Scope and roles
This policy applies to the public Keyrax website, user accounts and the Keyrax Pro workspace. Keyrax is the controller for account, security, support and website analytics data.
A company using Keyrax generally decides why client, site, equipment and work-history data is entered into its workspace. For that workspace content, the company is the controller and Keyrax processes the data to provide the service.
Data we process
- Account and membership data: name, email address, sign-in method, company memberships, roles and permissions.
- Workspace data entered by users: clients and contacts, sites or vehicles, equipment, tasks, work records, notes, photos and documents.
- Contractor report data submitted through a protected work-order link, including report text and uploaded files.
- Technical and security data: IP address, browser and device information, timestamps, request and error logs, and session identifiers.
- Website analytics data, such as pages viewed, visit source, approximate location and device category, only after analytics consent.
Purposes and legal bases
- Provide accounts, workspaces, team access and requested product functions — performance of a contract or steps requested before a contract.
- Protect accounts, prevent abuse, diagnose faults and maintain the service — our legitimate interests in operating a secure and reliable service.
- Send account verification, password recovery and service messages — performance of the service and security.
- Measure public-site usage with Google Analytics — consent, which may be refused or withdrawn at any time.
- Keep records required by applicable law and respond to lawful requests — compliance with legal obligations.
Recipients and service providers
Data is available to authorised members of the relevant company according to their permissions. A contractor receives only the information deliberately shared in a work order.
We may use hosting, storage, email delivery, authentication, security and monitoring providers acting on our instructions. Google receives analytics data only after consent and receives authentication data when a user chooses Google sign-in. On sign-in, registration and password reset forms Cloudflare Turnstile checks that the visitor is not a bot; for this Cloudflare processes the IP address and technical browser and device data. We do not sell personal data.
International transfers
Some service providers may process data outside Latvia or the European Economic Area. Where required, transfers are protected by an adequacy decision, standard contractual clauses or another lawful safeguard.
Retention
Account and workspace data is kept while the relevant account or company workspace is active and afterwards only as needed for backups, security, dispute resolution and legal obligations. Logs are retained for a limited operational period. Analytics data follows the retention setting of the Keyrax Google Analytics property.
Deleting a user account does not automatically remove data that belongs to a company workspace and is needed by its other members. A company may contact us about export or deletion of its workspace.
Your rights
- Request access to and a copy of your personal data.
- Correct inaccurate data and request deletion or restriction where applicable.
- Receive portable data where the right to portability applies.
- Object to processing based on legitimate interests.
- Withdraw consent at any time without affecting processing that took place before withdrawal.
- Lodge a complaint with the Latvian Data State Inspectorate (Datu valsts inspekcija) or another competent supervisory authority.
Security and contact
Keyrax uses company separation, permission checks, protected file delivery, access controls and other technical and organisational measures. No online system can guarantee absolute security.
Contact the privacy address shown on this page to exercise your rights or ask a data-protection question. We may need to verify your identity before fulfilling a request.
We may update this policy when the service or legal requirements change. The effective date at the top identifies the current version.