Privacy Policy — Keystone Dataworks BizHub
Effective date: [Set on publish]
Operator: Keystone Dataworks
Contact: [privacy@keystonedataworks.com]
1. Scope
This policy describes how BizHub (the hosted bookkeeping application at your configured PUBLIC_BASE_URL) collects, uses, stores, and protects information when you sign in or use the demo environment.
2. Data we process
| Category | Examples | Purpose |
|---|---|---|
| Account data | Email, password hash, MFA secrets (encrypted), role | Authentication and access control |
| Business records | Customers, contracts, time entries, invoices, expenses, receipts | Bookkeeping you enter or migrate |
| Technical logs | IP address, user agent, audit log entries | Security, incident response |
| Uploaded files | Receipts, MSAs, branding images | Business operations and UI theming |
We do not sell personal data.
3. Lawful basis
We process data to perform the service you request, to secure multi-tenant isolation, and to meet legal obligations (tax record retention, breach notification where applicable).
4. Hosting and subprocessors
- Application and database run on infrastructure you control (e.g. Namecheap VPS).
- Optional: OpenAI or local Ollama for invoice recap drafts when you enable LLM features.
5. Retention
See Data Retention. You may request export or deletion subject to legal hold requirements.
6. Your rights
Depending on jurisdiction you may request access, correction, deletion, or restriction. Contact the operator email above.
7. Security
TLS in transit, Argon2 passwords, MFA for owner accounts, PostgreSQL row-level security between tenants, auth-gated file downloads.
8. Changes
Material changes will be posted at /legal/privacy with an updated effective date.
Template — review with legal counsel before publishing.