Privacy Policy
Last updated 19 August 2026 · version 2026-08-19
1. Who is responsible
The controller for the personal data described in this policy is:
- Krzysztof Ozegowski
- Enigami.tech — Enigami.tech is a trade name; it is not (yet) a registered legal entity.
- Pfäffikon, Switzerland
- E-mail: hello@kneecap.care
Postal address available on request by e-mail. There is no separate data protection officer; write to the address above and you reach the person who runs the service.
This policy covers the Kneecap.care web application at https://kneecap.care, the public pages around it, and the e-mails we send — both the e-mails we send to you (sign-up confirmation, password reset, magic link) and the document e-mails we send to your clients on your instruction.
Kneecap.care is operated from Switzerland, so the revised Swiss Federal Act on Data Protection (revFADP, in force since 1 September 2023) applies. Where you or your clients are in the European Economic Area, the GDPR applies in addition; we have written this policy to satisfy both. Article references are given for each law where they differ.
2. What data we process
Almost everything below is data you type into the app yourself. We do not buy data, we do not enrich it from third-party sources, and we do not build profiles.
Account data
- Your e-mail address (your login identity).
- Your password — stored only as a salted hash by Supabase Auth. Neither we nor Supabase can read your password.
- Your display name and, if you upload one, your avatar image.
- Account timestamps (created, last sign-in).
Security data
- Two-factor authentication: the metadata of your TOTP factor held by Supabase Auth (factor id, status, enrolment time) and the shared secret used to verify your codes.
- Trusted devices: the label you gave the device, when it was created, when it was last used and when it expires. The device token itself is stored in an
httpOnlykc_devicecookie, which page JavaScript cannot read; your browser sends it with each request, and our database only ever stores its SHA-256 hash. - Backup codes: only a hash of each code, plus whether and when it was used. We cannot show you a code again after it is generated.
- Your step-up settings (whether sending, destructive actions or security changes require a fresh TOTP code).
- A short log of sensitive authentication attempts (which account, which kind of attempt, when) used to rate-limit brute-force attempts.
Company profile and bank data
- Your company name, address, contact e-mail, phone number, website, registration number, the sender name used on outgoing e-mails and your reply-to address.
- Your logo, if you upload one.
- Your bank accounts: label, IBAN, QR-IBAN, BIC, bank name and bank address. These are business banking details, not transaction data — we never see your account balance or payments.
Your clients' data — entered by you
- Client name, address and country, e-mail address, phone number and any notes you add.
- Where your client is a sole trader or a natural person, this is personal data about someone who is not our user. Section 4 explains the roles: you are the controller for it, we only process it for you.
Documents
- Invoices, proforma invoices and offers: number, title, dates, status, currency, notes and every line item (title, description, quantity, price, discount, VAT).
- A snapshot of the client, bank account and company data as it was when the document was saved — this is what the PDF prints, so an old document keeps showing the details that were correct at the time.
- QR-bill data (reference number and the additional information printed on the payment part) when you enable the Swiss QR-bill.
- The archived PDF itself: once a document is issued (or an offer is sent), the exact bytes are stored in a private storage bucket so the file you sent can always be reproduced. The same bucket holds the PDF of every payment reminder you send for an invoice.
Activity logs
- Status history per document (which status changed to which, and when).
- The e-mail send log per document: recipient address, time, whether delivery to our e-mail provider succeeded or failed, the provider's message id and, on failure, the error message. Payment reminders sent for an invoice are logged the same way, together with the reminder level, the reminder fee you charged and the new payment deadline you set.
Technical data
- Server and authentication logs kept by our hosting and auth providers: IP address, user agent, requested path, timestamps and error traces. We use these for security and troubleshooting; they are short-lived and are not linked to a marketing profile.
- The strictly necessary cookies described in the Cookie notice.
- Usage analytics (only with your consent): pseudonymous page views and feature-usage events from Google Analytics 4 and PostHog (EU). We do not use session recording, autocapture, surveys or advertising features; events never contain document numbers, client names, amounts or e-mail addresses; page addresses are scrubbed of document and client identifiers before they are sent; PostHog is tied to your internal account id only, never to your e-mail.
Consent records
- Your cookie choice is stored in the
kc_consentcookie (12 months). If you are signed in when you decide — or sign in later with a decision already in the cookie — we also store the decision (version, analytics yes/no, timestamp, where you made it) in our database as proof of consent, for as long as your account exists.
3. Why we process it and on what legal basis
| Purpose | Data used | Legal basis |
|---|---|---|
| Providing the service: your account, your company profile, your clients, your documents and their PDFs | Account, company profile, client, document and archive data | Performance of our contract with you — art. 31(2)(a) revFADP, art. 6(1)(b) GDPR |
| Account security: sign-in, two-factor authentication, trusted devices, backup codes, step-up confirmation, rate limiting | Account and security data, authentication attempts, technical data | Performance of the contract and our overriding legitimate interest in keeping accounts and your clients' data safe — art. 31(1) revFADP, art. 6(1)(b) and (f) GDPR |
| Sending a document by e-mail to a recipient you choose, from our domain with your sender name | Recipient address, document PDF, sender name, reply-to address, send log | Performance of the contract (you instruct the send) — art. 31(2)(a) revFADP, art. 6(1)(b) GDPR |
| Complying with legal duties (for example responding to a lawful order or keeping records we are required to keep) | Whatever the duty covers | Legal obligation — art. 31(1) revFADP, art. 6(1)(c) GDPR |
| Usage analytics | Pseudonymous usage events and device type | Your consent, which you may withdraw at any time via "Cookie settings" in the footer — art. 6(1)(a) GDPR. Nothing is loaded before you consent. |
| Improving the product: debugging errors, understanding which features are used | Aggregated or pseudonymous technical data and error logs | Our legitimate interest in a working, improving product — art. 31(1) revFADP, art. 6(1)(f) GDPR |
We never sell personal data, we do not share it for advertising, and we do not use it to train machine-learning models. There is no automated decision-making with legal or similarly significant effects.
4. Your clients' data — we act for you
When you store client details or issue a document, you decide why and how that data is processed. In data protection terms you are the controller and Kneecap.care is your processor (art. 9 revFADP, art. 28 GDPR). By using the service you instruct us to process that data on your behalf, and this section is the data processing agreement between us. It applies for as long as your account exists.
We commit to the following:
- Instructions. We process your clients' data only to run the service for you — that is, to do what your use of the app asks for. We do not use it for our own purposes.
- Confidentiality. Access is limited to the operator named in section 1, who is bound to confidentiality. There are no other staff.
- Sub-processors. We use the providers listed in section 5 and remain responsible for them. We will announce a new sub-processor in-app or by e-mail before it starts processing, so that you can object by deleting your account.
- Security. We apply the technical and organisational measures described in section 7.
- Deletion. Deleting a client removes the client record, but the copy of that client's details embedded in documents you already issued stays with those documents — which is also what your own bookkeeping duty requires. Only draft documents can be deleted. When you delete your account, every document, snapshot, archived PDF and uploaded file goes with it. See section 6.
- Assistance. If one of your clients exercises their rights against you, the export and deletion features in Profile → Export my data and Profile → Delete account let you answer them yourself; if that is not enough, write to us and we will help.
- Breach notification. If a personal data breach affects your data, we will notify you without undue delay after becoming aware of it, with the information you need to fulfil your own notification duties.
- Audit. On written request we will provide the information needed to demonstrate compliance with this section.
You remain responsible for having a legal basis to hold your clients' data, for the accuracy of what you enter, and for informing your clients as their own privacy law requires.
5. Sub-processors and international transfers
We keep the provider list as short as the service allows. Each provider processes only what it needs, under a data processing agreement:
| Provider | Role | Where the data sits | Data | Transfer basis |
|---|---|---|---|---|
| Supabase | Postgres database, authentication and file storage | AWS eu-central-1 (Frankfurt, Germany) | Account data, application data (clients, invoices, documents) and uploaded files | Swiss/EU — no third-country transfer for data at rest |
| Vercel | Hosting and serverless functions (fra1) plus the global edge network | Frankfurt (fra1) with global edge points of presence | Request metadata and server logs (IP address, user agent, requested path) | EU-US Data Privacy Framework and Standard Contractual Clauses |
| Resend | Transactional e-mail delivery (document e-mails and auth e-mails) | eu-west-1 (Ireland) | Recipient address, subject, message body and the attached PDF | EU-US Data Privacy Framework and Standard Contractual Clauses |
| OVHcloud | DNS for kneecap.care and the hello@kneecap.care mailbox | European Union | E-mail correspondence sent to or from the contact address | EU — no third-country transfer |
| Google Analytics 4 | Usage statistics — only with your consent (cookie banner) | United States | Pseudonymous usage data (page views, product events, device type) | EU-US Data Privacy Framework and Standard Contractual Clauses |
| PostHog EU | Product analytics — only with your consent; no session recording | Frankfurt, European Union | Pseudonymous product-usage events | EU — no third-country transfer |
Where your data physically lives. Your account, your clients, your documents and your archived PDFs are stored in Frankfurt, Germany, and stay there. Outgoing e-mails are processed in Ireland. Our application functions — PDF rendering, e-mail sending, the account and document routes — are pinned to the Frankfurt (fra1) region. Besides the static shell of the site, the routing and authentication proxy runs on every request at whichever of Vercel's edge points of presence is closest to you, and processes your session cookie, the trusted-device cookie and request metadata (IP address, user agent, requested path) there.
Third-country transfers. Vercel and Resend are US-headquartered companies, so support access from the United States cannot be excluded even though the data at rest stays in the EU. Those transfers rely on the EU-US Data Privacy Framework and/or the European Commission's Standard Contractual Clauses, combined with the Swiss addendum recognised by the Federal Council. Google Analytics 4 is a transfer to the United States on the same basis and runs only if you consent; Google states that Google Analytics 4 does not log or store individual IP addresses. PostHog EU also runs only after your consent and stores its data in the European Union; events carry pseudonymous identifiers only.
Beyond these providers we disclose personal data only when the law requires it (for example a valid order from a Swiss authority or court) or when you ask us to. We do not sell personal data to anyone.
6. How long we keep data
- Account, company profile, clients and documents: for as long as your account exists. You can delete individual clients and draft documents at any time. Deleting a client does not rewrite documents you already issued: they keep the snapshot of the client's details as printed, because that is what makes an issued document a faithful record. Issued documents cannot be deleted individually.
- On account deletion: your account, your company profile, your clients, all documents and their line items, your bank accounts, your numbering series, your security data and every archived PDF and uploaded file are deleted. See section 8 for how to trigger it.
- Send logs and archived PDFs: these belong to the document and are kept and deleted with it. They are what lets you prove later what you sent, to whom and when. They are all deleted when you delete your account.
- Security data: trusted devices expire after 30 days and can be revoked earlier under Profile → Security; backup codes live until you regenerate them or disable two-factor authentication. Recovery-code attempt records are kept for up to 24 hours after the last attempt (older records are purged daily by a scheduled job) and are deleted with your account.
- Hosting, authentication and e-mail-delivery logs: retained short-term by our providers under their own retention schedules — currently one hour at our hosting provider, one day at our database and authentication provider, and thirty days at our e-mail provider (which logs the recipient address, subject and delivery status of each message) — and then deleted automatically.
- E-mail correspondence sent to hello@kneecap.care: kept as long as needed to handle your request and to document that we handled it.
- Analytics data (only with consent): retained according to the provider's retention settings (PostHog: by default up to one year; GA4: set to the shortest offered period, 2 months) — event data thereafter falls away or is aggregated. Withdrawing consent stops further collection; see the Cookie notice.
Your own retention duty. Swiss bookkeeping law requires you to keep your business records — including the invoices you issue — for ten years (art. 958f of the Swiss Code of Obligations). That duty is yours, not ours: deleting your account deletes your data here permanently and we cannot restore it. Export your data before you delete your account and keep the export with your accounting records.
Backups. Be aware that Kneecap.care currently runs on the free tier of its database provider, which includes no automated backups. If data is lost we may not be able to restore it. This is stated plainly in section 7 of the Terms of Service as well. On the other hand it means that when data is deleted, it is genuinely gone rather than lingering in a backup for weeks.
7. How we protect data
- All traffic to and from Kneecap.care is encrypted with TLS; data at rest is encrypted by our database and storage providers.
- Every table is protected by PostgreSQL Row-Level Security, so a signed-in session can only reach rows belonging to that user. Application queries add the same filter on top of it.
- Archived PDFs, logos and avatars live in private storage buckets that are never publicly readable. Archived PDFs are streamed to you through your signed-in session; your logo and avatar are loaded through short-lived, signed links.
- Two-factor authentication with a TOTP app is available and recommended. You can mark a device as trusted for 30 days, keep single-use backup codes for the day you lose your phone, and require a fresh code before sending a document, deleting data or changing security settings.
- Password hashes live in the protected schema of Supabase Auth, which the application cannot query at all. Backup-code hashes and trusted-device token hashes are never readable by the browser — the database revokes access to those columns even for the account that owns them.
- Sensitive operations run server-side with privileged credentials that never reach the browser; secrets are held as environment variables with least-privilege scopes.
- Our infrastructure is hosted in EU data centres (Frankfurt and Ireland).
No system is perfectly secure. We cannot guarantee that our measures will defeat every attack, and you play a part too: use a strong, unique password, enable two-factor authentication, keep your backup codes somewhere safe and revoke trusted devices you no longer use under Profile → Security.
8. Your rights
Under the revFADP and, where it applies, the GDPR you have the right to:
- obtain information about, and a copy of, the personal data we hold about you (access);
- have inaccurate data corrected (rectification);
- have your data deleted (erasure);
- ask us to restrict processing while a dispute is resolved;
- receive your data in a common, machine-readable format and pass it on (portability / data delivery);
- object to processing based on our legitimate interest; and
- withdraw a consent you gave, with effect for the future.
Two of these are self-service and immediate: Profile → Export my data gives you a machine-readable archive of your account, company profile, clients, documents and archived PDFs, and Profile → Delete account permanently deletes your account and everything in it. Most of what the app stores you can also edit or delete directly in the relevant screen.
For anything else, write to hello@kneecap.care. To protect your data we may need to verify your identity — normally by asking you to write from the e-mail address registered on the account. Exercising these rights is free of charge; we answer within 30 days and tell you if a request genuinely needs longer.
If you are one of our users' clients and want to know what is stored about you, please contact that business directly: they are the controller for their client and document data (see section 4). If you cannot reach them, write to us and we will forward your request.
If you are not satisfied with how we handled your request, you can complain to the Swiss Federal Data Protection and Information Commissioner (FDPIC), www.edoeb.admin.ch, or — if you are in the EEA — to the supervisory authority of your country of residence or workplace.
9. Data breaches
If personal data we hold is lost, disclosed or altered without authorisation and this is likely to result in a high risk to the persons concerned, we notify the FDPIC as soon as possible (art. 24 revFADP) and, where the GDPR applies, the competent supervisory authority within 72 hours (art. 33 GDPR). We inform affected users directly when the law requires it or when the notice helps you protect yourself (art. 34 GDPR), and we tell you what happened, what data was affected and what we did about it. If the breach affects your clients' data, we notify you so that you can meet your own duties as controller.
10. Children
Kneecap.care is a business tool for companies and self-employed professionals. It is not directed at anyone under 18 — the Terms of Service require you to be at least 18 and legally able to enter into contracts — and we do not knowingly collect data from minors. If you believe a minor has created an account, write to hello@kneecap.care and we will delete it.
11. Development notice
Kneecap.care is in active development. You use it at your own risk: features may change, errors may occur, and documents (invoices, proforma invoices, offers, QR-bills) may be generated incorrectly. You are responsible for checking every document before you send or rely on it, and the operator accepts no liability for damages caused by incorrectly generated documents or by unavailability of the service.
For data protection this means two practical things: features described here may change as the product evolves, and you should keep your own copies of anything you rely on. We will keep this policy in step with what the software actually does.
12. Changes to this policy
We may update this policy when the service changes or the law does. The version and effective date at the top of this page always tell you which wording is current. Material changes — a new purpose, a new sub-processor, a new category of data — are announced in the app or by e-mail before they take effect. Minor clarifications take effect when published. Continuing to use Kneecap.care after a change means the new version applies to you.
13. Contact
Questions, requests or complaints about privacy: hello@kneecap.care. See also the Terms of Service, the Cookie notice and the Imprint.