Privacy Policy
Last updated 2026
This explains what personal data kitset.io holds, why, where it is processed and how long it stays. It is written to describe what the software actually does rather than to describe every thing it might conceivably do.
1. Two different roles
Where you are our customer — your billing contact, your Owner's account, the emails you send us — we are the controller of that data and this policy governs it.
Where your workspace holds data about your staff, you are the controller and we are your processor. You decide what goes in and why; we only process it to run the service on your behalf. Those terms are in the Data Processing Addendum.
2. What is stored
About the people in a workspace
Name, email address, job title, department, team, manager, cost centre, work location, role, licence type, account status, when the email was verified, when the password was last changed, and the time of the last sign-in.
About their activity
An audit trail of meaningful changes, naming the actor, what changed, a short summary and the time. Active sessions, each with a browser user-agent string, an IP address and timestamps. Failed sign-in counters, keyed to a one-way digest of the account and source address rather than to the address itself.
Content you create
Whatever the installed modules hold: vendor and contract records, purchase requests and decisions, business-system ownership and access lists, policies and training with per-person acknowledgements and quiz results, handovers and their action items, employee transition checklists, asset assignments, and workplace records such as incidents and visitors. Some of this is personal data about your staff; you choose what to put in.
Files
Files attached to records, plus their filename, size, type, who uploaded them and when. Stored in private object storage and served only through short-lived signed links.
Queued and sent messages with their recipient, subject and body, and delivery outcomes. Addresses that hard-bounce or file a spam complaint are added to a suppression list so we stop mailing them.
Security credentials
Passwords are stored only as salted, iterated hashes and cannot be recovered. Two-factor secrets are encrypted at rest with a key kept separately from the session-signing key. Recovery codes and invitation, reset and verification tokens are stored only as one-way digests — we cannot read the original value of any of them.
Technical logs
One structured line per request: method, path, status, duration, and the workspace and user where a session was resolved. Query strings are deliberately excluded because they carry single-use account tokens. Credentials are redacted at the logging handler.
3. What is not stored
- Payment card details. Checkout happens on Stripe; we receive an identifier and a status, never a card number.
- No advertising or cross-site tracking. There are no third-party analytics, no advertising pixels and no tracking cookies anywhere on this site or in the product.
- No training data. Your workspace content is never used to train machine learning models.
4. Cookies
The public pages you are reading set no cookies at all. Signing in sets two: a session cookie, which is HTTP-only and, in production, secure-only; and a token used to protect against cross-site request forgery. Both are strictly necessary to operate the service and neither is used for tracking. Your browser may also keep small local preferences, which never leave your device.
5. Why we process it
- To provide the service — performance of our contract with you.
- To keep it secure — rate limiting, audit trails and session management, on the basis of our legitimate interest in preventing abuse.
- To bill you — performance of the contract and our legal obligation to keep financial records.
- To email you about the service — operational messages such as invitations, reminders and security notices are part of the service, not marketing.
6. Who else sees it
Only the providers listed on the subprocessors page, each doing one specific job under contract. We do not sell personal data, and we do not share it for anyone else's marketing. We will disclose data if legally compelled, and will tell you unless we are prohibited from doing so.
7. Where it is processed
The application and database run in Singapore, and object storage is in
ap-southeast-1. Transactional email is sent through a provider in
us-east-1 in the United States, which means message content and recipient addresses
are transferred there. Payment processing involves the United States and Ireland. Where a
transfer leaves a jurisdiction with transfer restrictions, we rely on the provider's standard
contractual clauses.
8. How long it is kept
We do not operate automatic retention schedules. Workspace data, including the audit trail and the email log, is kept for as long as the workspace exists. We would rather state that plainly than imply a policy that is not implemented.
On termination or on request we delete workspace data within 30 days, except where the law requires us to keep it. Backups expire in the ordinary course within 30 days. The email suppression list is kept indefinitely, because forgetting that an address hard-bounced would mean mailing it again.
9. Erasing one person
A workspace Owner can erase an individual from the People screen, and we can do it on request if they cannot. It is not reversible, and it is worth being precise about what it does, because “delete” is the wrong word for part of it.
Removed: the person’s name, email address, job title, cost centre and reporting line; their password; their sessions, two-factor enrolment and recovery codes; their notifications; their permissions, group memberships and location access. Any equipment assigned to them is returned, and their access to every system record is revoked.
Kept, pointing at a deleted user: the audit trail, any training they completed, and the record that they held a piece of company equipment between two dates. Your workspace is the controller of this data and in most cases needs it as evidence — who approved a purchase, who acknowledged a policy, who had the laptop — so we retain the record of what happened with the person’s identity taken off it. Where the audit trail named them in a line we can prove is about them, that name is replaced and the entry is marked as having been redacted.
What we cannot reach: free text a colleague typed. A handover note, a purchase justification or an uploaded file’s name may still mention the person. We count those entries and show the number when the erasure is confirmed, so nobody is told the record is clean when it is not.
10. Your rights
Depending on where you are, you may have the right to access, correct, delete, restrict or object to processing, and to receive your data in a portable form. Much of this you can do yourself inside the product; for anything else, write to [email protected] and we will respond within 30 days.
If you are an employee of one of our customers, your employer controls your workspace data. Please ask them first; if you contact us directly we will forward your request to them and tell you we have done so.
You may also complain to your local data protection authority. In Singapore that is the Personal Data Protection Commission.
11. Security
Measures are described on the security page, including what we do not yet have. If we discover a personal data breach affecting your workspace, we will notify you without undue delay and within 72 hours of becoming aware of it, with what we know at the time.
12. Children
kitset.io is a workplace tool and is not directed at children. We do not knowingly create accounts for anyone under 16.
13. Changes
We will update the date at the top of this page when this policy changes, and give notice to workspace Owners for material changes.
14. Contact
FLOW FN PTE. LTD. (UEN 202617303Z), Singapore. Privacy: [email protected]. Data protection contact: [email protected].