Privacy
Last updated 4 Aug 2026
The short version
- Everything you put into KimonComply is held in the United Kingdom or the European Union.
- We do not sell your information, we do not advertise to you, and nothing here is watching how you use the product.
- The record trail is written once and cannot be edited afterwards. That is the point of it, and it is why some of what it holds cannot be removed.
- You can ask us to erase your details. Write to us and we will answer within one month.
Who is responsible for your information
KimonComply is run by Kimon Services Ltd, a company registered in England and Wales. Two different things are going on and it helps to keep them apart.
- Your account details, your name, your email address and your payment record are ours to look after, and we decide what happens to them.
- Everything you put into the product, your documents, registers, audits, findings and uploaded evidence, belongs to your organisation. We hold it and work with it on your organisation's behalf, and we do not use it for anything else.
What we hold
- Your name and email address, and which organisation you belong to and in what role.
- Your password, kept only as a scrambled version that cannot be read back into a password.
- Everything you put into KimonComply: documents and their versions, registers, audits, findings, photographs and the files you upload as evidence.
- The record trail: which account did what, and when.
- If you pay: a reference to your subscription, the country you are billed in, and your VAT number if you gave one. Never your card details.
We do not buy information about you from anyone, and we do not add anything to your record that you did not give us.
Where it is held, and who else touches it
Everything you put into KimonComply is held in the United Kingdom or the European Union, and so is your account. Below is every company involved, what each one holds and where. There is a longer version of this table, with the evidence behind each line, kept alongside the product's deployment notes.
Hostinger KVM VPS
The application itself and its database, which is nearly all of it: your documents, registers, audits, findings, the record trail, and people's names and email addresses.
Where: United Kingdom, in Manchester.
Cloudflare R2
The files you upload as evidence, the photographs attached to findings, and the PDFs the product produces.
Where: European Union, fixed permanently when the storage was created.
Resend
Sending our email and nothing else: reminders, notices and the messages the product sends you, along with the address they go to.
Where: European Union.
Better Auth
Signing in, your session, and which organisation you belong to. It is software running inside our own application rather than an outside service, so none of this leaves the machine above.
Where: The same machine in the United Kingdom.
Stripe
Payments, if you are on a paid plan. Your card details are typed on Stripe's own pages and never reach us. What we send is only what a payment needs: your email address, your billing country, and your VAT number if you gave us one.
Where: Stripe's own systems, under Stripe's arrangements, which are set out on its website.
There is nothing else. No advertising company, no analytics company and nobody buying a copy of anything.
Keeping it safe
Everything travels between your browser and us over an encrypted connection, always, and the same is true of the connections between the product and the companies above. Every file you upload is encrypted where it is stored.
We would rather tell you the limit than let you assume there is not one. The disk our records sit on is not itself encrypted, so what protects them there is who can reach the machine, and that is a very short list. Fixing this is on our list of work, and when it is done this page will say so.
Getting at your organisation's records requires being signed in and being a member of that organisation, and the database enforces that itself rather than trusting the screen to hide things.
The record trail, and why parts of it cannot be removed
KimonComply keeps a record trail: a list of what was done and when, each entry locked to the one before it. It cannot be edited and it cannot be deleted, by you, by your account admin or by us. That is not a limitation, it is the reason the trail is worth anything at all. An auditor can only rely on a history that nobody could have tidied up afterwards.
It does not hold your name or your email address. It holds dates, actions and account references, so once your details have been erased the trail names nobody. That is checked by an automated test rather than assumed.
Asking us to erase your details
You can ask us to erase the personal details we hold about you. Write to info@kimonservices.com and we will answer within one month, which is the time the law allows, and usually a great deal sooner. We will check who you are before we do anything, because handing somebody else's records to the wrong person would be the worse mistake.
When we erase someone, their name, email address and password are overwritten so they can no longer be read, their sessions are removed so nobody stays signed in, and their name is taken out of any competence record that carried it.
Two things are kept back, and we would rather be specific than vague about it. Audit reports and audit-ready packs that have already been issued stay exactly as issued, even where they carry the name of the auditor who ran the audit or the person who approved it. The basis for that is Article 17(3) of the UK GDPR, which allows information to be kept where it is needed to meet a legal obligation or to defend a legal claim. A certified organisation is required to keep records of the audits it has run, and an audit report with the auditor's name removed is no longer evidence that a competent, independent person did the audit, which is the whole point of it.
How long we keep things
While your account is open we keep your records for as long as you want them, and closing an account does not delete them either, as our terms explain.
What is kept back after an erasure request is not kept forever. The bound is the current certification cycle and the one after it, roughly six to seven years, because that is the window a certification body may look back over. After that the reason for keeping it has gone. Keeping it indefinitely was considered and rejected, because a claim that something is necessary with no end date is not really a claim of necessity at all.
Your rights
- To be told what we hold about you, and to be given a copy of it.
- To have anything wrong about you corrected.
- To ask us to erase your details, subject to the two things named above.
- To object to what we are doing with your information, or to ask us to limit it.
- To complain to the Information Commissioner's Office, the UK regulator, at ico.org.uk. We would rather you came to us first, but you do not have to.
To use any of these, write to info@kimonservices.com.
Cookies
We set one cookie, and its only job is to keep you signed in. There is no advertising and no analytics anywhere in this product. Our cookies page says exactly what is set and why there is no banner asking your permission.
Changes to this notice, and how to reach us
If we change how any of this works, we will change this page and the date at the top of it. If a change matters to you we will tell you by email rather than leaving you to notice.
Anything at all about your information, write to info@kimonservices.com. It is a mailbox somebody reads.
