These documents are available in English, German, French and Italian. If a translation conflicts with the English version, the English version prevails.
1. Controller
The controller responsible for personal data processing described in this Privacy Policy is Kavea, Lindenstrasse 38, 6015 Luzern, Switzerland ("Kavea", "we", "us"). Contact: support@kavea.app. Authorised representatives: Maralgua Sharav & Dawid Kapka.
This Privacy Policy is designed primarily under the Swiss Federal Act on Data Protection (revFADP / nDSG). Where the EU General Data Protection Regulation (GDPR) or other foreign law applies to particular processing (for example because we offer services to customers in the EEA/UK), we additionally observe those requirements as applicable.
2. Scope
This Policy explains how we process personal data when you visit our marketing website, contact us, or use the hosted Kavea application.
It does not cover websites or services of third parties that we merely link to. For those, the respective providers’ policies apply.
3. Categories of personal data
Depending on how you interact with us, we may process: identification and contact data (name, email address, telephone number, business name and address); communication content; technical and usage data (IP address, date and time of access, requested resources, browser and device information, approximate location derived from IP); account and role data for Workspace Users; and operational Customer Data that may incidentally include personal data (for example staff names in shift schedules).
We do not intentionally collect special categories of personal data (sensitive data) via the marketing website. Please do not submit such data via the contact form unless we expressly request it for a specific purpose.
4. Purposes and justification
We process personal data for the following purposes: to provide and secure our website and Service; to respond to enquiries; to conclude and perform contracts with Customers; to authenticate Users; to send transactional messages (for example invitations and password resets); to improve reliability and prevent abuse; to comply with legal obligations; and to establish, exercise or defend legal claims.
Under Swiss data-protection law, processing is typically justified by our overriding private interests (Art. 31 para. 2 lit. a revFADP), by the performance of a contract with the data subject or the Customer, by consent where we ask for it, or by a legal obligation. Where GDPR applies, the corresponding legal bases include Art. 6(1)(b), (c) and (f) GDPR and, where required, Art. 6(1)(a) GDPR.
5. Visiting this website
When you visit this website, our web server and hosting infrastructure automatically process technical data required to deliver pages and protect the service (including IP address, timestamp, requested URL, referrer and user-agent). This processing is necessary for the website to function and for IT security.
Server logs are retained only as long as needed for security and troubleshooting and are then deleted or anonymised; as a rule within 14 days, unless a longer retention is required to investigate an incident.
This website does not use advertising cookies, analytics trackers or social-media plugins. See our Cookie Policy for details on technically necessary storage.
6. Contact form and email
If you contact us via the contact form or by email, we process the data you provide (typically name, email address, business details and message content) to handle and respond to your request and, where relevant, to prepare a contractual relationship.
We retain enquiry data for as long as needed to complete the request and for a reasonable follow-up period, and longer if statutory retention or limitation periods require it.
7. Hosted Kavea application
Kavea is a multi-tenant hosted service. Workspace data is stored in a shared PostgreSQL database with logical isolation between Workspaces (including row-level security controls).
Account data (such as name, email address, authentication credentials in hashed form, language preferences and role assignments) is processed to provide access to the Customer’s Workspace and to operate security features such as password reset.
Transactional emails (for example Workspace invitations and password-reset messages) are sent through our mail service and related email infrastructure providers acting on our instructions.
For personal data that the Customer enters about its staff or other data subjects, the Customer typically acts as controller. In that case we process such data as a service provider / processor to the extent required to provide Kavea. Customers must ensure they have a lawful basis and provide appropriate notices to their data subjects.
8. Recipients and processors
We disclose personal data only to recipients who need it for the purposes described above. This may include hosting and infrastructure providers, email delivery providers, and professional advisers (for example lawyers or auditors) under confidentiality obligations.
We do not sell personal data and we do not share it with third parties for their own advertising purposes.
Where we engage processors, we select them with due care and bind them by contract to process data only on our documented instructions and to implement appropriate security measures.
9. Cross-border disclosure
We prefer to process and store personal data in Switzerland or in countries with an adequate level of data protection recognised under Swiss (and, where applicable, EU) law.
If personal data is disclosed to a country without an adequate statutory level of protection, we implement appropriate safeguards as required by Art. 16 et seq. revFADP (and Art. 46 GDPR where applicable), such as standard contractual clauses, unless an exception under applicable law applies.
10. Retention
We retain personal data only as long as necessary for the purposes for which it was collected, including to meet contractual, accounting, tax and limitation-period requirements.
Within the application, granular activity audit logs are typically retained for approximately 30 days and then automatically pruned, unless a longer period is required for security investigation or legal compliance. Account and Workspace data are retained for the life of the subscription and for a reasonable wind-down period thereafter.
11. Security
We implement appropriate technical and organisational measures to protect personal data against unauthorised access, loss, alteration or disclosure, taking into account the state of the art, implementation costs, and the nature, scope and risk of processing. Measures include access controls, encryption in transit, logical tenant isolation and least-privilege administration.
No method of transmission or storage is completely secure. Absolute security cannot be guaranteed.
12. Your rights
Subject to the conditions and exceptions of applicable law (in particular Art. 25–29 revFADP and, where applicable, Chapter III GDPR), you may request access to your personal data, correction of inaccurate data, deletion, restriction of processing, objection to processing based on overriding interests, and data portability.
Where processing is based on consent, you may withdraw consent at any time with effect for the future. Withdrawal does not affect the lawfulness of processing before withdrawal.
To exercise your rights, contact us at support@kavea.app. We may need to verify your identity before fulfilling a request.
You may lodge a complaint with the competent supervisory authority. In Switzerland this is the Federal Data Protection and Information Commissioner (FDPIC). EU/EEA data subjects may also contact their local supervisory authority where GDPR applies.
13. Automated individual decisions
We do not use personal data for automated individual decision-making that produces legal effects concerning you or similarly significantly affects you within the meaning of Art. 21 revFADP / Art. 22 GDPR solely by automated means without human involvement.
Operational recommendations inside Kavea (for example replenishment suggestions) are tools for the Customer’s staff and do not replace human decisions.
14. Children
Kavea and this website are directed at businesses and adult professionals. We do not knowingly collect personal data from children.
15. Changes to this Privacy Policy
We may update this Privacy Policy from time to time to reflect legal, technical or business developments. The current version is always published on this page with the "Last updated" date.
Where changes are material, we will provide additional notice where required by law (for example by email or in-product notice for registered Customers).