Parties
Controller: the customer holding a Kiste account ("Customer").
Processor: Luka Löhr, Kiste, [address], Karlsruhe, Germany ("Kiste").
This agreement is concluded together with the main contract (Terms) in electronic form (Art. 28(9) GDPR). A signed copy is available on request.
1. Subject matter and duration
Kiste processes personal data that the Customer stores or processes in their machines only to provide the agreed service. Subject matter, nature and purpose, types of data and data subjects are set out in Annex 1. This agreement applies for as long as Kiste processes such data for the Customer.
2. Instructions
(1) Kiste processes the data only on documented instructions from the Customer, including with regard to transfers to third countries, unless EU or German law requires otherwise; in that case Kiste informs the Customer beforehand unless the law prohibits it. Instructions are the main contract, this agreement and the Customer's use of Kiste's functions (console, CLI, API); further instructions are given in text form.
(2) If Kiste considers an instruction unlawful, it informs the Customer without delay and may suspend it until the Customer confirms or changes it.
3. Confidentiality
Kiste grants access to the data only to persons bound to confidentiality or under a statutory duty of secrecy, and only as far as needed for the service. Kiste does not look at the contents of the Customer's machines unless the Customer instructs it in the individual case or the law requires it.
4. Security of processing
Kiste implements the technical and organisational measures under Art. 32 GDPR set out in Annex 2. Kiste may develop them further provided the level of protection does not decrease.
5. Assistance with data subject rights
Kiste assists the Customer with appropriate measures in responding to requests under Chapter III GDPR. If a data subject contacts Kiste, Kiste forwards the request to the Customer within five working days and does not answer it itself. The Customer can access, correct, export and delete data in their machines at any time themselves.
6. Further assistance
Taking into account the information available to it, Kiste assists the Customer with the obligations under Articles 32 to 36 GDPR (security, breach notification, data protection impact assessment, prior consultation), in particular by providing the description of its measures and of the processing.
7. Subprocessors
(1) The Customer gives general authorisation to engage subprocessors. Those engaged at signature are listed in Annex 3 and at kiste.run/subprocessors.
(2) Kiste informs the Customer by e-mail at least 30 days before engaging a new subprocessor or replacing one. The Customer may object within that period on reasonable data protection grounds. If the parties cannot agree, the Customer may terminate the main contract as of the date of the change.
(3) Kiste imposes obligations on every subprocessor by contract that correspond to this agreement and remains liable for it under Art. 28(4) GDPR.
8. Personal data breaches
Kiste notifies the Customer of a breach affecting the Customer's data without undue delay, normally within 24 hours of becoming aware of it, by e-mail to the account's address. The notice contains the information under Art. 33(3) GDPR as far as known; Kiste supplies missing information as soon as it is available and takes immediate measures to contain the breach.
9. Deletion and return
(1) The Customer can copy their data out of their machines at any time until the contract ends.
(2) After the contract ends Kiste deletes the Customer's machines, their disks and memory images within 30 days. The encrypted backups become unreadable as soon as Kiste deletes the account's key, which is part of this deletion; the objects themselves are deleted once their storage lock (a protection against ransomware) expires, at most 31 days later. Retention duties under EU or German law remain unaffected. On request Kiste confirms the deletion in text form.
10. Demonstrating compliance and audits
(1) On request Kiste provides the information needed to demonstrate compliance with Art. 28 GDPR, in particular the description of measures, records and results of security reviews, and in future certificates or reports from independent bodies.
(2) If this is not sufficient, the Customer may carry out audits including inspections, itself or through an auditor bound to confidentiality, as a rule once per calendar year, with at least 30 days' notice, during normal business hours and without access to other customers' data. The powers of supervisory authorities remain unaffected.
11. Location of processing, third countries
Kiste processes machines and their disks in Germany. Backups are stored encrypted in Cloudflare R2 in Europe; Cloudflare holds no key. Traffic between users and machines travels encrypted over Cloudflare's global network. Transfers to third countries take place only under the conditions of Articles 44 et seq. GDPR (see Annex 3).
12. Liability, final provisions
Liability follows Art. 82 GDPR; otherwise the liability provisions of the main contract apply. In case of conflict this agreement prevails over the main contract as regards the protection of personal data. German law applies.
Annex 1: Subject matter of processing
| Nature and purpose | Providing virtual machines: storing disks and memory images, execution, network traffic, streaming the desktop, encrypted backups, forwarding published services on kiste.stream |
|---|---|
| Types of data | any data the Customer stores or processes in their machines; Kiste does not know it. Depending on use it may include special categories under Art. 9 GDPR. |
| Data subjects | determined by the Customer, e.g. the Customer's staff, customers and users, visitors of their published services |
| Duration | until the Customer deletes the data or the machine, at the latest per section 9 |
For account data (e-mail address, sign-ins, billing) Kiste is itself the controller; see the Privacy Policy.
Annex 2: Technical and organisational measures
Confidentiality
- Every machine is its own Firecracker microVM with its own kernel (hardware virtualisation, KVM), started through the jailer with its own user ID, chroot, PID namespace, network device and cgroup with CPU, memory and process limits.
- Network rules: machines cannot reach other machines, the server, the control plane, private networks or metadata services; outbound SMTP port 25 is blocked.
- The server has no port open to the Internet; it is reachable only through a Cloudflare Tunnel and accepts only requests from the control plane. Its firewall denies everything by default.
- Passwords hashed with PBKDF2-SHA-256, salt and a secret pepper; tokens stored only as SHA-256 hashes; sign-ins revocable one by one; brute-force protection; rate limits per IP address, account and service.
- Every query is restricted to the signed-in account. Published services run on their own domain (kiste.stream), separate from kiste.run's cookies.
- Only the operator has access to servers, logs and databases; logs can be read only through Cloudflare Access with a dedicated service token.
Encryption and pseudonymisation
- HTTPS with TLS 1.2 or later and HSTS; desktop streaming with DTLS-SRTP; connections between control plane, server and database through Cloudflare Tunnel and Access.
- Backups: zstd-compressed and encrypted with AES-256-GCM under a per-account key, wrapped by a master key only Kiste holds. Deleting the account key makes every copy unreadable.
- Secrets of webhooks, environments and published services stored encrypted.
- Logs carry the account ID, no e-mail addresses, no tokens or passwords.
- Encryption at rest of the disks on the server: planned (LUKS2 with TPM2), not yet in place.
Integrity
- All code changes in Git; tests and checks in CI on every push; Rust dependencies checked for known vulnerabilities.
- Server software shipped in coordinated release trains; Cloudflare Workers deployed only from CI, followed by a verification.
- Per-account event log of security-relevant actions; uniform logs with a request ID across all components.
Availability and resilience
- Running machines backed up automatically every five minutes when changed and before stop, restart and delete, to two separate stores; restore on any server.
- Quotas and limits keep one customer from affecting others; verified by load tests.
- DDoS protection by Cloudflare.
- Currently one compute server in Karlsruhe: if it fails, machines stand still until restored.
Regular testing
- Security reviews in every repository (architecture, threat model, API penetration tests, cryptography, system audit) with independent confirmation of every finding and every fix.
- Procedures for security incidents and breach notification; vulnerability reporting at kiste.run/security.
- An information security management system following ISO/IEC 27001 is being built; there is no certification.
Annex 3: Subprocessors
| Provider | Cloudflare, Inc., 101 Townsend St., San Francisco, CA 94107, USA |
|---|---|
| Service | Delivery of kiste.run and kiste.stream, control plane (Workers), account database (D1), encrypted backups (R2), tunnels between control plane and servers, DNS, attack protection, STUN/TURN for the desktop |
| Location | D1 and primary backup store in the EU jurisdiction; second backup store western Europe; traffic over the global network |
| Safeguards | EU–US Data Privacy Framework, Standard Contractual Clauses; backups encrypted with keys Cloudflare does not hold |
Payments are handled by Stripe Payments Europe, Ltd. (Dublin, Ireland). Stripe processes account data for this as an independent controller, not machine contents, and is therefore not a subprocessor under this agreement.
Questions about this agreement: luka@lukaloehr.com.