Kadro Legal

Privacy Policy

Version interim-1 · Published 4 August 2026

This is an interim policy. It has not been reviewed by an attorney. It is published now, rather than left absent, because we are already processing personal information and you are entitled to be told what happens to it. A reviewed version is expected in November 2026 and will replace this one.

1. Who is responsible

The responsible party, as POPIA uses that term, is KZN2026 (PTY) Ltd, registration number 2026/605478/07, a private company registered in the Republic of South Africa.

Our Information Officer can be reached at [email protected]. Use the same address for any request under this policy; we would rather you asked us than wondered.

2. What we collect, and why

Because you gave it to us

What Why
Your name and email address To have an account at all, and to email you about it
Your password, stored only as a hash To let you in and nobody else
Your avatar, if you set one So your colleagues can tell who is who
Your boards, cards, comments and files This is the product; it is what you came for
Billing details and billing contacts To invoice you, and to send the invoice to the right person

Because using a website produces it

What Why
IP addresses, and the browser you used Security: rate limiting, detecting attacks, and the audit trail below
Login history — when, from where, and whether it worked So you and we can see if somebody else has been in your account
Audit logs of significant actions So a change to your organisation's data can be traced to who made it
API request logs To find faults, and to see abuse
Your agreement to these documents, with the time, IP and browser Because "you agreed" is worth nothing if we cannot show when and to what

We do not sell any of it. We do not use your boards or cards to train machine learning models.

3. On what basis

Under POPIA, we process this information because:

Where we ever need your consent for something outside those, we will ask for it separately and you will be able to withdraw it.

4. Who else touches it

We use a small number of service providers ("operators", in POPIA's terms). Each is bound to process the information only for us:

Who What they do Where they do it
Laravel Cloud Runs the application and the PostgreSQL database United Statesus-east-2, Ohio
Cloudflare R2 Stores attachments, avatars, feedback screenshots, audit-log exports and database backups Western EuropeWEUR
Resend Sends transactional email — invitations, notifications, invoices United Statesus-east-1
Pusher Delivers live board updates over websockets European Union — cluster eu
Google Sign in with Google, only if you choose it Global
Unsplash Serves board background images you pick, so your browser contacts them directly Global

5. Your information leaves South Africa

It does, and you should know exactly where it goes: the United States (the application, the database and outgoing email) and Western Europe (files and backups). These are two different destinations under two different regimes, and saying "it is all in the cloud" would not be an answer.

Section 72 of POPIA permits this where the recipient is bound by an agreement that upholds principles substantially similar to POPIA's. Each provider above is engaged under its own data-processing terms to that effect. If you would like to know more about a specific one, ask.

6. How long we keep it

7. What you can ask for

Under POPIA you may:

Email [email protected]. We will reply, and if we cannot do what you have asked we will say why rather than go quiet.

The Information Regulator (South Africa) can be reached at [email protected].

8. Security

Passwords are stored hashed, never in plain text. Traffic is encrypted in transit. Two-factor authentication is available on every account and we recommend it. Access to production data is limited to the people who need it to run the service.

If a breach affects your personal information, we will notify you and the Information Regulator as POPIA requires.

9. Children

Kadro is not intended for children under 18, and we do not knowingly collect their information.

10. Changes to this policy

We will publish a new version rather than quietly editing this one, and every version stays retrievable. If a change is material, we will ask you to read and agree to it before you carry on.

Version interim-1. This is the version recorded against your acceptance. Superseded versions are kept, so an older record can still be read against the text it referred to — ask us if you need one.