Kendis Oy (“Kendis”, “we”, “us”) provides the Kendis planning platform at app.kendis.io (the “Service”) and the website kendis.io and its subdomains (the “Website”). This Privacy Policy explains how we process personal data when you visit the Website, contact us, attend our events or training, or use the Service as an administrator or user of a customer account. It applies to all Hosting Regions we offer.
This Privacy Policy should be read together with the terms applicable to your use of the Service and, for customers, the Kendis License Agreement, its Data Processing Addendum (“DPA”) and the Hosting and Subprocessor Schedule (trust.kendis.io/subprocessors) (the “Schedule”).
Who we are
Kendis Oy is a company incorporated in Finland with Business ID 2874062-5 and registered office at Lapinlahdenkatu 16, 00180 Helsinki, Finland. Kendis Oy is the data controller for the processing described in this Privacy Policy, except where Section 2 states otherwise.
Privacy enquiries: privacy@kendis.io. Security reports: security@kendis.io.
Our two roles: controller and processor
Kendis processes personal data in two different capacities. Which one applies depends on the data concerned.
| Category | What it is | Kendis' role | Governing document |
|---|---|---|---|
| Account Data | Personal data about our customers' contacts and administrators, prospects and Website visitors: names, business contact details, login and role information, billing details, support communications, usage and technical data. | Controller | This Privacy Policy |
| Licensee Data | Content that a customer and its users enter into or synchronise with the Service: boards, features, objectives, dependencies, risks, comments, attachments, data imported from Jira or Azure DevOps, and the names and email addresses of the customer's users. | Processor, acting on the customer's instructions | License Agreement, DPA and Schedule; the customer's own privacy notice |
If you use the Service through an account operated by your employer or another organisation, that organisation is the controller of Licensee Data and decides how it is used. Questions and rights requests about Licensee Data should be directed to that organisation; we will assist it as required by the DPA.
Optional AI features. The Service includes optional AI features that are off by default and can be enabled only by a customer administrator. Their use is governed by the Kendis AI Terms of Use. When AI features are enabled, Kendis processes the relevant Licensee Data as processor on the customer's instructions, and any AI Subprocessor engaged is identified in the Schedule.
Personal data we collect
| Category | Examples | Source |
|---|---|---|
| Identity and contact | Name, work email address, telephone number, job title, employer, country | You, or your organisation when it creates your user |
| Account and administration | Login credentials (passwords are stored hashed), authentication method, role and permissions, account settings, selected Hosting Region, licence details | You; generated by the Service |
| Billing | Billing contact, invoicing address, VAT number, purchase orders, payment status. Card details are entered directly with our payment processor and are not stored by Kendis | You; our payment processor |
| Communications | Support tickets, chat conversations, emails, demo and support bookings, event and training registrations, survey responses | You |
| Usage and technical | IP address, browser and operating system, device type, pages viewed, referring site, feature usage, timestamps, error and security logs | Collected automatically |
| Marketing | Newsletter and marketing subscriptions, preferences, email engagement (opens and clicks), training progress | You; collected automatically |
| Prospect data | Business contact details of individuals at organisations we believe may be interested in the Service | Public sources and business data providers |
We do not intentionally collect special categories of personal data (for example health data or data revealing political opinions) and ask that you do not submit such data to us.
Why we process personal data and on what legal basis
| Purpose | Legal basis (GDPR Article 6(1)) |
|---|---|
| Creating and administering accounts, authenticating users, providing the Service and support | (b) performance of a contract, or steps taken at your request before entering into one |
| Invoicing, payment collection and accounting | (b) performance of a contract; (c) legal obligation under the Finnish Accounting Act |
| Service communications: security notices, Subprocessor change notices, release notes, maintenance windows | (b) performance of a contract; (f) legitimate interest in keeping customers informed |
| Securing the Service and the Website, preventing fraud and abuse, logging, incident response, operating our ISO/IEC 27001 controls | (f) legitimate interest in security; (c) legal obligation |
| Understanding how the Service and Website are used in order to improve them | (f) legitimate interest; (a) consent, for analytics cookies |
| Marketing to business contacts, newsletters, event invitations | (f) legitimate interest in promoting the Service to business contacts, with the right to opt out at any time; (a) consent where required by law |
| Responding to enquiries, demo requests and event or training registrations | (b) or (f) |
| Establishing, exercising or defending legal claims; complying with law and regulatory requests | (c) legal obligation; (f) legitimate interest |
Where we rely on legitimate interests, we have assessed that our interests are not overridden by your rights and freedoms. You may object to processing based on legitimate interests at any time (Section 11).
Hosting Regions and where personal data is processed
Customers select a Hosting Region when they order the Service. Licensee Data is stored and processed only in the selected Hosting Region, including backups. The Hosting Region cannot be changed after the account is created.
| Hosting Region | Infrastructure provider | Processing and backup location | Transfer of Licensee Data outside the EEA |
|---|---|---|---|
| Germany | OVHcloud (OVH Hosting Limited, Ireland), including OVHcloud Managed MongoDB | Germany | None. Licensee Data remains within the European Economic Area, and content delivery and edge security are provided from EEA locations. |
| United States | Amazon Web Services, Inc. and MongoDB, Inc. (MongoDB Atlas) | Northern Virginia and other United States locations | Yes. Transfers are made under the EU Standard Contractual Clauses and, for Amazon Web Services, the EU-US Data Privacy Framework (Section 8). |
Where the Germany Hosting Region is selected, access to Licensee Data is restricted to authorised personnel of Kendis and its Subprocessors located in the European Economic Area, the United Kingdom or Switzerland, as set out in Section 6 of the Schedule.
Account Data is processed in Kendis' business systems (customer relationship management, support, billing, email and productivity tools) irrespective of the Hosting Region. Some of these systems are operated by providers located outside the EEA; they are identified in Section 5 of the Schedule together with the transfer mechanism relied upon.
Cookies and similar technologies
The Website and the Service use cookies and similar technologies. Before non-essential cookies are set you are asked for consent through our cookie banner, in accordance with the ePrivacy Directive (2002/58/EC) as implemented in Finland by the Act on Electronic Communications Services (917/2014). You can change or withdraw your choices at any time through the banner or your browser settings. Blocking strictly necessary cookies may prevent parts of the Service from working.
| Type | Purpose | Basis |
|---|---|---|
| Strictly necessary | Sign-in, session management, security, load balancing and remembering your cookie choices | Necessary to provide the service you requested |
| Analytics | Counting visitors and understanding how the Website and Service are used so that we can improve them | Consent |
| Functionality | Remembering preferences such as language and interface settings | Consent |
The cookies currently in use are listed in the Cookie Schedule at the end of this Privacy Policy.
International transfers
Kendis is established in Finland. Whether personal data leaves the European Economic Area depends on the data concerned:
- Licensee Data, Germany Hosting Region: not transferred outside the EEA.
- Licensee Data, United States Hosting Region: processed in the United States by Amazon Web Services, Inc. and MongoDB, Inc. under the EU Standard Contractual Clauses (Commission Implementing Decision (EU) 2021/914). Amazon Web Services is additionally certified under the EU-US Data Privacy Framework.
- Account Data, all Hosting Regions: some of the providers listed in Section 5 of the Schedule are located in, or process data in, the United States or other countries outside the EEA.
For every transfer outside the EEA we rely on one of the following safeguards under Chapter V of the GDPR: (i) a European Commission adequacy decision, including the EU-US Data Privacy Framework for recipients certified under it; or (ii) the EU Standard Contractual Clauses, supported by a transfer impact assessment and supplementary measures such as encryption in transit and at rest and access restrictions. Transfers to the United Kingdom and Switzerland are covered by adequacy decisions. The transfer mechanism used for each provider is stated in the Schedule, and a copy of the relevant Standard Contractual Clauses is available on request.
How long we keep personal data
| Data | Retention period |
|---|---|
| Licensee Data | For the term of the customer's subscription, then deleted in accordance with the deletion timelines in the DPA |
| Account Data of customers | For the term of the subscription and for as long as needed afterwards to close the account, resolve disputes and meet legal obligations |
| Billing and accounting records | For the period required by the Finnish Accounting Act (currently six years from the end of the financial year, and ten years for the ledgers themselves) |
| Support and chat conversations | Three years from the last interaction |
| Marketing and prospect data | Until you opt out or object, or until we have had no engagement from you for twenty-four months |
| Website analytics data | Fourteen months |
| Security and access logs | Twelve months, unless retained longer for an investigation |
Data may persist in encrypted backups for a limited period after deletion from live systems, after which it is overwritten in the ordinary backup cycle.
How we keep personal data secure
Kendis operates an information security management system certified to ISO/IEC 27001. Measures include encryption of data in transit (TLS) and at rest, single sign-on and multi-factor authentication, role-based access control, named individual accounts with no shared credentials, logging of administrative access, vulnerability management, regular backups and a tested incident response process. Our Subprocessors are bound by written contracts imposing equivalent obligations.
In the event of a personal data breach we notify affected customers as required by the DPA and the supervisory authority within 72 hours where required by the GDPR. If you believe your data has been compromised, contact security@kendis.io.
Your rights
Subject to the conditions in the GDPR, you have the right to:
- access the personal data we hold about you and receive a copy;
- have inaccurate or incomplete data corrected;
- have your data erased;
- restrict our processing of your data;
- receive the data you provided to us in a structured, machine-readable format and have it transmitted to another controller;
- object to processing based on legitimate interests, including direct marketing; and
- withdraw consent at any time where processing is based on consent, without affecting processing carried out before withdrawal.
We do not make decisions based solely on automated processing that produce legal or similarly significant effects.
To exercise any of these rights, email privacy@kendis.io. We may need to verify your identity. We respond within one month, extendable by two further months for complex requests, and do not charge a fee unless a request is manifestly unfounded or excessive. Where a request concerns Licensee Data we will refer it to the customer that controls that data and assist the customer as required by the DPA.
If you are dissatisfied with how we handle your data you may lodge a complaint with the Office of the Data Protection Ombudsman of Finland (Tietosuojavaltuutetun toimisto, tietosuoja.fi) or with the supervisory authority in the EEA member state where you live or work.
Marketing communications
We send marketing emails, newsletters and event invitations to business contacts who have consented or, where permitted by law, whose organisation has a customer or prospective customer relationship with us. Every marketing email contains an unsubscribe link, and you can also opt out by emailing privacy@kendis.io. Opting out of marketing does not stop service communications that are necessary to operate your account, such as security notices and Subprocessor change notices.
Children
The Website and the Service are directed at businesses and are not intended for children under 16. We do not knowingly collect personal data from children. If you believe a child has provided personal data to us, contact us and we will delete it.
Third-party websites
The Website and the Service contain links to third-party websites and services, including integration partners. We are not responsible for their privacy practices and this Privacy Policy does not apply to them.
Changes to this Privacy Policy
We may update this Privacy Policy from time to time. Each version carries a version number and effective date. Material changes are notified to customer account administrators by email or in the Service before they take effect, and the current version is always published at kendis.io/privacy-policy.
| Version | Effective date | Change |
|---|---|---|
| 2.0 | 10 August 2026 | Complete revision. Adds the Germany Hosting Region; distinguishes Kendis' controller and processor roles; aligns transfer mechanisms with the EU Standard Contractual Clauses and the EU-US Data Privacy Framework; replaces UK references with Finnish law and supervisory authority; adds legal bases, retention periods and a reference to the Hosting and Subprocessor Schedule. |
| 1.0 | 2018 | First publication as the Data Protection & Compliance Policy. |
Contact
Kendis Oy, Lapinlahdenkatu 16, 00180 Helsinki, Finland. Business ID 2874062-5.
Privacy: privacy@kendis.io. Security: security@kendis.io.
This Privacy Policy is governed by the laws of Finland.
Cookie Schedule
The cookies currently set by the Website and the Service. If you believe this list is incomplete, let us know at privacy@kendis.io.
| Cookie | Type | Purpose | Duration |
|---|---|---|---|
| Session cookie | Strictly necessary | Maintains your signed-in session while you use the Service | Session |
| Cookie consent | Strictly necessary | Remembers the cookie choices you made in the banner | 12 months |
| Analytics cookies | Analytics | Measure how visitors use the Website and Service so that we can improve them (Google Analytics) | Up to 14 months |
| Preference cookies | Functionality | Remember language and interface settings | 12 months |

