All legal documents
On this page
1. Introduction
Kayana for Business - also trading as Kayana, Kayana World Limited and any other Kayana entities that may be formed across jurisdictions - hereinafter referred to as “Company” ("Company", "we", "us", or "our") is committed to protecting your privacy and handling your personal data with transparency and integrity. This Privacy Policy describes how we collect, use, disclose, and protect personal information when you interact with us online, through our website [www.kayanaforbusiness.com], applications, or other services (collectively hereinafter referred to as the “Services”) which would include the following:
- Use our software platforms, websites, apps, or cloud services
- Purchase or use our hardware products
- Interact with our customer support or technical services
- Visit our offices or attend our events
- Otherwise engage with us online or offline
This policy is designed to meet the privacy requirements of the following jurisdictions:
- UK General Data Protection Regulation (UK GDPR)
- EU General Data Protection Regulation (EU GDPR)
- California Consumer Privacy Act (CCPA/CPRA)
- Personal Information Protection and Electronic Documents Act (PIPEDA) – Canada
- Australian Privacy Act and Australian Privacy Principles (APPs)
- New Zealand Privacy Act 2020
By using our Services or Products, you consent to the practices described in this Privacy Policy.
2. Scope
This Privacy Policy applies to:
- All users of our websites, mobile apps, softwares, hardwares, businesses across jurisdictions, platforms, or SaaS products
- Customers who purchase or use our hardware devices
- Business clients, vendors, and partners and the like
- Individuals who interact with us in person, via phone, email, online, chat or any other form of communication
3. What We Collect
We may collect the following categories of personal information:
A. Information You Provide to Us
- Full name, title, company name
- Email address, phone number, postal address
- Usernames, passwords, or account credentials
- Technical support inquiries, chats, or emails
- Feedback, survey responses, or testimonials
- Employment or professional details (for B2B users)
B. Automatically Collected Data
Via our software, apps, websites, or hardware devices:
- IP address, device ID, browser type
- Location data (GPS, IP geolocation)
- Operating system and platform
- Usage data (pages visited, features used, customisations used)
- Telemetry from hardware devices (e.g., device performance, errors etc)
- Diagnostic data from software and firmware
C. Information from Third Parties
- Analytics or advertising providers
- Partners, resellers, or integrations
- Public databases or social networks, as applicable
D. Biometric and Facial Recognition Information (Employee App Only)
Where enabled by an employer or authorised organisation using our employee application (including Kayana for its own employees), we may collect and process biometric information and facial recognition data for workforce management, attendance verification, identity verification, access control, security, fraud prevention, and related employment administration purposes.
Where facial recognition or biometric verification features are enabled within our employee application, we may collect and process biometric information, including:
- Facial photographs and images captured through a device camera;
- Facial geometry and biometric identifiers derived from such images;
- Biometric templates generated from facial images;
- Liveness detection data;
- Authentication records, timestamps, and verification results.
Such information is collected solely for authorised workforce management, attendance verification, identity verification, access control, security, fraud prevention, and related operational purposes, and only where permitted by applicable law and for no other purpose.
4. How We Use Your Information
We use your personal data for the following purposes:
A. To Provide and Maintain Our Products & Services
- Account registration and management
- Providing access to apps, platforms, or devices
- Processing transactions and orders
- Device setup, onboarding, firmware/software updates
B. To Improve and Develop Products
- Analysing usage and performance data
- Conducting testing, diagnostics, and troubleshooting
- Applying AI/ML models (only with appropriate safeguards and prior approval as may be needed)
C. To Communicate with You
- Transactional emails (receipts, alerts)
- Product updates, security notices
- Marketing, promotions (only with your consent)
- Customer service, live chat, or support tickets
D. To Ensure Safety and Legal Compliance
- Preventing fraud, abuse, and unauthorised access
- Monitoring system integrity and hardware reliability
- Complying with applicable laws and regulations in the applicable jurisdictions
E. Use of Facial Recognition and Biometric Information
Where facial recognition functionality is enabled, biometric and facial recognition information may be used solely for the following purposes:
- Employee identity verification
- Workforce attendance and timekeeping
- Access control and workplace security
- Fraud prevention and detection
- Verification of authorised access to systems, premises, devices, or services, as applicable
- Compliance with organisational security requirements
We do not use biometric or facial recognition information for advertising, marketing, behavioural profiling, automated marketing decisions, or the sale of personal information.
Biometric information will only be processed for the purposes described in this Privacy Policy or as otherwise required by applicable law and for no other purposes.
5. Legal Bases for Processing (UK/EU)
We only process personal data where we have a legal basis, such as:
- Consent (e.g., marketing, analytics cookies)
- Contractual necessity (e.g., account access, device updates, software updates)
- Legal obligations (e.g., tax, compliance)
- Legitimate interests (e.g., business operations, fraud prevention)
6. Disclosure of Your Information
We may share your personal data with:
A. Service Providers & Vendors
For tasks such as hosting, payments, logistics, analytics, and customer service
B. Business Partners & Affiliates
Where you request integrations or product connections and customisations
C. Law Enforcement & Regulators
When required by law, subpoena, or any other legal processes as applicable
D. Corporate Transactions
In connection with a merger, sale, reorganization, or asset transfer
We do not sell or rent your personal data in any way whatsoever.
E. Disclosure of Biometric Information
Biometric information and facial recognition data may be disclosed only:
- To service providers acting on our behalf that support identity verification, authentication, hosting, storage, or security functions
- To the employer or organisation that administers the employee application (including Kayana itself)
- Where required by applicable law, regulation, court order, or lawful governmental request
We do not sell, lease, trade, monetise, or otherwise commercially disclose biometric information to third parties.
We do not permit third parties to use biometric information for their own marketing, advertising, analytics, or independent business purposes.
7. International Transfers
We may transfer your personal data to countries outside your own, including the United States, UK, EU, or others where we or our service providers operate, as may be needed.
Where applicable, we ensure adequate protection through:
- Standard Contractual Clauses (SCCs)
- UK Addendum to SCCs
- Adequacy decisions
- Binding Corporate Rules (BCRs)
8. Retention of Your Information
- We retain personal data:
- As long as necessary to provide our services or support your devices
- As long as required for legal, regulatory, compliance or tax reasons
- Or until you request deletion, subject to applicable law
- Anonymised or aggregated data may be retained indefinitely.
- Biometric information, facial images, facial recognition templates, and related authentication records collected through the employee application will be retained for a maximum period of ninety (90) days from the date of collection or creation unless:
- A shorter retention period is required by applicable law
- Retention is necessary to comply with a legal obligation;
- Retention is necessary for the establishment, exercise, or defence of legal claims.
- Upon expiry of the retention period, biometric information will be securely deleted, anonymised, or irreversibly destroyed in accordance with our data retention and security procedures.
- The face recognition data/information is used to confirm the identity of the person that is signing in and therefore keep an accurate record with a trail for any audit purposes, as applicable.
- We believe that 90 days is sufficient time for any issues to be resolved by HR and handle any issues that may arise and retain for the purposes of auditing employee activity only.
- Facial photographs are transmitted to and stored on our cloud infrastructure provider, Amazon Web Services (AWS), solely to provide backend hosting and storage for the Kayana Employee application.
- Sharing of facial photographs is necessary to operate the app's backend storage and delivery infrastructure. AWS acts as a data processor on our behalf and has no independent right to use the data at any point whatsoever.
- AWS stores attendance verification photographs on our behalf as part of cloud hosting (Amazon S3). They store the data only for as long as we instruct - subject to the same 90-day maximum retention period - after which it is deleted per our instruction.
- AWS does not process face data for any independent purpose. Their privacy practices are documented at https://aws.amazon.com/privacy/.
- Crash/Analytics Data
- We use Firebase Analytics and Firebase Crashlytics (Google LLC) and Sentry (Functional Software, Inc.) to monitor app performance and stability. These services collect device identifiers, app usage data, and crash reports. Google retains analytics data for up to 14 months. Sentry retains crash data for 90 days. Neither service is used to identify employees for advertising purposes. See Google's Privacy Policy and Sentry's Privacy Policy for details.
- We collect crash reports and limited analytics to monitor application stability, diagnose technical issues, and improve the reliability and performance of the app. This information helps our engineering team identify and resolve bugs that may impact employees while using the application.
- Crash and analytics data is not used for advertising, marketing, or user profiling.
- Crash and analytics data is shared with our service providers (Sentry and Firebase) solely for the purpose of application monitoring, crash reporting, diagnostics, and performance analysis.
- These providers process the data on our behalf to help identify and troubleshoot application issues. The data is not shared for advertising, marketing, or any unrelated purposes.
- Our crash reporting and analytics providers (Sentry and Firebase) do not receive or store users' face data.
- Face data is stored securely in Amazon Web Services (AWS) S3 using industry-standard security controls. Access to this data is restricted to authorized personnel, and the data is retained for 90 days, after which it is automatically deleted according to our retention policy.
- Sentry’s privacy policy can be found at: https://sentry.io/legal/privacy/3.3.2/in-app/?userCurrentVersion=3.3.1
- Firebase’s privacy policy can be found at: https://firebase.google.com/support/privacy
9. Your Rights and Choices
Depending on your jurisdiction, you may have the right to:
| Jurisdiction | Key Rights Available |
|---|---|
| UK/EU (GDPR) | Access, correction, deletion, portability, restriction, objection, withdraw consent |
| California (CCPA/CPRA) | Know, delete, correct, opt-out of sale/sharing, limit sensitive data use |
| Canada (PIPEDA) | Access, correction, withdraw consent |
| Australia/NZ | Access, correction, complaint rights |
To exercise your rights, contact: (info@kayana.co.uk)
We may require verification of your identity before fulfilling your request.
Where biometric information is processed, individuals may have additional rights under applicable law, including the right to request information regarding the collection and use of biometric data, request deletion of biometric information, withdraw consent where consent is the lawful basis for processing, and lodge complaints with applicable supervisory authorities.
10. Tokens and Similar Technologies
We use tokens and tracking technologies for:
- Website functionality
- Analytics (e.g., Google Analytics)
- Marketing (e.g., ad personalisation)
As part of our payment technology solutions, we use secure tokens to facilitate and protect interactions between users, merchants, and financial institutions. These tokens play a critical role in ensuring the privacy, integrity, and security of payment-related data.
Types of Tokens We Use
We may generate and use various types of tokens, including:
- Authentication Tokens – To verify user and system identities during login and transaction flows.
- Session Tokens – To maintain persistent, secure sessions across our platform.
- Access Tokens – To control access to APIs, dashboards, and secure endpoints used by our clients and their users.
- Payment Tokens – In certain solutions, we tokenise sensitive payment information (such as credit card numbers) to ensure that raw payment data is never stored or transmitted directly within our systems.
Purpose of Token Use
These tokens are used for:
- Securing payment transactions
- Preventing unauthorised access
- Managing secure communication between systems
- Enabling compliance with industry standards (e.g., PCI DSS)
- Supporting seamless integration with third-party services (e.g., banks, acquirers, wallets)
Tokens may be stored temporarily in secure environments or within the user’s device (e.g., in a browser or mobile application) and are designed to expire after a set duration or upon logout. We do not use tokens to track users across third-party services or for behavioral profiling.
Data Protection and Compliance
Tokens themselves do not contain personally identifiable information (PII), but may be associated with user or transaction data stored securely in our systems. We implement strict access controls, encryption, and secure key management practices to protect tokenised data in accordance with applicable privacy and data protection laws.
Clients integrating our technology are responsible for using tokens in compliance with applicable regulations and for configuring token usage within their own environments securely.
11. Data Security
We implement physical, technical, and administrative safeguards to protect your personal information from loss, theft, unauthorised access, and misuse.
Examples include:
- Data encryption (in transit and at rest)
- Access control and multi-factor authentication
- Regular vulnerability scanning and patching
- Secure device firmware updates
No system is 100% secure, but we take industry-standard precautions.
Biometric information and facial recognition data are protected using enhanced security measures, including encryption in transit and at rest, role-based access controls, restricted personnel access, audit logging, and secure deletion procedures. Access to biometric information is limited to personnel and service providers with a legitimate business need and appropriate authorisation.
12. Children’s Privacy
Our Services and Products are not intended for individuals under the age of:
- 13 (United States)
- 16 (UK/EU, unless parental consent is given)
We do not knowingly collect data from children without legal consent. Contact us if you believe a child has provided personal data.
13. Third-Party Links and Services
Our websites, apps, or devices may link to or integrate with third-party services (e.g., payment processors, APIs, smart home platforms). We are not responsible for their privacy practices.
Please review their privacy policies separately, as applicable.
14. Changes to This Policy
We may update this Privacy Policy periodically. Updates will be posted on our website with an updated "Last Updated" date.
Material changes will be notified to you directly via email or in-product notifications.
15. Cookie Policy
- We use cookies, pixels, local storage, SDKs, and similar technologies (“Cookies”) to operate, secure, improve, and analyse our Services.
- Cookies may be placed by us or by authorised third-party service providers acting on our behalf.
- We use the following categories of Cookies:
- Strictly Necessary Cookies - required for the operation, security, authentication, and core functionality of the Services.
- Performance and Analytics Cookies - help us understand usage patterns, troubleshoot issues, and improve performance.
- Functional Cookies - remember preferences and settings to enhance user experience.
- Advertising and Targeting Cookies - used to deliver relevant advertising, measure campaign effectiveness, and track interactions across websites and services where permitted by law.
- Where required by applicable law, including in the United Kingdom and European Economic Area or any other applicable jurisdiction, we obtain your consent before placing non-essential Cookies on your device.
- You may withdraw or modify your consent preferences at any time through our cookie settings tool or browser settings.
- Strictly Necessary Cookies do not require consent where permitted by law.
- We may use third-party analytics, advertising, hosting, security, and support providers that deploy Cookies and similar technologies. These third parties may collect information about your interaction with our Services and other websites or online services over time.
- Where required by applicable law, we implement appropriate contractual and data protection safeguards with such providers.
- Depending on your location, you may have rights relating to Cookies and personal data processing under applicable laws, including:
- the UK GDPR and Data Protection Act 2018;
- the EU GDPR and national implementing laws, including Spanish data protection requirements;
- applicable US state privacy laws;
- Canada’s PIPEDA and provincial privacy laws; and
- the Australian Privacy Act 1988.
- Most browsers allow you to control or disable Cookies through browser settings. Please note that disabling certain Cookies may affect the functionality or availability of parts of the Services.
- You can also manage your preferences through our cookie consent banner or settings interface where available.
- We may update this Cookie section from time to time to reflect legal, technical, or operational changes. Material changes will be communicated where required by applicable law.
16. Contact Us
For privacy-related questions or requests, please contact us via email:
info@kayana.co.uk
If you're located in the EU or UK, you also have the right to lodge a complaint with your local data protection authority (DPA), as applicable.
17. Biometric Information and Facial Recognition Notice
Where our employee application includes facial recognition, facial authentication, or biometric verification functionality, we may collect, generate, store, use, and process biometric information and facial images for identity verification, attendance management, access control, security, fraud prevention, and related workforce administration purposes.
The information collected may include facial photographs, facial images captured through a device camera, facial geometry, biometric identifiers, biometric templates, liveness detection information, authentication records, timestamps, and verification results.
Facial images may be used to create biometric templates that enable identity verification and authentication. We use biometric information and facial images solely for the purposes described in this Privacy Policy and do not sell, rent, trade, monetise, or use such information for advertising, marketing, behavioural profiling, or unrelated commercial purposes.
Biometric information and facial images may be disclosed only to:
- Authorised service providers acting on our behalf for identity verification, authentication, hosting, storage, and security services;
- The employer or organisation administering the employee application; and
- Regulatory authorities, courts, law enforcement agencies, or other parties where required by applicable law.
Biometric information, biometric templates, facial photographs, facial images, authentication records, and related verification data are retained for a maximum period of ninety (90) days from collection or creation unless a longer retention period is required by law or necessary for the establishment, exercise, or defence of legal claims.
Upon expiry of the applicable retention period, such information will be securely deleted, anonymised, or irreversibly destroyed in accordance with our retention and security procedures.
We maintain appropriate technical and organisational safeguards, including encryption, access controls, secure storage, audit logging, and secure deletion procedures, to protect biometric information and facial images from unauthorised access, use, disclosure, alteration, or loss.
Individuals may exercise applicable privacy rights by contacting us at info@kayanaforbusiness.com
18. App Tracking Transparency
The Kayana Employee Application does not track users across third-party apps or websites for advertising or marketing purposes. All data collected within the app is used solely for the operational purposes described in this Privacy Policy and is not shared with advertising networks, data brokers, or third-party analytics services for cross-app tracking purposes.
If this position changes in any future version of the application, we will:
- Present an ATT permission prompt to users prior to any tracking commencing
- Clearly explain the purpose of tracking in the NSUserTrackingUsageDescription string shown to users
- Respect the user's choice to decline tracking, without impacting core app functionality
- Update this Privacy Policy accordingly
19. In-App consent for Biometric Data Collection
Consent Mechanism
Prior to activating any facial recognition or biometric verification feature for the first time, the application presents a clear in-app consent prompt to the user. This prompt:
- Identifies the specific biometric data to be collected (facial images, biometric templates)
- Explains the purpose of collection (identity verification, attendance, access control)
- Identifies who will have access to the data (Kayana, the employer, and authorised service providers)
- Requires the user to affirmatively confirm consent before collection begins
Camera Permission
The application requests access to the device camera solely for the purpose of capturing facial images for biometric verification and attendance recording. The iOS permission prompt shown to users reads as follows:
Kayana Employee App requires camera access to capture your facial image for identity verification and attendance recording. Images are used solely for workforce management purposes and are not used for advertising or marketing.
Withdrawing Consent
Users may withdraw their consent to biometric data collection at any time by:
- Contacting their employer's HR department or system administrator
- Submitting a data deletion request to info@kayana.co.uk
- Revoking camera permissions through iOS device Settings at any time
Withdrawal of consent will not affect the lawfulness of any processing carried out prior to withdrawal. Where biometric features are mandated by the employer as a condition of employment, the employee should refer to their employer's HR policies.
20. Data Minimisation
In accordance with Apple App Store Guideline 5.1.1(i) and applicable data protection law, the Kayana Employee Application collects only the minimum personal data necessary to deliver the specific functionality for which each data type is required.
We do not collect personal data speculatively, in anticipation of future features, or for purposes beyond those described in this Privacy Policy. We regularly review the data we collect and delete or anonymise data that is no longer necessary for its original purpose.
Specific data minimisation commitments include:
- Biometric images and templates are used solely for identity verification and are not stored beyond the 90-day maximum retention period
- Crash and diagnostic data is anonymised or pseudonymised wherever technically feasible
- Location data is collected only in the foreground and only where enabled by the employer administrator
- Analytics data is aggregated and not used to build individual user profiles
21. Employer and employee data responsibilities
The Kayana Employee Application is designed for deployment by employers ("Employer Administrators") to their workforce. The data protection responsibilities under this model are as follows:
| Role | Party | Responsibilities |
|---|---|---|
| Data Controller (Employment Data) | The Employer / Employer Administrator | Determines the purposes and means of processing employee personal data via the app; responsible for obtaining employment-context consent and maintaining employee-facing privacy notices |
| Data Processor (App Infrastructure) | Kayana World Limited | Processes employee data on behalf of and under the instruction of the Employer; maintains this Privacy Policy; ensures platform security and compliance |
| Sub-Processor | AWS, Firebase, Sentry | Process data on Kayana's behalf under data processing agreements; no independent data use rights |
Employees using this application should refer to their employer's own workplace privacy notice for information about how their employment data is used in the context of their employment relationship. This Privacy Policy governs Kayana's own data processing obligations as a technology platform provider.
Where an employee wishes to exercise data rights relating to employment records (e.g., attendance records, HR data), they should contact their employer directly. Where rights relate to Kayana's platform-level data processing, contact us at info@kayanaforbusiness.com.
22. Account deletion
In accordance with Apple App Store Guideline 5.1.1(v), users of the Kayana Employee Application who have an account may request deletion of their account and associated personal data.
How to Request Account Deletion
Account deletion can be requested by:
- Submitting a written deletion request to info@kayana.co.uk from the email address associated with your account
- Contacting your employer's system administrator, who can initiate deletion via the employer administration portal
What Is Deleted
Upon a valid account deletion request, we will delete or anonymise the following data within 30 days of the verified request:
- Account credentials and profile information
- Biometric templates and facial recognition data (subject to the 90-day retention policy, after which deletion is automatic)
- Authentication records and attendance logs linked to your identity
- Analytics identifiers associated with your account
Data That May Be Retained
The following data may be retained after account deletion where there is a legal, regulatory, or contractual basis to do so:
- Transaction and financial records required for tax or audit compliance
- Data subject to a legal hold or active legal proceeding
- Aggregated or anonymised data that cannot reasonably be linked back to you
- Data that the employer is independently required to retain under employment law
Where data is retained post-deletion, it will be held securely and used only for the purpose for which retention is justified. You will be informed of any such retention and the basis for it in response to your deletion request.



