Privacy Policy

logKeet · Effective June 6, 2026

This policy describes how we collect, use, and protect your data in compliance with GDPR (EU) 2016/679, India's DPDP Act 2023, and CCPA (California).

1. What We Collect

  • Account data: Name, work email, phone number, company name — collected at signup.
  • Authentication data: Hashed passwords (bcrypt), SSO tokens — never stored in plain text.
  • Usage analytics: Events, sessions, device info, crash reports sent by your app via our SDK — stored on your behalf.
  • Billing data: Subscription plan, payment status — payment card details are handled by our payment processor, not stored by us.
  • Communication data: Emails you send via campaigns/push notifications through our platform.
  • Log data: IP addresses, request timestamps, user agent — retained for security and debugging.
We do not sell, rent, or share your personal data with third parties for marketing purposes.

2. Legal Basis for Processing

  • Contract performance (Art. 6(1)(b) GDPR): Processing your account data to provide the service you signed up for.
  • Legitimate interest (Art. 6(1)(f) GDPR): Security monitoring, fraud prevention, service improvement.
  • Legal obligation (Art. 6(1)(c) GDPR): Retaining billing/invoice records as required by tax law.
  • Consent (Art. 6(1)(a) GDPR): Marketing communications — you can withdraw at any time.

3. Data Retention Schedule

We keep your data only as long as necessary. The table below is our binding retention schedule:

Data CategoryRetention PeriodLegal Basis
Active account dataDuration of subscriptionContract
Analytics events — raw (SDK)Up to 2 years from event timestampContract
Analytics events — hourly rollupsUp to 90 daysContract
Analytics events — daily rollupsUp to 3 yearsContract
Custom metricsUp to 1 year from metric timestampContract
Trial account data30 days after trial expiry, then purgedLegitimate interest
Cancelled subscription data90 days after cancellation, then purgedLegitimate interest
Admin-deleted company data30-day grace period, then hard-purgedLegitimate interest
User deletion requestAnonymized within 30 daysGDPR Art. 17 / DPDP S.12
Billing & invoice records7 yearsLegal obligation (tax law)
Audit logs (anonymized)1 yearSOC 2 / ISO 27001
OTP / verification codes24 hoursSecurity

4. Your Rights (GDPR / DPDP / CCPA)

  • Right of access (Art. 15): Request a copy of all personal data we hold about you.
  • Right to rectification (Art. 16): Correct inaccurate data — available in your profile settings.
  • Right to erasure (Art. 17 / DPDP S.12): Request deletion of your data. We will anonymize or delete within 30 days. Note: billing records required by law cannot be deleted.
  • Right to data portability (Art. 20): Export your data in machine-readable format from Dashboard → Settings → Export Data.
  • Right to object (Art. 21): Object to processing based on legitimate interests.
  • Right to restrict processing (Art. 18): Request we limit how we use your data while a dispute is resolved.
  • CCPA rights: California residents have the right to know, delete, and opt-out of sale of personal information (we do not sell data).
To exercise any right, email privacy@logkeet.com with subject "Privacy Request". We will respond within 30 days.

5. Account & Data Deletion

  • Company deletion: When an admin deletes a workspace, data enters a 30-day grace period before permanent deletion. This allows recovery from accidental deletion.
  • User account: Users can request personal data erasure by emailing us. We anonymize your account (replace PII with pseudonyms) within 30 days.
  • Trial expiry: Inactive trial accounts are suspended after expiry and purged 30 days later.
  • What gets deleted: All analytics events, sessions, user profiles, crash reports, campaigns, and account data.
  • What is retained: Invoice and billing records (7-year legal requirement), anonymized aggregate statistics (no PII), and anonymized audit logs (1 year).

6. Security Measures

  • Passwords hashed with bcrypt (cost factor 10) — never stored in plain text.
  • All data in transit encrypted with TLS 1.2+ (HTTPS enforced, HSTS enabled).
  • API access controlled via JWT tokens with 24-hour expiry.
  • Audit log of all administrative actions retained for 1 year.
  • Infrastructure hosted on Hetzner Online GmbH data centres in Helsinki, Finland (EU).
  • Database backups encrypted at rest and retained for 30 days; copies stored in Cloudflare R2 (EU) and Hetzner Object Storage (EU).
  • Sensitive credentials (API keys, OAuth secrets) encrypted at rest using AES-256-GCM.

7. International Data Transfers

  • EU data residency: All customer data is stored exclusively on servers located in Helsinki, Finland (Hetzner Online GmbH) — within the European Economic Area (EEA). No transfer outside the EEA occurs for primary data storage.
  • Backup storage: Encrypted backups are stored in Cloudflare R2 (EU region) and Hetzner Object Storage (EU region). Both use Standard Contractual Clauses (SCCs) where applicable.
  • Email delivery via SMTP — emails in transit may cross international network infrastructure. We do not control intermediate routing.
  • EU Representative: As a company established in India serving EU data subjects, we have appointed an EU Representative under GDPR Article 27. Contact: privacy@logkeet.com.

8. Cookies & Tracking

  • Strictly necessary cookies only: We set three cookies — a session authentication token (lk_session, httpOnly), a CSRF protection token (lk_csrf), and a theme preference in localStorage (lk-theme-v2, not a cookie). No consent is required for strictly necessary cookies under ePrivacy Directive Recital 25.
  • No tracking cookies: We do not use Google Analytics, Meta Pixel, Hotjar, or any third-party advertising or analytics trackers on our platform or website.
  • No cookie consent banner required: Because we use only strictly necessary cookies, EU law does not require us to display a cookie consent banner. We inform you of this here for full transparency.
  • Our SDK collects analytics events on behalf of your company — governed by your own privacy policy with your end users. The SDK does not set cookies on your users' browsers.

9. Contact & Data Protection Officer

  • Privacy requests & complaints: privacy@logkeet.com
  • Response time: We acknowledge within 5 business days, resolve within 30 days.
  • EU supervisory authority: If you are in the EU and not satisfied with our response, you may lodge a complaint with your local Data Protection Authority.
  • India DPDP: Complaints may be escalated to the Data Protection Board of India.

10. Changes to This Policy

  • We will notify you by email at least 30 days before any material changes take effect.
  • Continued use of the service after the effective date constitutes acceptance.
  • Historical versions of this policy are available on request.

logKeet · Privacy Policy · Effective June 6, 2026

← Back to Sign In