Privacy Policy – Keystrike
Last updated: July 16, 2026

Legal

Privacy Policy

This Privacy Policy describes how Keystrike collects, uses, and shares your personal data when you use our services or otherwise interact with us. It also covers your rights and choices regarding how we process your personal data.

If you do not agree with our policies and practices, please do not use our services.

Information We Collect About You

When you visit, use, or navigate our services, we may process your personal data depending on how you interact with us, the choices you make, and the products and features you use. The personal data we collect may include:

  • Names
  • Email addresses
  • Domain and user names
  • Device data (such as device ID, device name, operating system, and IP address)
  • Usage data

All personal information you provide must be true, complete, and accurate. You must notify us of any changes to such personal information.

We also automatically collect certain information when you visit, use, or navigate our services. This may include your IP address, browser and device characteristics, operating system, language preferences, referring URLs, device name, browser type, hardware model, country, location, and information about how and when you use our services. This information is primarily needed to maintain the security and operation of our services, and for our internal analytics and reporting purposes.

We may collect information through cookies and similar technologies to access or store information. Specific information about how we use such technologies and how you can refuse certain cookies is set out in our Cookie Policy.

Usage data is service-related, diagnostic, and performance information our servers automatically collect when you access or use our services. This may include your IP address, device information, browser type, settings, and information about your activity in the services — such as date/time stamps, pages and files viewed, searches, features used, and device event information (system activity, error reports, and hardware settings).

How We Process Your Personal Data

We process your data to provide, improve, and administer our services, communicate with you, for security and fraud prevention, and to comply with law. We may also process your information for other purposes with your prior consent.

How We Disclose Your Personal Data

We may share your data with third-party vendors, service providers, contractors, or agents who perform services for us or on our behalf. We have contracts in place with all third parties to ensure they cannot use your personal data for any purpose other than what we have instructed, will not share it with any other organisation, and will protect and retain it in line with our instructions.

Our current Sub-Processors are:

Google Cloud Platform Cloud computing services
Sendgrid Email delivery
Zendesk Helpdesk and customer support
Google Analytics Web and mobile analytics

How We Store and Secure Your Personal Data

We have implemented appropriate technical and organisational measures to ensure a level of security appropriate to risk, including the measures referred to in Article 32(1) of the GDPR.

  • Your personal data is encrypted at rest in Google Cloud Platform using Google encryption keys.
  • Access to your personal data is only available through a bastion host configured to withstand attacks from external networks.
  • We employ least-privilege access mechanisms and role-based access controls to ensure access to personal data is for an appropriate, approved purpose.
  • We conduct third-party penetration testing yearly to identify and mitigate security vulnerabilities.
  • We employ a point-in-time restore of data.

In assessing the appropriate level of security, we take into account in particular the risks presented by processing, especially from a personal data breach.

How Long Do We Keep Your Information?

How long we keep your personal data depends on the type of data and how we process it. We will only keep your personal data for as long as it is necessary for the purposes set out in this Privacy Policy and our legitimate business interests, or where a longer retention period is required or permitted by law (such as for tax, accounting, or other legal requirements).

When we have no ongoing legitimate business need to process your personal data, we will either delete or anonymise it, or — if this is not possible (for example, because it has been stored in backup archives) — we will securely store it and isolate it from any further processing until deletion is possible.

As described in the "Your Privacy Rights and Choices" section below, your personal data will be deleted at an earlier date if you request us to do so.

Your Privacy Rights and Choices

We respect your control over your information. Upon request, we will confirm whether we hold or are processing personal data we have collected from you. You have the right to:

Access, rectification, or erasure of your personal data
Restrict processing of your personal data
Data portability
Object to the processing of your personal data
Withdraw your consent
Complain to a data protection authority

To exercise any of these rights, please email us at privacy@keystrike.com or use the contact details in the "How to Contact Us" section below. We will consider and act upon any request within a reasonable timeframe in accordance with applicable data protection laws. Under certain circumstances we may not be able to fulfil your request — for example, if it interferes with our regulatory obligations, affects legal matters, we cannot verify your identity, or it involves disproportionate cost or effort — but we will always respond with an explanation.

If you believe we are unlawfully processing your personal data, you have the right to complain to your local data protection supervisory authority. You can find contact details for EEA data protection authorities at edpb.europa.eu.

If we rely on your consent to process your personal data, you may withdraw that consent at any time. Withdrawal does not affect the lawfulness of processing carried out before the withdrawal.

Should we need to use your personal data for a purpose not previously disclosed, or share it with an external party not covered by this Privacy Policy, we will offer you the opportunity to opt out by contacting us at privacy@keystrike.com.

You can unsubscribe from marketing communications at any time by clicking the unsubscribe link in any email we send, or by contacting us directly. You will be removed from our marketing lists. However, we may still send service-related messages necessary for the administration and use of your account.

To review or change your account information, or to request account termination, log in to your account settings. Upon a request to terminate your account, we will deactivate or delete your account and information from our active databases. We may, however, retain some information in our files to prevent fraud, troubleshoot problems, assist with investigations, enforce our legal terms, or comply with applicable legal requirements.

How We Transfer Your Personal Data Internationally

As we operate globally, we may need to transfer personal data to countries outside of where it was originally collected. We are headquartered in the U.S. and, if you are located outside the U.S., we may transfer your personal data to the U.S. or other countries between our group companies or our third-party providers. We offer data residency within the EU/EEA or within the U.S. in accordance with our customers' choosing.

We will protect your personal data in accordance with this Privacy Policy wherever it is processed. For transfers of personal data from individuals in the EEA, Switzerland, or the UK, we have implemented appropriate safeguards including Standard Contractual Clauses (approved by the European Commission and Swiss authorities), the UK Addendum to the Standard Contractual Clauses, and additional safeguards where appropriate.

When transferring personal data from the EEA, UK, and Switzerland to the U.S., we adhere to the Data Privacy Framework Program. Further details are in the "Data Privacy Framework Notice" section below.

Our Sub-Processors may also transfer your personal data internationally. To protect your data, we ensure appropriate transfer agreements are in place with all Sub-Processors listed above.

Data Privacy Framework Notice

Keystrike Inc. complies with the EU-U.S. Data Privacy Framework (EU-U.S. DPF) and the UK Extension to the EU-U.S. DPF, and the Swiss-U.S. Data Privacy Framework (Swiss-U.S. DPF) as set forth by the U.S. Department of Commerce.

Keystrike Inc. has certified to the U.S. Department of Commerce that it adheres to the EU-U.S. DPF Principles with regard to personal data received from the EU and UK, and to the Swiss-U.S. DPF Principles with regard to personal data received from Switzerland. If there is any conflict between the terms in this Privacy Policy and the DPF Principles, the Principles shall govern.

To learn more about the Data Privacy Framework Program and to view our certification, please visit dataprivacyframework.gov.

In compliance with the EU-U.S. DPF, the UK Extension, and the Swiss-U.S. DPF, Keystrike Inc. commits to resolve DPF Principles-related complaints about our collection and use of your personal information. EU, UK, and Swiss individuals with inquiries or complaints regarding our handling of personal data received in reliance on the EU-U.S. DPF, the UK Extension, and the Swiss-U.S. DPF should first contact us at privacy@keystrike.com, or by post using the information in the "How to Contact Us" section below.

Keystrike Inc. commits to refer unresolved complaints to TRUSTe, an alternative dispute resolution provider based in the United States. If you do not receive timely acknowledgment of your complaint from us, or if we have not addressed it to your satisfaction, please visit feedback-form.trustarc.com/watchdog/request for more information or to file a complaint. These dispute resolution services are provided at no cost to you.

For complaints regarding DPF compliance not resolved by any other DPF mechanism, you have the possibility, under certain conditions, to invoke binding arbitration. Further information can be found on the official DPF website: dataprivacyframework.gov — Annex I. The Federal Trade Commission has jurisdiction over our compliance with the DPF Principles.

If we transfer data received under the DPF Principles to a third-party agent, we assume responsibility for processing of that personal data. If our agent handles your data in a manner inconsistent with the DPF Principles, we will remain liable unless we are not responsible for the specific event that caused the damage.

Under certain circumstances we may be required to disclose your personal data in response to lawful requests by public authorities, including to fulfil national security or law enforcement requirements.

Cookie Disclosure

We use cookies and similar tracking technologies — such as pixels and local storage — to collect and store information when you use our services. Cookies are small text files placed on your device that help us recognise you, remember your preferences, and understand how you interact with our services.

Where required by law, we will ask for your consent before placing non-essential cookies. You can manage or withdraw your cookie preferences at any time through our cookie consent tool or by adjusting your browser settings. Please note that restricting cookies may affect the functionality of our services.

For a full list of the cookies we use, their purpose, and their duration, please refer to our Cookie Policy. You can also review and update your preferences via our cookie settings panel at any time.

Changes to Our Privacy Policy

This Privacy Policy will be updated continuously so that it is always up-to-date. If the changes are significant, we will notify you through the service and/or by email. Your continued use of the service following any amendment will confirm your consent to those changes.

How to Contact Us

If you have questions or comments regarding this Privacy Policy, you may contact us by email at privacy@keystrike.com, or by post at one of the addresses below.

United States

Keystrike Inc.
Att. Valdimar Oskarsson, CEO
8 The Green, Suite #1128
Dover, DE 19901
Kent County, Delaware USA

EEA (Iceland)

Keystrike ehf.
Att. Valdimar Oskarsson, CEO
Urdarhvarf 4
203 Kopavogur
Iceland