Privacy Policy
Last updated: August 2026
In short: our public website has no advertising or analytics trackers, the contact form is used only to answer your inquiry, and workforce data inside a customer workspace belongs to that customer — we process it to run the service they configured, never for advertising.
1. Introduction
This Privacy Policy explains how Kavena handles information collected through the public Kavena website and information processed inside customer workspaces of the Kavena workforce management platform.
It is written in plain language so that both business customers and the employees whose data is processed can understand what happens to that information.
2. Who operates Kavena
Kavena is currently operated by its independent developer as a freelance software service. It is not incorporated as a company, corporation or other separate legal entity at this time.
References to “Kavena”, “we”, “us” and “our” in this policy refer to the software platform and its independent operator. Business contact is handled by email at admin@kavena.app. No physical office address is published.
3. Information collected through the public website
The public website is primarily informational. We do not run advertising trackers, marketing pixels or third-party analytics on it.
Standard technical information — such as IP address, browser type and requested URL — may be processed by our hosting infrastructure in server logs in order to deliver the site, keep it available and protect it against abuse.
Cookies: the public marketing pages do not set advertising or analytics cookies and do not use a consent banner, because no non-essential tracking is in place. Signed-in areas of the application use essential browser storage (for example, to keep your session active and remember interface preferences such as sidebar state). If we introduce analytics or non-essential cookies in the future, this policy will be updated first.
4. Contact-form information
When you submit the contact form on our website, it may collect:
- First name
- Last name
- Work email address
- Subject of your inquiry
- Your message
- Optional company information (company name, phone number, country or region, company size, preferred contact method)
We use this information to:
- Respond to your inquiry
- Arrange a demo where requested
- Answer product or business questions
- Detect and prevent spam or abuse of the form
- Keep a limited record of business communication where necessary
We do not use contact-form submissions for newsletters or marketing mailing lists. Submissions are stored in our backend database and a notification is sent by email to our business inbox.
5. Information processed inside customer workspaces
When an organisation uses Kavena, it creates a workspace (a “tenant”) and enters workforce information needed to operate attendance, scheduling, HR, leave and payroll preparation. This can include employee records, working schedules, punch and attendance records, leave and absence data, contract information and payroll-preparation figures.
We process that information to provide and support the configured software service. We do not use customer workforce data for advertising, and we do not sell it. Workspace data is isolated per tenant according to the application’s existing multi-tenant architecture and database access rules.
6. Customer and Kavena responsibilities
The customer organisation decides what workforce information it enters into Kavena and how it is used inside its own business. Kavena processes that information to deliver the service the customer has configured.
Formal legal labels such as “controller” and “processor” can depend on the jurisdiction involved and on the contract between the parties. We therefore do not assert those roles as absolute claims here; where a specific legal framework applies, the applicable roles should be confirmed in the agreement between the customer and Kavena.
7. Employee data
Employee records in a workspace may include name, employee code, job position, contract details, contact details, identification and licence reference data where the customer chooses to record it, and related HR information.
The customer is responsible for determining which employee data it is legally permitted to collect, store and use in its jurisdiction, and for keeping that data accurate and up to date.
8. Attendance and workforce data
Kavena records clock-in and clock-out events, breaks, worked and payable hours, overtime, schedules, leave and related adjustments. Manual corrections made by administrators are recorded with the author, timestamp and — where provided — a reason, so that changes remain auditable.
Depending on the customer’s configuration, attendance events may also be associated with a location or kiosk device, and a punch photo may be captured where the customer has enabled that option.
9. PIN and employee-code data
Employees may identify themselves at a kiosk using a PIN or an employee code, depending on how the workspace is configured. These credentials are stored in the workspace so that punches can be matched to the right employee, and access to them in the application is restricted to authorised administrative roles.
Customers should treat PINs and employee codes as access credentials: they should be issued individually, not shared, and rotated when appropriate.
10. Optional biometric features
Kavena supports optional fingerprint verification with supported reader hardware. Biometric functionality is optional and is not required to use Kavena.
- Each customer decides whether to enable supported biometric functionality in its own workspace.
- The current Kafino deployment uses PIN authentication rather than fingerprint authentication.
- Customers are responsible for obtaining any employee notices, consent or other legal authorisation required in their jurisdiction before enabling biometric functionality.
- Where biometric data is processed, Kavena applies reasonable technical safeguards and restricts access to it within the application.
Because biometric processing is enabled per customer, biometric data is not processed for every customer or every employee.
11. How information is used
- To provide, operate and support the Kavena platform
- To authenticate users and protect accounts and workspaces
- To produce attendance, scheduling, HR, leave and payroll-preparation outputs configured by the customer
- To send operational and transactional messages (for example, account emails or notifications the customer has enabled)
- To respond to inquiries submitted through the public website
- To maintain security, prevent abuse and troubleshoot technical problems
- To meet obligations that apply to us
We do not use this information for advertising.
12. Legal or contractual basis where applicable
Where a data-protection framework such as the EU/EEA GDPR applies, the processing described here will generally rest on the performance of a contract (providing the service to a customer), our legitimate interests in operating and securing the platform and responding to business inquiries, compliance with legal obligations, or — for specific features such as biometric verification — a basis that the customer must establish with its own workforce.
Which basis applies depends on the jurisdiction and on the agreement with the customer. We do not claim that any particular certification or compliance outcome has been independently audited.
13. Data hosting and service providers
Kavena runs on managed cloud infrastructure rather than self-maintained servers. The application database, authentication and file storage are provided by a managed PostgreSQL backend hosted in an Amazon Web Services region in Ireland (EU). The web application and its server endpoints are served through the platform’s managed edge hosting.
Additional providers may be used only for specific functionality the customer or we enable — for example an email delivery provider for transactional and notification email, and an AI provider where an optional AI-assisted feature is switched on for a workspace. Where an optional integration with a customer’s own external system is configured, data is exchanged only with that system.
14. Data retention
Workspace data is retained for as long as the customer’s workspace is active, because attendance, leave and payroll history is normally required for business and record-keeping purposes. Customers can delete or correct records inside the application, subject to the audit records that document such changes.
Contact-form submissions are kept only as long as needed to handle the inquiry and to keep a limited record of business communication. On termination, workspace data can be exported or deleted on request, subject to any retention obligation that applies. Backup retention periods of the underlying managed infrastructure are set by that provider and are not separately guaranteed by us.
15. Security practices
- Traffic to the website and application is served over HTTPS.
- The managed database and storage provide encryption at rest as part of the hosted platform.
- Access to workspace data is restricted per tenant through database row-level security policies.
- Application roles and permissions limit which users can see or change sensitive records such as credentials and payroll data.
- Administrative changes to attendance data are recorded in audit tables.
- Sensitive server credentials are held as server-side secrets and are not exposed to browsers.
We do not claim any security certification, and no service can guarantee absolute security. We continue to improve safeguards as the platform develops.
17. International data processing
Kavena serves customers in the Caribbean and elsewhere while the primary database region is in the EU (Ireland). This means data may be accessed from, or transmitted between, different countries — including the customer’s own country of operation and the region where the infrastructure is hosted.
Edge hosting may serve content from locations close to the visitor. Where a specific cross-border transfer mechanism is required by law, it should be addressed in the agreement between the customer and Kavena.
18. Individual privacy requests
If you are an employee or user of a customer workspace and want to access, correct or delete your information, please contact your employer or workspace administrator first — they control the data in that workspace and can usually action the request directly.
You can also write to admin@kavena.app. Where we act only on a customer’s instructions, we will refer the request to that customer and support them in responding.
19. Customer responsibility for employee notices and consent
Customers are responsible for informing their employees about the use of Kavena, for providing any privacy notices required in their jurisdiction, and for obtaining any consent or other legal authorisation needed — in particular before enabling optional features such as biometric verification, punch photos or location-linked attendance.
20. Children’s privacy
Kavena is a business tool intended for use by organisations and their workforce. It is not directed at children, and we do not knowingly collect information from children through the public website. Where a customer employs young workers in line with local law, the customer remains responsible for handling their data lawfully.
21. Policy updates
We may update this policy as the platform develops or as legal requirements change. The “Last updated” date at the top of the page reflects the current version. Material changes affecting customers will be communicated through the usual business contact channels.
22. Contact information
For privacy questions, requests or concerns about this policy, email admin@kavena.app.
See also our Terms of Service.