Data policy.
Effective Date: September 13, 2026
This Data Policy describes the security practices Keep The Fees LLC ("KTF") applies to the information it holds through the Keep The Fees platform. It is one of the documents that make up KTF's agreement with each Shop, alongside the Terms of Service and the Privacy Policy. It describes KTF's current practices.
Capitalised terms have the meanings given in the Terms of Service.
1. Hosting
The Services are hosted on Microsoft Azure. Azure provides the physical and network security of the data centres, and KTF configures and operates its own environment within them.
2. Encryption
KTF maintains encryption of data in transit and at rest using industry-standard methods: data moving between users and the Services is encrypted using TLS/HTTPS, and data stored in the databases that hold Shop, Client, and Artist Data is encrypted at rest.
3. Access control
Access to the Services and their underlying infrastructure is granted on a role basis. Users are assigned roles and permissions that correspond to their responsibilities, and access is limited to what those responsibilities require. Shops control the permissions of their own users within the Services.
4. Administrative access logging
Administrative access to production systems and data is logged.
5. Monitoring and review
KTF monitors its security practices on an ongoing basis and reviews them as the Services, the threat environment, and applicable requirements change. KTF may modify its safeguards from time to time, provided the protection afforded is not materially reduced.
6. Service providers
KTF engages third-party providers to host, deliver, support, secure, and improve the Services, as described in the Privacy Policy. KTF requires each such provider to maintain confidentiality and data protection obligations no less protective than KTF's own, and remains responsible for those providers' performance of those obligations to the extent set out in the Data Processing Addendum. Services a Shop selects and connects itself operate under their own terms.
7. Security incidents
If a security incident affects a Shop's data, KTF notifies the Shop as required by Section 501.171, Florida Statutes, or within such shorter period as applicable law requires. KTF provides the information reasonably available at the time of notification (the nature of the incident, the categories of data involved, and the steps taken) and supplements it as the investigation progresses. Notification is not an acknowledgment of fault.
Because KTF processes Client and Artist Data on a Shop's behalf, KTF's notification runs to the Shop. The Shop is responsible for any notice it must give to its own clients, personnel, or regulators, and KTF provides the information the Shop needs to do so.
8. Retention and deletion
KTF retains Shop, Client, and Artist Data for as long as the Shop's account is active and as needed to provide the Services. After termination, the Shop may request an export within thirty (30) days; KTF provides it within fifteen (15) business days of a valid request, and deletes or de-identifies the Shop's data within ninety (90) days after the later of the end of the request period or the fulfilment of a timely request, subject to the exceptions stated in the Terms of Service and the Privacy Policy. Aggregated Data, which identifies no Shop or individual and excludes all Health Information, may be retained indefinitely.
9. The Shop's responsibilities
The Shop is responsible for the security of its own devices, networks, and credentials; for configuring user permissions within the Services appropriately; for the security of any endpoint it designates to receive data from the Services; and for the handling of data by any third-party service it selects and connects.
10. Google API services
Where the Services connect to Google APIs, KTF's use and transfer to any other app of information received from Google APIs will adhere to the Google API Services User Data Policy, including the Limited Use requirements.
11. Questions
Questions about this Policy may be sent to [email protected].