Privacy Policy

KzNet Technologies · Effective 2026-09-05 · Version 1.0

This policy explains what personal information KzNet Technologies collects, why, and what we do with it. It covers our website at kznettech.com and our hosted CRM application at app.kznettech.com. It is written in plain language on purpose. If something here is unclear, write to privacy@kznettech.com.

1. Who we are

KzNet Technologies is a small technology firm based in the United States. We build websites and custom web applications for small businesses, and we operate a hosted CRM (customer relationship management) application for our clients. We are the operator of the services described here and the party responsible for how the information in this policy is handled.

2. Two kinds of data, two roles

The CRM holds two different kinds of information, and our responsibility is different for each.

If your information is in a client's workspace because you are one of their customers, that client is responsible for it. Section 9 explains how to reach them through us.

3. The website (kznettech.com)

The public website is a set of static pages. It runs no analytics, no advertising, and no tracking scripts. It sets no cookies on public pages. Our web server keeps standard access logs (IP address, requested page, browser type, time) for security and troubleshooting. Those logs rotate and are not used to build profiles of visitors.

The password-protected client area sets a cookie so you stay signed in. That cookie holds no personal information beyond the sign-in itself.

If you contact us through the address on the site, we keep your message and our reply so we can follow up.

4. The hosted CRM (app.kznettech.com)

4.1 Account data we collect

4.2 Workspace data we process on your behalf

Whatever you and your team put into the CRM: contacts, companies, notes, tasks, logged communications, quotes, invoices, and files. We store it, back it up, display it to your authorized users, and otherwise leave it alone. We do not read it, analyze it, sell it, share it with anyone, or use it to train any software model.

Each client's workspace is isolated from every other client's at the database level. Row-level security is enforced by the database itself, not only by application code.

4.3 What we use account data for

We do not send marketing email to CRM account holders, and we do not use account data for advertising of any kind.

5. Connected accounts: Google, Microsoft, and GitHub

The CRM can connect to third-party accounts you already own so that activity shows up in your CRM automatically. Every connection is optional, is started by you, and can be disconnected at any time.

5.1 Google account data (Gmail)

When you connect a Google account, the CRM asks Google for permission to read your mail and send mail as you, and for your email address to identify the connection. This is what the CRM does with that access, and all it does:

Access tokens for your Google account are stored encrypted in our database and nowhere else. Disconnecting the account inside the CRM deletes those tokens. You can also revoke the CRM's access at any time from your Google Account's Security → Third-party access page. Messages already logged to a contact stay in your workspace, because they are your records; you can delete them like any other record.

KzNet Technologies' use and transfer of information received from Google APIs to any other app will adhere to the Google API Services User Data Policy, including the Limited Use requirements. Specifically: Google user data is used only to provide the auto-logging and sending features described above. It is not used for advertising. It is not sold. It is not transferred to anyone except as needed to provide the feature, to comply with the law, or as part of a merger or acquisition with prior notice to you. No person at KzNet Technologies reads it, except with your explicit permission to resolve a support issue, for security purposes, or where the law requires. It is not used to train or improve any machine-learning or AI model.

5.2 Microsoft 365 account data (Outlook)

Connecting a Microsoft 365 mailbox works the same way, with one difference: the CRM also asks for permission to update read state, so that reading a message in the CRM marks it read in Outlook. The same rules apply: only mail matching a CRM contact is logged, nothing older than the connection is imported, the exclusion list applies, sending happens only when you click send, and tokens are stored encrypted and deleted when you disconnect. You can revoke access from your Microsoft account's Privacy → Apps and services page.

5.3 GitHub

If you connect a repository to a client account, the CRM stores a read-only token, encrypted, and shows commit titles and links on that client's timeline. It reads nothing else from the repository and writes nothing to it.

6. Who else handles the data

We do not sell personal information and we do not share it for advertising. We use a short list of service providers to run the service. Each one handles data only to the extent needed to do its job for us.

ProviderWhat it does for usWhen it sees your data
DigitalOceanHosts our servers and database, in the United States.Always. All service data lives here.
StripeProcesses payments and stores card details.When you pay for a plan or a service.
ResendDelivers the email we send you: sign-in codes, receipts, notices.When we email you.
GoogleGmail access, as described in section 5.1.Only if you connect a Google account.
MicrosoftOutlook access, as described in section 5.2.Only if you connect a Microsoft 365 account.
GitHubRepository activity, as described in section 5.3.Only if you connect a repository.

The CRM loads an icon font from a public content-delivery network (cdnjs, operated by Cloudflare). Your browser contacts that network directly to fetch the font file, which discloses your IP address to it in the same way as loading any public web page. No account data is sent.

We will give account holders at least 30 days' notice by email before adding a provider that would handle workspace data.

We will disclose information if we are legally required to, for example by a valid court order. Where we are allowed to, we will tell you first.

7. How long we keep things

8. How we protect it

If we learn of a security incident that affects your data, we will tell affected account holders without undue delay, describe what happened and what we are doing about it, and keep a record of the incident.

9. Your choices and rights

If you hold an account with us, you can at any time:

If you are a customer of one of our clients and your information is in their workspace, they are responsible for it. If you write to us instead, we will forward your request to that client within five business days and tell you we have done so. We will not act on their records without their instruction, because they are not ours to change.

Depending on where you live, you may have additional rights under laws such as the GDPR or state privacy laws. We honor those rights whether or not the law strictly requires us to.

10. Children

Our services are for businesses and are not directed at children. We do not knowingly collect personal information from anyone under 16. If you believe a child has given us information, write to us and we will delete it.

11. Where data is stored

Our servers are in the United States. If you use the service from outside the United States, your data is transferred to and stored there.

12. Changes to this policy

When we change this policy we update the version and date at the top and keep the current version at kznettech.com/privacy. If a change materially affects how we handle your data, we will email account holders before it takes effect.

13. Contact

Privacy questions and requests: privacy@kznettech.com
Security reports: security@kznettech.com
General enquiries: info@kznettech.com