SecDoma

Privacy Notice

How SecDoma processes account, communication, device, security, and support information across cloud and self-hosted deployments.

Last updated: 7 August 2026

Scope

This notice supplements the KiTech Software Privacy Policy for SecDoma. It applies where KITECH SOFTWARE LTD operates SecDoma Cloud or otherwise determines how personal information is processed.

For an organisation-managed or self-hosted deployment, the organisation or deployment operator will normally be the controller for information processed within that environment. Its privacy notice and administrator instructions may apply in addition to this notice.

Information SecDoma may process

  • Account and profile information: name, display name, username, email address, profile image, authentication and recovery information, preferences, and account status.
  • Organisation and access information: tenant, organisation, workspace, community, membership, role, invitation, policy, and permission records.
  • Communication content: messages, reactions, files, images, audio, video, meeting information, and other content you choose to create, send, or store.
  • Communication metadata: participants, timestamps, delivery state, conversation identifiers, moderation events, and information needed to route and synchronise communications.
  • Device and service information: device type, operating system, application version, language, IP address, session information, diagnostics, crash information, and service-performance data.
  • Security and audit information: authentication events, access records, administrative actions, abuse reports, blocked-user information, and security alerts.
  • Support information: correspondence, diagnostic material, screenshots, and information supplied when requesting help.

Device permissions

SecDoma may request access to the following only when needed for a feature you choose to use:

  • notifications for messages, calls, meetings, and security events;
  • microphone and camera for calls, voice messages, and media capture;
  • photos, media, files, or storage for attachments and downloads;
  • screen-capture or screen-sharing capabilities when you start a share; and
  • contacts or calendar information where an optional integration is enabled.

You can manage operating-system permissions through your device settings. Disabling a permission may prevent the related feature from working.

Why information is used

Information may be used to:

  • create and secure accounts;
  • deliver messages, calls, meetings, notifications, files, and collaboration features;
  • apply organisation, tenant, community, safety, retention, and access policies;
  • prevent fraud, spam, abuse, unauthorised access, and other security threats;
  • provide support and diagnose reliability or compatibility problems;
  • maintain audit, compliance, and operational records; and
  • meet legal obligations and protect the rights and safety of users and organisations.

Sharing and processors

Information may be shared with the people and organisations you communicate with, administrators of environments you join, and service providers required to operate SecDoma. Material providers used by KiTech Software are listed in the Subprocessors notice.

Information is not sold. We do not disclose communication content to advertisers for behavioural advertising.

Cloud, regional, and self-hosted processing

SecDoma may support regional hosting and cross-organisation or cross-deployment communication. Product configuration, organisation policy, and the participants in a communication may affect where information is stored or replicated. Any specific contractual residency commitment takes priority over this general notice.

In a self-hosted deployment, the operator controls the infrastructure and will normally determine storage location, backups, logging, retention, integrations, and administrative access. KiTech Software may have no access unless support or another managed service is requested.

Retention and deletion

Retention depends on the account type, deployment, organisation policy, conversation type, legal obligations, security needs, and backup lifecycle. See the Data Retention Policy and the applicable organisation or deployment policy.

To delete a SecDoma account, follow the SecDoma account-deletion instructions. Deleting an account does not necessarily remove information that another organisation controls, content another participant must retain, or records that must be preserved by law.

You do not have to close your account to have specific information deleted. You can request deletion of eligible information on its own through the Privacy Choices page.

Your choices and rights

You may manage profile information, permissions, notification settings, blocked users, and available privacy controls in SecDoma and your device settings. Rights requests concerning information controlled by KiTech Software can be made through the Privacy Choices page.

For an organisation-managed or self-hosted account, contact the organisation or deployment operator first because it may be responsible for the information and request.

Children and safety

SecDoma environments that permit use by children or young people must apply appropriate access, safeguarding, reporting, moderation, and age-related controls. See the Child Safety Standards.

Contact

Privacy questions about SecDoma may be sent to hello@kitechsoftware.com.