Legal
- Data Privacy
Data Privacy Section
Effective Date: October 8, 2025
Introduction
Konnetta ("we," "us," or "our") operates the web application accessible at https://konnetta.com (the "Platform"), which serves as a global marketplace connecting clients ("Clients") with vetted vendor ("Vendors") for in-person professional engagements, including but not limited to photography, videography, content creation, tour guiding, and drone services. This Data Privacy Section ("Section") supplements our Privacy Policy by providing detailed disclosures on the processing, protection, and deletion of personal data in accordance with applicable data protection regulations, such as the General Data Protection Regulation (GDPR), the California Consumer Privacy Act (CCPA as amended by the California Privacy Rights Act, CPRA), and equivalent frameworks worldwide.
This Section outlines our data minimization principles, lawful bases for processing, user rights, and mechanisms for data deletion to ensure transparency and compliance, particularly for Platform features involving user sign-ups, job postings, secure bookings via escrow, in-app messaging, ratings, and real-time service matching. By accessing or using the Platform, you acknowledge and consent to the data practices described herein, subject to your rights under applicable law. This Section is incorporated into our Terms of Service ("Terms"), and any inconsistencies shall be resolved in favor of the Terms to the extent permissible.
We prioritize data privacy through pseudonymization, encryption, and accountability measures. For inquiries, including data subject access requests or deletion demands, contact us at privacy@konnetta.com.
Article 1: Principles of Data Processing
We adhere to core data protection principles to ensure ethical and lawful handling of personal data.
1.1 Lawful, Fair, and Transparent Processing
All processing activities are grounded in legitimate bases, including user consent, contractual necessity (e.g., fulfilling bookings), legitimate interests (e.g., fraud prevention), and legal obligations (e.g., record-keeping for tax purposes). Processing is conducted fairly, without deception, and with clear communication of risks.
1.2 Purpose Limitation and Data Minimization
Personal data is collected solely for specified, explicit, and legitimate purposes, such as enabling service discovery, secure transactions (via third-party processors like Stripe and PayPal, without our storage of payment details), and Platform enhancements. We limit collection to what is strictly necessary, avoiding excessive or irrelevant data.
1.3 Accuracy and Storage Limitation
We maintain data accuracy through user-verifiable profiles and periodic audits. Storage durations are predefined and justified (see Article 4), with proactive deletion or anonymization upon purpose fulfillment.
Article 2: Categories of Personal Data Processed
Our processing is scoped to essential data types, excluding sensitive categories unless consented to for specific features.
2.1 Identifiable Personal Data
- Controller Data: Names, email addresses, phone numbers, and demographic details (e.g., travel destinations) provided during registration or profile setup.
- Behavioral Data: Usage logs, including search queries for services, booking histories, and interaction timestamps from in-app chats or ratings.
2.2 Technical and Derived Data
- Device and Network Data: IP addresses, browser fingerprints, and approximate geolocation (for service matching, with opt-in consent where mandated by law).
- Third-Party Derived Data: Vetting confirmations from integrated services (e.g., identity verification) and transaction metadata from payment gateways, sans financial credentials.
No biometric, health, or political data is processed without explicit, granular consent.
Article 3: Purposes and Lawful Bases for Processing
Processing is purpose-bound and justified under legal frameworks.
3.1 Core Operational Purposes
- Service Delivery: Matching Clients with Vendors, processing escrow payments, and facilitating in-person meetups (lawful basis: contract performance).
- Platform Integrity: Fraud detection, dispute resolution, and 24/7 support interactions (lawful basis: legitimate interests).
3.2 Enhancement and Analytics Purposes
- Aggregated insights for feature improvements, such as refining real-time recommendations (lawful basis: legitimate interests, with pseudonymization).
- Marketing communications, including service updates (lawful basis: consent, revocable at any time).
3.3 Compliance Purposes
- Responding to regulatory inquiries or enforcing Terms (lawful basis: legal obligation).
Automated decision-making is limited to non-profiling activities (e.g., basic eligibility checks) and subject to human oversight.
Article 4: Data Retention and Deletion Mechanisms
Retention is time-limited, and deletion is user-empowered to align with "data deletion information" requirements for Platform live-mode activation (e.g., Meta App Dashboard).
4.1 Retention Schedules
- Active User Data: Retained for the duration of account activity plus 12 months post-last interaction to support potential disputes.
- Transactional Data: 7 years from completion, per statutory audit requirements.
- Log Data: 90 days for security purposes, then anonymized.
4.2 Deletion Procedures
Users may exercise their right to erasure at any juncture. To request deletion:
- Log in to your account dashboard and select "Delete Account" for self-service removal of non-mandatory data.
- Alternatively, email privacy@konnetta.com with your full name, email, and a description of data to be deleted (e.g., "all profile and booking history").
We acknowledge receipt within 48 hours and process the request within 30 days (or 90 days for complex cases under CCPA/CPRA), confirming completion via email.
Exceptions apply for data required by law (e.g., tax records), which we segregate and delete upon expiry.
Upon deletion, data is irretrievably purged from primary systems and backups (overwritten per secure protocols like NIST SP 800-88). For GDPR subjects, this fulfills the "right to be forgotten"; for CCPA subjects, it enables "deletion requests" without waiver of service access.
Inactive accounts are automatically flagged for deletion after 24 months, with prior notification.
Article 5: Data Subject Rights and Remedies
We empower users with comprehensive rights, verifiable through identity authentication.
5.1 Core Rights
- Access and Portability: Obtain a structured, machine-readable copy of your data (e.g., JSON export) free of charge, twice annually.
- Rectification and Restriction: Update inaccuracies or restrict processing during disputes.
- Objection and Withdrawal: Object to processing based on legitimate interests; withdraw consent without detriment.
5.2 Enforcement and Appeals
Requests are processed within one month (extendable to three under heavy load). If unsatisfied, appeal to our Data Protection Officer or supervisory authorities (e.g., CNIL in France, ICO in the UK). No fees apply unless requests are excessive.
5.3 Special Category Rights
CCPA/CPRA users may opt out of data sales (none occur) or limit sensitive data use. Global users benefit from equivalent local rights.
Article 6: Cross-Border Data Transfers and Safeguards
Data may traverse jurisdictions for global operations.
6.1 Transfer Mechanisms
- To affiliates or processors in the EEA, UK, or adequacy-recognized countries (e.g., via EU-US Data Privacy Framework).
- Otherwise, via Standard Contractual Clauses (SCCs) or Binding Corporate Rules, supplemented by Transfer Impact Assessments (TIAs).
6.2 User Protections
You may challenge transfers via rights exercises. We monitor adequacy and suspend non-compliant flows.
Article 7: Accountability and Governance
We maintain robust governance to uphold this Section.
7.1 Records and Audits
Processing records are kept per Art. 30 GDPR, with annual third-party audits.
7.2 Breach Notification
In the event of a personal data breach posing high risk, we notify affected users and authorities within 72 hours (GDPR) or as required (e.g., 45 days under some U.S. laws).
7.3 Updates
This Section may be amended for regulatory evolution; material changes notified 30 days in advance via Platform notice or email.
Article 8: Contact and Governing Provisions
For all data privacy matters:
Konnetta
5900 Balcones Drive Suite 100, Austin, TX 78731, United States
Email: privacy@konnetta.com
Data Protection Officer: [Appoint if required, e.g., dpo@konnetta.com]
Governing Law: This Section is governed by the laws of the State of Texas, United States, with venue in Travis County, Texas, subject to mandatory local protections.
Last revised: October 8, 2025.