Legal
Privacy Policy
This Privacy Policy explains how Kintex AIS handles personal data for website visitors, account holders, and customer organisation content hosted on the platform.
Last updated: 28 July 2026
1. Who we are
Kintex provides Kintex AIS (Kintex Asset Inspection Software). For personal data we process as a business (for example account emails of organisation admins, billing contacts, and website visitors), we act as a data controller under the UK GDPR and Data Protection Act 2018.
For personal data that your Organisation stores in inspections, issues, photos, and similar Customer Data, your Organisation is typically the controller and we act as a processor, processing that data on your instructions to provide the Service. A separate data processing agreement can be put in place for enterprise customers on request.
2. Categories of personal data
Depending on how you use Kintex AIS, we may process:
- Account identity: name, email address, authentication identifiers, password hashes (via our auth provider)
- Organisation membership: company name, roles, scopes, invite records, archive status
- Usage and technical data: log-ins, device/app type, IP address, approximate location derived from IP, diagnostics, and security logs
- Customer content that may include personal data: inspector names, free-text notes, photos of people or identifiable badges/faces if Users capture them, task assignees, certificate holder names
- Communications: support messages and email notifications related to the Service
- Commercial data: plan tier, subscription status, invoice metadata (payment card data, if introduced, would be handled by a payment provider)
3. How we collect data
We collect data directly from you (registration, profile, onboarding), from your Organisation’s admins (invites and role assignment), automatically through the web and mobile apps (security and product logs), and from subprocessors needed to run the platform (for example authentication and hosting).
4. Purposes and lawful bases
We process personal data to:
- Provide and operate the Service (contract / legitimate interests)
- Authenticate Users and secure accounts (contract / legitimate interests / legal obligation)
- Send service notices (for example task assignment, security alerts) (contract / legitimate interests)
- Improve reliability and features using aggregated or diagnostic data (legitimate interests)
- Comply with law and enforce our Terms (legal obligation / legitimate interests)
- With consent where required (for example non-essential cookies or marketing, if introduced)
5. Processors and subprocessors
We use infrastructure and platform providers to deliver Kintex AIS. In particular, core hosting, authentication, database, file storage, and serverless functions are provided via Google Firebase / Google Cloud (project regions include Europe for Firestore and Functions where configured, and may include other Google regions for Storage or global services).
We may also use email delivery, error monitoring, or analytics providers. We require processors to protect data under appropriate terms. A current subprocessor list can be provided on request for pilot or enterprise customers.
6. International transfers
Where personal data is transferred outside the UK/EEA (for example through global cloud services), we rely on appropriate safeguards such as the provider’s standard contractual clauses, UK international data transfer agreements/addenda, or adequacy decisions, as applicable.
7. Retention
Account and Organisation data are kept while your Organisation is active and for a reasonable period afterward for backups, dispute resolution, and legal compliance. You may request deletion of an Organisation subject to verification and residual backup cycles.
Inspection history, issues, and photos are retained as Customer Data under your Organisation’s control until deleted by authorised Users or upon Organisation deletion, subject to backup retention windows.
Security logs are kept for a limited period appropriate to security and abuse prevention.
8. Security measures
We apply technical and organisational measures appropriate to a cloud SaaS product, including encryption in transit (HTTPS/TLS), authentication via a managed identity provider, access control within the application (roles and organisation scoping), and server-side rules/functions that restrict cross-organisation access.
No method of transmission or storage is completely secure. You must use strong passwords, manage User access carefully, and protect devices used for field inspections.
9. Your rights (UK GDPR)
Where we are the controller, individuals may have rights to access, rectification, erasure, restriction, portability, and objection, and rights related to automated decision-making (we do not use solely automated decisions that produce legal or similarly significant effects about you in Kintex AIS).
To exercise rights, contact us using the details below. If we process your data only as a processor for an Organisation, we will direct you to that Organisation or assist them as required.
You may lodge a complaint with the UK Information Commissioner’s Office (ICO) or another supervisory authority.
10. Children
Kintex AIS is a business product for professional users. It is not directed at children, and we do not knowingly collect personal data from children under 16 for the Service.
12. Customer responsibilities for inspection content
Organisations must ensure a lawful basis for any personal data in Customer Data (including images of staff or sites), configure access appropriately, and respond to data subject requests relating to that content. Avoid capturing unnecessary personal data in photos and notes.
13. Changes to this Privacy Policy
We may update this Privacy Policy by posting a revised version with a new “Last updated” date. Material changes will be communicated where practicable.
14. Contact
Privacy requests: privacy@kintex.example. Replace @kintex.example addresses with your production contact emails before pilot go-live.
This Privacy Policy is a working product policy for Kintex AIS and is not formal legal advice. Confirm entity details, contact emails, and subprocessors before production go-live.