KiTech Software legal
Privacy Policy
How KITECH SOFTWARE LTD collects, uses, shares, retains, and protects personal information across its websites, products, services, and selected partner applications.
1. Who we are
KITECH SOFTWARE LTD is a private limited company registered in England and Wales under company number 10528257.
Our registered office is:
Unit 82a James Carter Road
Mildenhall
Bury St. Edmunds
England
IP28 7DE
In this policy, “KiTech”, “KiTech Software”, “we”, “our”, and “us” refer to KITECH SOFTWARE LTD unless a product-specific notice identifies another organisation as the controller of your personal information.
You can contact us at hello@kitechsoftware.com.
2. Scope of this policy
This policy applies to KiTech Software websites, cloud services, desktop and mobile applications, APIs, documentation, customer support, developer services, and other services that link to it.
Individual products may publish additional privacy notices that explain their specific data practices. Those notices supplement this policy and take priority where they describe a product-specific practice in greater detail.
This policy does not apply to third-party services that KiTech does not control. Those services are governed by their own privacy notices.
3. Our role when processing information
Our legal role depends on the service and how it is operated:
- KiTech-operated products: KITECH SOFTWARE LTD will normally act as the data controller.
- Partner applications: the partner, KiTech, or both organisations may act as controllers. KiTech may instead act only as a processor on the partner’s instructions. The application’s product-specific notice will identify the relevant roles.
- Customer-managed or self-hosted products: the organisation operating the deployment will normally control the information processed within it. KiTech may have no access to that information unless support, diagnostics, hosting, or another service is requested.
4. Information we may collect
The information collected depends on the product, deployment model, features used, and choices made by the user or organisation.
Information you provide
This may include:
- name, username, display name, and profile details;
- email address, telephone number, and contact information;
- organisation, employment, membership, or account details;
- authentication, account-recovery, and security information;
- communications with us, support requests, and feedback;
- billing, subscription, and transaction information;
- preferences, consents, and configuration choices; and
- information submitted when applying to participate in a programme, partnership, beta, or research activity.
Content and product data
Depending on the product, this may include:
- messages and other communications;
- files, documents, images, audio, and video;
- contacts and calendar information when a user enables those features;
- workspace, organisation, project, or community information;
- application configuration and integration data; and
- data created, uploaded, or managed through a product.
Product-specific notices explain whether KiTech can access content, whether content is end-to-end encrypted, and which party controls the information.
Technical and usage information
This may include:
- IP address and approximate location derived from it;
- device, browser, operating-system, and application information;
- application version, language, and regional settings;
- identifiers used for security, installation, licensing, or service operation;
- access logs, audit events, and security events;
- feature interactions and service-performance information;
- crash reports, diagnostics, and error data; and
- cookie or similar-technology data where those technologies are used.
Information obtained from other sources
We may receive information from:
- an organisation that creates or manages an account for you;
- a partner responsible for a partner application;
- an identity, authentication, payment, hosting, or integration provider;
- another user who invites or communicates with you;
- public sources where lawful and appropriate; and
- authorities or professional advisers where required by law.
Where required, we will provide additional privacy information about the source and categories of information obtained.
5. Why we use personal information
We may use personal information to:
- provide, operate, maintain, and secure products and services;
- create and administer accounts;
- authenticate users and recover accounts;
- deliver requested communications and product functionality;
- process subscriptions, purchases, and payments;
- provide support and respond to enquiries;
- diagnose faults and improve reliability, accessibility, and performance;
- prevent fraud, spam, abuse, and security threats;
- enforce agreements and acceptable-use requirements;
- maintain audit, compliance, and business records;
- communicate material service, security, or policy changes;
- understand product usage where analytics are enabled and lawful;
- develop and test new features using appropriate safeguards; and
- comply with legal and regulatory obligations.
We will not use personal information for an incompatible purpose without providing appropriate notice and, where required, obtaining consent.
6. Lawful bases
Under UK data-protection law, we rely on one or more of the following lawful bases:
- Contract: processing is necessary to provide a product or service you requested or to take steps before entering into a contract.
- Legal obligation: processing is necessary to comply with applicable law, regulation, court orders, accounting requirements, or lawful authority requests.
- Legitimate interests: processing is necessary for our legitimate interests or those of another organisation, provided those interests are not overridden by your rights and interests.
- Consent: you have made a clear choice that permits the processing. You may withdraw consent at any time, without affecting processing already carried out lawfully.
- Vital interests or public task: used only where the circumstances and applicable law support that basis.
Where we rely on legitimate interests, those interests may include operating and securing services, preventing misuse, improving reliability, managing business relationships, and protecting legal rights.
Product-specific notices may provide a more detailed purpose-and-lawful-basis table.
7. Whether information is required
Some information is required to create an account, enter into a contract, comply with law, or provide requested functionality. Where information is required, the relevant form, product, or notice will explain this and the possible consequences of not providing it.
Optional permissions and product features should remain optional unless they are necessary for the feature requested.
8. How we share information
We do not sell personal information.
We may disclose information:
- to infrastructure, communications, payment, support, security, analytics, and other service providers acting on our behalf;
- to an organisation that administers your account or deployment;
- to a partner responsible for a partner application;
- to another user or organisation when you choose to communicate, collaborate, publish, or share information;
- to professional advisers, auditors, insurers, and financial institutions;
- to courts, regulators, law-enforcement bodies, or public authorities where disclosure is lawful and necessary;
- to protect users, KiTech, our partners, or the public from harm, fraud, abuse, or security threats; and
- in connection with a merger, acquisition, financing, restructuring, or transfer of relevant business assets, subject to appropriate safeguards.
Our Subprocessors page will identify material service providers used to process personal information on our behalf.
9. International transfers
Information may be processed in countries other than the country where it was collected when required to provide a service or use an approved provider.
Where UK data-protection law restricts a transfer, we use an appropriate transfer mechanism, such as:
- UK adequacy regulations;
- the UK International Data Transfer Agreement;
- the UK Addendum to the EU Standard Contractual Clauses; or
- another lawful safeguard or exception.
Product-specific notices describe available regional hosting or data-residency commitments.
10. Retention
We retain personal information only for as long as reasonably necessary for the purpose for which it was collected, including to provide services, maintain security, meet legal and accounting obligations, resolve disputes, and enforce agreements.
Retention periods vary according to the information, product, deployment model, contractual requirements, legal obligations, and whether an account or service remains active.
When information is no longer required, we delete or anonymise it unless continued retention is required or permitted by law. Backup copies may remain for a limited period until they are overwritten or securely removed.
More detail will be provided in our Data Retention Policy and product-specific notices.
11. Security
We use technical and organisational measures designed to protect information against unauthorised access, alteration, disclosure, loss, and destruction. Measures may include:
- encryption in transit and, where appropriate, at rest;
- access controls and least-privilege principles;
- secure development and change-management practices;
- logging, monitoring, and incident response;
- vulnerability management and responsible disclosure processes;
- separation of customer or tenant data where applicable; and
- backup, recovery, and resilience controls.
No system can be guaranteed to be completely secure. Users and organisations are also responsible for protecting credentials, devices, recovery methods, and deployment configurations under their control.
12. Automated decision-making and AI
We do not make solely automated decisions that produce legal or similarly significant effects unless a product-specific notice clearly explains the processing, the lawful basis, the logic involved, the likely consequences, and the rights available to you.
Where a product includes artificial-intelligence features, the product-specific notice will explain what information is processed, whether information is sent to another provider, whether content is used for model training, and what controls are available.
13. Children and age-restricted services
Our products are not directed at children unless the relevant product documentation explicitly states otherwise.
Where a service is intended for, or may be used by, children or young people, we will apply age-appropriate design, transparency, consent, verification, and safeguarding measures required by applicable law. Product-specific notices will explain any age requirements or age-assurance processing.
14. Your rights
Depending on the circumstances and applicable law, you may have the right to:
- receive information about how your personal information is used;
- access personal information held about you;
- correct inaccurate or incomplete information;
- request deletion of information;
- restrict or object to processing;
- receive certain information in a portable format;
- withdraw consent at any time;
- object to direct marketing;
- request human review of certain automated decisions; and
- complain to a data-protection authority.
These rights may be subject to legal conditions, limitations, exemptions, and the roles of the organisations involved. For an organisation-managed, partner, or self-hosted service, the relevant organisation may need to handle your request.
To exercise a right concerning information controlled by KiTech, email hello@kitechsoftware.com. We may need to verify your identity before completing a request.
You may also complain to the UK Information Commissioner’s Office. We encourage you to contact us first so that we can try to resolve the concern.
15. Cookies and similar technologies
Our website and products may use cookies, local storage, or similar technologies for essential operation, preferences, security, and—where enabled—analytics.
Our Cookie Policy will explain the technologies used on the public website and the choices available. Product-specific notices describe technologies used within individual applications.
16. Partner applications
KiTech may develop, maintain, host, or support applications on behalf of selected partners. A partner application must provide a product-specific privacy notice that identifies:
- the controller or joint controllers;
- KiTech’s role;
- the information collected;
- the purposes and lawful bases;
- recipients and processors;
- retention and deletion arrangements; and
- how users can exercise their rights.
A partner application may use the following standard statement where accurate:
This application is developed and maintained by KiTech Software on behalf of its partner. Its product-specific privacy notice supplements the KiTech Software company policies and identifies which organisation controls your personal information.
17. Changes to this policy
We review this policy regularly and update it when our services, processing, or legal obligations change.
The version, effective date, and last-updated date appear at the top of this page. Where a change materially affects how personal information is used, we will provide additional notice where appropriate.
18. Contact
Privacy enquiries and requests concerning information controlled by KiTech may be sent to:
KITECH SOFTWARE LTD
Unit 82a James Carter Road
Mildenhall
Bury St. Edmunds
England
IP28 7DE
Email: hello@kitechsoftware.com
Related documents
- Terms of Service
- Cookie Policy
- Security Policy
- Responsible Disclosure Policy
- Data Retention Policy
- Data Deletion Policy
- Subprocessors
- Contact