1. Data We Collect
We collect the following types of information:
- Account Information: Name, email address, phone number, and business details you provide during registration.
- Payment Information: Processed securely via our payment processor. We do not store your full card details on our servers.
- Website Content: Text, images, logos, and other content you upload to your website.
- Usage Data: How you interact with our platform, including pages visited and features used.
- Technical Data: IP address, browser type, device information, and approximate location (country-level) for service optimization.
- Client End-User Data: Information collected through the websites we manage for you (e.g., contact form submissions, booking requests). We process this data solely on your behalf to provide the Service. You are the 'Data Controller' responsible for this data; we act only as a 'Data Processor' under your instructions.
2. How We Use Your Data
- To deliver and manage your website, domain, and email services.
- To process payments and send invoices.
- To communicate service updates, renewals, and important notices.
- To send marketing communications (only if you opt-in).
- To improve our services through anonymized analytics.
- To detect and prevent fraud or abuse.
- To comply with legal obligations.
Legal Basis for Processing (NDPR/GDPR)
We process your data under the following legal bases:
- Contractual Necessity: To fulfill our service obligations (e.g., hosting your site, registering your domain).
- Legal Obligation: To comply with tax and financial laws (e.g., keeping invoices for 7 years).
- Legitimate Interest: To prevent fraud, ensure security, and improve our proprietary tools.
- Consent: For marketing communications (which you can withdraw at any time).
3. Data Sharing
We share your data only with third-party service providers who help us operate our business. These providers are contractually obligated to protect your data and use it only for the purposes we specify.
Categories of Third-Party Providers:
- Payment ProcessorsTo securely process your payments
- Domain RegistrarsTo register and manage your domain (WHOIS data)
- Email ProvidersTo set up your corporate email and send transactional emails
- Hosting ProvidersTo host your website and store your data securely
- Analytics ToolsTo understand how users interact with our platform (anonymized)
- Geolocation ServicesTo detect your country for currency display (IP-based, no personal data stored)
Creation of Third-Party Accounts (Authorized Agent)
To provide functionality (like Analytics, Contact Forms, or Email services), we may create accounts with third-party providers on your behalf using your business email address. By using our service, you authorize Keva Labs to accept the Terms of Service of these providers as your agent. Credentials for these accounts are managed by us during your subscription and transferred to you upon request or cancellation.
Proprietary Tools & APIs
Certain dynamic features of your website (e.g., widgets, dashboards, booking systems) may rely on Keva Labs' proprietary APIs. Data processed by these tools is handled according to this policy. If you opt for a Standalone Subscription to these tools after leaving our hosting service, we will continue to process this data to fulfill that service.
We do not sell, rent, or trade your personal information to third parties for marketing purposes.
4. International Data Transfers
Your data may be transferred to and processed in countries outside of Nigeria, including the United States and European Union, where our third-party service providers operate.
- We only use providers who maintain adequate data protection standards.
- Where required, we ensure appropriate safeguards are in place, such as Standard Contractual Clauses or equivalent mechanisms.
- By using our services, you consent to the transfer of your data to these countries.
5. Marketing Communications
We may send you marketing communications about our products, services, and promotions.
- Opt-In Required: We only send marketing emails if you explicitly consent during registration or later via your account settings.
- Easy Unsubscribe: Every marketing email includes an unsubscribe link. You can opt-out at any time.
- Service Emails: We will still send essential service-related emails (payment confirmations, renewal notices, security alerts) even if you unsubscribe from marketing.
6. Cookies & Tracking
We use cookies and similar technologies to:
- Essential Cookies: Required for authentication, security, and core functionality.
- Analytics Cookies: To understand how visitors use our site and improve our services.
- Preference Cookies: To remember your settings and choices (e.g., currency preference).
You can control cookies through your browser settings. Disabling essential cookies may affect site functionality.
7. Data Security
We implement industry-standard security measures:
- All data transmitted via HTTPS/TLS encryption
- Passwords are hashed and never stored in plain text
- Payment data is processed by PCI-compliant providers
- Regular security monitoring and access controls
- Secure data centers with physical and digital protections
8. Your Rights
Under GDPR, NDPR, and other applicable data protection laws, you have the right to:
Access
Request a copy of the personal data we hold about you
Correction
Request correction of inaccurate or incomplete data
Deletion
Request deletion of your data (subject to legal retention requirements)
Portability
Request your data in a machine-readable format
Restriction
Request that we limit how we process your data
Objection
Object to processing based on legitimate interests
To exercise these rights, contact us at privacy@kevalabs.com. We will respond within 30 days.
9. Data Retention
- Active Accounts: Data is retained for the duration of your service.
- Suspended Accounts (Non-Payment): Data is retained for a maximum of 60 days from the date of suspension to allow for payment rectification. After 60 days, website content and configurations may be permanently deleted.
- Cancelled Accounts (Voluntary): You have 15 days after your requested cancellation date to export your data. After this period, data is deleted.
- Financial Records: Invoices and payment records are retained for 7 years for tax and legal compliance.
- Backup Retention: System backups may retain data for up to 90 days after deletion for disaster recovery purposes.
10. Children's Privacy
Our services are intended for business use and are not directed at children under 16. We do not knowingly collect personal information from children. If you believe we have collected data from a child, please contact us immediately.
11. Changes to This Policy
We may update this Privacy Policy from time to time. When we make material changes, we will notify you via email at least 30 days before the changes take effect. The "Last Updated" date at the top of this page indicates when the policy was last revised.
12. Contact Us
For privacy-related inquiries or to exercise your data rights:
Keva Labs (Data Controller)
Email: privacy@kevalabs.com