Preamble
KANAP (hereinafter "KANAP"), an EURL (single-member limited liability company) registered with the RCS Saverne under number 939 098 190, whose registered office is located at 2, rue du Finhay, 67210 Obernai, France, attaches the highest importance to the protection of your personal data. This privacy policy (hereinafter the "Policy") aims to inform you in a clear and transparent manner about the processing of personal data implemented by KANAP in connection with the use of the online IT management platform "KANAP" (hereinafter "the Platform").
KANAP undertakes to comply with the General Data Protection Regulation (GDPR) and French Law No. 78-17 of January 6, 1978 relating to data processing, files, and freedoms, as amended.
1. Data controller
The data controller for personal data collected via the Platform is KANAP, an EURL (single-member limited liability company) registered with the RCS Saverne under number 939 098 190, whose registered office is located at 2, rue du Finhay, 67210 Obernai, France.
For data entered by customers into the Platform (budget data, financial information, user data within tenants), the customer organization acts as the data controller, and KANAP acts as the data processor.
2. Personal data collected
KANAP collects the following personal data from users of the Platform:
- Account information: First name, last name, email address, job title, organization name
- Authentication data: Login credentials (passwords are hashed and never stored in plain text)
- Usage data: Platform usage logs, session information, IP addresses
- Financial data: Budget items, CAPEX/OPEX data, allocation information, contract details entered by users
- Billing information: Company name, billing address, VAT number
Payment information (credit card details) is not known to KANAP. It is processed directly by the secure payment platform (Stripe).
3. Purposes of processing
- Service provision: Data is necessary to provide access to the Platform, manage user accounts, and deliver the IT management service.
- Service improvement: Usage data is used to improve the quality and functionality of the service, identify technical issues, and optimize performance.
- Customer support: Data is used to respond to user inquiries, provide technical assistance, and resolve issues.
- Billing and invoicing: Data is necessary to process subscriptions, issue invoices, and manage payments.
- Security: Data is processed to ensure the security of the Platform, detect and prevent fraud, unauthorized access, and security incidents.
- Legal compliance: Data is processed to comply with legal and regulatory obligations.
4. Legal basis for processing
- Contract performance: Processing is necessary to provide the KANAP service (account management, Platform access, etc.).
- Legitimate interest: Processing for service improvement, security, and fraud prevention is based on KANAP's legitimate interest in developing and providing a quality and secure service.
- Legal obligation: Processing may be necessary to comply with legal obligations (accounting, tax, anti-money laundering, etc.).
- Consent: For certain optional features or communications, processing may be based on the user's explicit consent.
5. Data recipients
KANAP may share your personal data in the following cases:
- Service providers: KANAP may use service providers (hosting, infrastructure, payment processing, email services, etc.) who may have access to personal data in the course of their duties. These providers are bound by confidentiality and security obligations and act as data processors under KANAP's instructions.
- Legal obligations: KANAP may be required to disclose personal data to administrative or judicial authorities when required by law.
KANAP undertakes not to share users' personal data for commercial purposes other than those mentioned above. KANAP will never sell or rent your personal data to third parties.
The service providers (sub-processors) that process personal data on behalf of KANAP for the cloud service are:
- Hetzner Online GmbH (Germany): hosting of the servers, database and file storage.
- Cloudflare (United States): network, CDN and TLS termination in front of the servers, with contractual safeguards for transfers outside the European Union.
- Resend (transactional email, United States): account activation, password reset and notification emails.
- Stripe (payments, Ireland and United States): payment processing and subscription billing.
- AI model provider for the built-in AI features of the cloud service: AI features are off by default. The built-in model receives no data until the workspace has accepted its provider and where it processes data, both named in the application. An administrator of the workspace gives this confirmation, which covers the assistant, the agents and scheduled processing, and a new confirmation is asked if the provider or the location changes. Administrators can use their own model provider instead. The provider may process data outside the European Union.
Customers who self-host KANAP choose their own providers, and KANAP does not process their data. Customers of the cloud service who connect their own AI model provider choose that provider, and KANAP does not send their data to its built-in model.
6. Data retention period
- Account data and the data entered by customers into the Platform are retained for the duration of the contract. On termination, they are deleted at the customer's request.
- Billing and invoicing data is retained for 10 years in accordance with French accounting and tax regulations.
- Payment data is not retained by KANAP and is managed directly by the payment processor (Stripe).
7. Data security
- HTTPS for all connections to the Platform
- Encryption at rest of secrets and credentials stored by the Platform (AES-256-GCM)
- Role-based access control and authentication mechanisms
- Hosting in the European Union (Hetzner, Germany)
- Password hashing using industry-standard algorithms (Argon2id)
- Multi-tenant isolation using Row-Level Security (RLS) in the database
- Source code published under AGPL v3, and a private channel to report vulnerabilities
8. User rights
In accordance with the GDPR, you have the following rights regarding your personal data:
- Right of access
- Right to rectification
- Right to erasure
- Right to restriction of processing
- Right to object
- Right to data portability
- Right to withdraw consent
To exercise your rights, you can contact KANAP at [email protected]. You also have the right to lodge a complaint with the French Data Protection Authority (CNIL).
9. International data transfers
The Platform is hosted in the European Union, in Germany. Some providers listed in section 5 may process personal data outside the European Union, for example Cloudflare for network traffic. In that case, KANAP ensures that appropriate safeguards are in place (the EU-US Data Privacy Framework or standard contractual clauses).
10. Cookies and tracking technologies
The KANAP website sets no advertising or analytics cookies and shows no cookie banner. We measure audience with Cloudflare Web Analytics, which works without cookies and without storing anything on your device. The contact and trial forms use Cloudflare Turnstile, a security check that tells people from automated programs. The website remembers your light or dark theme choice in your browser, only when you pick one.
The application uses only the cookies needed to sign in and keep your session. It also stores interface preferences, such as your theme and table layout, in your browser. You can remove them at any time in your browser settings.
11. Modifications to the policy
KANAP reserves the right to modify this Policy at any time. Users will be notified of changes by any means, including a notification on the Platform or by email.
For any questions regarding this privacy policy, please contact [email protected].