Skip to content

Privacy notice.

Working draft, to be reviewed by counsel before launch. Last updated 29 September 2026.

How Keykem handles personal data on keykem.com, in the client space and in the partner space. It covers what we collect and why, who sees it, how long we keep it, and your rights. We collect as little as we can, store it in the EU and never sell it.

1. Who we are, and what this notice covers

The controller of your personal data is [company name, S.r.l.], trading as Keykem, [registered office], VAT number [VAT number].

For anything about your personal data, write to [privacy email address] or send a letter to our registered office. [data protection officer: name and contact, if one is appointed]

This notice covers:

  • keykem.com;
  • the client space and the partner space;
  • the calls, emails and messages we exchange with you.

It does not cover the websites we build and run for our clients. Each of those sites has its own notice (see section 11).

Keykem works with businesses. This notice is about the people we deal with there: owners, managers and staff, our partners, and people who contact us or are introduced to us. Our services are not meant for children.

We apply the EU General Data Protection Regulation (GDPR) and the Italian Personal Data Protection Code. For people in Morocco, we also apply Law 09-08 (see section 8).

2. What we collect, why, and on what legal basis

WhenWhat we collectWhyLegal basis
You send a request through Start today Your business's name, trade, city and country, whether it is open yet, what you already have, the plan you lean towards, the languages and launch timing you want; your name, your role, email, phone or WhatsApp number, and how you prefer to be contacted To call you back, understand your project and prepare a quote Steps you asked for before a contract (GDPR Art. 6(1)(b)). If you act for a company: our legitimate interest in answering its request (Art. 6(1)(f))
We talk by phone, email or WhatsApp What you tell us, the date, your contact details To answer you and keep track of what we agreed As above, then the contract
You accept a quote The business's legal name, address and VAT or registration number; the name and role of the person who accepts; the version of the documents accepted, the time, IP address and browser To make the contract, and to prove it Contract (Art. 6(1)(b)); our legitimate interest in proving the agreement (Art. 6(1)(f))
You use the client space Name, email, role, business, sign-in events and devices signed in; later, the public key of your passkey To give you and your team secure access Contract
We make and run your project Briefs, texts, logos, photos and other files, approvals, comments and change requests To make, publish and run what you ordered Contract
You pay and we invoice Billing contact, legal entity, billing address, VAT number, amounts, invoice numbers and payment status. Stripe handles card and bank details; we never see your full card number To take payment, issue invoices and keep our accounts Contract; our legal duties under Italian tax and accounting law (Art. 6(1)(c))
You join the partner program Name, email, phone, country; your tax profile (individual or business, tax residence, tax number, VAT number, address); bank details; your rate card, introductions, commissions and payouts. Clicks on your link, as totals only To run the program, credit and pay you, and meet our tax duties Contract; legal duties (Art. 6(1)(c))
A partner introduces you to us Your business's name, your name and role, a phone number or email, the partner who introduced you, the date, and the partner's confirmation that you agreed to hear from us To contact you about Keykem, and to credit the partner Our legitimate interest (Art. 6(1)(f)). We tell you at first contact, and stop if you object
We send you service emails Your email and what the message is about Sign-in codes, quotes, invoices, project updates, security notices Contract; our legitimate interest in keeping accounts secure
You ask for our news Your email, the date, and the wording you agreed to At most one email a month about our work Your consent (Art. 6(1)(a)). You can withdraw it at any time
You visit keykem.com The page, the site you came from, your country and type of device, stored only as daily totals. No cookie, and your IP address is not stored To know which pages are useful Our legitimate interest. The totals we keep do not identify anyone
You accept the partner referral cookie The partner's code and the date To credit the partner who recommended us Your consent (see the cookie notice)
You sign in or use your space IP address, browser, time, action and result, for sign-ins, failed attempts and staff access to client files To protect accounts, detect abuse and investigate incidents Our legitimate interest in security (Art. 6(1)(f))
You use a right, or there is a dispute Your request, our reply and supporting documents To answer you, and to establish or defend legal claims Legal duty; our legitimate interest

What you must give us

Our forms mark each field as required or optional. Without the required fields we cannot answer your request, make a contract with you or pay you. You can skip optional fields.

What we never ask for

  • Passwords of any kind, including those for your Google profile, domain or social accounts. We use invitations instead.
  • ID card or passport numbers.
  • Health information. See section 11 for doctors' sites.
  • Your card number. You type it only into Stripe's secure payment page.

No automated decisions

We make no decisions about you by automated means alone, and we build no profiles for advertising.

3. Where your data comes from

  • From you.
  • From a colleague who invites you to your business's client space.
  • From a partner who introduces you to us.
  • From Stripe, which tells us whether a payment went through.
  • From public registers, such as the EU VAT register (VIES), when we check a VAT number.

4. Who receives your data

Our team

Only the Keykem staff who need it for their work. Every member of staff has a named account and has signed a confidentiality undertaking. Staff cannot open a client's files by default. Access is granted for a limited time, with a written reason. It is recorded, and the client's owner is told.

Our service providers

These providers process data only on our instructions, under a written data processing agreement.

ServiceProviderWhere the data is
Hosting for keykem.com, the client and partner spaces, and client sites[application host][country and region]
Database, sign-in and file storage[database provider][country and region]
Backups[backup provider][country]
Service emails[email provider][country — must be EU storage]
PaymentsStripe, [Stripe contracting entity][country]
Protecting forms against bots[bot-check provider][country]
Error tracking and uptime checks[monitoring provider][country]
Fonts on our pages (receives your IP address when your browser loads a font)[web font provider][country]
Email, calendar and documents for our team[workspace provider][country]
Partner payouts[partner payout bank or provider][country]

Stripe also uses some data for its own purposes, such as preventing fraud and meeting its legal duties. For that, it is responsible under its own privacy notice.

The full list of our providers, with their legal names and addresses, is at [sub-processor list address]. We update it before any change.

Others, who decide for themselves

  • Our accountant [accounting firm], our bank [bank name] and our lawyers, who are bound by professional secrecy.
  • Tax and other public authorities, when the law requires it.
  • WhatsApp (Meta), if you choose to write to us there. Meta handles those messages under its own terms.
  • Google, when we manage your Google Business Profile at your request, under Google's terms.
  • A buyer of our business, if that ever happens. The same protections would apply.

Partners

A partner who introduced your business sees only its name, where it stands (introduced, talking, started, live or closed) and the partner's own commission. A partner never sees your contact details, our notes or our conversations.

We never sell personal data or share it for advertising.

5. Transfers outside the EU

We store personal data in the European Union, in [data storage region and country]. Some of it can leave the EU in two cases.

  • Part of our team works from Morocco. When a staff member there opens data stored in the EU, even only on screen, the law treats it as a transfer. Morocco has no EU adequacy decision. We protect these transfers with [transfer safeguard: standard contractual clauses or another mechanism — to confirm by counsel]. We add practical measures: named accounts, access limited to what each task needs, no downloads or local copies, encrypted laptops and a log of every access.
  • Some providers belong to groups based outside the EU, for example in the United States, and may reach data for support or security. We use them only with the European Commission's standard contractual clauses or an adequacy decision, such as the EU–US Data Privacy Framework for certified companies. The safeguard for each provider is in the list at [sub-processor list address].

You can ask for a copy of these safeguards at [privacy email address].

If you are in Morocco, your data is stored in the EU, which Moroccan law treats as a transfer abroad. We have filed this transfer with the CNDP (see section 8).

6. How long we keep your data

DataHow long
Start today requests that do not lead to a project12 months after our last contact
People introduced by a partner who do not become clients12 months after the introduction closes. If you object, we delete your details at once and keep only a short note so that we don't contact you again
Client account and client-space contentWhile you are a client. After you leave, 30 days to export your content and 30 more to download it. Then we delete it
Contracts, accepted quotes and proof of acceptanceThe life of the contract, plus 10 years (the Italian limitation period)
Invoices, payment records, accounting records, and letters and emails about them10 years (Italian Civil Code, Art. 2220)
Partner accountWhile you are a partner. After you leave, until your last commission period ends and is paid
Commissions, payouts and partner tax documents10 years
Security and sign-in logs, and the log of staff access12 months
News emailsUntil you unsubscribe. We then keep your address on a do-not-email list, so we never write to you again
Your cookie choice6 months
Partner referral cookie90 days
ID documents sent with a rights requestOnly until we have checked who you are
Records of rights requests and our replies[period — to confirm]
BackupsDeleted data leaves our backups within [backup retention period]

When a period ends, we delete the data or make it anonymous for good.

7. Your rights

You can:

  • see the data we hold about you, and get a copy;
  • have it corrected;
  • have it deleted;
  • have its use limited while a question is settled;
  • receive the data you gave us in a common format, or have it sent to another company;
  • object to uses based on our legitimate interest. You can object to marketing at any time, without giving a reason, and we stop at once;
  • withdraw your consent at any time. This does not affect what we did before;
  • complain to a supervisory authority (section 8).

How to use them

Write to [privacy email address], or use Your details in your client or partner space. It is free.

We may ask you to confirm who you are, using as little information as possible. If we ask for an ID document, we delete it once we have checked it.

We answer within one month. If a request is complex, we may take up to two more months; if so, we tell you why within the first month. If you are in Morocco, we correct or delete your data within 10 days, as Law 09-08 requires.

The law requires us to keep some data even if you ask us to delete it. Invoices are one example: Italian law requires us to keep them for 10 years. When that happens, we tell you what we keep and why, and use it for nothing else.

To stop our news, click the unsubscribe link in any of our emails. One click is enough.

8. Supervisory authorities: the Garante and the CNDP

If you are unhappy with how we handle your data, tell us first and we will try to put it right. You can also complain to a supervisory authority at any time:

  • in Italy, where we are established: the Garante per la protezione dei dati personali, garanteprivacy.it;
  • in the EU country where you live or work, or where you believe the problem happened;
  • in Morocco: the Commission nationale de contrôle de la protection des données à caractère personnel (CNDP), cndp.ma.

People in Morocco: Law 09-08 and our CNDP filings

We apply Law 09-08 to the personal data of people in Morocco. [scope — to confirm by Moroccan counsel]

  • Declaration of our processing: CNDP receipt number [CNDP receipt number].
  • Transfer of data to the European Union: [CNDP transfer authorisation reference].
  • Partner referral cookie: [CNDP cookie declaration receipt number].

Under Law 09-08, you have the right to be informed, to access your data, to have it corrected, to object to its use for legitimate reasons, and to object to marketing at any time.

9. Signing in without passwords

We do not use passwords.

  • Today, you sign in with a six-digit code that we email to you. It works once, for 10 minutes.
  • Soon, you will be able to add a passkey, which you unlock with your fingerprint, your face or your device's PIN.

Your fingerprint and your face never leave your device, and we never receive them. We receive only a public key, and your device's signed confirmation that it checked it was you. So we process no biometric data.

We store each passkey's public key and a device name, such as "iPhone", so that you can see your passkeys and remove them.

10. How we protect your data

  • Your data is stored in the EU and encrypted, both in transit and at rest.
  • Each client's data is walled off from every other client's. Automated tests check these walls every time we change our software.
  • There are no passwords to steal. Our staff use named accounts and a second sign-in factor. [hardware security keys for staff — to confirm]
  • Staff cannot open a client's files by default (section 4).
  • We record sign-ins, refused access and staff access in a log that cannot be edited.
  • We check uploaded files for malware, and remove hidden location data from photos.
  • We back up every day, and keep a separate copy in the EU.
  • We never write the contents of forms into our logs.

If a breach puts your data at risk, we tell the supervisory authority within 72 hours where the law requires it. If the risk to you is high, we tell you without undue delay. For our clients' sites, we tell the client within 24 hours of learning of it.

No system connected to the internet is completely secure. Data sent over an open network can be intercepted by others. We use encryption to reduce that risk.

11. Sites we run for our clients

We build and host websites for hotels, restaurants, clinics, salons and venues. When you visit one of those sites, send an enquiry or make a booking, the business that owns the site decides how your data is used. That business is the controller.

We are its processor. We host the site and handle the data only on the business's instructions, under a processor agreement. It follows Article 28 of the GDPR and, in Morocco, Article 23 of Law 09-08.

  • Each business has its own privacy notice on its site. Please send your questions and requests to that business.
  • If you write to us about a client's site, we pass your request to the business within 48 hours and help it answer.
  • We never use data from client sites for our own purposes. We never combine it across clients, and never sell it.
  • We do not send the content of enquiries by email. The business gets a notice, and reads the message in its secure space.
  • On a doctor's site, an appointment request reveals something about health. Online booking is switched on only once the practice holds the authorisations the law requires. Forms on doctors' sites ask for no medical details.

12. Changes to this notice

We update this notice when our services or the law change. This is version [version number], dated [date].

If a change affects you significantly, we tell you before it applies, by email or in your space. Earlier versions are available on request.

This is a working draft to be reviewed by an Italian lawyer and a Moroccan lawyer before launch.