GDPR Compliance Statement

Last updated: April 20, 2026

This page details how Keptly complies with the EU General Data Protection Regulation (Regulation 2016/679 — GDPR) and the French Data Protection Act ("Loi Informatique et Libertés").

1. Our commitment

Privacy-by-design is a core principle of Keptly. We:

2. Data controller vs. data processor

ScenarioRole of KeptlyRole of Merchant
Merchant account data (shop email, billing, settings)ControllerData subject
End-customer data processed in the AppProcessorController
Website visitor data (getkeptly.com)ControllerData subject

As a data processor for the merchant's customer data, Keptly processes data only on documented instructions from the merchant (via the App's settings and the installed scopes), in accordance with Article 28 GDPR.

3. Data Processing Agreement (DPA)

A standard Data Processing Agreement is available on request at hello@getkeptly.com. This DPA:

4. Data subject rights

You can exercise the following rights at any time:

RightGDPR ArticleHow to exercise
AccessArt. 15Email us
RectificationArt. 16Email us
Erasure ("right to be forgotten")Art. 17Email us / uninstall the App
RestrictionArt. 18Email us
PortabilityArt. 20Email us — we provide a JSON export
ObjectionArt. 21Email us
Withdraw consentArt. 7(3)Email us / unsubscribe link
Lodge a complaintArt. 77Contact the CNIL (www.cnil.fr)

All requests are answered within one (1) month, extendable to three (3) months if the request is complex, per Art. 12(3) GDPR.

5. Sub-processors

The complete, up-to-date list of sub-processors is available in our Privacy Policy, Section 5. We notify controllers of any intended addition or replacement of sub-processors at least 30 days in advance.

6. International data transfers

Data transferred outside the EEA is protected by:

7. Data retention and deletion

Keptly applies the strictest possible retention policy:

8. Security measures

9. Data Protection Officer (DPO)

Given the scale of our processing (primarily B2B, no sensitive data categories under Art. 9 GDPR), we are not required to designate a DPO under Art. 37 GDPR. Vincent Lebrun, as the legal representative of Synnervate, handles all data protection inquiries.

10. Supervisory authority

The competent supervisory authority for Keptly is the Commission Nationale de l'Informatique et des Libertés (CNIL):

11. Contact

For any GDPR-related question, to request a DPA, or to exercise a right:

Vincent Lebrun — Synnervate
4 allée Catherine Sauvage, 35136 Saint-Jacques-de-la-Lande, France
Email: hello@getkeptly.com