Privacy Notice
Last updated 25 August 2026
1. Who we are
Kinetic OS is operated by Sandra Sims ("we", "us"). We are the data controller for personal data processed through this service and decide why and how that data is used. You can reach us at the support address shown in your account or by replying to any service email.
2. Data we collect and why
- Account data (name, email address, login credentials, workspace and team membership) — to create and secure your account and provide the service. Legal basis: performance of our contract with you.
- Content data (playbooks, captured SOPs, onboarding tracks, step progress, saved searches and export presets) — to store and display the work you create. Legal basis: performance of our contract.
- Usage and telemetry data (pages viewed, feature usage, device and browser type, approximate location from IP address) — to keep the service reliable and improve it. Legal basis: our legitimate interest in operating and improving a secure product.
- Security and audit data (IP address, timestamps, shared-link access attempts, allowed/rejected outcomes) — to detect abuse, enforce rate limits and investigate incidents. Legal basis: legitimate interest in security and fraud prevention.
- Support data (messages you send us and their attachments) — to answer your questions. Legal basis: legitimate interest and contract performance.
- Marketing data (email preferences) — only where you have opted in. Legal basis: consent, which you may withdraw at any time.
Payment card details are never collected or stored by us. Payments are handled by our reseller and Merchant of Record, Paddle.com, under its own privacy notice.
3. Who we share with
- Service providers / subprocessors — hosting, database, email delivery, analytics and support tooling, acting on our instructions.
- Paddle.com, our Merchant of Record, for the sale of subscriptions, subscription management, payments, invoicing and tax compliance.
- Professional advisers (legal, accounting) where necessary.
- Authorities where we are legally required to disclose data.
We never sell your personal data. Where data is transferred outside the UK/EEA, we rely on adequacy decisions or Standard Contractual Clauses with appropriate safeguards.
4. Retention
We keep account and content data for as long as your account is active, and for up to 90 days after closure so you can recover it. Security and audit logs are kept for up to 12 months. Records we must keep for tax or legal reasons are retained for the period required by law. After that, data is deleted or anonymised.
5. Your rights
Depending on where you live, you may have the right to access, correct, delete, restrict or object to processing of your personal data, to receive it in a portable format, and to withdraw consent at any time. Contact us and we will respond within one month. If you are in the UK or EEA, you also have the right to complain to your local supervisory authority.
6. Security
We apply appropriate technical and organisational measures, including encryption in transit, row-level access controls, least-privilege database policies, signed shared links, rate limiting and access logging. No system is perfectly secure, but we work to protect your data and to notify you of incidents where required.
7. Cookies
We use essential cookies and local storage to keep you signed in, remember your theme preference and store playbook progress. We may use limited analytics cookies to understand feature usage. You can clear or block cookies in your browser settings; essential cookies are required for the service to work.
8. Changes
We will update this notice when our practices change and revise the date above. Material changes will be communicated in-product or by email.