KanvasKanvas

Privacy Policy — Kanvas

Last updated: 20 May 2026·Effective date: 20 May 2026

This policy describes how "Oceanic Horizon Holdings Pty Ltd" manages personal information collected through the Kanvas mobile application, operating under Australia's Privacy Act 1988 and related frameworks.

1. Information We Collect

Directly provided

  • Account details including name, email, hashed password, profile photo, timezone, and workspace information
  • Workspace content such as messages, tasks, projects, documents, and file uploads
  • Text submitted to the Kenny AI assistant
  • Support communications

Automatically collected

  • Device specifications, operating system, app version, language settings, and network type
  • Authentication tokens and session identifiers
  • Push notification tokens when enabled
  • Approximate location derived from IP address (not precise GPS data)

From third parties

  • Name, email, and profile information when signing in via Apple, Google, or Microsoft

The organization does not intentionally collect sensitive information such as health or biometric data.

2. How We Use Your Information

Personal information serves these purposes:

  • Application provision, maintenance, and feature improvement
  • User authentication and account security
  • Workspace collaboration and real-time functionality
  • AI assistant response generation
  • Transactional notifications regarding accounts and security
  • Crash diagnostics and fraud prevention
  • Aggregate usage analysis for product enhancement
  • Legal compliance and lawful request responses

The organization explicitly states it does not sell personal information and does not use user content for AI model training without separate consent.

3. Legal Bases (EEA / UK only)

GDPR compliance relies on:

  • Contractual necessity for service delivery
  • Legitimate interests in security and product improvement
  • Consent for notifications and analytics
  • Legal obligations for data retention and disclosure

Individuals may withdraw consent at any time.

4. How We Share Information

Within workspace: User-posted content appears to workspace members; administrators may export or delete content.

Service subprocessors handle:

  • Infrastructure (hosting, databases, file storage, push notifications, app distribution)
  • Analytics and diagnostics (crash reporting, performance monitoring, session replay)
  • AI assistant processing

Each subprocessor must maintain security controls and follow organizational instructions. A current subprocessor list is available upon request.

Legal and safety: Information may be shared when legally required or necessary to protect rights and safety.

Business transfers: Personal information may transfer to successors in merger or acquisition scenarios.

The organization does not sell or rent personal information for third-party marketing.

5. Cross-Border Transfers

Subprocessors may process information in Australia and the United States. International transfers comply with Standard Contractual Clauses where GDPR applies.

6. Push Notifications

Device tokens deliver alerts when notifications are enabled. Users can disable notifications through device settings.

7. Data Security

"Industry-standard technical and organisational measures" protect personal information through encryption, access controls, and audit logging. The organization acknowledges no system is completely secure and cannot guarantee absolute protection.

Data breaches likely to cause serious harm will be reported to affected individuals and relevant regulators.

8. Data Retention

  • Account information is retained during active use and briefly afterward for legal compliance
  • Workspace content persists while the workspace exists; owners may delete anytime
  • Crash and analytics logs remain for up to 24 months
  • Earlier deletion is available upon request

9. Your Rights

Individuals may have rights to access, correct, delete, object to processing, receive portable copies, and withdraw consent depending on jurisdiction.

Complaint channels:

  • Australia: Office of the Australian Information Commissioner
  • EEA/UK: Local data-protection authority
  • California: CCPA/CPRA enforcement rights apply

Requests should be directed to support@theoceanic.co with responses within 30 days or legally required timeframes.

10. Children

The application is not directed to users under 16, and the organization does not intentionally collect information from this age group.

11. Apple- and Google-Specific Disclosures

The application does not request AppTrackingTransparency permission and does not track activity across external platforms. Platform-specific data safety disclosures align with this policy's categories.

12. Third-Party Sites

The organization is not responsible for third-party privacy practices when links or integrations are included in the application.

13. Changes to This Policy

Material policy updates will be communicated through the application or email at least 14 days before implementation. The header date reflects the current version.

14. Contact

Oceanic Horizon Holdings Pty Ltd — Privacy Officer
Email: support@theoceanic.co