Privacy Policy
1. Introduction
Kinxshn ("we", "us", or "our") is committed to protecting the privacy and personal data of everyone who uses our App. This Privacy Policy explains what data we collect, why we collect it, how we use and protect it, and your rights in relation to it.
This Policy applies to all users of the App, including operators, principals, and guests. It should be read alongside our Terms and Conditions, which are incorporated by reference.
If you have any questions about this Policy or how we handle your data, please contact us at [email protected].
2. Who We Are
Kinxshn is the data controller in respect of personal data collected directly through the App. Where we process personal data on behalf of an operator organisation, we act as a data processor and do so strictly in accordance with that operator's documented instructions and applicable law.
For the purposes of UK GDPR and EU GDPR, the data controller is:
Kinxshn
Email: [email protected]
Website: www.kinxshn.com
If you are an operator and require a Data Processing Agreement (DPA) in connection with your use of the App, please contact us at [email protected]. A standard Data Processing Agreement is available for download at kinxshn.com/legal/dpa.pdf.
3. Data We Collect
We collect the following categories of personal data:
3.1 Account and Identity Data
- Name and email address (used for account creation and authentication)
- Organisation name and your role within that organisation (e.g., operator, principal, guest)
- Authentication tokens and session data generated through passwordless login (magic links)
3.2 Voice and Audio Data
- Audio recordings captured through your device's microphone when you use voice interaction features
- Transcribed text generated from your voice input
- Metadata associated with voice sessions (e.g., duration, timestamp, device type)
3.3 Usage and Interaction Data
- Records of your interactions with AI agents, including prompts, responses, and AI-generated artifacts (such as leases, charges, tasks, and work orders)
- In-app activity logs, feature usage patterns, and navigation data
- Device information including device type, operating system, and app version
- IP address and approximate geographic location derived from it
3.4 Communications Data
- Messages or queries you send to our support team
- Feedback or responses you submit through the App
3.5 Push Notification Data
- Device push tokens required to deliver notifications to your device
- Notification interaction data (e.g., whether a notification was opened)
3.6 Data We Do Not Collect
We do not knowingly collect sensitive personal data (special category data) such as health information, racial or ethnic origin, political opinions, religious beliefs, or biometric data, unless you voluntarily provide such information in the course of interacting with the App. If you believe you have inadvertently submitted such data, please contact us at [email protected].
We do not collect data from individuals under the age of 18. The App is intended solely for business users aged 18 and over.
4. How We Use Your Data
We use your personal data for the following purposes:
4.1 Providing the App and Its Services
- Creating and managing your account
- Authenticating your identity and managing your session
- Processing voice input and delivering AI agent responses
- Generating, storing, and surfacing AI-generated business artifacts
- Sending push notifications relevant to your account and workflow
4.2 Improving and Developing the App
- Analysing usage patterns and interaction data to improve features and performance
- Reviewing AI interactions for quality assurance, safety monitoring, and model improvement
- Conducting internal research and product development
4.3 Security and Fraud Prevention
- Detecting and investigating suspicious activity or potential security incidents
- Enforcing our Terms and Conditions and applicable legal obligations
- Protecting the rights, property, and safety of Kinxshn, our users, and others
4.4 Legal and Compliance Purposes
- Complying with applicable laws and regulations
- Responding to lawful requests from courts, regulators, or law enforcement authorities
- Establishing, exercising, or defending legal claims
4.5 Communications
- Responding to support enquiries and feedback
- Notifying you of material changes to these policies (as required by our Terms)
- Sending service-related communications (e.g., account alerts, security notices)
4.6 Community Integration
Where Kinxshn connects building activities with local communities, your professional profile data (name, organisation, role) may be used to facilitate introductions and service matching with community members and local providers, based on your operator's configuration and your consent preferences.
4.7 AI and Automated Decision-Making
Kinxshn uses AI agents to process personal data and assist with property management functions. The following types of automated decisions may be made:
- Maintenance prioritisation and resource allocation
- Experience adaptation based on user interaction patterns
- Task and work order generation and routing
You will be clearly informed when interacting with an AI agent. You have the right to request human review of any automated decision that significantly affects you. You may exercise this right via the in-app button or by contacting us at [email protected].
5. Lawful Basis for Processing (UK/EU Users)
We rely on the following lawful bases under UK GDPR / EU GDPR to process your personal data:
- Contract performance — to create and manage your account, authenticate you, and deliver the core services you or your organisation have contracted for.
- Legitimate interests — to improve the App, ensure security, prevent fraud, and develop new features, where those interests are not overridden by your fundamental rights and freedoms.
- Consent — for the collection and processing of audio and voice data, and for any optional marketing communications. You may withdraw consent at any time without affecting the lawfulness of processing before withdrawal.
- Legal obligation — where processing is required to comply with a legal obligation to which we are subject.
Where we rely on legitimate interests, you have the right to object to that processing. See Section 9 for details of your rights. A Legitimate Interest Assessment (LIA) has been conducted for each processing activity relying on this basis. You may request a copy by contacting us at [email protected].
For users in Switzerland, processing is governed by the Swiss Federal Act on Data Protection (nFADP). The principles of proportionality, good faith, and transparency apply to all processing of Swiss data subjects' personal data.
6. Voice and Audio Data
Given the sensitive nature of audio data, we apply additional protections:
- Voice data is collected only when you actively use voice interaction features in the App
- Audio recordings are transmitted over encrypted connections and are not stored indefinitely — they are processed to generate transcriptions and then deleted in accordance with our retention schedule (see Section 8)
- Transcriptions may be retained to support AI quality improvement, subject to appropriate anonymisation or pseudonymisation where feasible
- We do not sell voice data to third parties or use it for purposes unrelated to the App
Before using voice features for the first time, you will be asked to provide explicit consent to the collection and processing of your audio data. You may withdraw this consent at any time via Settings > Privacy > Voice Data. You are also responsible for obtaining any required consents from third parties whose voices may be captured while using the App (e.g., other participants in a conversation).
7. Sharing Your Data
We do not sell your personal data. We share it only in the following limited circumstances:
7.1 Within Your Organisation
Your account data and AI-generated artifacts may be visible to other authorised users within your organisation, as determined by your operator's access controls. Kinxshn is not responsible for how operators configure or manage access within their accounts.
7.2 Service Providers and Sub-processors
We share data with third-party service providers who assist us in operating the App, subject to appropriate data processing agreements. These may include:
- Cloud infrastructure providers (for hosting and storage)
- AI model providers (for natural language processing and agent functionality)
- Push notification providers (for delivering in-app notifications)
- Analytics providers (for understanding App usage and performance)
- Customer support tooling providers
All sub-processors are required to process data only as instructed by us, implement appropriate security measures, and comply with applicable data protection law.
7.3 Legal Disclosure
We may disclose your data to courts, regulators, law enforcement, or other public authorities where required to do so by law, or where we reasonably believe disclosure is necessary to protect our legal rights, prevent fraud, or protect the safety of any person.
7.4 Business Transfers
In the event of a merger, acquisition, or sale of all or part of our business, your personal data may be transferred to the acquiring entity. We will notify you of any such transfer and ensure appropriate protections are in place.
8. Data Retention
We retain personal data only for as long as necessary to fulfil the purposes for which it was collected, or as required by applicable law. Our general retention approach is as follows:
- Account and identity data: retained for the duration of your account and for up to 3 years following account closure, unless a longer period is required by law.
- Voice recordings: deleted within 30 days of capture, following transcription processing.
- AI interaction transcriptions and artifacts: retained for the duration of your organisational subscription and for up to 12 months following its termination, unless deletion is requested earlier.
- Usage and analytics data: retained in aggregated or pseudonymised form for up to 24 months.
- Support and communications data: retained for up to 3 years from the date of the last interaction.
- Consent records: retained for the duration of the consent plus 3 years to demonstrate compliance.
- AI agent processing logs: logs of automated decisions are retained for 3 years for audit and accountability purposes.
Where retention is required for legal or compliance reasons, we may retain specific data beyond these periods. When data is no longer needed, it is securely deleted or anonymised.
9. Your Rights
9.1 Rights Under UK GDPR / EU GDPR
If you are located in the United Kingdom or European Economic Area, you have the following rights in respect of your personal data:
- Right of access: you may request a copy of the personal data we hold about you.
- Right to rectification: you may request that we correct inaccurate or incomplete data.
- Right to erasure: you may request deletion of your personal data where there is no compelling reason for its continued processing.
- Right to restriction: you may ask us to restrict the processing of your data in certain circumstances (e.g., while accuracy is contested).
- Right to data portability: you may request a copy of your data in a structured, machine-readable format.
- Right to object: you may object to processing based on legitimate interests or for direct marketing purposes.
- Rights related to automated decision-making: you have the right not to be subject to decisions based solely on automated processing that produce legal or similarly significant effects, unless certain conditions are met.
- Right to withdraw consent: where we rely on consent as a lawful basis, you may withdraw it at any time without affecting the lawfulness of prior processing.
To exercise any of these rights, please contact us at [email protected]. You may also exercise your rights directly within the App via Settings > Privacy > My Data Rights, where you can download, correct, or delete your data. We also provide a dedicated data subject rights request form at kinxshn.com/privacy-rights.html for submitting formal requests. We will respond within 30 days. In complex or high-volume cases, we may extend this to 60 days and will notify you accordingly.
You also have the right to lodge a complaint with a supervisory authority. The relevant supervisory authorities for Kinxshn's operating jurisdictions are: UK — ICO (ico.org.uk), France — CNIL (cnil.fr), Belgium — APD/GBA (dataprotectionauthority.be), Germany — your State Data Protection Authority (Landesdatenschutzbeauftragte), Austria — DSB (dsb.gv.at), Switzerland — FDPIC (edoeb.admin.ch), Spain — AEPD (aepd.es).
9.2 Rights Under US Law
If you are located in the United States, you may have additional rights depending on your state of residence. In particular:
- California (CCPA/CPRA): California residents have the right to know what personal data is collected, request deletion, opt out of the sale of personal data (we do not sell personal data), and not be discriminated against for exercising these rights.
- Virginia, Colorado, Connecticut, and other states: Residents of these states may have similar rights under their applicable state privacy laws.
To submit a rights request under US law, please contact us at [email protected] with the subject line "US Privacy Rights Request". We will respond in accordance with applicable law.
10. International Data Transfers
Kinxshn operates across European and US jurisdictions. As a result, your personal data may be transferred to and processed in countries outside the UK or European Economic Area (EEA), including the United States.
Where such transfers occur, we ensure appropriate safeguards are in place to protect your data, including:
- Standard Contractual Clauses (SCCs): approved by the European Commission and UK ICO for transfers to third countries.
- UK International Data Transfer Agreements (IDTAs): for transfers from the UK.
- Adequacy decisions: where the destination country or territory has been deemed to offer an adequate level of data protection.
For transfers of Swiss data subjects' personal data, we rely on the Swiss Federal Council's adequacy decisions or Swiss-approved Standard Contractual Clauses as required by the nFADP.
You may request details of the specific safeguards we rely on for international transfers by contacting us at [email protected].
11. Security
We implement appropriate technical and organisational measures to protect your personal data against unauthorised access, loss, destruction, or alteration. These include:
- Encryption of data in transit using TLS and at rest using AES-256 encryption
- Access controls limiting data access to authorised personnel only
- Multi-factor authentication enforced for all staff accessing personal data systems
- Regular security reviews and vulnerability assessments
- Penetration testing conducted at least annually
- Incident response procedures for detecting and responding to data breaches
In the event of a personal data breach that is likely to result in a risk to your rights and freedoms, we will notify the relevant supervisory authority within 72 hours of becoming aware of it, and will notify affected individuals without undue delay where required by law. For data subjects in Switzerland, we will notify the FDPIC as soon as possible in accordance with the nFADP.
While we take data security seriously, no system is completely secure. You are responsible for maintaining the security of your account credentials and for notifying us promptly if you suspect unauthorised access.
12. Cookies and Tracking Technologies
The App may use cookies, device identifiers, or similar tracking technologies to support authentication, session management, and analytics. These may include:
- Essential technologies: required for the App to function correctly, including session tokens and authentication state.
- Analytics technologies: used to understand how users interact with the App and to improve performance. These may be provided by third-party analytics providers.
Where required by applicable law, we will seek your consent before deploying non-essential tracking technologies. Non-essential cookies are not placed until consent is given. Our consent banner provides equally prominent accept and refuse options. You may manage your preferences through our cookie preference centre or your device or App settings. Disabling essential technologies may affect App functionality. For a full list of cookies by name, provider, purpose, and duration, please refer to our dedicated cookie policy at kinxshn.com/cookies.html.
13. Children's Privacy
The App is intended solely for use by business professionals aged 18 and over. We do not knowingly collect personal data from individuals under the age of 18. If we become aware that we have collected data from a minor, we will delete it promptly. If you believe a minor has submitted data through the App, please contact us at [email protected].
14. Third-Party Links and Services
The App may integrate with or link to third-party services. This Privacy Policy applies only to data processed by Kinxshn. We are not responsible for the privacy practices of third-party services and encourage you to review their privacy policies before providing them with any personal data.
15. Changes to This Policy
We may update this Privacy Policy from time to time. Where changes are material, we will notify you via in-app notification or email at least 14 days before the changes take effect. Your continued use of the App after the effective date of any changes constitutes your acceptance of the revised Policy.
The date of the most recent update is shown at the top of this document. We recommend reviewing this Policy periodically.
16. Contact and Complaints
If you have any questions, concerns, or requests relating to this Privacy Policy or the handling of your personal data, please contact us:
Kinxshn — Data Privacy
Email: [email protected]
Website: www.kinxshn.com
We take all privacy complaints seriously and will respond promptly. If you are not satisfied with our response, you have the right to escalate your complaint to the relevant supervisory authority: UK — ICO (ico.org.uk), France — CNIL (cnil.fr), Belgium — APD/GBA (dataprotectionauthority.be), Germany — your State Data Protection Authority (Landesdatenschutzbeauftragte), Austria — DSB (dsb.gv.at), Switzerland — FDPIC (edoeb.admin.ch), Spain — AEPD (aepd.es).
17. Swiss Data Protection
If you are located in Switzerland, the processing of your personal data is additionally governed by the Swiss Federal Act on Data Protection (nFADP). The Federal Data Protection and Information Commissioner (FDPIC) is the competent supervisory authority. You may lodge complaints at edoeb.admin.ch.