Kinsync

Privacy Policy

Effective date: 25 July 2026 · Version 1.0 · Applies to users in Pakistan

Important: Kinsync processes sensitive family and business information. This Policy explains how we collect, use, store, and protect your data in accordance with applicable laws of Pakistan, including the Constitution of Pakistan (Article 14 — dignity and privacy of home), the Prevention of Electronic Crimes Act, 2016 (PECA), the Electronic Transactions Ordinance, 2002 (ETO), and principles aligned with the Personal Data Protection Bill (as published by the Ministry of IT & Telecom). Where sector-specific rules apply (SECP, FBR, NADRA), we comply to the extent applicable to our role as a technology service provider.

1. Data Controller

Kinsync (“we”, “us”, “Platform”) is the data controller for personal data processed through the Kinsync web application and related services. For queries or complaints, contact: privacy@kinsync.local.

Where a Founder registers a family business, the Founder acts as the primary account administrator. Certain family governance data is shared among authorised members of the same business roster under the Founder’s governance workflow.

2. Scope

This Policy applies to:

It does not govern third-party websites, payment gateways, or professional advisers (lawyers, accountants) you engage independently.

3. Categories of Personal Data We Collect

3.1 Identity & contact data

3.2 Business & governance data

3.3 Emergency & sensitive data

3.4 Technical data

4. Lawful Basis & Purpose of Processing

We process personal data for the following purposes and on the following bases:

5. Consent Layers (Family Members)

Family members consent separately to:

  1. Storage and processing of personal and governance-related data on the Platform;
  2. Sharing contact information with other authorised family members in the same business roster (where enabled);
  3. Receiving notifications via selected channels (in-app, email, WhatsApp, SMS, phone);
  4. Activation of emergency contacts during Founder incapacity protocols (where designated).

You may withdraw consent for non-essential processing via account settings or by emailing privacy@kinsync.local. Withdrawal does not affect the lawfulness of processing before withdrawal. Certain records (e.g., prior acknowledgments, audit logs) may be retained as required by law or legitimate business needs.

6. CNIC & NADRA-Related Information

CNIC numbers are collected solely for identity verification and family-business governance integrity. We do not sell CNIC data. Access is restricted to authorised roles, encrypted at rest, and logged. We do not claim affiliation with NADRA. Users must provide accurate CNIC information; false information may violate PECA 2016 and applicable criminal law.

7. Data Sharing & Disclosure

We may share data:

We do not sell personal data to advertisers or data brokers.

8. Cross-Border Transfers

Primary data is stored on servers configured for deployment in or accessible from Pakistan. If data is processed outside Pakistan (e.g., cloud backup regions), we implement appropriate safeguards — contractual clauses, encryption, and access controls — consistent with applicable Pakistani data-protection principles and your consent where required.

9. Security Measures

We implement administrative, technical, and physical safeguards including:

No system is completely secure. You are responsible for safeguarding your login credentials and notifying us promptly of suspected unauthorised access.

10. Data Retention

11. Your Rights

Subject to applicable law, you may request:

Founders may request a full audit report of data access within their business roster. Submit requests to privacy@kinsync.local. We respond within 30 days unless extension is permitted by law.

If unsatisfied, you may lodge a complaint with the relevant Pakistani authority (including the Federal Investigation Agency for offences under PECA 2016, or future data-protection authority once established).

12. Children & Minors

The Platform is intended for adults (18+) participating in family business governance. We do not knowingly collect data from children under 18 without parental/guardian authority in a family business context. If you believe we have collected a child’s data improperly, contact us for deletion.

13. Marketing & Communications

Transactional and governance notifications (document ready, flags, quarterly pulse, emergency alerts) are essential to the service and cannot be fully opted out of while remaining an active participant. Non-essential marketing communications require separate consent.

14. Cookies & Similar Technologies

We use session cookies and similar technologies for authentication, security, and preferences. You may control cookies via browser settings; disabling essential cookies may prevent login.

15. Changes to This Policy

We may update this Policy to reflect legal, technical, or business changes. Material changes will be notified via email or in-app notice at least 14 days before taking effect. Continued use after the effective date constitutes acceptance where permitted by law.

16. Contact & Grievance Officer

Kinsync — Privacy & Data Protection
Email: privacy@kinsync.local
Postal: [Registered office address — to be inserted before production launch]

This Privacy Policy is provided in English. Urdu translation may be made available on request.