Privacy policy
What we hold, why we are allowed to, and what you can make us do about it. We do not sell your data or train models on it. We have no standing access to your workspace; support can access it only when you explicitly grant access, with a defined scope and expiry.
Il resto del sito è tradotto; questo documento no. Un contratto con quindici stesure solleva la domanda di quale faccia fede quando due non coincidono, quindi esiste una sola versione autentica ed è questa. Il testo inglese è quello che si applica al tuo accordo con noi.
The short version
Di te conserviamo il meno possibile, e non abbiamo accesso permanente a quello che c’è dentro il tuo spazio di lavoro. Non conserviamo password, e l’assistenza può entrare solo quando sei tu a concederlo, con un ambito e una scadenza.
We do not sell your data, we do not mine it to build features for other customers, and we do not use it to train models. There is no clause further down that quietly allows us to start.
Everything below says the same thing in the detail a data protection officer needs.
Who is responsible for what
Keelvy is operated by Baleanza LLC, a company incorporated in the United States of America, registered at 30 N Gould St Ste R, Sheridan, WY 82801, USA.
For the personal data of your own customers and staff that you put into your workspace, you are the controller and we are your processor. You decide what goes in and why; we handle it on your instructions and for no other purpose.
For data about you as our customer — your account, your billing, your emails to support, how you use the product — we are the controller. Each section below says which of the two it covers.
Data protection questions go to privacy@keelvy.com and reach a person.
If you reached this page from a shop
You may have arrived here after ordering from a brand whose shop runs on Keelvy — the page you were on sits at keelvy.app, so our name is the one you found.
The name, address, phone number and order you gave belong to that brand, not to us. They decide what to collect, why, how long to keep it and who may see it; we only hold it on their instruction, in their own separate area of the system. We do not use it, we do not market to you, and we do not pass it to anyone else.
So requests about that data — a copy of it, a correction, deletion — go to the brand you bought from, and they are the ones who must answer. Write to privacy@keelvy.com if you cannot reach them and we will point you to the right contact, but we cannot answer on their behalf.
If you write to us before you are a customer
Three forms on this site reach us: a message, an application to the partner program, and the product-news list. What you type into one is what we hold, and we hold it whether or not anything comes of it. For all of it we are the controller.
- A message or a partner application: your name, work email, company, website and what you wrote. We use it to answer you and to decide on an application — our legitimate interest in replying to somebody who asked us to.
- The product-news list: your email, and the fact and date that you asked to join. That one runs on your consent. Every email carries an unsubscribe link, and using it ends the whole thing.
- Product news when you did not join that list: if you contacted us about buying Keelvy, we may later write to you about Keelvy — our own product, nothing else, and never on anybody else’s behalf. You can refuse at the moment you write to us, and you can stop it from any email we send. We do not sell your details, and we do not pass them to anyone for their own marketing.
- All of it sits in our CRM, HubSpot, on servers in the European Union. A message or an application is kept for two years from your last contact with us; the news list, until you leave it.
What we collect about you as a customer
Deliberately short. As controller, we hold:
- Account details: your name, work email, and the workspace you belong to. Sign-in runs through an identity provider, so no password for you exists here.
- Billing details: what you subscribed to, what you paid, the country we charge tax for, and the invoices. Card numbers are handled by our payment provider and never reach us.
- Product usage: which screens are opened and which actions run, so we can find what is slow or broken. Not the contents of your catalog.
- Support correspondence: what you wrote and what we replied.
- Technical logs: IP address, browser and timestamps, kept briefly for security and debugging.
The data inside your workspace
Your catalog, photographs, prices, recipes, customers, orders and documents are yours. We hold them to run the service.
Some of it is personal data of other people — a buyer’s contact details, a supplier’s representative, your own staff on a timesheet. For that, you are the controller: you decide what to collect and you answer to those people. We process it only to provide the service, only on your instruction, and we do not use it for anything of our own.
Nobody here browses your workspace. If support needs to look at something, you grant access, it expires automatically, and the grant is written into the change journal you can read.
The lawful basis
For your account and your subscription: performance of the contract we have with you. We cannot provide the service without it.
For product usage, technical logs and error reports: our legitimate interest in a service that works and is secure, limited to what is needed for that.
For billing records we must keep: compliance with a legal obligation.
For anything else — a case study, naming your brand, a marketing email beyond what your subscription requires — your consent, which you can withdraw at any time without affecting the service.
That covers you as a customer. Before you were one, product news about Keelvy could reach you on a different basis, and the section on writing to us before you are a customer says which and how to refuse it.
Where you are the controller, the lawful basis for the personal data in your workspace is yours to establish. We help you meet the requests that follow from it.
The processor commitments
These apply to everything in your workspace, and stand as our data processing terms. We:
- Process it only on your documented instructions, and tell you if we believe an instruction breaks data protection law.
- Keep it confidential, and bind everybody with access to the same duty.
- Apply the technical and organizational measures set out on the security page — encryption in transit and at rest, no stored passwords, permissions enforced where data is read.
- Engage no new sub-processor without giving you notice and the chance to object.
- Help you answer requests from the people whose data it is, and help you with impact assessments where the law requires one.
- Tell you about a personal data breach without undue delay, and within seventy-two hours of becoming aware.
- Delete or return it when the arrangement between us ends, and confirm we have.
- Make available what you need to demonstrate compliance, and submit to audit on reasonable notice.
Who else touches it
As few as we can manage. Each is bound by a contract holding them to this policy. These are the categories; the current provider in each, what it receives and the date the list last changed are on our subprocessors page, where you can also subscribe to be told before it changes. Where we have not yet confirmed a provider’s region the page says so plainly rather than leaving it blank, and we will give you the answer on request.
We will give ten days’ notice before a new provider starts processing your data. If you object on reasonable grounds within that time and we cannot agree on an alternative, you may end your subscription without penalty and we refund the unused part. Replacing a provider inside a category listed below does not change our agreement; adding a new category does.
- Hosting and database infrastructure, in the European Union.
- The identity provider that handles sign-in.
- The payment provider that handles subscriptions and cards.
- Email delivery for the messages the service itself sends.
- Error and performance monitoring, configured not to capture catalog content.
- A model provider, only for the requests you send the assistant, and only when you have switched it on.
- A payment provider for our own subscription billing. Card details never reach us — you enter them on the provider’s page.
- Named with no provider engaged today, so you can see what we have not quietly left out: content delivery, product analytics, session recording, website analytics.
Where it is held, and transfers
The application and the database that serves it run in the European Union, in Stockholm.
Restore points are held separately from the live database, under their own keys, in storage neither we nor anybody else can delete before its retention ends. They are not in the same place as the database, and we will tell you exactly where on request — our subprocessors page lists every provider we use and states which of their regions we are still confirming.
Where a processor operates outside the EU, the transfer runs on the European Commission’s standard contractual clauses with a transfer assessment behind it, and we will provide both on request.
Our own company is incorporated in the United States, so that transfer mechanism covers our access to data held in Europe as well as any processor’s.
How long we keep it
While your workspace is open we keep what you put in — that is the point of the service. The change journal window on your tier decides how far back the who-changed-what trail stays instantly searchable; past that it is archived, not deleted. Orders, production orders, deliveries, documents and stock movements are kept in full for as long as your workspace exists, on the cheapest tier exactly as on the dearest.
After you cancel, your data stays available for export for thirty days and is then deleted, including from restore points as their retention rolls over. Ask us within that window and we will extend it.
Three kinds of record outlive that, for three years from closure, because tax law requires the issuer to be able to produce them: issued fiscal documents together with the legal entity that issued them, payroll records, and the access needed to open those documents. Nothing else survives — not packing lists, delivery notes, purchase orders, production orders or stocktake sheets.
The closing screen tells you exactly how many records go, which remain and until what date, before you confirm. We would rather say this than claim we delete everything and leave you to discover otherwise.
Technical logs are kept for thirty days. Support correspondence is kept for two years. Billing records are kept for as long as tax law requires and cannot be deleted on request.
A message, a partner application or anything else sent through a form on the marketing site is kept for two years from your last contact with us. The product-news list is kept until you leave it.
Your rights
Wherever you are, you can ask us to show you what we hold about you, correct it, delete it, restrict what we do with it, or hand it over in a portable form. You can object to processing based on legitimate interest, and withdraw consent you gave.
You do not need to ask us for your workspace data. Export it yourself section by section whenever you like, or request a complete archive of the workspace — products, media, customers, recipes, orders, purchases, documents and branding, with a written note against anything not included so you read it before you leave rather than after.
One limit stated plainly: erasing a single named person from a workspace, separately from closing the whole workspace, is not something the system can do today. Where you need that, tell us and we will work through it with you by hand.
We make no automated decisions about you with legal effect, and we do not profile you.
Write to privacy@keelvy.com and we will answer within thirty days, usually much sooner, and free of charge. If you are in the EU or the UK and we have not resolved it, you may complain to your national data protection authority.
If your own customers ask you about their data
When one of your buyers or staff exercises a right against you, we help you answer: find the records, export them, correct them, or remove them. We will not answer on your behalf, because they are your customer and it is your relationship.
On your instruction we delete or return the data in your workspace, and we do the same automatically when the arrangement between us ends, subject to the three-year records described above.
Nobody here has standing access to your workspace. When support needs to look, you grant it: one named person, one workspace, a stated reason, and an expiry of at most seven days that the database itself enforces. The grant is never deleted, only revoked, and it appears in the change journal inside your own workspace — so the question “who read my data and when” has an answer you can check without asking us.
The assistant
The assistant is switched off until you turn it on, per workspace, so pointing it at live data stays your deliberate act.
When you use it, the text of your request and the records needed to answer it are sent to the model provider for that request. They are not used to train the provider’s models, and they are not retained by us beyond the change journal entry.
It acts inside the permissions of whoever issued its token, and every write it makes is recorded against that person with the previous value behind it. Revoke the token and it stops on the next call.
How it is protected
Encryption in transit and at rest, no stored passwords, permissions enforced where data is read rather than in the interface, and a journal of every write.
The security page sets out each arrangement in detail: hosting, encryption, sign-in, permissions, backups and how support access is granted and expires.
If something goes wrong
If personal data in your workspace is exposed, we tell you without undue delay and within seventy-two hours of becoming aware: what happened, what was affected, and what we are doing about it. Under the law that notice has to come from you to the people affected, and we give you what you need to make it.
If you have found something that looks wrong, tell your account contact or write to support and it reaches the right people the same day.
Children
The service is for businesses and is not directed at children. We do not knowingly collect data about anybody under sixteen. If you believe we hold any, write to privacy@keelvy.com and we will remove it.
Changes to this policy
We update it when what we do changes. If a change materially affects you we will tell you by email, and the date at the top always shows when it last changed. Previous versions are available on request.