Privacy Policy
Version 1.1 · Last updated 1 May 2026
1. Data Controller Information
Kanbanq Sp. z o.o. (REGON: 542009470, NIP: 5253050479) is the data controller for your personal data.
Our registered office is located in Warsaw, Poland.
You can contact us at privacy@kanbanq.app or dpo@kanbanq.app for data protection matters.
2. Legal Basis for Processing
We process your personal data based on the following legal grounds under GDPR Article 6:
• Contract performance: to provide our services and fulfil our contractual obligations
• Legitimate interests: to improve our services, ensure security, and communicate with you
• Consent: for analytics cookies and optional features (you can withdraw consent at any time)
• Legal obligation: to comply with applicable laws and regulations
3. Information We Collect
Account information: name, email address, and authentication data when you create an account.
Usage data: information about how you use our Service, including features accessed and actions taken.
Device information: IP address, browser type, operating system, and device identifiers.
Communication data: messages you send to us and records of our communications with you.
Project data: content you create, upload, or store in your projects. You remain the owner of this data.
Analytics data: aggregated usage statistics collected via Firebase Analytics (only with your consent).
4. How We Use Your Information
To provide, maintain, and improve our services and develop new features.
To process transactions and send related information including confirmations and receipts.
To send technical notices, updates, security alerts, and support messages.
To respond to your comments, questions, and provide customer service.
To detect, prevent, and address technical issues and security vulnerabilities.
To comply with legal obligations and protect our rights and the rights of others.
5. Data Sharing and Transfers
We do not sell, trade, or otherwise transfer your personal information to third parties for their marketing purposes.
We may share data with trusted service providers who assist us in operating our Service, under strict data processing agreements.
We may disclose information in response to legal requests or to protect our rights, property, or safety.
For EU users: data transfers outside the EU are protected by appropriate safeguards such as Standard Contractual Clauses.
We may share aggregated, anonymised information that cannot identify you for analytics purposes.
6. Data Security and Retention
We implement appropriate technical and organisational security measures to protect your personal data.
Your data is encrypted in transit using TLS and at rest using industry-standard encryption.
We regularly review and update our security practices and conduct security assessments.
We retain personal data only as long as necessary for the purposes outlined in this policy.
Account data is retained until you delete your account, after which it is deleted within 30 days.
Some data may be retained longer if required by law or for legitimate business purposes.
7. Your Rights Under GDPR
Right of access: you can request a copy of the personal data we hold about you.
Right of rectification: you can correct inaccurate or incomplete personal data.
Right of erasure: you can request deletion of your personal data ("right to be forgotten").
Right of portability: you can export your data in a machine-readable format.
Right to restrict processing: you can limit how we process your personal data.
Right to object: you can object to processing based on legitimate interests.
Right to withdraw consent: you can withdraw consent for processing based on consent at any time.
To exercise these rights, contact us at privacy@kanbanq.app with proof of identity.
8. Cookies
We use analytics cookies to understand how visitors use our website. These are only set with your explicit consent.
You can accept or decline analytics cookies when you first visit the site. You can change your preference at any time by clearing your browser storage.
For full details of which cookies we use and why, please see our Cookie Policy.
We do not use third-party advertising cookies or tracking pixels.
9. International Data Transfers
Your data may be processed in countries outside the European Economic Area (EEA).
We ensure adequate protection through approved transfer mechanisms such as Standard Contractual Clauses.
We work only with service providers that provide adequate data protection guarantees.
You can request information about specific safeguards by contacting us.
10. Changes to This Policy
We may update this Privacy Policy from time to time to reflect changes in our practices or applicable law.
We will notify you of material changes via email or through our Service at least 30 days before they take effect.
We encourage you to review this policy periodically for the latest information on our privacy practices.
Your continued use of our Service after changes take effect constitutes acceptance of the updated policy.
11. Contact Information
For general privacy questions: privacy@kanbanq.app
For data protection officer enquiries: dpo@kanbanq.app
For exercising your rights: privacy@kanbanq.app (include proof of identity)
Postal address: Kanbanq Sp. z o.o., Warsaw, Poland
You also have the right to lodge a complaint with the Polish Data Protection Authority (UODO) if you believe we have not handled your personal data properly.