Privacy Policy

Last updated: 25 June 2026

This Privacy Policy explains how Keonda (“we”, “us”, or “our”) collects, uses, stores, and shares your personal data when you use the Keonda application and related services (the “Service”).

We are committed to protecting your privacy and processing your personal data in accordance with the UK General Data Protection Regulation (UK GDPR) and the Data Protection Act 2018.

Please read this policy carefully. By using the Service, you acknowledge that you have read and understood how we handle your personal data.

1. Who We Are (Data Controller)

Keonda is operated by MEDDEV LTD, registered in England and Wales.

For the purposes of UK GDPR, we are the data controller of your personal data.

If you have any questions about this Privacy Policy or how we handle your data, please contact us at:

support@keonda.dev

keonda.dev

If you are a business user and upload data relating to your own customers or employees, you act as the data controller for that data and we act as your data processor. Please refer to our Data Processing Agreement (DPA) for details.

2. What Personal Data We Collect

We collect the following categories of personal data:

  • Name — provided by you at registration
  • Email address — provided by you at registration and used for account communications
  • Payment information — collected at the point of subscription (processed by our payment processor; we do not store full payment card details)
  • Usage and interaction data — how you navigate and use the Service (e.g. features used, clicks, session duration, error logs)
  • Device and browser information — browser type, operating system, IP address, and similar technical identifiers

We do not collect any special categories of personal data (such as health, biometric, or racial/ethnic data) and ask that you do not upload such data to the Service.

3. How and Why We Use Your Data

The table below sets out the purposes for which we use your personal data and the legal basis under UK GDPR that we rely on for each:

Category of DataPurposeLegal Basis (UK GDPR)
Name and email addressAccount creation, login, and communicationsContract performance (Art. 6(1)(b))
Payment informationProcessing subscription payments (handled by our payment processor)Contract performance (Art. 6(1)(b))
Usage and interaction dataUnderstanding how the Service is used; improving performance and reliabilityLegitimate interests (Art. 6(1)(f))
Device and browser informationSecurity, fraud prevention, and compatibilityLegitimate interests (Art. 6(1)(f))
Your ContentDelivering the Service to youContract performance (Art. 6(1)(b))

Where we rely on legitimate interests as our legal basis, we have carried out a balancing test to ensure our interests do not override your rights and freedoms. You have the right to object to processing based on legitimate interests — see Section 8 for how to exercise this right.

4. Your Content

Any content you upload or create within the Service (“Your Content”) is treated as strictly confidential. We do not access, read, analyse, or use Your Content for any purpose other than delivering the Service to you.

Your Content is never used to train artificial intelligence or machine learning models, improve the Service, or for any commercial purpose.

We may access Your Content only in the limited circumstances described in our Terms of Service (section 8.2): with your consent, under legal compulsion, or to address a serious security incident.

5. Third Parties We Share Data With

We do not sell your personal data. We share it only with the following categories of trusted third-party service providers who process it on our behalf, under contractual obligations to keep it secure and use it only as instructed:

Payment Processor

We use a third-party payment processor (such as Stripe) to handle subscription payments. Your payment information is processed directly by them and is subject to their privacy policy. We do not store full card details on our systems.

Analytics Provider

We use an analytics service (such as Google Analytics or Mixpanel) to collect anonymised usage and interaction data. This helps us understand how the Service is used. We configure these tools to minimise personal data collection where possible.

Email Provider

We use a third-party email service provider (such as Mailchimp or SendGrid) to send transactional and account-related emails (e.g. welcome emails, billing notifications, password resets). Your name and email address are shared with this provider for this purpose only.

Cloud Hosting Provider

The Service and your data are hosted on infrastructure provided by a cloud hosting provider (such as AWS, Google Cloud, or Microsoft Azure). Your data is stored on servers located in [SPECIFY REGION — e.g. the United Kingdom or European Economic Area]. Where data is processed outside the UK, we ensure appropriate safeguards are in place (such as UK International Data Transfer Agreements or Standard Contractual Clauses).

We require all third-party processors to implement appropriate technical and organisational security measures and to process personal data only in accordance with our instructions.

6. Data Retention

We retain your personal data only for as long as necessary for the purposes set out in this policy, or as required by law.

  • Active accounts: We retain your data for as long as your account remains active.
  • Free users: Following account deletion, your personal data and Your Content are permanently deleted within 30 days.
  • Paid users: Following account deletion or subscription cancellation, your personal data and Your Content are permanently deleted within 60 days.
  • After deletion: No personal data or content is retained. Anonymised, aggregated usage statistics that cannot identify you may be retained indefinitely.

We may retain certain data for longer periods where required by law (for example, financial records for tax and accounting purposes, typically 6 years under UK law).

7. Security

We implement industry-standard technical and organisational measures to protect your personal data against unauthorised access, loss, alteration, or disclosure. Your Content is stored as submitted and access is restricted to authorised systems and personnel only.

Whilst we take reasonable steps to protect your data, no method of transmission or storage over the internet is completely secure. In the event of a personal data breach that is likely to result in a risk to your rights and freedoms, we will notify the Information Commissioner’s Office (ICO) within 72 hours and will inform affected users without undue delay where required to do so.

8. Your Rights

Under UK GDPR, you have the following rights in relation to your personal data:

  • Right of access — you can request a copy of the personal data we hold about you.
  • Right to rectification — you can ask us to correct inaccurate or incomplete data.
  • Right to erasure — you can ask us to delete your personal data in certain circumstances.
  • Right to restrict processing — you can ask us to limit how we use your data in certain circumstances.
  • Right to data portability — you can request your data in a structured, commonly used, machine-readable format.
  • Right to object — you can object to processing based on legitimate interests or for direct marketing purposes.
  • Rights related to automated decision-making — we do not currently make solely automated decisions that significantly affect you.

To exercise any of these rights, please contact us at support@keonda.dev. We will respond within one month of receiving your request. There is no charge for exercising your rights unless requests are manifestly unfounded or excessive.

You also have the right to lodge a complaint with the Information Commissioner’s Office (ICO) at www.ico.org.uk or by calling 0303 123 1113.

9. Cookies

We use cookies and similar tracking technologies to operate the Service and collect usage data. A full list of the cookies we use and their purposes is available in our Cookie Policy.

You can manage your cookie preferences through your browser settings or our cookie consent tool. Disabling certain cookies may affect the functionality of the Service.

10. Children’s Privacy

The Service is not intended for use by individuals under the age of 18. We do not knowingly collect personal data from children. If you believe we have inadvertently collected data from a child, please contact us immediately and we will delete it promptly.

11. Changes to This Privacy Policy

We may update this Privacy Policy from time to time. Where changes are material, we will notify you by email or via a prominent notice within the Service at least 30 days before the changes take effect. The “last updated” date at the top of this policy will always reflect the most recent version.

Your continued use of the Service after the effective date of any changes constitutes your acceptance of the updated policy.

12. Contact Us

If you have any questions, concerns, or requests regarding this Privacy Policy or how we handle your personal data, please contact us at:

Keonda (operated by MEDDEV LTD)

support@keonda.dev

keonda.dev