KitNDocs Privacy Notice
Last updated 30 August 2026
This notice explains how Passeri Studio Ltd, trading as KitNDocs, processes personal information. We use "Passeri", "we", "us" and "our" for the company. It covers the current application at https://kitndocs.app, the website at https://kitndocs.com, and the retained archive from the earlier service.
Passeri Studio Ltd is registered in England and Wales under company number 17254010. Its registered office is 66 Paul Street, London EC2A 4NA, United Kingdom.
Email support@kitndocs.com with a privacy question or request.
1. Our role and the customer's role
The role depends on why information is processed.
When an organisation controls the information
An organisation normally decides why it keeps operational information in KitNDocs. This includes information about its equipment, staff, contacts, maintenance, issues, evidence and certificates. For that information:
- the organisation is normally the controller.
- Passeri is normally its processor and acts on its documented instructions.
Ask the organisation first if your request concerns its operational records. We will help the organisation respond where the law requires it.
When Passeri controls the information
Passeri acts as controller when we decide why information is used. This includes account administration, service security, Support, fault investigation, telemetry that does not include customer-controlled operational content, and legal compliance. It also includes our relationship with a person or customer.
A person can use KitNDocs in more than one organisation. Organisation records and Passeri's own information can have different controllers. This can apply when both sets concern the same person.
2. Information we process
Depending on how KitNDocs is used, we may process:
- Account and identity information: Clerk user identifier, name, email address, profile details, organisation membership and sign-in information.
- Organisation information: organisation name, settings, disciplines, time zone, members and briefing recipients.
- People information: contacts, staff names, engagement dates, custody and assignment information. A contact may be a person who has no KitNDocs account.
- Equipment and maintenance information: descriptions, serial numbers, markings, models, manufacturers, readings, tasks, schedules, dates and notes. This also includes issues, defects, service state, work and the person or system associated with an act.
- Files and documents: photographs, JPEG, PNG, WebP and PDF files, filenames, labels, sizes, thumbnails, placeholders, certificates, void and restore details.
- Signature information: the points used to draw a signature mark, including position, timing and reported pressure. The data is linked to a certificate and the person or system that created it. KitNDocs does not treat the mark as biometric authentication.
- Assistant information: questions, answers, conversation identifiers, tool calls and records returned to the assistant. This also includes model, token and timing information, errors, user identifiers and organisation identifiers.
- Briefing and delivery information: recipients, rendered briefing content, send attempts, provider identifiers, delivery status and error information.
- Support information: messages sent through Support, contact details and the information needed to investigate a problem.
- Telemetry and technical information: browser and device information, pages, actions, exception details and identifiers. This also includes network and request information, traces and logs.
- Change-history information: most organisation tables keep the values before and after a write. They also keep table and record identifiers, organisation, person or system, operation, time and any available change category. An earlier value can contain personal information that was later corrected or removed from the current row.
- Legacy information: account, equipment, document and related information retained from the earlier KitNDocs service for recovery and closure work.
Free-text fields, files, support messages and assistant questions can contain information about other people. Do not add personal information that is not reasonably needed.
3. How we get information
We get information:
- from you when you sign in, enter information, upload a file, draw a signature, ask the assistant or contact Support.
- from members of an organisation when they enter information about staff, contacts, equipment and work.
- from Clerk when it supplies identity and organisation membership.
- from service providers when they return delivery, authentication, storage, analytics, support, model or fault information.
- from legacy KitNDocs systems and archives kept for recovery and closure.
4. Why we use information and our legal bases
We use personal information only where we have an applicable legal basis. Depending on the purpose, we use it to:
- provide KitNDocs and fulfil an agreement with a person or customer.
- follow a customer's documented instructions when we act as processor.
- authenticate people and enforce organisation access.
- store, show and organise operational records and evidence.
- store due dates and usage limits stated by an operator, then derive due, overdue and service state from them.
- prepare, send and investigate morning briefings.
- answer assistant questions and store assistant messages.
- provide Support and investigate reported errors.
- secure, monitor and maintain the service.
- establish, exercise or defend legal claims.
- meet legal obligations.
- use optional browser technology where valid consent is required and has been given.
Passeri can rely on legitimate interests to operate and secure the service. The interests can also include preventing misuse, investigating faults and improving reliability. We must balance those interests against the rights of the people concerned.
We do not sell private customer records. We do not use them for third-party advertising. We do not claim a general right to use them to train models.
5. Automated calculations and the assistant
KitNDocs stores due dates and usage limits stated by an operator. It derives due, overdue and service state from those values and configured rules. These outputs support the organisation's work. Passeri does not make the real-world decision that equipment is safe, serviceable or airworthy.
The assistant uses read-only tools. It can retrieve organisation records that the signed-in person is allowed to read. The assistant cannot change records.
Questions, recent assistant messages and retrieved information are sent through Vercel AI Gateway to Anthropic's model. When server-side PostHog is configured, it receives assistant inputs, outputs and operational metadata. We use this information to investigate faults and answer quality.
Assistant messages remain stored. Start again changes the conversation identifier and does not remove earlier messages. The current product has no self-service assistant-message deletion control.
6. Who receives information
We use the following providers for the stated purposes:
| Provider | Purpose |
|---|---|
| Clerk | Authentication, identity, profiles and organisation membership |
| Supabase | PostgreSQL database and private file storage |
| Vercel | Hosting, server functions and AI Gateway |
| Anthropic | Producing assistant answers through Vercel AI Gateway |
| PostHog | Product telemetry, exception capture, Support and AI observability when configured |
| Brevo | Sending morning briefings and returning delivery information |
We may also disclose information:
- to a customer organisation and people it authorises.
- to advisers, insurers, auditors or prospective buyers under appropriate duties.
- when required by law, court order or a regulator.
- to protect rights, safety, records or the service.
7. International processing
KitNDocs may work with customers and service providers in the United Kingdom, the EEA, the United States and elsewhere. A person's location does not by itself prevent them or their organisation from using the service. Remote access, model processing, telemetry and Support can involve international transfers.
Where transfer rules apply, we use the lawful route available for that transfer. Depending on the recipient and where the information comes from, this may include UK or EU adequacy arrangements, the UK Extension to the EU-US Data Privacy Framework, the EU-US Data Privacy Framework, the UK's International Data Transfer Agreement or Addendum, European Commission Standard Contractual Clauses, or another permitted safeguard. We complete any assessment required for the chosen route.
The approved subprocessor schedule will identify the countries and safeguards used for each provider.
8. Browser storage and analytics
KitNDocs uses browser storage for authentication, preferences, telemetry and Support. When browser PostHog is configured, it starts without an in-product consent control. It can identify a signed-in person by Clerk identifier, email address and name.
The separate Cookie and Storage Notice explains the browser technology used by KitNDocs. It also explains the current limits on consent controls.
9. Change history, correction and erasure
Most writes to organisation tables create a restricted change-history row. It contains the values before and after the write and the person or system that made it. Some tables, including assistant messages and temporary file reservations, are exceptions. Some records are insert-only. Others can be edited. Certain rows or stored bytes can be removed.
The history is append-only to ordinary application access and is tamper-resistant. It is not protected by a cryptographic hash chain, and it is not a complete customer-visible export.
Correcting a current row does not necessarily remove its earlier value from the change history. The applicable controller must assess each erasure request. Legal duties, record integrity and legal-claims needs can affect the answer. Audit integrity alone is not an automatic exemption from data-protection law.
10. Files
Organisation files are kept in private Supabase Storage and are served through authenticated KitNDocs access.
A member of the organisation can void a file. The file is hidden at once and can be restored for 28 days. After that time restoration is refused. A scheduled process then attempts to destroy the original and thumbnail shortly afterwards. The filename, label, size, void and restore details, tombstone and relevant earlier values remain.
This process does not prove when a provider backup or other supplier copy expires. A person or organisation remains responsible for keeping genuine maintenance or regulatory evidence for as long as applicable rules require.
11. Retention
We keep personal information only for as long as the purpose needs it. Customer instructions, security, legal duties and legal claims can affect that period. KitNDocs does not yet have one approved period for every category.
In particular:
- removing a person or organisation from Clerk does not automatically remove KitNDocs records.
- organisation operational records and their change history remain until a lawful return, restriction, deletion or retention decision is carried out.
- assistant messages remain stored and Start again does not remove them.
- briefing content, delivery information, support information and telemetry remain subject to an approved retention schedule that is not yet complete.
- file-byte destruction follows the process in section 10, while metadata and relevant history remain.
- backup and provider copies can expire on a later supplier cycle.
We periodically review whether identifiable information is still needed. We erase, anonymise or restrict it where the law requires.
12. Legacy KitNDocs archive
The earlier KitNDocs service has a restricted archive containing account, equipment, document and related information. It is retained for recovery verification and the service-closure process. It is not treated as deleted merely because the earlier application closes.
Access remains restricted and each recovery request is checked. No final deletion date has been approved.
Contact support@kitndocs.com if you believe the archive contains information about you. You can also contact us to exercise a right.
13. When Passeri acts as processor
A customer agreement or data processing agreement governs processing that Passeri performs for an organisation. This privacy notice is not, by itself, a complete data processing agreement.
14. Security
KitNDocs uses authenticated access and database restrictions that separate organisations. It uses encrypted connections to the hosted database and serves private files through authenticated access. Restricted privileged access exists for defined cross-organisation work and storage administration.
No internet service is completely secure. These controls do not amount to a claim of security certification or uninterrupted availability. They do not prove a particular backup regime or encryption at rest.
Tell support@kitndocs.com promptly if you believe information or an account has been compromised.
15. Your rights
Depending on the law and the processing role, you may have rights to:
- receive information about processing.
- access personal information.
- correct inaccurate information.
- request erasure or restriction.
- object to some processing.
- receive portable information where the right applies.
- withdraw consent without affecting earlier lawful processing.
- complain to a data-protection authority.
These rights are not absolute. Record-keeping duties, other people's rights, security and legal claims can affect the response.
Email support@kitndocs.com. Include enough information for us to identify you and the relevant organisation. We may need to verify your identity. If the organisation controls the information, we will normally send the request to it or act on its instructions.
You can complain to the UK Information Commissioner's Office at https://ico.org.uk/make-a-complaint/. You may also have the right to contact the authority where you live or work.
16. Changes and contact
The version and last-updated date above identify this notice.
Contact us at:
Passeri Studio Ltd (trading as KitNDocs), 66 Paul Street, London EC2A 4NA, United Kingdom. Email support@kitndocs.com.