Data Processing Agreements
Every third-party service that handles Enki App user data is bound by a formal Data Processing Agreement. This page lists our processors, what they handle, and the protections in place.
Last updated: May 2026 · EnkiLabs Technologies
EnkiLabs Technologies acts as a Data Controller under GDPR, PIPEDA, and Quebec Law 25. This page lists the third-party Data Processors we use to deliver Enki App, the data they handle, and the agreements that bind them to the same privacy standards we uphold.
1. Our Third-Party Processors
| Processor | Role | Data Handled | DPA Status |
|---|---|---|---|
| Google Firebase Google LLC, USA |
Authentication, real-time database, push notifications, cloud storage | Account credentials, check-in events, device tokens, encrypted vault data | Accepted |
| Google Cloud Platform Google LLC, USA |
Server infrastructure, compute, object storage | Encrypted location data, logs, contract configurations | Accepted |
| RevenueCat RevenueCat Inc., USA |
Subscription management and in-app purchase processing | User ID, subscription status, purchase history (no payment card data) | Accepted |
| Apple App Store / Google Play | App distribution and payment processing | Governed by their own privacy policies; EnkiLabs does not receive payment data | Platform Terms |
| SendGrid (Twilio) Twilio Inc., USA |
Transactional email delivery (trigger alerts, account notices) | Recipient email addresses, notification content | Accepted |
| Twilio SMS Twilio Inc., USA |
SMS notifications to emergency contacts on trigger activation | Emergency contact phone numbers, alert message content | Accepted |
2. What a DPA Requires from Each Processor
- Process personal data only on documented instructions from EnkiLabs.
- Ensure all personnel processing data are bound by confidentiality obligations.
- Implement appropriate technical and organisational security measures (Article 32, GDPR).
- Assist EnkiLabs in responding to data subject rights requests.
- Delete or return all personal data at the end of the service relationship.
- Provide all information necessary to demonstrate compliance and allow audits.
- Notify EnkiLabs without undue delay upon becoming aware of a personal data breach.
3. Sub-processors
Our primary processors may themselves use sub-processors (e.g., Google Firebase uses Google's global infrastructure). We verify that each primary processor maintains a publicly available sub-processor list and requires sub-processors to meet equivalent data protection standards.
You will be notified of any material change to our processor list that affects how your data is handled.
4. Data Minimisation & Access Controls
- Least-privilege access: Each processor receives only the data necessary to perform its specific function.
- Vault data zero-knowledge: The contents of your Digital Legacy Vault are encrypted with your Master PIN-derived key before leaving your device. EnkiLabs and its processors cannot read vault contents.
- Location data: Transmitted only at check-in and only to designated emergency contacts upon a confirmed trigger. Not shared with any third-party processor for analytics or advertising.
- Emergency contacts: Stored encrypted. Phone numbers are transmitted to Twilio only at the moment of trigger activation.
5. Your Rights & Contact
To exercise your rights regarding processor-held data, or to request a copy of any specific DPA, contact:
Email: privacy@enkilabstech.com
Subject line: DPA Request — [your name]