Third Party Index

Snapshot 20310

Document
Privacy policy
URL
https://kendis.io/privacy-policy/
Fetched
HTTP status
200
Content type
text/html; charset=utf-8
Fetch mode
static
Size
121034 bytes
SHA-256 (raw)
50e0714b6afcf88688d873a154a6d2b9ac4f8de614f93e2796133fdb13f61811
SHA-256 (normalized text)
e5f8b0058050a7842e9dac0c4638f3236bdce28a4653ede8994af185013b96be

Normalized text

Scripts and page chrome removed; this is what change detection compares.

Contents
Contents
Kendis Oy (“Kendis”, “we”, “us”) provides the Kendis planning platform at app.kendis.io (the “Service”) and the website kendis.io and its subdomains (the “Website”). This Privacy Policy explains how we process personal data when you visit the Website, contact us, attend our events or training, or use the Service as an administrator or user of a customer account. It applies to all Hosting Regions we offer.
This Privacy Policy should be read together with the terms applicable to your use of the Service and, for customers, the Kendis License Agreement, its Data Processing Addendum (“DPA”) and the Hosting and Subprocessor Schedule (trust.kendis.io/subprocessors) (the “Schedule”).
1
Who we are
Kendis Oy is a company incorporated in Finland with Business ID 2874062-5 and registered office at Lapinlahdenkatu 16, 00180 Helsinki, Finland. Kendis Oy is the data controller for the processing described in this Privacy Policy, except where Section 2 states otherwise.
Privacy enquiries: [email protected]. Security reports: [email protected].
2
Our two roles: controller and processor
Kendis processes personal data in two different capacities. Which one applies depends on the data concerned.
Category	What it is	Kendis' role	Governing document
Account Data	Personal data about our customers' contacts and administrators, prospects and Website visitors: names, business contact details, login and role information, billing details, support communications, usage and technical data.	Controller	This Privacy Policy
Licensee Data	Content that a customer and its users enter into or synchronise with the Service: boards, features, objectives, dependencies, risks, comments, attachments, data imported from Jira or Azure DevOps, and the names and email addresses of the customer's users.	Processor, acting on the customer's instructions	License Agreement, DPA and Schedule; the customer's own privacy notice
If you use the Service through an account operated by your employer or another organisation, that organisation is the controller of Licensee Data and decides how it is used. Questions and rights requests about Licensee Data should be directed to that organisation; we will assist it as required by the DPA.
Optional AI features. The Service includes optional AI features that are off by default and can be enabled only by a customer administrator. Their use is governed by the Kendis AI Terms of Use. When AI features are enabled, Kendis processes the relevant Licensee Data as processor on the customer's instructions, and any AI Subprocessor engaged is identified in the Schedule.
3
Personal data we collect
Category	Examples	Source
Identity and contact	Name, work email address, telephone number, job title, employer, country	You, or your organisation when it creates your user
Account and administration	Login credentials (passwords are stored hashed), authentication method, role and permissions, account settings, selected Hosting Region, licence details	You; generated by the Service
Billing	Billing contact, invoicing address, VAT number, purchase orders, payment status. Card details are entered directly with our payment processor and are not stored by Kendis	You; our payment processor
Communications	Support tickets, chat conversations, emails, demo and support bookings, event and training registrations, survey responses	You
Usage and technical	IP address, browser and operating system, device type, pages viewed, referring site, feature usage, timestamps, error and security logs	Collected automatically
Marketing	Newsletter and marketing subscriptions, preferences, email engagement (opens and clicks), training progress	You; collected automatically
Prospect data	Business contact details of individuals at organisations we believe may be interested in the Service	Public sources and business data providers
We do not intentionally collect special categories of personal data (for example health data or data revealing political opinions) and ask that you do not submit such data to us.
4
Why we process personal data and on what legal basis
Purpose	Legal basis (GDPR Article 6(1))
Creating and administering accounts, authenticating users, providing the Service and support	(b) performance of a contract, or steps taken at your request before entering into one
Invoicing, payment collection and accounting	(b) performance of a contract; (c) legal obligation under the Finnish Accounting Act
Service communications: security notices, Subprocessor change notices, release notes, maintenance windows	(b) performance of a contract; (f) legitimate interest in keeping customers informed
Securing the Service and the Website, preventing fraud and abuse, logging, incident response, operating our ISO/IEC 27001 controls	(f) legitimate interest in security; (c) legal obligation
Understanding how the Service and Website are used in order to improve them	(f) legitimate interest; (a) consent, for analytics cookies
Marketing to business contacts, newsletters, event invitations	(f) legitimate interest in promoting the Service to business contacts, with the right to opt out at any time; (a) consent where required by law
Responding to enquiries, demo requests and event or training registrations	(b) or (f)
Establishing, exercising or defending legal claims; complying with law and regulatory requests	(c) legal obligation; (f) legitimate interest
Where we rely on legitimate interests, we have assessed that our interests are not overridden by your rights and freedoms. You may object to processing based on legitimate interests at any time (Section 11).
5
Hosting Regions and where personal data is processed
Customers select a Hosting Region when they order the Service. Licensee Data is stored and processed only in the selected Hosting Region, including backups. The Hosting Region cannot be changed after the account is created.
Hosting Region	Infrastructure provider	Processing and backup location	Transfer of Licensee Data outside the EEA
Germany	OVHcloud (OVH Hosting Limited, Ireland), including OVHcloud Managed MongoDB	Germany	None. Licensee Data remains within the European Economic Area, and content delivery and edge security are provided from EEA locations.
United States	Amazon Web Services, Inc. and MongoDB, Inc. (MongoDB Atlas)	Northern Virginia and other United States locations	Yes. Transfers are made under the EU Standard Contractual Clauses and, for Amazon Web Services, the EU-US Data Privacy Framework (Section 8).
Where the Germany Hosting Region is selected, access to Licensee Data is restricted to authorised personnel of Kendis and its Subprocessors located in the European Economic Area, the United Kingdom or Switzerland, as set out in Section 6 of the Schedule.
Account Data is processed in Kendis' business systems (customer relationship management, support, billing, email and productivity tools) irrespective of the Hosting Region. Some of these systems are operated by providers located outside the EEA; they are identified in Section 5 of the Schedule together with the transfer mechanism relied upon.
6
Who we share personal data with
We share personal data only where necessary for the purposes in Section 4, with:
Subprocessors and service providers. Hosting and database infrastructure for each Hosting Region, content delivery and edge security, transactional email delivery, customer relationship management, customer support and messaging, payment processing, business productivity and document storage, website and product analytics, marketing email, newsletter publishing and our customer training portal. The current list, including each provider's legal entity, location, the data it receives and the transfer mechanism relied upon, is maintained in the Schedule at trust.kendis.io/subprocessors. Customers are notified of additions or replacements in accordance with the DPA.
Integration partners, at your direction. When a customer connects the Service to Jira, Azure DevOps or another tool, data flows between the Service and that tool as configured by the customer. The customer's agreement with the integration provider governs that provider's processing.
Professional advisers and certification bodies. Auditors, accountants, legal advisers and our ISO/IEC 27001 certification body, bound by confidentiality.
Authorities. Courts, regulators and law enforcement where disclosure is required by applicable law. Where a request concerns Licensee Data we will, unless legally prohibited, refer the requesting authority to the customer and notify the customer in accordance with the DPA.
Business transfers. A purchaser or prospective purchaser of all or part of our business, subject to this Privacy Policy and appropriate confidentiality safeguards.
We do not sell personal data and do not share it with third parties for their own marketing.
7
Cookies and similar technologies
The Website and the Service use cookies and similar technologies. Before non-essential cookies are set you are asked for consent through our cookie banner, in accordance with the ePrivacy Directive (2002/58/EC) as implemented in Finland by the Act on Electronic Communications Services (917/2014). You can change or withdraw your choices at any time through the banner or your browser settings. Blocking strictly necessary cookies may prevent parts of the Service from working.
Type	Purpose	Basis
Strictly necessary	Sign-in, session management, security, load balancing and remembering your cookie choices	Necessary to provide the service you requested
Analytics	Counting visitors and understanding how the Website and Service are used so that we can improve them	Consent
Functionality	Remembering preferences such as language and interface settings	Consent
The cookies currently in use are listed in the Cookie Schedule at the end of this Privacy Policy.
8
International transfers
Kendis is established in Finland. Whether personal data leaves the European Economic Area depends on the data concerned:
Licensee Data, Germany Hosting Region: not transferred outside the EEA.
Licensee Data, United States Hosting Region: processed in the United States by Amazon Web Services, Inc. and MongoDB, Inc. under the EU Standard Contractual Clauses (Commission Implementing Decision (EU) 2021/914). Amazon Web Services is additionally certified under the EU-US Data Privacy Framework.
Account Data, all Hosting Regions: some of the providers listed in Section 5 of the Schedule are located in, or process data in, the United States or other countries outside the EEA.
For every transfer outside the EEA we rely on one of the following safeguards under Chapter V of the GDPR: (i) a European Commission adequacy decision, including the EU-US Data Privacy Framework for recipients certified under it; or (ii) the EU Standard Contractual Clauses, supported by a transfer impact assessment and supplementary measures such as encryption in transit and at rest and access restrictions. Transfers to the United Kingdom and Switzerland are covered by adequacy decisions. The transfer mechanism used for each provider is stated in the Schedule, and a copy of the relevant Standard Contractual Clauses is available on request.
9
How long we keep personal data
Data	Retention period
Licensee Data	For the term of the customer's subscription, then deleted in accordance with the deletion timelines in the DPA
Account Data of customers	For the term of the subscription and for as long as needed afterwards to close the account, resolve disputes and meet legal obligations
Billing and accounting records	For the period required by the Finnish Accounting Act (currently six years from the end of the financial year, and ten years for the ledgers themselves)
Support and chat conversations	Three years from the last interaction
Marketing and prospect data	Until you opt out or object, or until we have had no engagement from you for twenty-four months
Website analytics data	Fourteen months
Security and access logs	Twelve months, unless retained longer for an investigation
Data may persist in encrypted backups for a limited period after deletion from live systems, after which it is overwritten in the ordinary backup cycle.
10
How we keep personal data secure
Kendis operates an information security management system certified to ISO/IEC 27001. Measures include encryption of data in transit (TLS) and at rest, single sign-on and multi-factor authentication, role-based access control, named individual accounts with no shared credentials, logging of administrative access, vulnerability management, regular backups and a tested incident response process. Our Subprocessors are bound by written contracts imposing equivalent obligations.
In the event of a personal data breach we notify affected customers as required by the DPA and the supervisory authority within 72 hours where required by the GDPR. If you believe your data has been compromised, contact [email protected].
11
Your rights
Subject to the conditions in the GDPR, you have the right to:
access the personal data we hold about you and receive a copy;
have inaccurate or incomplete data corrected;
have your data erased;
restrict our processing of your data;
receive the data you provided to us in a structured, machine-readable format and have it transmitted to another controller;
object to processing based on legitimate interests, including direct marketing; and
withdraw consent at any time where processing is based on consent, without affecting processing carried out before withdrawal.
We do not make decisions based solely on automated processing that produce legal or similarly significant effects.
To exercise any of these rights, email [email protected]. We may need to verify your identity. We respond within one month, extendable by two further months for complex requests, and do not charge a fee unless a request is manifestly unfounded or excessive. Where a request concerns Licensee Data we will refer it to the customer that controls that data and assist the customer as required by the DPA.
If you are dissatisfied with how we handle your data you may lodge a complaint with the Office of the Data Protection Ombudsman of Finland (Tietosuojavaltuutetun toimisto, tietosuoja.fi) or with the supervisory authority in the EEA member state where you live or work.
12
Marketing communications
We send marketing emails, newsletters and event invitations to business contacts who have consented or, where permitted by law, whose organisation has a customer or prospective customer relationship with us. Every marketing email contains an unsubscribe link, and you can also opt out by emailing [email protected]. Opting out of marketing does not stop service communications that are necessary to operate your account, such as security notices and Subprocessor change notices.
13
Children
The Website and the Service are directed at businesses and are not intended for children under 16. We do not knowingly collect personal data from children. If you believe a child has provided personal data to us, contact us and we will delete it.
14
Third-party websites
The Website and the Service contain links to third-party websites and services, including integration partners. We are not responsible for their privacy practices and this Privacy Policy does not apply to them.
15
Changes to this Privacy Policy
We may update this Privacy Policy from time to time. Each version carries a version number and effective date. Material changes are notified to customer account administrators by email or in the Service before they take effect, and the current version is always published at kendis.io/privacy-policy.
Version	Effective date	Change
2.0	10 August 2026	Complete revision. Adds the Germany Hosting Region; distinguishes Kendis' controller and processor roles; aligns transfer mechanisms with the EU Standard Contractual Clauses and the EU-US Data Privacy Framework; replaces UK references with Finnish law and supervisory authority; adds legal bases, retention periods and a reference to the Hosting and Subprocessor Schedule.
1.0	2018	First publication as the Data Protection & Compliance Policy.
16
Contact
Kendis Oy, Lapinlahdenkatu 16, 00180 Helsinki, Finland. Business ID 2874062-5.
Privacy: [email protected]. Security: [email protected].
This Privacy Policy is governed by the laws of Finland.
CS
Cookie Schedule
The cookies currently set by the Website and the Service. If you believe this list is incomplete, let us know at [email protected].
Cookie	Type	Purpose	Duration
Session cookie	Strictly necessary	Maintains your signed-in session while you use the Service	Session
Cookie consent	Strictly necessary	Remembers the cookie choices you made in the banner	12 months
Analytics cookies	Analytics	Measure how visitors use the Website and Service so that we can improve them (Google Analytics)	Up to 14 months
Preference cookies	Functionality	Remember language and interface settings	12 months
ISO 27001 | GDPR Compliant