Data processing agreement

Data processing agreement

Last updated 6 October 2026

What this agreement is

This data processing agreement is part of the terms between your business ("you") and Axentra Portal L.L.C. S.O.C, Tamani Arts Office, Business Bay, Dubai (Dubai Economy and Tourism licence 1581964), the operator of Kept ("we"). It applies whenever Kept processes personal data on your behalf. You decide why and how that data is processed (you are the controller); we process it only for you (we are the processor).

It is written for Federal Decree-Law No. 45 of 2021 on the Protection of Personal Data. If your business is established in the DIFC or ADGM, it also covers the processor requirements of DIFC Data Protection Law No. 5 of 2020 and the ADGM Data Protection Regulations 2021. If the EU General Data Protection Regulation applies to you, it covers Article 28 of that regulation.

It takes effect when you accept the terms. If you need a signed copy, write to hello@getkept.ae.

Subject, duration and purpose

We process personal data to provide Kept to you: to store, organise, calculate, display, export and send your accounting, VAT, corporate tax, payroll and e-invoicing records; to read documents automatically; and to support you when you ask. Processing lasts for as long as you use Kept and ends with deletion as described below.

Whose data and what data

People: your users; your customers, suppliers and their contact persons; your employees and contractors; your owners, shareholders and related parties.

Data: names and contact details; tax registration numbers; bank account details; invoices, receipts, payments and other documents; salaries, allowances, leave and end-of-service details; Emirates ID, passport and labour card numbers; and anything else contained in documents you put into Kept.

Kept is not built for health or other sensitive data. Do not put such data into Kept unless your accounting needs it.

Our obligations

We process the data only on your documented instructions: these terms, your use of Kept's features, and instructions you send us in writing. If we think an instruction breaks the law, we tell you.

Everyone who can access the data is bound to confidentiality. We do not sell the data, use it for our own purposes or use it to train AI models.

We help you answer requests from the people the data is about (Kept's export and correction features do most of this) and, where needed, with risk assessments and questions from a data protection authority.

Sub-processors

You allow us to use the providers listed in our privacy policy. Each one is bound by a contract with data protection obligations at least as protective as this agreement, and we remain responsible to you for them.

We announce a new provider on the privacy policy page and by email to account owners at least 30 days before it starts processing your data. If you object for a reasonable data protection reason and we cannot resolve it, you may end your plan and we refund the prepaid, unused part.

Security measures

• Encryption of every connection to Kept and of stored data at our database provider.

• Each business in its own separate space, enforced by security rules inside the database, and role-based access inside a business.

• Books that are not edited or deleted (corrections are new, visible entries) and a log of who changed what and when.

• Regular backups by our database provider.

• Technical access to the systems only for the people who run Kept, and keys and passwords kept out of the code and changed regularly.

We review these measures as Kept and the risks change, and do not reduce their overall level.

Personal data breaches

If we become aware of a breach affecting your personal data, we tell you without undue delay and no later than 72 hours after we became aware of it. We tell you what happened, which data and people are affected, what we have done and what you should do, and we help you with any notice you must give to an authority or to the people affected.

Transfers outside the UAE

Kept's database is hosted in Tokyo, Japan; we are moving it to Mumbai, India. Some providers process data in the United States or Ireland, as listed in the privacy policy. We make these transfers only with the safeguards the applicable law allows, in particular the providers' data protection agreements and, where a provider offers them, standard contractual clauses. For a business in the DIFC or ADGM, transfers to a country not recognised as adequate there are made under such contractual safeguards.

When your plan ends

When your plan ends, your books stay readable and exportable in common formats. When the owner asks us in writing to delete the company, we delete its data within 30 days, and copies in backups are overwritten within a further 30 days, unless UAE law requires us to keep it. We confirm the deletion in writing on request.

Information and audits

We answer reasonable written questions about how we protect your data and give you the security reports and certifications our main providers publish. Where the law requires it, you or an auditor bound to confidentiality may inspect our compliance once a year, at your cost and with 30 days' notice.

Liability and order of documents

Liability under this agreement follows the terms. If this agreement and the terms differ on the protection of personal data, this agreement applies.

Contact

Questions about this agreement or about personal data in Kept: hello@getkept.ae.