Privacy Policy
This policy explains what personal data we collect when you visit kindlehdgs.com or use Kindle Holdings, why we collect it, who we share it with, and the choices you have. It applies to everyone, wherever you are.
01Who we are
The Kindle Holdings service is provided by KINDLE HOLDINGS PTE. LTD., a company incorporated in Singapore (UEN TBC: UEN), with its registered office at TBC: registered office address (“we”, “us”).
For the personal data of people who visit our website or administer a workspace, we are the controller. For the personal data our customers put inside their workspace — issue text, comments, attachments, the names of their own users — we act as a processor on the customer's instructions. Our Data Processing Addendum governs that relationship.
02What we collect
You give us
- Account data — name, work email, password hash, workspace name, role, avatar if you upload one.
- Billing data — company name, billing address, tax ID. Card numbers go straight to our payment processor; we never see or store them.
- Support data — anything you write to us in a ticket, email or call.
- Workspace content — issues, comments, attachments and any personal data you choose to put in them.
We collect automatically
- Usage data — pages and features used, timestamps, referring URL, actions taken in the app.
- Device and log data — IP address, browser and OS version, language, crash reports.
- Cookies and local storage — see the Cookie Policy.
We receive from others
- Identity providers — if you sign in with Google or SAML SSO, we receive your email, name and directory identifier.
- Code hosts — if you connect GitHub or GitLab, we receive repository, branch, pull request and commit metadata, and the account identifiers of the people involved.
03How we use it
- To provide, operate and secure the service, including authentication and abuse prevention.
- To bill you and keep the accounting records the law requires us to keep.
- To answer support requests and tell you about changes that affect your workspace.
- To understand which features are used, so we can decide what to build and what to remove.
- To send product and marketing email, where you have opted in or where we are permitted to email an existing customer. Every such message has a one-click unsubscribe.
We do not sell personal data, and we do not share it for cross-context behavioural advertising. We do not use your workspace content to train machine learning models.
04Legal bases (EEA and UK)
| Purpose | Basis |
|---|---|
| Providing the service you signed up for | Performance of a contract |
| Billing, tax and statutory records | Legal obligation |
| Security, fraud prevention, product analytics | Legitimate interests |
| Marketing email to non-customers, non-essential cookies | Consent |
Where we rely on legitimate interests, we have weighed them against your rights and recorded the assessment. You can object at any time using the contact details below.
05Cookies
We use a small number of strictly necessary cookies, plus local storage for your theme preference, plus analytics that you can decline. The full inventory — name, purpose, duration — is in the Cookie Policy.
06Who we share with
We share personal data with service providers who process it only on our instructions, under written contract:
| Provider | Purpose | Region |
|---|---|---|
| TBC: cloud host | Application hosting and databases | TBC: region |
| TBC: payment processor | Subscription billing | TBC: region |
| TBC: email provider | Transactional and product email | TBC: region |
| TBC: analytics provider | Product analytics | TBC: region |
| TBC: support desk | Support ticketing | TBC: region |
The current list is maintained at Sub-processors. We also disclose data where we are legally compelled to, and to an acquirer in a merger or asset sale — in which case we will tell you before your data becomes subject to a different policy.
07International transfers
We are based in Singapore and our providers operate in several countries, so your data will cross borders. For transfers out of the EEA or UK we rely on the European Commission's Standard Contractual Clauses together with the UK Addendum, plus a transfer risk assessment. For transfers out of Singapore we take the steps the Personal Data Protection Act requires to ensure a comparable standard of protection. A copy of the relevant clauses is available on request.
08How long we keep it
| Data | Retention |
|---|---|
| Workspace content | For the life of the workspace, then 30 days in backup before deletion |
| Account records | Until the account is closed, then 90 days |
| Invoices and tax records | 5 years, as Singapore law requires |
| Security and access logs | 12 months |
| Support tickets | 24 months from resolution |
09Your rights
Depending on where you live you may have the right to access your data, correct it, delete it, restrict or object to processing, withdraw consent, receive a portable copy, and not be subject to solely automated decisions with legal effect. We do not make such decisions.
Singapore (PDPA) — you may request access to and correction of your personal data, and withdraw consent to marketing.
California (CCPA/CPRA) — you may request to know, delete and correct, and to opt out of sale or sharing. We do not sell or share personal data as those terms are defined, so there is nothing to opt out of. We will not discriminate against you for exercising any right.
To exercise a right, email TBC: privacy@ email. We answer within 30 days and will verify your identity first. If you are unhappy with the outcome you may complain to your supervisory authority, or in Singapore to the Personal Data Protection Commission.
If your data sits inside a customer's workspace, send your request to that customer — we will forward it and help them respond.
10Security
We encrypt data in transit and at rest, restrict access to the people who need it, and log administrative actions. The detail is on our Security page. No system is perfectly secure; if we suffer a breach that is likely to result in a risk to you, we will notify you and the relevant regulator within the timeframes the law sets.
11Children
Kindle Holdings is a workplace tool and is not directed at children. We do not knowingly collect personal data from anyone under 16. If you believe a child has given us data, contact us and we will delete it.
12Changes to this policy
We will post any change here and update the date at the top. If a change materially reduces your rights we will give at least 30 days' notice by email or in the app before it takes effect.
13Contact us
Data protection enquiries: TBC: privacy@ email
Data Protection Officer: TBC: DPO name
Postal: TBC: registered office address
See also the Contact page.