Konnetta

Legal

Data Privacy Section

Effective Date: October 8, 2025

Introduction

Konnetta ("we," "us," or "our") operates the web application accessible at https://konnetta.com (the "Platform"), which serves as a global marketplace connecting clients ("Clients") with vetted vendor ("Vendors") for in-person professional engagements, including but not limited to photography, videography, content creation, tour guiding, and drone services. This Data Privacy Section ("Section") supplements our Privacy Policy by providing detailed disclosures on the processing, protection, and deletion of personal data in accordance with applicable data protection regulations, such as the General Data Protection Regulation (GDPR), the California Consumer Privacy Act (CCPA as amended by the California Privacy Rights Act, CPRA), and equivalent frameworks worldwide.

This Section outlines our data minimization principles, lawful bases for processing, user rights, and mechanisms for data deletion to ensure transparency and compliance, particularly for Platform features involving user sign-ups, job postings, secure bookings via escrow, in-app messaging, ratings, and real-time service matching. By accessing or using the Platform, you acknowledge and consent to the data practices described herein, subject to your rights under applicable law. This Section is incorporated into our Terms of Service ("Terms"), and any inconsistencies shall be resolved in favor of the Terms to the extent permissible.

We prioritize data privacy through pseudonymization, encryption, and accountability measures. For inquiries, including data subject access requests or deletion demands, contact us at privacy@konnetta.com.

Article 1: Principles of Data Processing

We adhere to core data protection principles to ensure ethical and lawful handling of personal data.

1.1 Lawful, Fair, and Transparent Processing

All processing activities are grounded in legitimate bases, including user consent, contractual necessity (e.g., fulfilling bookings), legitimate interests (e.g., fraud prevention), and legal obligations (e.g., record-keeping for tax purposes). Processing is conducted fairly, without deception, and with clear communication of risks.

1.2 Purpose Limitation and Data Minimization

Personal data is collected solely for specified, explicit, and legitimate purposes, such as enabling service discovery, secure transactions (via third-party processors like Stripe and PayPal, without our storage of payment details), and Platform enhancements. We limit collection to what is strictly necessary, avoiding excessive or irrelevant data.

1.3 Accuracy and Storage Limitation

We maintain data accuracy through user-verifiable profiles and periodic audits. Storage durations are predefined and justified (see Article 4), with proactive deletion or anonymization upon purpose fulfillment.

Article 2: Categories of Personal Data Processed

Our processing is scoped to essential data types, excluding sensitive categories unless consented to for specific features.

2.1 Identifiable Personal Data

  • Controller Data: Names, email addresses, phone numbers, and demographic details (e.g., travel destinations) provided during registration or profile setup.
  • Behavioral Data: Usage logs, including search queries for services, booking histories, and interaction timestamps from in-app chats or ratings.

2.2 Technical and Derived Data

  • Device and Network Data: IP addresses, browser fingerprints, and approximate geolocation (for service matching, with opt-in consent where mandated by law).
  • Third-Party Derived Data: Vetting confirmations from integrated services (e.g., identity verification) and transaction metadata from payment gateways, sans financial credentials.

No biometric, health, or political data is processed without explicit, granular consent.

Article 3: Purposes and Lawful Bases for Processing

Processing is purpose-bound and justified under legal frameworks.

3.1 Core Operational Purposes

  • Service Delivery: Matching Clients with Vendors, processing escrow payments, and facilitating in-person meetups (lawful basis: contract performance).
  • Platform Integrity: Fraud detection, dispute resolution, and 24/7 support interactions (lawful basis: legitimate interests).

3.2 Enhancement and Analytics Purposes

  • Aggregated insights for feature improvements, such as refining real-time recommendations (lawful basis: legitimate interests, with pseudonymization).
  • Marketing communications, including service updates (lawful basis: consent, revocable at any time).

3.3 Compliance Purposes

  • Responding to regulatory inquiries or enforcing Terms (lawful basis: legal obligation).

Automated decision-making is limited to non-profiling activities (e.g., basic eligibility checks) and subject to human oversight.

Article 4: Data Retention and Deletion Mechanisms

Retention is time-limited, and deletion is user-empowered to align with "data deletion information" requirements for Platform live-mode activation (e.g., Meta App Dashboard).

4.1 Retention Schedules

  • Active User Data: Retained for the duration of account activity plus 12 months post-last interaction to support potential disputes.
  • Transactional Data: 7 years from completion, per statutory audit requirements.
  • Log Data: 90 days for security purposes, then anonymized.

4.2 Deletion Procedures

Users may exercise their right to erasure at any juncture. To request deletion:

  • Log in to your account dashboard and select "Delete Account" for self-service removal of non-mandatory data.
  • Alternatively, email privacy@konnetta.com with your full name, email, and a description of data to be deleted (e.g., "all profile and booking history").

We acknowledge receipt within 48 hours and process the request within 30 days (or 90 days for complex cases under CCPA/CPRA), confirming completion via email.

Exceptions apply for data required by law (e.g., tax records), which we segregate and delete upon expiry.

Upon deletion, data is irretrievably purged from primary systems and backups (overwritten per secure protocols like NIST SP 800-88). For GDPR subjects, this fulfills the "right to be forgotten"; for CCPA subjects, it enables "deletion requests" without waiver of service access.

Inactive accounts are automatically flagged for deletion after 24 months, with prior notification.

Article 5: Data Subject Rights and Remedies

We empower users with comprehensive rights, verifiable through identity authentication.

5.1 Core Rights

  • Access and Portability: Obtain a structured, machine-readable copy of your data (e.g., JSON export) free of charge, twice annually.
  • Rectification and Restriction: Update inaccuracies or restrict processing during disputes.
  • Objection and Withdrawal: Object to processing based on legitimate interests; withdraw consent without detriment.

5.2 Enforcement and Appeals

Requests are processed within one month (extendable to three under heavy load). If unsatisfied, appeal to our Data Protection Officer or supervisory authorities (e.g., CNIL in France, ICO in the UK). No fees apply unless requests are excessive.

5.3 Special Category Rights

CCPA/CPRA users may opt out of data sales (none occur) or limit sensitive data use. Global users benefit from equivalent local rights.

Article 6: Cross-Border Data Transfers and Safeguards

Data may traverse jurisdictions for global operations.

6.1 Transfer Mechanisms

  • To affiliates or processors in the EEA, UK, or adequacy-recognized countries (e.g., via EU-US Data Privacy Framework).
  • Otherwise, via Standard Contractual Clauses (SCCs) or Binding Corporate Rules, supplemented by Transfer Impact Assessments (TIAs).

6.2 User Protections

You may challenge transfers via rights exercises. We monitor adequacy and suspend non-compliant flows.

Article 7: Accountability and Governance

We maintain robust governance to uphold this Section.

7.1 Records and Audits

Processing records are kept per Art. 30 GDPR, with annual third-party audits.

7.2 Breach Notification

In the event of a personal data breach posing high risk, we notify affected users and authorities within 72 hours (GDPR) or as required (e.g., 45 days under some U.S. laws).

7.3 Updates

This Section may be amended for regulatory evolution; material changes notified 30 days in advance via Platform notice or email.

Article 8: Contact and Governing Provisions

For all data privacy matters:

Konnetta

5900 Balcones Drive Suite 100, Austin, TX 78731, United States

Email: privacy@konnetta.com

Data Protection Officer: [Appoint if required, e.g., dpo@konnetta.com]

Governing Law: This Section is governed by the laws of the State of Texas, United States, with venue in Travis County, Texas, subject to mandatory local protections.

Last revised: October 8, 2025.

FAQs

Frequently Asked
Questions

Find, book, and pay for high-quality content creators, tour guides, and more, securely and easily. Experience authentic local connections anytime, anywhere.

Konnetta is a travel-focused platform designed to connect clients with trusted local service providers in their destination. Starting with content creators like photographers, videographers, and drone pilots, Konnetta makes it easy to find, book, and pay for high-quality local services.

Creating an account is free. You only pay when you book a service provider.

In such rare cases, Konnetta offers a full refund and helps you rebook with another verified provider.

All providers go through an identity verification process before being approved to join the platform.