Privacy Policy
Last updated: 11 March 2026
1. Data Controller
The data controller for data collected through the KeySuite Service is Kyvos Studio, [legal form, address to be completed]. Contact: privacy@keysuite.app.
2. Data Collected
We collect the following categories of data:
- Identification data: name, surname, professional email address
- Connection data: IP address, session identifiers, timestamps
- Usage data: features used, actions performed (audit logs)
- Business data: organisational charts, checklists, handover notes (entered by the user)
3. Processing Purposes
Data is processed for the following purposes:
- Provision and operation of the Service
- User account management and authentication
- Security and abuse prevention (audit logs)
- Service improvement (anonymised analytics)
- Service-related communications (notifications, support)
4. Legal Basis
Data processing is based on contract performance (Service provision) and the Publisher's legitimate interest (security, improvement). Marketing communications, where applicable, are based on user consent.
5. Hosting and Security
Data is hosted in France by Scaleway SAS (DC2/DC3 datacentres, Paris). We implement the following security measures:
- Encryption in transit (TLS 1.3) and at rest
- Secure authentication (bcrypt/scrypt hashing, optional MFA)
- Regular backups with geographically separated retention
- Immutable audit logs (append-only)
- Automated vulnerability scanning (Trivy)
6. Data Retention
- Account data: subscription duration + 30 days after cancellation
- Audit logs: 12 rolling months
- Connection data: 12 months (legal obligation)
- Business data: subscription duration, export available before deletion
7. Sub-processors
- Scaleway SAS — Infrastructure hosting (France)
- PostHog — Product analytics (EU, anonymous mode, no personal data)
- Cal.com — Demo booking (self-hosted)
No personal data is transferred outside the European Union. No data is sold to third parties.
8. Your Rights
Under the GDPR, you have the following rights:
- Access: obtain a copy of your personal data
- Rectification: correct inaccurate data
- Erasure: request deletion of your data
- Portability: receive your data in a structured format (JSON/CSV)
- Objection: object to processing on legitimate grounds
- Restriction: request restriction of processing
To exercise your rights, contact us at privacy@keysuite.app. We respond within 30 days.
9. Cookies and Trackers
The keysuite.pro website uses PostHog in anonymous mode (no cookies, no personal identification). No advertising or profiling cookies are set. The only cookies used are essential technical cookies (theme preference, language).
10. Complaints
If you believe that the processing of your data does not comply with regulations, you may file a complaint with the CNIL (French data protection authority): www.cnil.fr, or with your local supervisory authority.
This privacy policy is being finalised with our legal counsel. For any questions, contact us at privacy@keysuite.app.