Who we are
Kanera is operated by Happen Software Limited. In this policy, “Kanera”, “we”, “us”, and “our” refer to Happen Software Limited and the Kanera services we provide.
Happen Software Limited is registered in Ireland.
This policy applies to the Kanera website, hosted Kanera workspaces, support, billing, and related communications. It does not govern self-hosted deployments where another organisation controls the environment and data processing.
Information we collect
- Account information, such as name, email address, organisation and workspace membership, authentication status, accepted Terms version and time, and billing status.
- Workspace content, such as boards, cards, notes, comments, files, custom fields, automations, and related metadata that users add to Kanera.
- Product analytics profile information for hosted Kanera, including internal user and organisation identifiers, the authenticated user’s display name and email address, the organisation name, and—when an owner uses the product—the owner’s display name, email address, and internal user identifier.
- Usage and device information, such as browser type, IP address, approximate region, user agent, timezone, timestamps, security and application logs, and diagnostic events.
- Billing and payment information processed through our payment providers. We do not store full payment card numbers on Kanera systems.
- Support and communication information, such as messages you send us, contact details, and the context needed to respond.
Cookies and browser storage
kanera_rt is a strictly necessary HttpOnly refresh-token cookie used to keep you signed in. It is limited to authentication routes, uses SameSite=Lax, is sent only over HTTPS in production, and normally expires after 10 days. The raw refresh token is not stored in our database; we store a hash and rotate the token when it is used. Short-lived access tokens are held in browser memory rather than local storage.
kanera_cookie_consent is a strictly necessary first-party cookie shared across kanera.app subdomains. It records the version, time, and analytics choice needed to honour your preference on the website, documentation, and hosted app. It expires after six months, when Kanera asks you to choose again.
If you accept analytics, PostHog uses a first-party cookie and matching local-storage entry named ph_<project-token>_posthog for a pseudonymous device, session, campaign, and identity record. The cookie expires after no more than 180 days; local storage remains until consent expires or is withdrawn, Kanera removes it, or you clear site data. PostHog is not loaded and this storage is not created before consent.
After an analytics-enabled signup link is selected, kanera_analytics_registration_started records the funnel hand-off for 30 minutes. kanera_analytics_source, kanera_analytics_medium, kanera_analytics_campaign, and kanera_analytics_landing_page record the consented acquisition context for 30 days. These first-party cookies are shared with the hosted app and are removed when analytics consent is withdrawn.
Where browser product analytics is enabled for hosted Kanera, we use it to connect acquisition, activation, collaboration, ongoing work, and subscription outcomes. We disable autocapture, session replay, heatmaps, form capture, and input capture, and respect browser Do Not Track choices. Browser analytics is not enabled without consent or for self-hosted installations, local development, automated tests, support impersonation sessions, or organisations explicitly marked as internal or test. Separately, hosted Kanera sends a limited set of server-side product events under the legitimate-interests basis described below; those events do not read or write information on your device.
The web app uses local browser storage for preferences and device-local state such as theme, layout, filters, recent boards, notification preferences, and cross-tab logout. It may also hold unsent card, checklist, comment, or note drafts for recovery; those drafts are pruned after 30 days. Browser storage remains on the device until Kanera removes it under those rules or the user clears site data.
Where information comes from
We receive information directly from you, from workspace owners or administrators who invite you, automatically when you use Kanera, and from Stripe or Cloudflare when they provide their services to us.
Account, authentication, and billing information is required where needed to create an account, provide hosted Kanera, secure the service, or manage a paid plan. Workspace content, profile details beyond the required account fields, and support information are provided when you or your organisation choose to use those features.
Our data protection roles
Happen Software Limited is the controller for personal information used to operate the Kanera website, create and administer accounts, manage billing, secure the service, provide support, and communicate with users.
For content placed in a hosted Kanera workspace by or for an organisation, that organisation is normally the controller and Happen Software Limited acts as its processor. Requests concerning workspace content may therefore need to be handled by the relevant workspace owner or administrator.
How we use information
- Provide, maintain, secure, and troubleshoot Kanera.
- Create and manage accounts, workspaces, permissions, plans, trials, billing, and support.
- Communicate about product updates, security notices, support requests, and administrative messages.
- Understand product performance and improve reliability, usability, and security.
- Measure a limited set of explicit acquisition, workspace activation, team adoption, collaboration, content-free work-creation, feature-adoption, and subscription events. We use names and email addresses only to make authenticated person and organisation profiles identifiable in PostHog; we do not attach them to each product event or send customer workspace content.
- Detect, prevent, and respond to fraud, abuse, service misuse, security incidents, and legal obligations.
- We do not use customer workspace data for advertising, data mining, or training AI models.
Legal bases for processing
- Contract: we process account, workspace, service, support, and billing information where it is necessary to provide Kanera or take steps requested before providing it.
- Legitimate interests: where applicable, we process limited B2B product analytics, usage, device, log, support, and account information to keep Kanera reliable and secure, prevent abuse, understand service performance and adoption, and improve the product. We consider necessity, proportionality, and the impact on users before relying on this basis.
- Legal obligations: we process and retain information where required for tax, accounting, legal, regulatory, fraud-prevention, or lawful-request obligations.
- Consent: where applicable law requires consent for analytics cookies or similar browser storage, or where we ask for consent for optional communications or browser permissions, you may withdraw it at any time without affecting processing that took place before withdrawal.
Service providers and infrastructure
We use infrastructure and storage providers to host the application, databases, encrypted backups, attachments, monitoring, and network services. Hosted workspace data is kept in Ireland and Germany. These providers process service data only to operate the systems contracted by us.
Stripe processes checkout, payment method, subscription, invoice, tax, and transaction information for hosted billing. Stripe may return customer and subscription identifiers, invoice status, partial payment-method details, and billing events to Kanera. We do not store full card numbers.
Cloudflare provides network security and Turnstile challenges. Turnstile receives the challenge token, IP address, and browser or device signals needed to assess the request. Cloudflare may also process normal network request information when traffic passes through its network.
PostHog Cloud EU processes limited website and product analytics for hosted Kanera under our data-processing agreement. An authenticated person profile receives the user’s internal identifier, display name, and email address. An organisation group profile receives its internal identifier and name plus the owner’s display name, email address, and internal user identifier when an owner uses the product. These identifiable fields are stored on those profiles only and are not attached to each product event.
Product events sent to PostHog contain normalised page patterns, campaign attribution, internal user and organisation identifiers, and allow-listed action metadata, including content-free creation events from the web app, public API, and MCP. We do not send card, board, workspace, list, custom-field, note, comment, or attachment names or content. Access to the PostHog project is restricted to authorised personnel, analytics is normally retained for 12 months, and PostHog processes it in its EU cloud environment.
Our configured email provider receives recipient addresses and the content of verification, invitation, notification, billing, support, and other service emails. If browser push is enabled, Kanera sends the push subscription endpoint and encrypted notification payload through the push service selected by the user’s browser or operating system.
We may disclose information when required by law, to protect rights and safety, to enforce our terms, or as part of a business transfer such as a merger, acquisition, or asset sale.
We do not sell personal information. We do not share customer workspace data for advertising, data mining, or AI model training.
Customer-authorised integrations
An organisation or workspace administrator may create personal or workspace API keys, authorise an OAuth or MCP client, configure a webhook, connect GitHub or Trello features, choose an SMTP or object-storage provider, or enable another integration. The integration receives the account, workspace, board, card, note, file, event, or other data needed for the action and allowed by the user’s permissions and the granted scope.
Webhook event payloads are sent to the administrator-selected endpoint. MCP and other API clients can read or change workspace data within the permissions and scopes granted to them. API keys, OAuth tokens, and client secrets are stored as hashes where later plaintext access is not required; configured integration secrets such as webhook signing secrets are encrypted at rest.
These disclosures occur at the customer’s direction. The customer is responsible for selecting the third party, configuring an appropriate scope, and reviewing that party’s terms and privacy practices. Our commitment not to train AI models on customer data does not control what an independently selected AI or MCP provider does with data the customer authorises Kanera to disclose.
Self-hosted deployments
If your organisation self-hosts Kanera, your organisation is responsible for the infrastructure, data, backups, security controls, and user requests associated with that deployment.
The self-hosted server does not contact Kanera for update checks or licensing and does not send workspace content to Kanera-hosted services by default. Hosted-mode licensing and billing checks are not active in the normal self-hosted mode.
The default web client loads the Inter font from Google Fonts, so a user’s browser may send Google an IP address, user agent, and request metadata. MCP metadata and HTML email templates reference branding assets on www.kanera.app, so an MCP client or email reader may request those public assets. These asset requests do not include workspace content.
Outbound data flows also occur when an administrator configures SMTP, S3-compatible storage, webhooks, browser push, OAuth or MCP clients, Trello or GitHub features, monitoring alerts, or other integrations. In those cases the self-hosting organisation chooses the provider and controls the configuration and disclosure.
Retention schedule
- Accounts and memberships: while the account is active. After verified account closure, access is blocked promptly and the live profile is deleted or anonymised within 30 days, except identifiers preserved in the records below or where deletion would damage another user’s content or required history.
- Workspace content: while the workspace is active. Deleting a workspace removes its live database content and stored attachment files as part of the deletion operation. Residual copies may remain in encrypted backups for up to 14 days.
- Read notifications: 90 days after they are read. All notifications, including unread notifications: no more than 365 days after creation.
- Workspace activity records: 730 days. Administrative audit records and audited support-access sessions: 1,095 days.
- Authentication records: access tokens normally expire after 5 minutes and refresh tokens after 10 days. Expired, used, consumed, or revoked session, reset, verification, and invitation records are removed after a further 30 days. OAuth access tokens expire after 15 minutes and OAuth refresh tokens after 30 days; connection and grant records remain until revoked and are then retained for up to 30 days.
- Operational and security logs: normally 30 days, unless a shorter provider limit applies or a specific incident requires preservation for up to 12 months.
- Product analytics, including identifiable person and organisation profile properties: normally 12 months in the PostHog EU project, reviewed periodically against the purpose of measuring acquisition, activation, adoption, and conversion.
- Email queue records: 30 days. Push-delivery queue records: 7 days. Successful webhook-delivery records: 7 days; failed delivery records: 14 days.
- Billing and tax records: 7 years after the end of the relevant financial year. Stripe may retain payment information under its own legal and contractual obligations.
- Support and contact messages: 3 years after the request is closed. We may retain a message longer if it forms part of a contract, complaint, security incident, or legal claim governed by another period in this schedule.
- Encrypted database backups: 14 days, after which they are overwritten or deleted through the backup cycle. A legal hold, active dispute, fraud investigation, or binding legal obligation may suspend deletion only for the affected records and for as long as necessary.
Your choices and rights
If the GDPR applies to you, you may have rights to access, correct, delete, restrict, or object to processing of your personal information, and to receive portable information where the right to data portability applies. These rights are subject to the conditions and exceptions in applicable law.
Where processing is based on consent, you may withdraw that consent at any time. Where processing is based on legitimate interests, you may object to that processing. You also have the right not to be subject to a decision based solely on automated processing that produces legal or similarly significant effects. Kanera does not use personal information for that type of automated decision-making.
To request access, export, correction, or deletion—including for product analytics—contact [email protected]. We may need to verify your identity and, for workspace content, may direct the request to the workspace owner or administrator.
You may also lodge a complaint with the Irish Data Protection Commission at https://www.dataprotection.ie. We encourage you to contact us first so we have an opportunity to address your concern.
International processing
Kanera processes hosted service data in Ireland and Germany. Both countries are within the European Economic Area, so movement of personal information between them is not a transfer outside the EEA.
Stripe and Cloudflare may process limited personal information outside the EEA. Where that involves a restricted transfer, we use an applicable European Commission adequacy decision, Standard Contractual Clauses, or another transfer mechanism permitted by the GDPR. You may contact us for more information about the safeguard relevant to your information.
Children
Kanera is a workplace service and is not directed to children. A person must be legally able to enter into these Terms, or use Kanera through an organisation that is authorised to provide access and takes responsibility for the account.
If you believe a child has provided personal information to hosted Kanera without appropriate authorisation, contact [email protected]. We will investigate and take appropriate action. An organisation that gives a child access to its workspace is responsible for providing any age-appropriate notice and obtaining any authorisation or consent required for its processing of that child’s workspace data.
Changes to this policy
We may update this policy when Kanera, our practices, or legal requirements change. We will post the revised version and effective date here. If a change materially affects how we use personal information, we will normally give at least 30 days’ notice by email or a prominent in-service notice, unless an urgent legal, regulatory, or security reason requires earlier effect. Where consent is required for a new use, we will request it before that use begins.
Version history
This is Privacy Policy version 1, effective July 20, 2026.