How Keykem handles personal data on keykem.com, in the client space and in the partner space. It covers what we collect and why, who sees it, how long we keep it, and your rights. We collect as little as we can, store it in the EU and never sell it.
1. Who we are, and what this notice covers
The controller of your personal data is [company name, S.r.l.], trading as Keykem, [registered office], VAT number [VAT number].
For anything about your personal data, write to [privacy email address] or send a letter to our registered office. [data protection officer: name and contact, if one is appointed]
This notice covers:
- keykem.com;
- the client space and the partner space;
- the calls, emails and messages we exchange with you.
It does not cover the websites we build and run for our clients. Each of those sites has its own notice (see section 11).
Keykem works with businesses. This notice is about the people we deal with there: owners, managers and staff, our partners, and people who contact us or are introduced to us. Our services are not meant for children.
We apply the EU General Data Protection Regulation (GDPR) and the Italian Personal Data Protection Code. For people in Morocco, we also apply Law 09-08 (see section 8).
2. What we collect, why, and on what legal basis
| When | What we collect | Why | Legal basis |
|---|---|---|---|
| You send a request through Start today | Your business's name, trade, city and country, whether it is open yet, what you already have, the plan you lean towards, the languages and launch timing you want; your name, your role, email, phone or WhatsApp number, and how you prefer to be contacted | To call you back, understand your project and prepare a quote | Steps you asked for before a contract (GDPR Art. 6(1)(b)). If you act for a company: our legitimate interest in answering its request (Art. 6(1)(f)) |
| We talk by phone, email or WhatsApp | What you tell us, the date, your contact details | To answer you and keep track of what we agreed | As above, then the contract |
| You accept a quote | The business's legal name, address and VAT or registration number; the name and role of the person who accepts; the version of the documents accepted, the time, IP address and browser | To make the contract, and to prove it | Contract (Art. 6(1)(b)); our legitimate interest in proving the agreement (Art. 6(1)(f)) |
| You use the client space | Name, email, role, business, sign-in events and devices signed in; later, the public key of your passkey | To give you and your team secure access | Contract |
| We make and run your project | Briefs, texts, logos, photos and other files, approvals, comments and change requests | To make, publish and run what you ordered | Contract |
| You pay and we invoice | Billing contact, legal entity, billing address, VAT number, amounts, invoice numbers and payment status. Stripe handles card and bank details; we never see your full card number | To take payment, issue invoices and keep our accounts | Contract; our legal duties under Italian tax and accounting law (Art. 6(1)(c)) |
| You join the partner program | Name, email, phone, country; your tax profile (individual or business, tax residence, tax number, VAT number, address); bank details; your rate card, introductions, commissions and payouts. Clicks on your link, as totals only | To run the program, credit and pay you, and meet our tax duties | Contract; legal duties (Art. 6(1)(c)) |
| A partner introduces you to us | Your business's name, your name and role, a phone number or email, the partner who introduced you, the date, and the partner's confirmation that you agreed to hear from us | To contact you about Keykem, and to credit the partner | Our legitimate interest (Art. 6(1)(f)). We tell you at first contact, and stop if you object |
| We send you service emails | Your email and what the message is about | Sign-in codes, quotes, invoices, project updates, security notices | Contract; our legitimate interest in keeping accounts secure |
| You ask for our news | Your email, the date, and the wording you agreed to | At most one email a month about our work | Your consent (Art. 6(1)(a)). You can withdraw it at any time |
| You visit keykem.com | The page, the site you came from, your country and type of device, stored only as daily totals. No cookie, and your IP address is not stored | To know which pages are useful | Our legitimate interest. The totals we keep do not identify anyone |
| You accept the partner referral cookie | The partner's code and the date | To credit the partner who recommended us | Your consent (see the cookie notice) |
| You sign in or use your space | IP address, browser, time, action and result, for sign-ins, failed attempts and staff access to client files | To protect accounts, detect abuse and investigate incidents | Our legitimate interest in security (Art. 6(1)(f)) |
| You use a right, or there is a dispute | Your request, our reply and supporting documents | To answer you, and to establish or defend legal claims | Legal duty; our legitimate interest |
What you must give us
Our forms mark each field as required or optional. Without the required fields we cannot answer your request, make a contract with you or pay you. You can skip optional fields.
What we never ask for
- Passwords of any kind, including those for your Google profile, domain or social accounts. We use invitations instead.
- ID card or passport numbers.
- Health information. See section 11 for doctors' sites.
- Your card number. You type it only into Stripe's secure payment page.
No automated decisions
We make no decisions about you by automated means alone, and we build no profiles for advertising.
3. Where your data comes from
- From you.
- From a colleague who invites you to your business's client space.
- From a partner who introduces you to us.
- From Stripe, which tells us whether a payment went through.
- From public registers, such as the EU VAT register (VIES), when we check a VAT number.
4. Who receives your data
Our team
Only the Keykem staff who need it for their work. Every member of staff has a named account and has signed a confidentiality undertaking. Staff cannot open a client's files by default. Access is granted for a limited time, with a written reason. It is recorded, and the client's owner is told.
Our service providers
These providers process data only on our instructions, under a written data processing agreement.
| Service | Provider | Where the data is |
|---|---|---|
| Hosting for keykem.com, the client and partner spaces, and client sites | [application host] | [country and region] |
| Database, sign-in and file storage | [database provider] | [country and region] |
| Backups | [backup provider] | [country] |
| Service emails | [email provider] | [country — must be EU storage] |
| Payments | Stripe, [Stripe contracting entity] | [country] |
| Protecting forms against bots | [bot-check provider] | [country] |
| Error tracking and uptime checks | [monitoring provider] | [country] |
| Fonts on our pages (receives your IP address when your browser loads a font) | [web font provider] | [country] |
| Email, calendar and documents for our team | [workspace provider] | [country] |
| Partner payouts | [partner payout bank or provider] | [country] |
Stripe also uses some data for its own purposes, such as preventing fraud and meeting its legal duties. For that, it is responsible under its own privacy notice.
The full list of our providers, with their legal names and addresses, is at [sub-processor list address]. We update it before any change.
Others, who decide for themselves
- Our accountant [accounting firm], our bank [bank name] and our lawyers, who are bound by professional secrecy.
- Tax and other public authorities, when the law requires it.
- WhatsApp (Meta), if you choose to write to us there. Meta handles those messages under its own terms.
- Google, when we manage your Google Business Profile at your request, under Google's terms.
- A buyer of our business, if that ever happens. The same protections would apply.
Partners
A partner who introduced your business sees only its name, where it stands (introduced, talking, started, live or closed) and the partner's own commission. A partner never sees your contact details, our notes or our conversations.
We never sell personal data or share it for advertising.
5. Transfers outside the EU
We store personal data in the European Union, in [data storage region and country]. Some of it can leave the EU in two cases.
- Part of our team works from Morocco. When a staff member there opens data stored in the EU, even only on screen, the law treats it as a transfer. Morocco has no EU adequacy decision. We protect these transfers with [transfer safeguard: standard contractual clauses or another mechanism — to confirm by counsel]. We add practical measures: named accounts, access limited to what each task needs, no downloads or local copies, encrypted laptops and a log of every access.
- Some providers belong to groups based outside the EU, for example in the United States, and may reach data for support or security. We use them only with the European Commission's standard contractual clauses or an adequacy decision, such as the EU–US Data Privacy Framework for certified companies. The safeguard for each provider is in the list at [sub-processor list address].
You can ask for a copy of these safeguards at [privacy email address].
If you are in Morocco, your data is stored in the EU, which Moroccan law treats as a transfer abroad. We have filed this transfer with the CNDP (see section 8).
6. How long we keep your data
| Data | How long |
|---|---|
| Start today requests that do not lead to a project | 12 months after our last contact |
| People introduced by a partner who do not become clients | 12 months after the introduction closes. If you object, we delete your details at once and keep only a short note so that we don't contact you again |
| Client account and client-space content | While you are a client. After you leave, 30 days to export your content and 30 more to download it. Then we delete it |
| Contracts, accepted quotes and proof of acceptance | The life of the contract, plus 10 years (the Italian limitation period) |
| Invoices, payment records, accounting records, and letters and emails about them | 10 years (Italian Civil Code, Art. 2220) |
| Partner account | While you are a partner. After you leave, until your last commission period ends and is paid |
| Commissions, payouts and partner tax documents | 10 years |
| Security and sign-in logs, and the log of staff access | 12 months |
| News emails | Until you unsubscribe. We then keep your address on a do-not-email list, so we never write to you again |
| Your cookie choice | 6 months |
| Partner referral cookie | 90 days |
| ID documents sent with a rights request | Only until we have checked who you are |
| Records of rights requests and our replies | [period — to confirm] |
| Backups | Deleted data leaves our backups within [backup retention period] |
When a period ends, we delete the data or make it anonymous for good.
7. Your rights
You can:
- see the data we hold about you, and get a copy;
- have it corrected;
- have it deleted;
- have its use limited while a question is settled;
- receive the data you gave us in a common format, or have it sent to another company;
- object to uses based on our legitimate interest. You can object to marketing at any time, without giving a reason, and we stop at once;
- withdraw your consent at any time. This does not affect what we did before;
- complain to a supervisory authority (section 8).
How to use them
Write to [privacy email address], or use Your details in your client or partner space. It is free.
We may ask you to confirm who you are, using as little information as possible. If we ask for an ID document, we delete it once we have checked it.
We answer within one month. If a request is complex, we may take up to two more months; if so, we tell you why within the first month. If you are in Morocco, we correct or delete your data within 10 days, as Law 09-08 requires.
The law requires us to keep some data even if you ask us to delete it. Invoices are one example: Italian law requires us to keep them for 10 years. When that happens, we tell you what we keep and why, and use it for nothing else.
To stop our news, click the unsubscribe link in any of our emails. One click is enough.
9. Signing in without passwords
We do not use passwords.
- Today, you sign in with a six-digit code that we email to you. It works once, for 10 minutes.
- Soon, you will be able to add a passkey, which you unlock with your fingerprint, your face or your device's PIN.
Your fingerprint and your face never leave your device, and we never receive them. We receive only a public key, and your device's signed confirmation that it checked it was you. So we process no biometric data.
We store each passkey's public key and a device name, such as "iPhone", so that you can see your passkeys and remove them.
10. How we protect your data
- Your data is stored in the EU and encrypted, both in transit and at rest.
- Each client's data is walled off from every other client's. Automated tests check these walls every time we change our software.
- There are no passwords to steal. Our staff use named accounts and a second sign-in factor. [hardware security keys for staff — to confirm]
- Staff cannot open a client's files by default (section 4).
- We record sign-ins, refused access and staff access in a log that cannot be edited.
- We check uploaded files for malware, and remove hidden location data from photos.
- We back up every day, and keep a separate copy in the EU.
- We never write the contents of forms into our logs.
If a breach puts your data at risk, we tell the supervisory authority within 72 hours where the law requires it. If the risk to you is high, we tell you without undue delay. For our clients' sites, we tell the client within 24 hours of learning of it.
No system connected to the internet is completely secure. Data sent over an open network can be intercepted by others. We use encryption to reduce that risk.
11. Sites we run for our clients
We build and host websites for hotels, restaurants, clinics, salons and venues. When you visit one of those sites, send an enquiry or make a booking, the business that owns the site decides how your data is used. That business is the controller.
We are its processor. We host the site and handle the data only on the business's instructions, under a processor agreement. It follows Article 28 of the GDPR and, in Morocco, Article 23 of Law 09-08.
- Each business has its own privacy notice on its site. Please send your questions and requests to that business.
- If you write to us about a client's site, we pass your request to the business within 48 hours and help it answer.
- We never use data from client sites for our own purposes. We never combine it across clients, and never sell it.
- We do not send the content of enquiries by email. The business gets a notice, and reads the message in its secure space.
- On a doctor's site, an appointment request reveals something about health. Online booking is switched on only once the practice holds the authorisations the law requires. Forms on doctors' sites ask for no medical details.
12. Changes to this notice
We update this notice when our services or the law change. This is version [version number], dated [date].
If a change affects you significantly, we tell you before it applies, by email or in your space. Earlier versions are available on request.
This is a working draft to be reviewed by an Italian lawyer and a Moroccan lawyer before launch.

