Keystne
Platform Hubs Architecture How it works
Docs Try the demo
Home/Legal/Privacy Policy
Privacy Policy Terms of Service POPIA Compliance Incident Response

Privacy Policy

TEMPLATE — FOR REVIEW BY LEGAL COUNSEL BEFORE PUBLICATION This document has not been reviewed by a qualified attorney and must not be relied upon as legal advice or published in its current form. It is provided as a starting-point template only.

Last updated: June 2026 Effective date: June 2026

Cognizance Processing (Pty) Ltd (“KeyOne”, “we”, “our”, or “us”), registration number [REG NUMBER], a company incorporated in South Africa, operates the KeyOne platform accessible at keyone.sh.

This Privacy Policy explains how we collect, use, share, and protect personal information in connection with our services. It must be read together with our Terms of Service and POPIA Compliance Statement.


1. Who This Policy Applies To

This policy applies to:

  • Visitors to keyone.sh and our documentation
  • Account holders — individuals who register for a KeyOne account
  • End users — employees and contractors of our corporate customers who access the platform under a customer’s tenant

2. Information We Collect

2.1 Information You Provide Directly

CategoryExamples
Identity informationFull name, job title, company name
Contact informationEmail address, phone number
Authentication credentialsPassword (stored as a one-way argon2id hash — we never store plaintext passwords)
Profile informationProfile photo, team membership
Support communicationsMessages sent to our support team

2.2 Information Collected Automatically

When you use the KeyOne platform, we automatically collect:

  • Usage data: actions you take that change data — what changed, which record, and when. We do not record which pages you visit or how long you spend on them; the platform contains no analytics or telemetry.
  • Network data: the IP address a request arrived from, stored against audited events. We do not derive your location from it.
  • Session data: login timestamps, session lifetime, and authentication events such as sign-in, sign-out, token refresh and password change.
  • Location data — KeyLink field app only: with your device’s permission, your position is read on your device to show how far you are from an outlet. It is not transmitted for that purpose. A precise position leaves your device only when you choose to submit an outlet position correction, and is then stored as that outlet’s proposed position with your name against it.
  • Device and browser data: none. We do not record your browser, its version, your operating system or your screen size.

2.3 Information From Third Parties

  • OAuth providers: When you sign in with Google or Microsoft, we receive your name, email address, and profile photo from that provider in accordance with their privacy policies
  • Customer data: If your employer uses KeyOne, your employer controls what data about you is shared with us

2.4 Business and Operational Data

If you are a KeyOne customer (a principal/brand owner):

  • Retailer POS and scan data you upload
  • SAP/ERP data you provide
  • Configuration, metric definitions, and analytical outputs

This data is yours. We process it only to deliver the service. See Section 6 for customer data handling.


3. How We Use Your Information

We use personal information for the following purposes:

PurposeLegal basis (POPIA)
Creating and managing your accountContract performance
Delivering the KeyOne platform and its featuresContract performance
Authenticating your identity on loginContract performance / Legitimate interest
Sending transactional emails (password reset, verification)Contract performance
Responding to support requestsContract performance
Maintaining platform security and preventing fraudLegitimate interest
Diagnosing technical issues and improving reliabilityLegitimate interest
Sending product updates and new feature announcementsLegitimate interest (you may opt out)
Complying with legal obligationsLegal obligation

We do not use your information for automated profiling that produces legal or similarly significant effects without explicit consent.


4. How We Share Your Information

We do not sell personal information to third parties.

We share personal information only in these circumstances:

4.1 Service Providers (Operators under POPIA)

We use third-party providers to operate the platform. Each is bound by a data processing agreement:

ProviderPurposeLocation
Cloud infrastructure provider (Fly.io)Hosting, computeFrankfurt (fra)
Managed Postgres (Neon)Application databaseFrankfurt, co-located with the above
Email delivery providerTransactional emailNot yet configured — no email currently leaves the deployment
AI model provider (Google, Gemini API)Answering questions you type into the AI analystOutside South Africa. No data processing agreement is in place with this provider as at 2026-10-05.

The AI analyst sends data to a third party, and you should know exactly what. Where a deployment is configured with a model provider, the question you type and the results of the queries the analyst runs to answer it are transmitted to that provider. Those query results are your organisation’s own business data, and they can contain personal information — a sales representative’s name against a store visit, for example. The analyst reports itself unavailable and sends nothing where no provider is configured.

Stated plainly because the rest of this table cannot be read as covering it: the sentence above the table — that each provider is bound by a data processing agreement — is not yet true of the model provider. That agreement, the s72 basis for the transfer, and any retention commitment from the provider are outstanding and are flagged for review by an admitted legal practitioner; see the POPIA notice’s residency section. Nothing here should be read as asserting that the transfer is already compliant.

In-region (South African) hosting is a target, not the present arrangement: the running machine is in fra because the database it must sit beside is. See the POPIA notice for the same statement in its residency context.

There is no separate analytical warehouse provider. An earlier version of this table listed ClickHouse; that belonged to a Python stack which has been retired, and no such system holds any data today.

4.2 Your Employer

If you access KeyOne under a corporate tenant, your employer (the customer) may have access to your activity logs within that tenant’s administrative panel.

4.3 Legal Requirements

We may disclose personal information when required by South African law, court order, or to protect the rights and safety of our users or the public.

4.4 Business Transfers

In the event of a merger, acquisition, or sale of assets, personal information may be transferred. We will notify affected users in advance.


5. Data Retention

This table states what the product actually deletes, and what it does not. An earlier version listed periods for account information, authentication logs, support communications, usage analytics and backups; none of those was enforced by any code, and one of them — authentication logs at 12 months — was the opposite of the truth.

Data typeWhat happens today
Single-use credentialsDeleted automatically. Invite and password-reset codes, demo and SSO exchange codes are swept hourly and removed 30 days after they expire. A refresh grace-replay row is removed an hour after its grace window closes, so the hourly sweep clears it within about two
Sessions and refresh tokensDeleted automatically, on a longer schedule. These are swept once a day, not hourly. A signed-out or expired session family is removed 90 days after its last token expired; a family on which token reuse was ever detected is kept for a year, because that row is the only record the attack happened
Authentication and administrative audit entriesKept indefinitely. Sign-in successes and failures, refresh-token reuse, sign-out, invites and resets are written to audit_log, and nothing prunes it. A retention period for this trail is a decision the operator has not yet taken
Resolved decisionsArchived after a configurable window (archive_after_days), not deleted
Customer data (tenant data)Deleted within 30 days of account termination — see section 6
BackupsHeld by the managed database provider under its own schedule; KeyOne does not set or control it

There is no support-ticketing system and no usage-analytics collection in this product, so neither is retained — the earlier table’s entries for them described neither an intention nor a fact.


6. Customer Data (Tenant Data)

Data uploaded by customers (retailer feeds, ERP data, analytical outputs) is treated as follows:

  • Each customer runs as a separate deployment with its own database, and within it every tenant-scoped table carries Postgres row-level security, FORCEd and keyed on app.tenant_id set per transaction. Infrastructure is in Frankfurt (see 4.1). There is no ks_{tenant} per-tenant database; that naming described an architecture this product does not use
  • We access it only to provide the contracted service
  • We do not use it to train models, analyse competitors, or share with other customers
  • The customer retains all rights to their data
  • On account termination, we delete tenant data within 30 days, with confirmation to the customer

7. Security

We implement the following controls to protect personal information:

  • Encryption in transit: TLS 1.2+ for all connections
  • Encryption at rest: provided by the host platform’s encrypted volumes. Application-level field encryption exists in the codebase but is not in use, and this notice does not claim it
  • Authentication: Argon2id password hashing; JWT with rotating refresh tokens and reuse detection; optional OIDC single sign-on where a deployment configures it
  • Access controls: four server-enforced roles with least privilege. Multi-factor authentication is not available. It was built and then removed from the product, and this notice previously claimed administrative access required it
  • Audit logging: authentication events (sign-in, failure, refresh reuse, sign-out, invite and reset) and administrative actions are written to an audit trail. Read access to tenant data is not itself logged, and is not claimed here
  • Penetration testing: an organisational commitment, not yet a scheduled engagement

Despite these measures, no system is completely secure. We will notify affected users and the Information Regulator of any breach as required under POPIA.


8. Your Rights Under POPIA

As a data subject under the Protection of Personal Information Act, 4 of 2013, you have the right to:

  • Access: request a copy of the personal information we hold about you
  • Correction: request correction of inaccurate or incomplete information
  • Deletion: request erasure of your personal information (subject to legal retention requirements)
  • Objection: object to our processing of your information for direct marketing
  • Restriction: request restriction of processing in certain circumstances
  • Portability: receive your personal information in a structured, commonly used format
  • Complaint: lodge a complaint with the Information Regulator of South Africa

To exercise these rights, contact our Information Officer at: privacy@keyone.sh

We will respond within 30 days of receiving a request.


9. Information Officer

Our designated Information Officer as required by POPIA is:

[Name TBC] Cognizance Processing (Pty) Ltd Email: privacy@keyone.sh Address: [Physical address TBC]


10. Children

KeyOne is a business-to-business service. We do not knowingly collect personal information from individuals under 18 years of age. If we become aware that we have collected information from a minor, we will delete it promptly.


11. Changes to This Policy

We will notify you of material changes to this policy by email and by displaying a notice on the platform at least 30 days before the change takes effect.


12. Contact Us

For privacy-related questions:

Cognizance Processing (Pty) Ltd Email: privacy@keyone.sh Website: keyone.sh


Template only — must be reviewed and approved by qualified South African legal counsel before publication.

Keystne

From raw retail data to shelf-level action — one commercial cockpit, ranked decision hubs, closed-loop execution.

Platform

Decision Engine Decision Hubs Architecture How it works Live demo

Company

Documentation Why KeyOne

Legal

Privacy Terms POPIA Incident response
© 2026 Cognizance Processing (Pty) Ltd t/a KeyOne. All rights reserved. South Africa · hello@keyone.sh