Last updated: April 20, 2026
This page details how Keptly complies with the EU General Data Protection Regulation (Regulation 2016/679 — GDPR) and the French Data Protection Act ("Loi Informatique et Libertés").
Privacy-by-design is a core principle of Keptly. We:
| Scenario | Role of Keptly | Role of Merchant |
|---|---|---|
| Merchant account data (shop email, billing, settings) | Controller | Data subject |
| End-customer data processed in the App | Processor | Controller |
| Website visitor data (getkeptly.com) | Controller | Data subject |
As a data processor for the merchant's customer data, Keptly processes data only on documented instructions from the merchant (via the App's settings and the installed scopes), in accordance with Article 28 GDPR.
A standard Data Processing Agreement is available on request at hello@getkeptly.com. This DPA:
You can exercise the following rights at any time:
| Right | GDPR Article | How to exercise |
|---|---|---|
| Access | Art. 15 | Email us |
| Rectification | Art. 16 | Email us |
| Erasure ("right to be forgotten") | Art. 17 | Email us / uninstall the App |
| Restriction | Art. 18 | Email us |
| Portability | Art. 20 | Email us — we provide a JSON export |
| Objection | Art. 21 | Email us |
| Withdraw consent | Art. 7(3) | Email us / unsubscribe link |
| Lodge a complaint | Art. 77 | Contact the CNIL (www.cnil.fr) |
All requests are answered within one (1) month, extendable to three (3) months if the request is complex, per Art. 12(3) GDPR.
The complete, up-to-date list of sub-processors is available in our Privacy Policy, Section 5. We notify controllers of any intended addition or replacement of sub-processors at least 30 days in advance.
Data transferred outside the EEA is protected by:
Keptly applies the strictest possible retention policy:
app/uninstalled webhookcustomers/redact webhook) trigger immediate deletion of that customer's recordGiven the scale of our processing (primarily B2B, no sensitive data categories under Art. 9 GDPR), we are not required to designate a DPO under Art. 37 GDPR. Vincent Lebrun, as the legal representative of Synnervate, handles all data protection inquiries.
The competent supervisory authority for Keptly is the Commission Nationale de l'Informatique et des Libertés (CNIL):
For any GDPR-related question, to request a DPA, or to exercise a right:
Vincent Lebrun — Synnervate
4 allée Catherine Sauvage, 35136 Saint-Jacques-de-la-Lande, France
Email: hello@getkeptly.com