Your business data stays yours
Keyada uses your business data only to provide the service you authorise.
Your data is encrypted in transit and at rest. It is never sold, never shared with other customers, and never used to train public AI models without your permission.
You control which systems are connected and can disconnect them at any time. When you close your account, your business data is deleted according to our published retention policy.
We are building Keyada’s security controls toward an independent SOC 2 examination.
Your business data stays protected
Keyada connects to important parts of your business. We understand the responsibility that creates.
Your financial, operational, customer and business information belongs to you. We use it only to provide Keyada’s service to your business, and we protect it through technical, organisational and contractual safeguards.
Our commitments to you
Your data remains yours
You retain ownership of the business data you connect to Keyada. Connecting a system does not transfer ownership of that information to us. You can disconnect an integration at any time.
We do not sell your data
Keyada does not sell, rent or trade your business data. We do not use your private business information for advertising, and we do not disclose it to other Keyada customers.
Your data is not used to train public AI models
We do not permit your private business data to be used to train public or shared artificial intelligence models without your explicit permission. Where third-party AI infrastructure is required to provide a feature, data access is restricted to the minimum necessary and is subject to appropriate privacy, security and contractual controls.
Data is encrypted
Business data handled by Keyada is encrypted:
- in transit while moving between your systems and Keyada; and
- at rest while stored within Keyada’s infrastructure.
Sensitive credentials, access tokens and integration secrets are protected separately and are never displayed in plain text to other customers.
Access is strictly limited
Access to customer data is restricted according to role and operational need. Keyada personnel do not access private business data unless necessary to provide support, maintain security, investigate an incident or meet a legal obligation. Access is limited, controlled and logged where technically supported.
Each customer’s business data is logically separated from other customers’ data.
We collect only what Keyada needs
Keyada is designed to access only the information required to provide the features you authorise. We do not intentionally collect unrelated information simply because it is available through a connected system. Where an integration allows limited permissions, we use the least-privileged permissions reasonably necessary.
You remain in control of connected systems
You can disconnect a connected business system at any time. This prevents Keyada from collecting new information from that system. You may also request deletion of previously collected business data, subject to the limited retention requirements below.
What happens when you leave Keyada
When a paid subscription ends, Keyada will stop collecting new information from connected business systems.
Unless you reactivate your account or we are legally required to retain certain information, we will delete or irreversibly anonymise your stored business data within 3 days of account closure. Residual copies may remain temporarily in encrypted backups for up to 7 days before being automatically removed through the normal backup lifecycle.
We may retain limited account, billing, consent, security or audit information where required for legal, fraud-prevention, dispute-resolution or regulatory purposes. This will not include more business data than reasonably necessary for those purposes.
You may request earlier deletion by contacting security@keyada.app.
Carefully controlled service providers
Like most secure cloud software companies, Keyada relies on specialist infrastructure providers for functions such as cloud hosting, database services, authentication, monitoring, communications and payment processing.
These providers are not permitted to use your business data for their own marketing or independent commercial purposes. They may process only the information necessary to provide their contracted service to Keyada and must do so under confidentiality, privacy and security obligations.
We remain responsible for selecting appropriate providers and limiting the information made available to them. A current list of material service providers will be available on our Subprocessors page.
Security by design
Keyada is being built around security principles that include:
- encryption in transit and at rest;
- least-privilege access;
- separation of customer data;
- secure credential and token storage;
- controlled production access and audit logging;
- dependency and vulnerability management;
- secure software-development practices;
- incident-response procedures;
- regular backup and recovery processes; and
- documented data-retention and deletion controls.
Security is an ongoing operating responsibility, not a one-time feature.
Working toward SOC 2
Keyada is implementing the policies, controls, evidence and operating practices required to work toward an independent SOC 2 examination. We will not claim SOC 2 certification or compliance until the appropriate independent assessment has been completed.
As we progress, we will publish clear updates about our security programme and the status of any external assurance.
If a security incident occurs
If we become aware of a security incident affecting your business data, we will investigate it promptly, take reasonable steps to contain and remediate it, and notify affected customers in accordance with applicable law and our contractual obligations.
Questions about security
We welcome security and privacy questions from prospective and existing customers. Contact us at security@keyada.app.
Formal privacy information
The following explains how Keyada (“Keyada”, “we”, “us” or “our”) collects, uses, stores and shares personal information when you visit keyada.app, join founding access, create an account or use the Keyada service.
1. Information we collect
Information you provide
- Contact details, including your name, work email address, business name and role.
- Account, subscription, onboarding and support information.
- Instructions, approvals, feedback and communications you send to Keyada.
Connected business information
When an authorised customer connects a business system, Keyada may receive information from that system that is needed to provide the service. Depending on the connection, this can include financial, customer relationship, pipeline, project, delivery, operational and workplace information. The exact information depends on the permissions granted and the connected provider.
Service and device information
We may collect service activity, diagnostic records, browser and device information, IP address, timestamps and information needed to operate, maintain and protect the service.
2. How we use information
- Provide, operate and improve Keyada.
- Analyse connected business activity and produce briefings, opportunities, recommendations and measured outcomes.
- Carry out actions that an authorised user has explicitly approved.
- Maintain business context, decision history and outcome records for the customer’s service.
- Manage accounts, subscriptions, communications, support and founding-access requests.
- Detect misuse, investigate problems and meet legal obligations.
3. Our basis for handling information
We handle information to provide the service requested by customers, with consent where required, for legitimate business purposes such as operating and improving the service, and to meet legal obligations. Customers are responsible for ensuring they have the authority to connect systems and provide business information to Keyada.
4. When information is disclosed
We may disclose the minimum necessary information to contracted service providers that help us host, operate, communicate, process payments, provide support or maintain Keyada, subject to the controls described above. We may also disclose information:
- with connected providers when an approved action requires it;
- when the customer directs or authorises us to do so;
- to comply with law or protect legal rights and safety; or
- as part of a genuine business reorganisation, subject to appropriate safeguards.
We do not sell, rent or trade personal or business information.
5. Storage, retention and international processing
Keyada and its service providers may process information in New Zealand and other countries where the infrastructure used to provide the service is located. Business-data deletion after account closure follows the 3-day deletion or anonymisation period and 7-day backup lifecycle described above. Limited account and legal records may be retained only where reasonably necessary to meet legal, accounting, security or dispute-resolution obligations.
6. Your choices and rights
Depending on the law that applies, you may ask to access, correct or delete personal information, object to or restrict certain uses, or withdraw consent. You may unsubscribe from marketing communication using the link provided or by contacting us. Some information may need to be retained where required by law or necessary to establish, exercise or defend legal claims.
7. Connected systems and third-party services
Connected providers have their own terms and privacy practices. Removing a connection stops future access through that connection. Customers may request deletion of previously collected business data at any time, subject only to the limited retention requirements described above.
8. Children
Keyada is a business service and is not directed to children. We do not knowingly invite children to create accounts or submit personal information.
9. Changes to this policy
We may update this policy as the service or legal requirements change. We will publish the updated version here and change the “last updated” date. Material changes may also be communicated directly to customers.
10. Contact
For privacy questions or requests, email privacy@keyada.app. We will respond in accordance with applicable privacy law, including the New Zealand Privacy Act 2020 where it applies.