Privacy Statement

LAST REVISED: July 1st, 2022

At Kisi, we take your privacy seriously. We are passionate about developing products that enhance the security and privacy of organizations and individuals. We believe that well-built, user-friendly systems make it easier to manage and secure physical environments in ways that respect the privacy of individuals while simultaneously keeping them safe.

This Privacy Policy explains who we are and how we collect, share, and use personal data.

Our Pledge on Privacy

We are transparent about the different types of information we collect and how we use them. We do not share your personal information with any third parties except in accordance with our Privacy Policy.

Specifically, Kisi will:

  • Be clear with individuals when collecting personal information via the site;
  • Incorporate privacy-by-design principles into our development of the Products;
  • Use industry-standard best practices and data security tools to keep your data safe and protect the Products from unauthorized access; and
  • Provide customers and administrators with information to help them understand how their use of the Products may include the processing of personal information.

Kisi will not:

  • Sell personal information to third parties;
  • Use personal information for any purpose other than the one for which we originally collected it without first providing further information;
  • Use or access customer data for any purpose other than developing, maintaining, enhancing the Products and providing them to the customer, and on occasion, where permissible, keeping you informed about further products and services; or
  • Share customer data across different customer environments.

In addition to the details of the policy below, for more information about our Products, how they are designed and manufactured, how our system is performing in real time, and how we safeguard your information, please visit this link: https://www.getkisi.com/security.

Privacy Policy

This Privacy Policy applies to https://www.getkisi.com and https://www.kisi.io (for Kisi Products) (collectively, the “Site”), which is owned and operated by Kisi Incorporated, together with our worldwide subsidiaries and affiliates (collectively, “Kisi,” “Company,” “we” or “us”). The data controller of your personal information is Kisi Incorporated, which also is the Kisi entity with whom you are contracting.

Kisi provides hardware products, and its cloud-based software platform via the Site, for enterprise physical security (such software platform, “Kisi Dashboard,” and together with the hardware products, our “Products”). This Privacy Policy explains how we collect, retain, use, and disclose personally identifiable information (“Personal Information”) gathered through the Site and the Products. This Privacy Policy is subject to and incorporates by reference our Terms of Service (located here: https://www.getkisi.com/legal/terms.

We may update this Privacy Policy from time to time in response to changing legal, technical or business developments. When we update our Privacy Policy, we will take appropriate measures to inform you, consistent with the significance of the changes we make. Please check back from time to time to review the current Privacy Policy which is effective as of the revision date listed below.

What Personal Information Does Kisi Collect And Why?

The Personal Information that we may collect about you broadly falls into the following categories:

A. Personal Information Collected Directly Through the Site, Kisi Dashboard, and Our Interactions With You

Certain parts of our Site and/or Kisi Dashboard may ask you to provide your contact details in order to register an account with us, to subscribe to marketing communications from us, and/or to submit enquiries to us.

Our website integrates ad conversion events to track the effectiveness of our advertising campaigns and optimize our marketing efforts. When you interact with our ads (e.g., clicks, views) and perform conversions (e.g., purchases, form submissions), certain data is collected and processed. This data may include information about your interactions, device details (such as IP address, device type, browser type), and timestamps of events.

We will also collect the following types of information and Personal Information directly from you through the Site, Kisi Dashboard and our interactions with you:

  • Your Kisi Dashboard account authentication information (e.g., email, encrypted password, profile image);
  • Personal Information contained in legal agreements (such as invoices and orders);
  • Personal Information included in any job inquiry when you respond to a Kisi job listing, including by emailing us;
  • Personal Information, including but not limited to IP address or location or device identifier, shared with Kisi as part of technical support services that we provide to customers, including account and - Product configuration information, usage data, and/or other similar information or to ensure account/location security or block malicious requests;
  • Personal Information you provide to us in communications with us, during a phone call with a Kisi representative or via webinars and events.

We use this information to:

  • Provide the Site, including its related offerings, services, and programs, and to improve the Site and Kisi Dashboard by better understanding how users access and use the Site and Kisi Dashboard and to customize their experience;
  • Authenticate Kisi Dashboard users;
  • Process Product orders;
  • Effectuate or enforce a transaction or agreement;
  • Respond to requests or inquiries including for customer service or job listings;
  • Provide technical support, troubleshooting, and security for users of the Site and Kisi Dashboard;
  • From time-to-time to send you information that we believe may be of interest to you, including news and offers about our products and services or those of our chosen partners, where permissible to do so under data protection law. Examples can include our blog, newsletter, and co-marketing efforts with our reseller partners.

For more information about Kisi Dashboard, please visit this link: https://www.getkisi.com/products/cloud-management-dashboard

B. Information that we collect automatically

When you interact with the Site and Kisi Dashboard, we strive to make your experience easy and meaningful. Our Site and Kisi Dashboard use technology, or those of third-party service providers, such as cookies, web beacons (clear GIFs) and similar technologies to track user activity and collect site data including analytics information about your use of and activity of the Site or within Kisi Dashboard (i.e., automatically collected through the Site, such as the website from which visitors came, Site visitors' IP address, browser type and other information relating to the device through which they access the Site or Kisi Dashboard). We may combine this data with the Personal Information we have collected from you.

  • Device Data: As with most websites and technology services delivered over the Internet, our servers automatically collect information when you access or use our Site or Kisi Dashboard and record it in log files. This log data may include your Internet Protocol (IP) address, device type and settings, hardware MAC address, device ID number, the address of the web page visited before using the Site or Kisi Dashboard, error logs, browser type and settings, the date and time the Site or Kisi Dashboard were used, information about browser configuration and plugins, and language preferences.
  • Location Data: We receive information from you that helps us approximate your location. We may, for example, use a business address submitted by your employer, or an IP address received from your browser or device to determine approximate location. We may also collect location information from devices in accordance with the consent process provided by your device.
  • Cookies: We (including our chosen third-party service providers) use cookies to track visitor activity on the Site and Kisi Dashboard. For more information about Cookies, Cookie Management, and Cookie Deactivation, visit: https://www.getkisi.com/legal/cookies.
  • Third Parties: As noted, we may also engage third parties to track and analyze Site and Kisi Dashboard activity on our behalf. To do so, these third parties may place cookies or web beacons to track user activity on our Site and within Kisi Dashboard. We use the data collected by such third parties to administer and improve the quality of the Site including Kisi Dashboard, analyze usage of the Site and Kisi Dashboard, and provide a more enhanced user experience on the Site and Kisi Dashboard, such as personalizing and delivering relevant offers and content based on user activity on the Site and Kisi Dashboard. We do not provide these third parties with your Personal Information.
  • Information for California residents only: our Site collects users data via third party cookies from Adroll. You can learn more about what data is collected on this page.

C. Information Collected Through the Products

Some information is processed and stored directly on the hardware Product. However, we collect the following types of Personal Information from and through certain of the Products as part of their routine functioning and/or in connection with enhanced features enabled by the customer:

  • Access Control:
    • Data about individuals using the access control devices (e.g. profile image, start/end date, badge ID, employee ID, etc.), associated access group(s), access level(s), and historical event information; and
    • Door usage data, including list of door events and entry/exit actions by individual user.
      For more information about Access Control, please click this link: https://www.getkisi.com/access-control-system

  • Sensors:

We use information collected from the Products to:

  • Authenticate users;
  • Provide the Products to customers and to improve them;
  • Send customer alerts (e.g., motion notifications, tamper alerts, etc.) generated by your Products;
  • Respond to customer requests or inquiries, and for similar, customer service-related purposes;

D. Information From Other Sources

From time to time, we may obtain Personal Information about you from third party sources, including publicly available sources such as professional contact pages of company websites.

We may also receive Personal Information about you from companies who provide us with marketing services, but only where these third parties either have your consent or are otherwise legally permitted to disclose your Personal Information to us.

The types of information we collect from other sources include your professional contact information (such as name, office address, work email address, work phone number).

We use this information to send you material that we believe may be of interest to you, including news and offers about our products and services, where permissible to do so under data protection law.

Legal Basis for Processing Personal Information

Our legal basis for collecting and using the Personal Information described above will depend on the Personal Information concerned and the specific context in which we collect it.

However, we will normally collect Personal Information from you only where we have your consent to do so, where we need the Personal Information to perform a contract with you, or where the processing is in our legitimate interests and not overridden by your data protection interests or fundamental rights and freedoms. In some cases, we may also have a legal obligation to collect Personal Information from you or may otherwise need the Personal Information to protect your vital interests or those of another person.

If we ask you to provide Personal Information to comply with a legal requirement or to perform a contract with you, we will make this clear at the relevant time and advise you whether the provision of your Personal Information is mandatory or not (as well as of the possible consequences if you do not provide your Personal Information).

Similarly, if we collect and use your Personal Information in reliance on our legitimate interests (or those of any third party), we will make clear to you at the relevant time what those legitimate interests are. If you have questions about or need further information concerning the legal basis on which we collect and use your Personal Information, please contact us using the contact details provided under the “How to Contact Us” heading below.

Disclosure of Information and Personal Information

We may disclose your Personal Information as follows:

  • In connection with the process of fulfilling orders, providing, or performing functions on our behalf (e.g., such as third-party service providers, contractors, payment processors, banks, and collection agencies);
  • To provide our Products and services;
  • To service providers to provide you, on our behalf, information relating to our Products or services that we believe you may find of interest;
  • To any competent law enforcement body, regulatory, government agency, court or other third party in response to a subpoena or where we believe disclosure is necessary (i) as a matter of applicable law or regulation, (ii) to exercise, establish or defend our legal rights, or (iii) to protect your vital interests or those of any other person;
  • To an actual or potential buyer (and its agents and advisers) in connection with any actual or proposed purchase, merger or acquisition of any part of our business, or to other third parties in the voluntary or involuntary dissolution (bankruptcy) of our business, provided that we inform the third party it must use your personal information only for the purposes disclosed in this Privacy Policy; and
  • To any other person with your consent to the disclosure.

Your Data Protection Rights (For EEA and UK residents)

You have the following data protection rights (depending on the context in which we process your information):

  • Access: You have the right to ask us for copies of your Personal Information. There are some exemptions, which means you may not always receive all the information we process. If you use Kisi Dashboard, you can access your Personal Information through your Kisi Dashboard account. For other access requests, please contact us at support@getkisi.com.
  • Erasure: You have the right to ask us to erase your Personal Information in certain circumstances. You can delete your Personal Information:
    • From Your Kisi Dashboard Account: Please contact Kisi Tech Support at support@getkisi.com if you have questions regarding how to delete your account or information associated with it. If you choose to delete your organization within Kisi Dashboard, then all the data associated with your organization’s Kisi account is likewise deleted, including any stored image thumbnails or archived video footage. You can access, amend, or delete your information, including Personal Information, through your Kisi Dashboard account. We may retain certain data for a longer period of time if we are required to do so for legal reasons. Refer to each Product’s specific website for more information about device specific retention and deletion periods.
    • From the Products: Customers can delete all information stored on a hardware Product by means of functionality within the Kisi Dashboard interface. If you are an individual whose information may have been collected by the Products in use by one of our customers, please contact the operator of the Kisi system to request deletion of such Personal Information.
  • Rectification: You have the right to ask us to rectify information you think is inaccurate and to complete information you think is incomplete. If you use Kisi Dashboard, you can amend your Personal Information held on Kisi Dashboard, through your Kisi Dashboard account. For other rectification requests, please contact us at support@getkisi.com.
  • Object/Restrict Processing / Request Portability: In certain circumstances, you can object to processing of your Personal Information, ask us to restrict processing of your Personal Information or request portability of your Personal Information. To make such a request, you can contact us at support@getkisi.com.
  • Opt-Out of Marketing Communications: You have the right to opt-out of marketing communications we send you at any time. You can exercise this right at any time by following the opt-out link or instructions contained in any such email and follow the instructions listed there. To opt-out of other forms of marketing (such as postal marketing or telemarketing), then please contact us at support@getkisi.com. Please note that it may take a few business days for us to process opt-out requests and we will need to retain your Personal Information on a suppression list to honor your opt-out request. If you opt-out of receiving marketing emails or promotions, we will still send you service-based emails where requested by you, or in reference to other customer service purposes in accordance with this Privacy Policy.
  • Withdraw Your Consent: Similarly, if we have collected and process your Personal Information with your consent, then you can withdraw your consent at any time by emailing support@getkisi.com. Withdrawing your consent will not affect the lawfulness of any processing we conducted prior to your withdrawal, nor will it affect processing of your personal information conducted in reliance on lawful processing grounds other than consent.
  • Complain to a DPA: You have the right to complain to a data protection authority about our collection and use of your Personal Information. For more information, please contact your local data protection authority.

We respond to all requests we receive from individuals wishing to exercise their data protection rights in accordance with applicable data protection laws.

Your Data Protection Rights (California Residents)

If you are a resident of California and interact with us as a consumer, you have certain rights under the California Consumer Privacy Act or “CCPA” (Cal. Civ. Code § 1798.100 et seq.), including to request access to and deletion of your Personal Information. You may exercise these rights as explained above with respect to EEA and UK residents, or by contacting us at support@getkisi.com. We do not sell your Personal Information, but we may allow our advertising partners to collect certain device identifiers and electronic network activity to show ads that are targeted to your interests. To opt out of having your Personal Information used for targeted advertising purposes, please unsubscribe via the link in the marketing email you have received.

Third-Party Links

The Site contains links to other, third-party websites. Any access to and use of such linked websites is not governed by this Privacy Policy, but, instead, is governed by the privacy policies of those third-party websites. We are not responsible for the information practices of such third-party websites.

Third Party Advertisers

Our Site uses third party advertisement platform providers and their free conversion tracking features on certain pages. If you visit our Site, the destination page may have code on it that will help us understand the path you took to arrive on that page.

International Users & GDPR

Your Personal Information may be transferred to, and processed in, countries other than the country in which you are resident. These countries may have data protection laws that are different to the laws of your country (and, in some cases, may not be as protective). The Site and Kisi Dashboard are primarily hosted in the United States, and customers have the option of storing video, image, and audio data in datacenters throughout the world (currently the United States, Canada, the European Union, and Australia).

By providing your information to Kisi, you acknowledge the transfer of your information to the United States for storage, use, processing, maintenance, and onward transfer of such information to other entities, regardless of their location. However, such activities will be done in accordance with this Privacy Policy and the Terms of Service. Kisi has implemented safeguards to ensure an adequate level of data protection where your Personal Information is transferred outside of the EEA and UK, such as by means of our customer data processing agreement through which we implement the standard contractual clauses for the transfer of Personal Information as approved by the European Commission (Article 46 GDPR). We have implemented similar appropriate safeguards with our third party service providers and partners. Further details can be provided upon request.

Data Retention

We retain Personal Information we collect from you where we have an ongoing legitimate business need to do so (for example, to provide you with a service you have requested or to comply with applicable legal, tax or accounting requirements). Please refer to each Product’s datasheet (available at https://docs.kisi.io/) specific website for more information about device specific retention and deletion periods.

When we have no ongoing legitimate business need to process your Personal Information, we will either delete or anonymize it or, if this is not possible (for example, because your personal information has been stored in backup archives), then we will securely store your Personal Information and isolate it from any further processing until deletion is possible.

Children and Minors

The Site and Products are not directed to individuals under the age of 18 and we do not knowingly collect information from anyone under 18. If you become aware that a child has provided us with personal information, please contact us at support@getkisi.com. If we become aware that a child under 18 has provided us with personal information, we will take steps to delete such information as soon as possible.

How to Contact Us

As a result, we encourage your questions and comments about any privacy concerns. Please direct any privacy related questions or comments to support@getkisi.com.