Privacy Policy
1. Data Controller
Kinsync (“we”, “us”, “Platform”) is the data controller for personal data processed through the Kinsync web application and related services. For queries or complaints, contact: privacy@kinsync.local.
Where a Founder registers a family business, the Founder acts as the primary account administrator. Certain family governance data is shared among authorised members of the same business roster under the Founder’s governance workflow.
2. Scope
This Policy applies to:
- Founders who register a business and purchase or use a subscription tier;
- Family members who join via an invite/join code;
- Emergency contacts designated by Founders or members;
- Visitors to our public website and legal pages.
It does not govern third-party websites, payment gateways, or professional advisers (lawyers, accountants) you engage independently.
3. Categories of Personal Data We Collect
3.1 Identity & contact data
- Full name, email address, mobile/WhatsApp number;
- CNIC number (where provided for identity verification);
- Date of birth, province, preferred language;
- Relationship to Founder, occupation, education level;
- Profile photo (optional);
- Social media handles (optional, for notification escalation only).
3.2 Business & governance data
- Business name, legal structure, NTN/SECP registration (if provided);
- Revenue range, subscription tier, province of operations;
- Succession Health Score responses and risk classifications;
- Pre-Governance questionnaire answers;
- Generated governance documents, clauses, flags, acknowledgments;
- Quarterly Pulse responses and change-impact records;
- Family roster, join codes, audit logs of platform activity.
3.3 Emergency & sensitive data
- Emergency contact names, relationships, phone numbers, and emails;
- Health-capacity related responses where disclosed in quarterly reviews;
- Family dispute status and flagging/discussion content.
3.4 Technical data
- IP address, browser type, device identifiers, session logs;
- Login timestamps, last-active timestamps, notification delivery status.
4. Lawful Basis & Purpose of Processing
We process personal data for the following purposes and on the following bases:
- Contract performance — to provide the governance platform, generate documents, manage family rosters, and deliver notifications you request (Contract Act, 1872; ETO 2002).
- Consent — for optional channels (SMS, social DMs), sharing contact details with other family members, and emergency-contact activation (obtained at registration and in notification preferences).
- Legal obligation — retention of records where required by tax, corporate, or regulatory law; cooperation with lawful requests under PECA 2016 and court orders.
- Legitimate interests — platform security, fraud prevention, join-code abuse protection, and service improvement — balanced against your privacy rights.
5. Consent Layers (Family Members)
Family members consent separately to:
- Storage and processing of personal and governance-related data on the Platform;
- Sharing contact information with other authorised family members in the same business roster (where enabled);
- Receiving notifications via selected channels (in-app, email, WhatsApp, SMS, phone);
- Activation of emergency contacts during Founder incapacity protocols (where designated).
You may withdraw consent for non-essential processing via account settings or by emailing privacy@kinsync.local. Withdrawal does not affect the lawfulness of processing before withdrawal. Certain records (e.g., prior acknowledgments, audit logs) may be retained as required by law or legitimate business needs.
6. CNIC & NADRA-Related Information
CNIC numbers are collected solely for identity verification and family-business governance integrity. We do not sell CNIC data. Access is restricted to authorised roles, encrypted at rest, and logged. We do not claim affiliation with NADRA. Users must provide accurate CNIC information; false information may violate PECA 2016 and applicable criminal law.
7. Data Sharing & Disclosure
We may share data:
- Within your business roster — Founders, family members, and emergency contacts see information according to role-based permissions defined in the Platform.
- Service providers — hosting, email, SMS/WhatsApp gateways, and backup providers under contractual confidentiality and data-processing terms.
- Legal & regulatory — where required by law, court order, SECP/FBR inquiry, or to protect rights, safety, and platform integrity.
- Professional advisers — only if you export or share documents with your lawyer; we do not automatically disclose to third parties.
We do not sell personal data to advertisers or data brokers.
8. Cross-Border Transfers
Primary data is stored on servers configured for deployment in or accessible from Pakistan. If data is processed outside Pakistan (e.g., cloud backup regions), we implement appropriate safeguards — contractual clauses, encryption, and access controls — consistent with applicable Pakistani data-protection principles and your consent where required.
9. Security Measures
We implement administrative, technical, and physical safeguards including:
- TLS 1.3 encryption in transit;
- Encryption at rest for sensitive governance and identity data;
- Role-based access control (Founder, Family Member, Emergency Contact, Admin);
- Password hashing (bcrypt), session timeout, and join-code brute-force protection;
- Audit logging of access and material changes;
- Daily encrypted backups with defined retention.
No system is completely secure. You are responsible for safeguarding your login credentials and notifying us promptly of suspected unauthorised access.
10. Data Retention
- Active accounts — data retained while your subscription/account is active and as needed to provide services.
- Governance documents & audit logs — retained for up to 7 years after last material activity, aligned with common Pakistani tax and business record practices, unless longer retention is required by law or dispute.
- Inactive accounts — may be anonymised or deleted after reasonable notice, subject to legal holds.
- Backups — purged on a rolling schedule consistent with the above.
11. Your Rights
Subject to applicable law, you may request:
- Access to personal data we hold about you;
- Correction of inaccurate or incomplete data;
- Deletion or restriction of processing (where not overridden by legal retention);
- Withdrawal of consent for optional processing;
- A copy of your data in a portable format where technically feasible;
- Information about automated scoring (Succession Health Score) — logic is rule-based from your responses, not opaque profiling for unrelated purposes.
Founders may request a full audit report of data access within their business roster. Submit requests to privacy@kinsync.local. We respond within 30 days unless extension is permitted by law.
If unsatisfied, you may lodge a complaint with the relevant Pakistani authority (including the Federal Investigation Agency for offences under PECA 2016, or future data-protection authority once established).
12. Children & Minors
The Platform is intended for adults (18+) participating in family business governance. We do not knowingly collect data from children under 18 without parental/guardian authority in a family business context. If you believe we have collected a child’s data improperly, contact us for deletion.
13. Marketing & Communications
Transactional and governance notifications (document ready, flags, quarterly pulse, emergency alerts) are essential to the service and cannot be fully opted out of while remaining an active participant. Non-essential marketing communications require separate consent.
14. Cookies & Similar Technologies
We use session cookies and similar technologies for authentication, security, and preferences. You may control cookies via browser settings; disabling essential cookies may prevent login.
15. Changes to This Policy
We may update this Policy to reflect legal, technical, or business changes. Material changes will be notified via email or in-app notice at least 14 days before taking effect. Continued use after the effective date constitutes acceptance where permitted by law.
16. Contact & Grievance Officer
Kinsync — Privacy & Data Protection
Email: privacy@kinsync.local
Postal: [Registered office address — to be inserted before production launch]
This Privacy Policy is provided in English. Urdu translation may be made available on request.