Kabidhi privacy policy
1. Who we are
Kabidhi is a trading name of Equinox Digital Ltd, company number 13228478, registered office 264 The Highway, London E1W 3DH, England. Equinox is the data controller for the personal data described in section 3 except where section 2 says otherwise.
Contact for anything in this policy: support@kabidhi.com. We have not appointed a data protection officer, because we are not a public body and our core activity is not large-scale monitoring or large-scale processing of special-category data; the contact above handles every request.
2. Two roles
Kabidhi is used by two kinds of people. Users open an account and send deliveries. Clients receive a link, look at a preview, and may approve, sign, pay and download. Clients never open an account.
We are the controller for: user accounts and billing; the evidence log we keep about every delivery, including what it records about a client; the delivery record we issue; and the security and abuse records of the service.
We are a processor, acting for the user, for: the files a user uploads and the previews we build from them; the contracts a user attaches; the name, email address and company of each client the user enters; and the emails we send in the user's name. For these, the user is the controller and the data processing terms apply. If you are a client and want to know why a user holds your details, ask the user.
3. What we collect
Everything below is what the product stores today. Nothing is collected that is not listed.
Users — account
- Email address, name, the plan you are on, and the country on your billing address if you subscribe (we learn it from Stripe; we do not ask for it at sign-up).
- Your password, stored only as a one-way hash.
- Whether and when you verified your email address.
- Your Stripe customer and subscription identifiers, if you take a paid plan, and your wallet balance and the record of each top-up and each delivery it pays for, if you use pay-as-you-go. If you collect payments: the identifier of each payment provider account you connect, with the country and payout currency the provider reports. Never your bank details and never a card number: the provider holds those.
- Your own payment instructions, if you choose to give your clients payment details of your own rather than collect through a provider: what we store is which way you chose to be paid, and never the instructions themselves.
- Brand settings: logo, colours, subdomain, the name you send as, and the legal name, address, VAT number and VAT rate you enter for your invoices.
Users — security
- Signed-in sessions: a hash of the session token, when it began, when it was last used, the IP address and browser identifier it was created from, so that a stolen session can be recognised and ended. Kept until the session expires: thirty days idle, ninety days at most.
- Sign-in, sign-up and password-reset attempts, by email address and by IP address, so that we can slow down someone guessing. Kept one day.
- Password-reset links (one hour) and email-verification links (twenty-four hours), stored as hashes.
- When you accept the terms of service, at sign-up and again whenever a changed version is put to you: which version you accepted (its number and a fingerprint of its exact text), the moment, and the IP address and browser identifier of the request, so that we can show what was agreed, when, and that it was you. The same for the moment you close your account, with your name and email address as they were, so that a delivery record issued after closure can still name its subject correctly.
Users — the work
- For every delivery: its title, your message to the client, the price, the currency, our stored fee, its state, and the six brand values fixed at the moment it was sent.
- For every file: its name, type, size, dimensions or duration, a fingerprint (SHA-256), and its scan state — section 8 explains the scan. The file itself is stored as section 4 describes.
- Your clients, as you enter them: name, email address, company.
- Every invoice issued for a milestone, as the rendered document.
- Wallet and subscription changes, if you use pay-as-you-go or take a paid plan.
Clients and the evidence log
- For every delivery, an append-only log of events: sent, viewed, approved, paid, downloaded, link resent, receipt signed, agreement requested and signed, code sent and verified, files deleted, and the like. For each event: the time, the IP address and browser identifier of the request that caused it — the client's for the client's actions, the user's for the user's own (sending, revoking, unlocking a download) — and the email address the client entered, if any, together with any note the client left on approval. This is what makes an approval, a signature or a download provable later.
- Receipts: the signer's name and email address, the wording they agreed to, a fingerprint of the file list, the IP address and browser identifier, for the same reason.
- Agreement signing: the client's email address, a hash of the code we sent (never the code), when it was sent and used, how many attempts, and the IP address it was requested from, so that a code cannot be requested without limit.
Emails
- For every email we send about a delivery: the recipient address, the sending name, the subject, and whether it was delivered, bounced or complained about. Not the body.
Payments
- For every payment: the provider's identifiers for it, the amount, our fee, its kind and state, and when it was paid. Never card details or payment credentials.
What we do not collect. We run no analytics, no advertising and no tracking. The only cookies are in section 10. Our error-reporting tool runs on our servers only, not in your browser, and is configured not to send personal data with a report.
4. Where it is stored
| Data | Where | Region |
|---|---|---|
| Your files (originals) | Backblaze B2 | EU Central, Amsterdam (eu-central-003) |
| Previews, delivery records, invoices, attached contracts | Cloudflare R2 | EU jurisdiction, Western Europe |
| Everything in section 3 (the database) and the job queue | Railway (Postgres and Redis) | europe-west4, Amsterdam |
| Email delivery | Resend | EU, Ireland |
| Video and audio transcoding, transiently | Mux | United States (Mux processes there; no EU option for video) |
| Payments, billing, identity checks on users who collect payments | Stripe | The provider's own processing; see section 11 |
| Errors, server side only | Sentry | European Union (Sentry's EU data region) |
Files move directly between your browser and the storage provider. They never pass through our application servers.
5. Why we use it, and on what basis
| Purpose | Data | Basis |
|---|---|---|
| Running your account and delivering your work | account, work, emails | Performance of our contract with you |
| Collecting payments and billing plans | payments, provider identifiers | Contract |
| Keeping the evidence log and issuing the delivery record | the log, receipts, signatures | Our legitimate interests, and the user's and the client's, in a delivery that can be proved: what was sent, when it was seen, approved, paid and downloaded, and by whom |
| Emailing a client a link on a user's behalf | client name and email | We act on the user's instruction as their processor; the user, as controller, is responsible for having a lawful basis, which is ordinarily their legitimate interest in delivering work to a client who has engaged them |
| Security, abuse prevention, rate limiting | sessions, attempts, IP addresses | Legitimate interests |
| Scanning uploaded files for malware (section 8) | the contents of files under 100 MB | Legitimate interests — ours, our users' and their clients', in not storing or passing on a malicious file |
| Retaining logs, records, invoices and contracts for six years | the log, records, invoices, contracts | Legal obligation (record-keeping under the Companies Act 2006) and legitimate interests (establishing what happened, within the limitation period) |
Standard positions adopted, not advice: legitimate interests for the transaction log, as platforms ordinarily rely on; processor-on-instruction for the client email, with the user carrying the basis, as transactional messaging initiated by a customer ordinarily is. Alternatives: contract for the log (weaker, since the client has no contract with us); consent for the email (unworkable, since the client has not been asked). Not taken.
Who at Equinox can read a file. Files are readable by our systems for two purposes: to build previews, and to scan for malware. Both are automatic, and no person sees the file in either. One role can read a file by hand: the operator who holds the storage credentials — today a single director of Equinox Digital Ltd. That happens only to investigate a fault a customer has reported, to act on a report of unlawful content sent to abuse@kabidhi.com, or where the law requires it. There is no administrative screen that browses customers' files, and building one is a decision we have not taken.
6. Who else receives it
We use these providers to run Kabidhi. Each receives only what its row says.
| Provider | What it receives | Why |
|---|---|---|
| Backblaze B2 | your original files | storage |
| Cloudflare | previews, delivery records, invoices, attached contracts; our DNS | storage |
| Mux | the whole original of a video or audio file, for as long as it takes to make the preview; the source is deleted from Mux when the preview is stored with us | transcoding |
| Stripe | for users who collect payments through Stripe: what Stripe asks for to verify you, on its own terms; for clients who pay through Stripe: the email address on the delivery, the amount and the delivery's title; for users who subscribe: your name and email address | payments and billing |
| Resend | the recipient address, subject and body of every email we send | |
| Railway | the database and queue in section 3 | hosting |
| Sentry | error reports from our servers, without personal data by default | error tracking |
We do not sell personal data. We may disclose it: to the providers above; to our professional advisers under a duty of confidence; where the law, a court or a regulator requires; to establish, exercise or defend our legal rights; to investigate abuse of the service; and, if the business or Equinox is sold or merged, to the buyer, who will be bound by this policy.
Payment providers as controllers. When you connect a payment provider account, that provider collects your identity and business details directly and is the controller for them under its own privacy policy.
7. How long we keep it
| Data | Kept for |
|---|---|
| Your files | Seven days after send on the free plan; thirty days on paid plans. Where a delivery collects payment, the window restarts when the payment clears and is never shortened by a payment. Extended as the terms of service describe; deleted by a nightly job. |
| Previews | Deleted with the files they preview. |
| Draft uploads never sent; deliveries waiting for a signature or deposit with nobody acting | Fourteen days from the last action, warned at seven. |
| The evidence log, delivery records, issued invoices, attached contracts, receipts and signature records, and the name, email address and company of the client each delivery was sent to | Six years from the delivery's last event, then deleted. Kept because UK company law requires records of a company's transactions to be kept for six years and because six years is the ordinary period within which a contractual dispute may be brought. Kept longer only where a specific legal obligation or a proceeding in progress requires a particular record, and then only that record, for only as long as required. |
| Account data | Until you close your account, then deleted, except the six-year records above and a subdomain name you have used, which is kept permanently so that it can never be given to another account (the terms of service, section 3). A name that contains your own name is therefore kept. |
| Your acceptance of the terms, and the record of your closure | Six years from the closure of your account, as the record of the contract between us: what you agreed to, when, and when it ended. |
| Sessions | Thirty days idle, ninety days at most. |
| Sign-in attempts | One day. |
| Email delivery status | With the delivery's records. |
| Payment records | Six years, with the delivery. |
8. How we keep it safe
- All connections are encrypted in transit.
- Files are encrypted at rest at both storage providers.
- Storage is private; nothing is reachable without a signed link. A link to an original is created only after payment is confirmed in the same request, lives ten minutes, and is never stored or logged. Preview links live one hour.
- Passwords are hashed with scrypt. Session tokens, sign-in codes and reset links are stored as hashes.
- The evidence log, receipts, signatures, issued invoices and contract records cannot be updated or deleted at the database; a correction is a new entry.
- Uploaded files are scanned for malware. The scanner is ours — it runs on our own servers at Railway, alongside the rest of the service — so the file is not sent to another company to be scanned and section 6 has no row for it. Files under 100 MB are scanned; a larger file is not, and is recorded as not scanned rather than treated as clean. A file the scan flags is quarantined: it is never sent to a client and never downloaded, what it was flagged as is stored against the file, and the user who uploaded it is told.
- Kabidhi is not end-to-end encrypted: we must read a file to build its preview and to scan it for malware, and we say so rather than say otherwise.
9. Your rights
Under UK data protection law you can ask us to: tell you what we keep about you; correct it; delete it; give it to you in a usable form; stop using it for a particular purpose; or object. You can complain to the Information Commissioner's Office (ico.org.uk).
Users. From your account page you can close your account, which deletes your personal data and files, and export what we keep about you. Anything else, email support@kabidhi.com.
Clients. Email support@kabidhi.com with the delivery link you received and we will respond. Where we act for a user we will pass your request to them and help them answer it.
What we cannot delete on request. If you ask us to delete your data, we delete everything except the evidence log, delivery records, issued invoices, receipts and signed agreements of the deliveries you were part of, and the record of your acceptance of the terms and of your closure, which we keep for the six years in section 7. We rely on the exceptions in UK GDPR Article 17(3) for processing required to comply with a legal obligation and for the establishment, exercise or defence of legal rights. Where we keep a record on that basis we use it for nothing else.
Where your name survives. Those records name you as you were when the delivery happened, and closing your account does not change them. The same is true of your clients: the name, email address and company you entered for a client a delivery was actually sent to stay with that delivery's records, because the delivery record names them and can be regenerated from them; a client you entered only on a draft that was never sent is deleted with the draft. In particular your name and email address remain in: every delivery record and invoice already rendered; the signatory name on a signed agreement; the issuer details on an issued invoice; the name, logo and address fixed on each delivery when it was sent; the message you sent with a delivery, which is part of the evidence the delivery record signs; and the closure record itself. Everything else about you is deleted or replaced with a placeholder.
We answer within one month.
10. Cookies
Kabidhi sets one cookie: kabidhi_session, which keeps a user signed in. It
is HTTP-only, sent only over secure connections in production, and expires
with the session. When a user connects a payment provider account, a second
short-lived cookie holds a security token during the connection and expires
within half an hour. There are no analytics, advertising or third-party
cookies. A client's delivery page sets no cookie.
11. International transfers
Your files, previews, records and our database are stored in the European Union, and email is sent from it. One step of the product leaves it: a video or audio file is sent to Mux, in the United States, to be transcoded into its preview, and deleted from Mux once the preview is stored. Where a provider in section 6 processes personal data outside the United Kingdom and the European Economic Area, we rely on one of the transfer mechanisms UK law provides: an adequacy regulation for the destination, or the UK International Data Transfer Agreement or the UK Addendum to the EU Standard Contractual Clauses, which each of those providers offers in its data processing terms.
Today that applies to: Stripe (processing in the EU and the United States under Stripe's own transfer terms); Mux (the whole video or audio file, transiently, processed in the United States under Mux's Data Privacy Framework certifications, with the UK Addendum to the Standard Contractual Clauses in Mux's data processing terms as the fallback); Cloudflare (data stored in the EU, with support access from elsewhere under Cloudflare's terms); and Sentry (its EU data region).
12. Children
Kabidhi is for businesses and is not directed at anyone under eighteen.
13. Changes
We will email users about material changes at least thirty days before they take effect, and the current version is always at app.kabidhi.com/privacy.
Equinox Digital Ltd, trading as Kabidhi. Company 13228478. Registered office 264 The Highway, London E1W 3DH.
Version: draft 7, 23 September 2026.