Last Updated: July 7, 2026
Kindilly ("Kindilly", "we", "us", or "our") operates a workplace appreciation and engagement application platform. This Privacy Policy details our formal practices regarding the collection, use, disclosure, storage, international transfer, and comprehensive protection of personal data belonging to individuals utilizing our systems.
This Policy is structured to comply with the Canadian Personal Information Protection and Electronic Documents Act (PIPEDA), the European Union General Data Protection Regulation (GDPR), the California Consumer Privacy Act (CCPA) as amended, and other applicable regional data protection legislations.
1. Corporate Accountability & Data Controller Information
Under global data privacy regulations, Kindilly acts as both a Data Processor (when delivering SaaS services directly to an enterprise corporate client under a commercial services agreement) and a Data Controller (when managing your direct account profile and platform operations).
We have designated a formal Privacy Compliance Officer to oversee our organizational compliance programs. If you have any inquiries regarding your data protection, you may reach our customer service team at:
Email: illy@kindilly.com
2. Legal Bases for Data Processing (GDPR Baseline)
For individuals residing within the European Economic Area (EEA), the United Kingdom, or comparable jurisdictions, we process personal information exclusively under the following valid legal bases:
- Performance of a Contract: To initialize your account, manage secure login architecture, process subscription invoicing, and fulfill our core obligations under our terms and agreements.
- Legitimate Interests: To ensure the core software environment remains safe, perform automated content moderation, protect against application vulnerabilities, and continuously optimize user interfaces.
- Consent: Where you provide explicit, affirmative opt-in authorization for specific non-core workflows, such as enabling location tracking or subscribing to optional administrative communications.
- Legal Obligation: To satisfy applicable regulatory reporting requirements, corporate tax records, or respond to lawful court orders.
3. Categories of Personal Data Collected
We collect only the minimum required data necessary to deliver a stable, secure SaaS platform:
- A. Identifiers Provided Directly: Full name, corporate or personal email address, phone number, physical mailing address, and cryptographically hashed password strings.
- B. Automated Technical Metrics: Login history metadata, internet protocol (IP) address blocks, client browser versions, device operating system parameters, and push notification tokens.
- C. Optional Ecosystem Data: Birthday matrices, gender identifiers, and external social media profile URLs—provided explicitly at your discretion within your profile setup.
- D. Core Transactional and Content Records: All appreciation posts, team rewards configurations, uploaded image or video files, and corporate ledger records generated through internal usage.
4. Technical Security & Backend Data Safeguards
Kindilly implements advanced technical and administrative security controls designed to fulfill the stringency of PIPEDA Principle 7 (Safeguards) and GDPR Article 32:
- Password Cryptography: User authentication credentials are never stored in readable text formats. We enforce industry-standard bcrypt cryptographic hashing algorithms to resist brute-force vectors.
- Data Encryption At Rest: Highly sensitive internal configurations, operational API parameters, external credentials, and key databases are protected using symmetric AES-256-CBC encryption schemes.
- Data Encryption In Transit: All communications between the user's web browser, the application layers, and external processing APIs are encapsulated over secure, forced HTTPS/TLS 1.3 communication tunnels.
5. Third-Party Data Transmissions & Processors
To maintain operational continuity, Kindilly shares specific data segments with verified third-party vendors under strict Data Processing Agreements (DPAs) that bind vendors to equivalent compliance baselines. All external API transmissions execute over secure HTTPS channels:
- Infrastructure & Cloud Storage: Secure cloud hosting, server resources, and database storage arrays (e.g., AWS, Google Cloud Storage).
- Communications & Alerts: SMS notification triggers, transactional email servers, and mobile push notifications (e.g., Twilio, OneSignal, SMTP providers).
- Content Safety & Automated AI: Advanced text analysis and computer vision algorithms to filter prohibited content and maintain organizational safety guidelines (e.g., Google Vision, OpenAI).
- Real-Time Communication Media: Video, live stream, or low-latency media rendering engines integrated inside application layers (e.g., Agora).
- Payment Processing & Auth: PCI-compliant credit card processing networks and secure single sign-on (OAuth) identity bridges.
6. Cross-Border International Data Transfers
Kindilly operates primarily from data center infrastructures located within Canada. Personal information may be transferred across international borders, including to Canada, the United States, or member states of the European Union, depending on resource optimization and backup configurations.
When transferring data across international boundaries, we implement valid legal frameworks, including PIPEDA compliance mandates, Standard Contractual Clauses (SCCs), and Data Transfer Impact Assessments (TIAs) to guarantee that your data is protected with equal care regardless of geography.
7. Data Retention, Minimization, and Account Erasure
7.1 Data Minimization Baseline
We retain personal data only for as long as necessary to complete the defined commercial processing purposes, satisfy statutory corporate tax records, or fulfill our contractual uptime agreements.
7.2 The Hard Delete Mechanism
In accordance with your right to deletion under PIPEDA, GDPR, and CCPA, users can trigger account closure at any time. When an account deletion event is approved, Kindilly triggers an automated, cascaded database purge script.
7.3 Data Erasure Scope
This backend execution permanently wipes all target entries from the main user tables, media file buckets, historical interaction logs, and transactional databases. This workflow deletes data entirely from active production environments. It is an irreversible architecture.
8. Comprehensive Data Subject Rights
Depending on your operational jurisdiction, you hold specific statutory data sovereignty rights:
- Right of Access and Portability: You have the right to request a clear, machine-readable transcript of all personal data points Kindilly holds concerning you. Access requests under PIPEDA are handled without charge and resolved within thirty (30) days.
- Right to Rectification: You can request immediate correction of inaccurate or incomplete information within our records.
- Right to Erasure ("Right to be Forgotten"): You can execute the automated deletion workflow to permanently scrub your footprint from our database infrastructure.
- Right to Restrict or Object: You can refuse certain processing paths, such as administrative updates, or withdraw previously granted consent parameters without impacting core system login requirements.
- Right to Lodge a Complaint: You maintain the legal right to report compliance issues to your relevant local authority, including the Office of the Privacy Commissioner of Canada (OPC) or European Data Protection Authorities (DPAs).
9. Privacy Policy Revisions
Kindilly reserves the right to adjust this Privacy Policy as our underlying cloud systems or regulatory realities evolve. Every update will feature a revised version timestamp at the top of the policy page. We recommend verifying this text periodically to ensure you remain fully informed of our active safety frameworks.