.
  • Assess any active material-change notice before using Arctickey for regulated production workloads.
  • Keep support tickets free of secrets and personal data unless the case requires it.

Change Notifications

Material subprocessor changes are marked in the table and can also be published in the Trust Center material log.

Customer Responsibilities

  • Deciding what personal data they write into their Valkey instances.
  • Configuring application-level retention for their own keys.
  • Exporting or deleting application data when required by their own users.
  • Requesting a DPA before using Arctickey for regulated production workloads.