Data Processing

Data Processing Agreements

Every third-party service that handles Enki App user data is bound by a formal Data Processing Agreement. This page lists our processors, what they handle, and the protections in place.

Last updated: May 2026  ·  EnkiLabs Technologies

Overview

EnkiLabs Technologies acts as a Data Controller under GDPR, PIPEDA, and Quebec Law 25. This page lists the third-party Data Processors we use to deliver Enki App, the data they handle, and the agreements that bind them to the same privacy standards we uphold.

1. Our Third-Party Processors

ProcessorRoleData HandledDPA Status
Google Firebase
Google LLC, USA
Authentication, real-time database, push notifications, cloud storage Account credentials, check-in events, device tokens, encrypted vault data Accepted
Google Cloud Platform
Google LLC, USA
Server infrastructure, compute, object storage Encrypted location data, logs, contract configurations Accepted
RevenueCat
RevenueCat Inc., USA
Subscription management and in-app purchase processing User ID, subscription status, purchase history (no payment card data) Accepted
Apple App Store / Google Play App distribution and payment processing Governed by their own privacy policies; EnkiLabs does not receive payment data Platform Terms
SendGrid (Twilio)
Twilio Inc., USA
Transactional email delivery (trigger alerts, account notices) Recipient email addresses, notification content Accepted
Twilio SMS
Twilio Inc., USA
SMS notifications to emergency contacts on trigger activation Emergency contact phone numbers, alert message content Accepted

2. What a DPA Requires from Each Processor

  • Process personal data only on documented instructions from EnkiLabs.
  • Ensure all personnel processing data are bound by confidentiality obligations.
  • Implement appropriate technical and organisational security measures (Article 32, GDPR).
  • Assist EnkiLabs in responding to data subject rights requests.
  • Delete or return all personal data at the end of the service relationship.
  • Provide all information necessary to demonstrate compliance and allow audits.
  • Notify EnkiLabs without undue delay upon becoming aware of a personal data breach.

3. Sub-processors

Our primary processors may themselves use sub-processors (e.g., Google Firebase uses Google's global infrastructure). We verify that each primary processor maintains a publicly available sub-processor list and requires sub-processors to meet equivalent data protection standards.

You will be notified of any material change to our processor list that affects how your data is handled.

4. Data Minimisation & Access Controls

  • Least-privilege access: Each processor receives only the data necessary to perform its specific function.
  • Vault data zero-knowledge: The contents of your Digital Legacy Vault are encrypted with your Master PIN-derived key before leaving your device. EnkiLabs and its processors cannot read vault contents.
  • Location data: Transmitted only at check-in and only to designated emergency contacts upon a confirmed trigger. Not shared with any third-party processor for analytics or advertising.
  • Emergency contacts: Stored encrypted. Phone numbers are transmitted to Twilio only at the moment of trigger activation.

5. Your Rights & Contact

To exercise your rights regarding processor-held data, or to request a copy of any specific DPA, contact:

Data Protection Contact

Email: privacy@enkilabstech.com
Subject line: DPA Request — [your name]