Kamu legal
Privacy Policy
How Kamu collects, uses, discloses, retains, and protects personal information.
1. PURPOSE AND SCOPE
This Privacy Policy explains how Kamu Administration Ltd. ("Kamu," "we," "us," or "our"), a wholly owned subsidiary of Razif Holdings Ltd., collects, uses, discloses, retains, and otherwise processes Personal Information when you access or use Kamu's websites, mobile applications, web applications, communications, artificial-intelligence features, marketplace, and related products and services (collectively, the "Services"). Kamu may publicly identify itself as "Kamu, a Razif company."
This Policy applies to:
- customers and prospective customers;
- individuals using personal or organization-managed Kamu accounts;
- Marketplace Providers and prospective Marketplace Providers;
- representatives, administrators, employees, and authorized users of organizations using the Services;
- visitors to our websites;
- people who contact support, participate in research, or receive communications from us;
- job, internship, student-project, contractor, and other applicants; and
- other individuals whose Personal Information we process in connection with the Services.
This Policy does not govern a third party's independent collection or use of Personal Information, including a Marketplace Provider's services or a third-party website, application, identity provider, payment processor, or integration used under its own privacy policy.
In this Policy:
- "Personal Information" means information about an identified or identifiable individual and includes "personal data," "personal information," and similar terms under applicable privacy law.
- "User Content" means information, prompts, messages, files, images, audio, video, documents, instructions, and other content submitted to, transmitted through, or created using the Services.
- "Marketplace Provider" means an independent professional, freelancer, contractor, business, or other service provider offering or performing services through the Kamu marketplace.
- "Connected Account" means a third-party account that you choose to connect to Kamu, such as a Google or Microsoft account.
- "Workspace" means an account or environment administered by an organization for its authorized users.
2. WHO IS RESPONSIBLE FOR YOUR INFORMATION
2.1 Kamu as the responsible organization
Kamu Administration Ltd. is responsible for the Personal Information described in this Policy unless another organization is identified as responsible at the point of collection.
Kamu determines the purposes and means of processing for consumer accounts, Marketplace Provider accounts, the Kamu marketplace, product administration, safety, fraud prevention, customer support, marketing, recruitment, and service improvement.
2.2 Organization-managed Workspaces
If you use the Services through a business, school, employer, or other organization, that organization may control your Workspace and certain data within it. The organization may be responsible for that information, while Kamu processes it on the organization's instructions and under an agreement with the organization. Workspace administrators may be able to access, export, retain, restrict, or delete account information and User Content associated with the Workspace. Direct privacy requests concerning organization-controlled data to the relevant organization. Kamu will assist as required by law and contract.
2.3 Razif Holdings Ltd.
Razif Holdings Ltd. may provide Kamu with shared corporate services, including legal, compliance, security, finance, administration, and technical support. When it processes Personal Information for those purposes, it must protect the information consistently with this Policy and applicable law. Razif Holdings Ltd. is not the operator of the Services or a party to your contract with Kamu solely because it owns Kamu.
2.4 Independent Marketplace Providers
Marketplace Providers are generally independent businesses and are not employees or agents of Kamu. They may independently collect and use information necessary to quote for, schedule, communicate about, or perform a requested service. Their independent processing is governed by their own notices and legal obligations. Kamu does not control information collected by a Marketplace Provider outside the Services.
3. INFORMATION WE COLLECT
The information we collect depends on how you interact with the Services, the features you enable, the permissions you grant, and whether you use a personal account, a Marketplace Provider account, or an organization-managed Workspace.
3.1 Information you provide directly
We may collect:
- Account and profile information, including name, username, email address, telephone number, profile photograph, preferred language, time zone, country or region, pronouns or other optional profile fields, password-derived authentication records, and account preferences.
- Organization and Workspace information, including organization name, role, title, department, authorized-user status, membership, administrator permissions, invitations, and business contact details.
- Marketplace and service information, including service requests, descriptions, categories, budgets, dates, addresses or service locations, availability, quotations, offers, assignments, milestones, completion status, ratings, reviews, disputes, refunds, and related communications.
- Marketplace Provider information, including business or professional details, service categories, experience, qualifications, licences, certifications, insurance information, work samples, availability, pricing, tax information, payout onboarding status, identity-verification information, and screening status where required.
- User Content, including conversations, prompts, responses, notes, tasks, routines, preferences, reminders, files, photographs, images, recordings, documents, and other content you choose to provide.
- Communications, including messages sent through the Services, support requests, survey responses, feedback, complaints, telephone or video-call information, and communications with customers, Marketplace Providers, Workspace administrators, or our personnel.
- Payment and transaction information, including purchase amount, currency, payment status, transaction identifiers, billing address, refunds, chargebacks, Marketplace Provider payouts, invoices, receipts, and limited payment-method details supplied by our payment processor. Full payment-card numbers and card security codes are generally collected directly by the payment processor and are not made available to Kamu.
- Consent and preference records, including privacy choices, marketing preferences, cookie choices, AI permissions, Connected Account permissions, and records of notices presented and choices made.
- Application and recruitment information, including resumes, cover letters, portfolios, professional profiles, education, qualifications, work history, references, interview notes, technical-assessment results, availability, eligibility information, and communications about an application.
Please do not provide sensitive information that is not reasonably necessary for the feature or transaction you are using. If you provide Personal Information about another person, you must have the authority to do so and, where required, must have given that person any required notice or obtained any required consent.
3.2 Information collected through devices and the Services
We may automatically collect:
- Device and technical information, including device type, operating system, browser type, application version, language, time zone, IP address, network information, device or application identifiers, and diagnostic information.
- Usage and event information, including screens or pages viewed, feature interactions, search queries, navigation paths, referral source, timestamps, session duration, crash reports, performance measurements, and errors.
- Security and audit information, including sign-in attempts, authentication events, session records, access logs, permission changes, administrative actions, suspected abuse, fraud signals, and records needed to investigate security incidents.
- Cookie and local-storage information as described in our Cookie Policy. Our current public website uses only technologies that are necessary to operate, secure, and remember essential preferences. We do not currently use third-party advertising cookies or cross-site behavioural advertising technologies. If that changes, we will update our notices and provide any legally required choices before activating them.
3.3 Device permissions and sensor information
Some functions require device-level permission. Depending on the feature you choose, we may collect or access:
- Microphone and audio information for voice input, voice conversations, transcription, calls, or audio attachments;
- Camera, photographs, and media for profile images, document capture, service evidence, attachments, visual assistance, or video features;
- Location information, including approximate or precise location, for local results, service addresses, provider availability, safety, routing, scheduling, or other location-dependent functions;
- Notification tokens to send push notifications that you enable; and
- Telephone and communication information when you use calling, messaging, or related communication functions.
You can manage device permissions through your operating-system settings. Disabling a permission may prevent the corresponding feature from functioning. Kamu does not collect background location unless the feature, in-product notice, operating-system permission, and applicable law expressly permit it.
3.4 Voice, images, and biometric information
Voice recordings, photographs, video, and identity documents may contain distinctive physical or behavioural characteristics. Kamu uses voice and image information to provide the feature you request, such as transcription, speech output, visual analysis, communication, verification, or service documentation.
Kamu does not use voice recordings, photographs, or video to identify you through facial recognition, voiceprint matching, or another biometric-identification system, and does not create biometric templates for that purpose, unless a specific feature clearly discloses the biometric processing and obtains any consent required by law before it occurs.
3.5 Identity and screening information
Where verification is necessary for account security, payments, legal compliance, trust, or marketplace safety, Kamu or a verification vendor may collect identification details, identity documents, selfies, liveness results, business records, licence or credential information, and verification status.
Marketplace Providers may also be asked to complete credential, licence, sanctions, fraud, criminal-record, or other legally permitted screening appropriate to the service category and location. Screening requirements and available records vary by jurisdiction and service. Kamu may receive the screening status, date, relevant result, and information necessary to assess eligibility. A completed verification or screening process reduces certain risks but is not a guarantee of identity, qualifications, conduct, safety, or service quality.
3.6 Information from other people and organizations
We may receive information from:
- other users who invite you, communicate with you, identify you as a participant, or submit information relating to a transaction;
- Marketplace customers and Marketplace Providers involved in a request or service;
- Workspace administrators and the organization that manages a Workspace;
- identity providers, payment processors, communications vendors, verification providers, and Connected Accounts;
- service partners, referral partners, educational or work-integrated-learning programs, and other organizations through which you apply or participate;
- public and professional sources, including business registries, credential registries, portfolios, and professional-networking profiles; and
- security, fraud-prevention, sanctions, and legal-compliance sources.
3.7 Information we derive
We may derive or infer information from the categories above, including language or feature preferences, likely service category, suggested providers, search relevance, fraud or safety risk indicators, usage trends, and product-performance measurements. We do not infer sensitive characteristics for advertising.
4. SIGN-IN AND CONNECTED ACCOUNTS
4.1 Email and password accounts
If you create an account using an email address and password, we collect the account information you submit and store a cryptographic representation of the password rather than the password in readable form. We may use email or telephone verification, multi-factor authentication, session information, and security signals to protect the account.
4.2 Sign in with Google
If you use Sign in with Google, Google provides information within the permissions displayed during sign-in. For standard authentication, this generally includes:
- a unique Google account identifier;
- your email address and email-verification status;
- your name; and
- your profile photograph, if you have one and choose to make it available.
Kamu uses this information to authenticate you, create or link your Kamu account, display your profile, prevent fraud, protect account security, and provide customer support. Using Sign in with Google does not, by itself, give Kamu access to your Gmail messages, Google Drive files, contacts, calendar, or other Google Workspace content.
4.3 Sign in with Apple
If you use Sign in with Apple, Apple provides a unique Apple user identifier and, depending on your choices and whether it is the first authorization, may provide your name and email address. If you use Hide My Email, Apple provides a private relay address. Kamu uses this information for authentication, account creation or linking, account security, fraud prevention, and support. We recognize the stable Apple-provided account identifier rather than treating an email address as the sole account identifier, and we honour Apple's private email relay.
When a Kamu account created with Sign in with Apple is deleted, or when revocation is otherwise required, Kamu revokes the applicable Sign in with Apple authorization tokens in accordance with Apple's requirements. You can also manage Sign in with Apple authorizations in your Apple Account settings.
4.4 Optional Google Workspace connections
Connecting Google Workspace is optional and separate from Sign in with Google. Kamu requests additional Google permissions only when you choose a feature that needs them. The Google authorization screen identifies the requested scopes before you grant access.
Depending on the feature and permissions you approve, Kamu may process:
| Optional connection | Information that may be processed | Purpose |
|---|---|---|
| Gmail read access | Message metadata, sender and recipient information, subject lines, message bodies, labels, threads, and attachments selected or retrieved for the feature you request | Find, summarize, organize, or use email information in a user-requested Kamu workflow |
| Gmail compose or send access | Recipient information, subject, body, attachments, draft state, and send status | Create a draft or send a message only when you request or confirm that action |
| Google Drive access | File and folder metadata and the contents of files selected, opened, or otherwise required for the action you request, subject to the permissions shown by Google | Find, open, summarize, organize, attach, or use a file in a user-requested Kamu workflow |
| Connection records | Google account identifier, granted scopes, encrypted authorization tokens, token expiry, connection state, and last synchronization information | Maintain and secure the connection, obtain fresh access when authorized, and allow disconnection |
Kamu does not use a Google Workspace connection to access Gmail or Drive data for unrelated purposes. Kamu does not send a Gmail message, alter a file, or perform another external action merely because an AI model suggested it. Kamu validates the requested action and requires any confirmation indicated by the feature before executing it.
Kamu’s use of information received from Google APIs will adhere to the Google API Services User Data Policy, including the Limited Use requirements.
Kamu does not use, transfer, or permit the use of Google Workspace API data to create, train, or improve generalized, foundation, frontier, or other cross-user artificial-intelligence or machine-learning models. Google Workspace data is used only to perform the user-facing action specifically requested by the user.
Kamu does not use Google Workspace API data for advertising, creditworthiness, lending, insurance eligibility, or sale to data brokers. Human access is prohibited except where you expressly request support, access is necessary for security or abuse investigation, access is required by law, or properly aggregated and de-identified operational access is permitted under Google's policies.
4.5 Optional Microsoft connections
If you connect a Microsoft account, the permissions shown by Microsoft may allow Kamu to process Outlook email metadata or content, message drafts or sending information, OneDrive file metadata or content, account identifiers, granted permissions, authorization tokens, and connection status. We use this information only to provide the user-requested connected feature, secure and maintain the connection, and comply with law. Connecting Microsoft is optional and separate from creating a Kamu account.
4.6 Disconnecting an account
You can disconnect an optional Connected Account through the applicable Kamu settings or revoke Kamu's authorization in the third party's account settings. Disconnection stops new access after the revocation takes effect. We delete or de-identify stored Connected Account content and tokens according to Section 12, except for records we must retain for security, legal compliance, a transaction, or a dispute.
Disconnecting Google, Microsoft, or Apple from the third party's settings does not automatically delete your Kamu account. To delete the Kamu account, use the account-deletion process in Section 13.
5. ARTIFICIAL INTELLIGENCE, AUTOMATION, AND PERSONALIZATION
5.1 How AI features work
The Services include conversational assistance, transcription, text generation, summarization, search, recommendations, personalization, workflow automation, and other AI-assisted functions. Depending on the feature you choose, Kamu may process:
- your prompt, instruction, message, and prior conversation context;
- your profile settings, preferences, memory, routines, or task information relevant to the request;
- selected files, images, audio, video, or Connected Account content;
- service-request, Marketplace Provider, scheduling, transaction, or location information relevant to the request; and
- the AI output, safety classification, tool request, feedback, and technical metadata needed to deliver, secure, and improve the feature.
Kamu limits the context sent to an AI system to information reasonably necessary for the requested feature. You should not include passwords, authentication codes, full payment-card numbers, government identifiers, medical records, or other highly sensitive information in an AI prompt unless the feature expressly requests that information and explains why it is needed.
5.2 Third-party AI service providers
Kamu may use third-party AI and speech providers, including Anthropic, OpenAI, and, where enabled, Groq or another provider identified in the relevant in-product disclosure. These providers process information on Kamu's behalf to generate a response, transcribe audio, create speech, analyze an image, calculate an embedding, perform safety checks, or complete another function you request.
Before Kamu sends your Personal Information or private User Content to a third-party generative-AI, speech, vision, or transcription service, we provide a clear in-product disclosure describing the information involved, the purpose, and the relevant provider or provider category, and obtain your affirmative permission. We do not activate that third-party processing unless you give permission. Your decision to permit one AI feature does not authorize unrelated use of your information.
You may withdraw permission for future third-party AI processing through the in-product permission control available with the AI feature or by using the choices described at https://kamu.ca/privacy/choices/. If no withdrawal control is available for a feature, that feature's third-party AI processing remains disabled. Withdrawal does not affect processing that occurred lawfully before withdrawal, and it may prevent AI-dependent features from functioning. If an AI feature is necessary to perform a specific action you request, we will explain the consequence before you proceed.
5.3 AI training and model improvement
Kamu does not sell private User Content to AI model developers. Kamu does not use private User Content to train a generalized or cross-user AI model unless we first provide a separate, specific explanation and obtain your express opt-in consent. Refusing such consent does not prevent you from using the core Services.
Where commercially and technically available, Kamu uses provider configurations and contractual terms intended to prevent third-party AI providers from using submitted business or API data to train generalized models. Provider processing remains subject to the applicable contract and data controls identified in our notice for that provider.
The stricter Google Workspace restrictions in Section 4.4 apply to all information received through Google Workspace APIs, regardless of any other consent or setting.
5.4 AI actions and human responsibility
AI output may be incomplete, inaccurate, outdated, or unsuitable for your circumstances. Review important output before relying on it. Kamu may use automated systems to recommend content, rank search results, detect fraud or abuse, suggest a Marketplace Provider, or identify a potentially unsafe action. We do not permit an AI model to create its own authorization or to bypass permissions, transaction controls, business rules, or required user confirmation.
Unless we clearly notify you otherwise and applicable law permits it, Kamu does not make a decision producing legal or similarly significant effects about you solely through automated processing. Where applicable law grants a right to information, human review, or objection concerning automated decision-making, you may exercise that right using the contact information in Section 18.
5.5 Feedback about AI output
If you rate, correct, or comment on an AI response, we may use that feedback, together with a limited portion of the associated interaction, to evaluate safety and improve the Kamu feature. We remove or minimize identifiers where reasonably possible. We do not use Google Workspace API data for generalized AI model training or improvement.
6. HOW WE USE PERSONAL INFORMATION
We use Personal Information for the following purposes:
- Provide the Services: create and maintain accounts; authenticate users; provide conversations, tasks, routines, reminders, searches, recommendations, files, communications, marketplace, payment, and Connected Account features; and preserve preferences across sessions.
- Operate marketplace transactions: publish service requests, identify or recommend Marketplace Providers, exchange quotations and offers, coordinate work, facilitate communication, process payments and payouts, document completion, and manage reviews, disputes, refunds, and support.
- Personalize the experience: remember user-selected preferences, adapt responses, prioritize relevant information, and provide requested recommendations or automations.
- Provide AI-enabled functions: process prompts and selected context, generate or transform content, transcribe or synthesize speech, analyze images, and carry out user-confirmed tools or workflows.
- Communicate: send service notices, account verification, security alerts, transaction updates, reminders, support responses, and other communications necessary to administer the Services.
- Send marketing where permitted: send product news, offers, surveys, or other promotional communications when we have the consent or other lawful basis required by applicable law. You can unsubscribe from marketing without losing essential service communications.
- Protect people and the Services: verify identity or eligibility; secure accounts; enforce permissions; prevent, detect, and investigate fraud, abuse, unauthorized access, harmful activity, payment risk, and violations of our Terms of Service; and protect the rights, safety, and property of users, Marketplace Providers, Kamu, and others.
- Support, debug, and improve: diagnose errors, measure reliability and performance, respond to support requests, test changes, maintain compatibility, develop features, and conduct privacy-protective analytics.
- Administer Workspaces: provide controls and records to authorized administrators, enforce organization settings, and perform an organization's documented instructions.
- Comply with law and agreements: maintain tax, accounting, and transaction records; respond to lawful process; protect and exercise legal rights; administer insurance; resolve disputes; and satisfy regulatory, audit, and contractual obligations.
- Recruit and manage relationships: assess applications; conduct interviews, references, and assessments; communicate about opportunities; administer work-integrated learning or student projects; and maintain records concerning current or prospective personnel.
- Carry out a business transaction: evaluate or complete a financing, reorganization, merger, acquisition, sale, transfer, or other corporate transaction subject to appropriate confidentiality and legal safeguards.
7. LEGAL BASES FOR PROCESSING
Where applicable law requires a legal basis, we rely on one or more of the following:
| Legal basis | Examples |
|---|---|
| Performance of a contract or steps requested before a contract | Creating an account; providing a requested AI or marketplace feature; processing a transaction; communicating about a service request |
| Consent | Optional device permissions; marketing where consent is required; optional Connected Accounts; certain AI disclosures; sensitive-information processing; cookies or similar technologies where consent is required |
| Legitimate interests | Securing the Services; preventing fraud; improving reliability; providing support; understanding use; enforcing our agreements; protecting users, provided those interests are not overridden by your rights |
| Compliance with legal obligations | Tax and accounting records; sanctions or identity obligations; responding to valid legal process; privacy and consumer-protection obligations |
| Protection of vital interests | Responding to an immediate and serious threat to a person's life or safety where permitted by law |
Where we rely on consent, you may withdraw it at any time for future processing. Where we rely on legitimate interests, you may have a right to object. We will explain any material consequence of a choice when required.
8. HOW WE DISCLOSE PERSONAL INFORMATION
We disclose Personal Information only as described in this Policy, at the point of collection, with your direction or consent, or as otherwise permitted by law.
8.1 Vendors and subprocessors
We may provide information to vendors that perform services for Kamu, including cloud hosting, data storage, software infrastructure, communications, identity, verification, background screening, customer support, security, fraud prevention, AI and speech processing, mapping, notifications, analytics, document handling, payment processing, professional advice, and business administration. They may process information only for authorized purposes and must protect it under contractual or legal obligations appropriate to the service.
8.2 Marketplace participants
When you create, quote for, accept, schedule, or perform a service, we disclose information reasonably necessary for the customer and Marketplace Provider to evaluate and complete the transaction. Depending on the stage and service, this may include a profile, service description, general or precise service location, availability, qualifications, quotation, messages, attachments, payment or completion status, rating, and contact information. We limit information made visible before a match or confirmed transaction where practicable.
Public profile and listing information can be viewed by other users and, where a feature is intentionally public, may be indexed by search engines. Do not put confidential or unnecessary Personal Information in a public field.
8.3 Workspace customers and administrators
Authorized Workspace administrators may access account details, membership, activity, settings, User Content, logs, and records associated with their Workspace, subject to the organization's instructions and applicable law. If you use an employer or organization email address, the organization may be able to assume management of the account after appropriate verification and notice.
8.4 Payment and financial partners
We use payment processors, including Stripe, to process customer payments and Marketplace Provider payouts. The processor may collect payment-card, bank-account, identity, tax, and transaction information directly under its own privacy policy. Kamu receives transaction status, payment tokens, limited payment-method details, payout or onboarding status, and records needed for accounting, fraud prevention, support, and disputes.
8.5 Identity, verification, and Connected Account providers
We exchange the minimum information necessary with Google, Apple, Microsoft, identity-verification vendors, and other connected services to authenticate you, maintain a connection you authorize, verify status, prevent fraud, or provide the feature you request. Additional limits for Google Workspace data are in Section 4.4.
8.6 Corporate affiliates and professional advisers
We may disclose information to Razif Holdings Ltd. and another controlled affiliate for the shared services described in Section 2.3. We may also disclose information to lawyers, accountants, auditors, insurers, banks, and other professional advisers who are bound by professional, contractual, or legal confidentiality obligations.
8.7 Legal, safety, and enforcement disclosures
We may disclose information if we reasonably believe disclosure is necessary to:
- comply with applicable law, a court order, warrant, subpoena, regulatory request, or other valid legal process;
- enforce our Terms of Service or another agreement;
- investigate, prevent, or address fraud, abuse, a security incident, unlawful activity, or a violation of rights;
- collect an amount owed or resolve a payment dispute;
- protect the rights, property, or safety of Kamu, a user, a Marketplace Provider, or another person; or
- respond to an emergency involving a risk of death or serious physical harm.
We review government and law-enforcement requests for facial validity and appropriate legal authority, and we may challenge or narrow a request where appropriate.
8.8 Business transactions
Personal Information may be disclosed under confidentiality safeguards in connection with a proposed or completed merger, financing, reorganization, insolvency, acquisition, sale of assets, or transfer of all or part of a business. A successor may use the information only consistently with this Policy unless it provides notice and obtains any consent required by law.
8.9 At your direction
We disclose information when you ask us to do so, including when you send a message, share a file, connect a third-party account, invite another person, authorize an integration, publish a profile, or confirm an external action.
9. SALE, ADVERTISING, AND MARKETING
Kamu does not sell Personal Information for money. Kamu does not currently share Personal Information for cross-context behavioural advertising, use third-party advertising cookies, or use private User Content for targeted advertising.
We may send marketing email, text message, or push notification only where permitted by applicable law. Canadian commercial electronic messages are sent in accordance with Canada's Anti-Spam Legislation and related requirements. Marketing communications identify the sender and include a working unsubscribe method. We may retain a minimal suppression record after you unsubscribe so that we can honour the request.
Account verification, password reset, security, legal, transaction, service-status, and other non-promotional messages are service communications and may continue while you maintain an account or transaction.
If Kamu later introduces advertising, optional analytics, or tracking that requires notice or consent, we will update this Policy and the Cookie Policy and provide legally required controls before that processing begins.
10. SENSITIVE PERSONAL INFORMATION
Some information described in this Policy may be sensitive, including precise location, financial information, government identification, verification or screening information, the content of private communications, voice or image information, and information revealing health, disability, racial or ethnic origin, religion, sexual orientation, political opinion, union membership, or other protected characteristics.
We process sensitive Personal Information only when reasonably necessary for a requested feature, safety, security, legal compliance, accessibility, or another disclosed purpose, and with express consent where required. We restrict access and apply safeguards appropriate to the sensitivity and context. Kamu does not use sensitive Personal Information to infer characteristics for advertising.
Kamu is not a medical provider, and the Services are not an emergency, medical-record, or clinical-care system. Do not use Kamu to communicate an emergency. Call the applicable emergency service if immediate assistance is needed.
11. SECURITY
Kamu maintains administrative, technical, and physical safeguards designed to protect Personal Information against loss, theft, misuse, unauthorized access, disclosure, alteration, and destruction. Depending on the system and risk, safeguards include access controls, least-privilege permissions, authentication protections, encryption in transit, encryption or equivalent protection for sensitive stored information, secure credential handling, network and application controls, logging, monitoring, backups, vulnerability management, vendor review, and incident-response procedures.
You are responsible for maintaining the confidentiality of your credentials and devices, using a strong and unique password where applicable, enabling available account protections, reviewing external actions before confirming them, and notifying us promptly of suspected unauthorized access.
No method of transmission, storage, or security control is completely secure. We cannot guarantee absolute security. If a breach creates a legally reportable risk, we will notify affected individuals and regulators as required by applicable law.
Security concerns may be reported to security@razif.ca. Please do not include active exploit code, passwords, or sensitive user data in an unencrypted initial email.
12. RETENTION AND DELETION SCHEDULE
We retain Personal Information only for as long as reasonably necessary for the purposes described in this Policy, including providing the Services, maintaining security and continuity, completing transactions, resolving disputes, enforcing agreements, and meeting legal, tax, accounting, insurance, and regulatory obligations.
The following periods are our standard maximums unless a shorter period is selected through a feature, a longer period is required by law or a legal hold, or the information is retained in de-identified form that cannot reasonably identify an individual:
| Information category | Standard retention period |
|---|---|
| Account, profile, Workspace membership, and preferences | While the account is active; deletion from active systems ordinarily within 30 days after verified account deletion, subject to the exceptions below |
| Authentication credentials, sessions, identity-provider identifiers, and Connected Account tokens | While needed to maintain the account or connection; tokens are revoked or deleted promptly after disconnection or account deletion; residual protected backup copies expire within 90 days |
| Google Workspace content temporarily retrieved or cached to perform a request | Only as long as needed for the user-requested action and ordinarily no more than 30 days unless the user deliberately saves the content in Kamu; protected backup copies expire within 90 days |
| Conversations, messages, tasks, routines, memories, files, AI inputs and outputs, and other User Content | Until the user deletes the content or the account is deleted; deletion from active systems ordinarily within 30 days and protected backup copies within 90 days, unless needed for a transaction, Workspace instruction, safety matter, or legal obligation |
| Raw voice or audio used for transcription or a live AI interaction | Transient processing where practicable and no more than 30 days unless the user deliberately saves the recording, a call-recording notice provides another period, or retention is required for a reported safety or support issue; transcripts follow the User Content period |
| Precise location collected for an immediate feature | For the session or transaction and ordinarily no more than 90 days, unless the location is part of a service record, dispute, safety investigation, or user-saved content |
| Marketplace request, offer, work, rating, dispute, and completion records | Life of the account or transaction plus up to 7 years where needed for contractual, tax, accounting, insurance, fraud, or dispute purposes |
| Payment, payout, invoice, refund, tax, and accounting records | Up to 7 years after the transaction or longer where applicable law requires |
| Marketplace Provider identity, licence, credential, insurance, verification, and screening records | While the provider is active; underlying sensitive screening material is minimized and ordinarily deleted within 2 years after it is no longer needed, while eligibility and audit records may be retained up to 7 years where required for safety, legal, or insurance purposes |
| Security, fraud, access, and audit logs | Ordinarily up to 24 months; longer if associated with an active investigation, legal hold, or serious incident |
| Customer-support and complaint records | Up to 3 years after resolution, or longer if connected to a transaction, legal claim, or regulatory matter |
| Marketing-consent and preference records | While marketing continues; unsubscribe and suppression records are retained as long as reasonably necessary to honour the choice and demonstrate compliance |
| Recruitment, internship, contractor, and student-project application records | Up to 2 years after the decision, unless you consent to a longer talent-pool period or law requires another period |
| Privacy requests, consent records, and compliance evidence | Up to 7 years after completion where reasonably necessary to demonstrate compliance or resolve a complaint |
Information in secure backups is isolated from ordinary use and deleted or overwritten according to the backup lifecycle. We may retain information beyond the standard period where required to comply with law, preserve evidence, collect an amount owed, protect safety, resolve a dispute, or comply with a valid legal hold. Once the exception ends, the information is deleted, de-identified, or returned to the ordinary schedule.
13. ACCOUNT DELETION AND REVOCATION
13.1 How to request deletion
You may initiate account deletion:
- in the Kamu application through Settings > Account > Delete Account;
- through the public account-deletion page at https://kamu.ca/account-deletion/, including if you no longer have the application installed; or
- by contacting privacy@razif.ca.
We may verify your identity and authority before deleting the account. We will not ask for your password by email. If the account is controlled by a Workspace, we may refer Workspace data requests to the organization while processing Personal Information for which Kamu is independently responsible.
13.2 What deletion does
After a verified request and any required notice period, Kamu will:
- disable access to the account;
- delete or de-identify Personal Information and User Content from active systems according to Section 12;
- revoke or delete available Google, Apple, Microsoft, and other Connected Account tokens associated with the deleted account;
- stop future marketing other than a minimal suppression record; and
- instruct applicable vendors to delete Personal Information where required and technically available.
Deleting the Kamu account does not delete information held independently by a Marketplace Provider, Workspace organization, identity provider, payment processor, or other third party. You must contact that party for its records.
13.3 Information that may remain
Deletion may be delayed or limited for amounts owed, incomplete services, chargebacks, fraud or safety investigations, tax and accounting records, legal claims, regulatory obligations, other users' rights, Workspace instructions, or other grounds permitted by law. Messages sent to another person may remain in that person's account or a transaction record, although we may remove or de-identify your profile where appropriate.
We will tell you if we deny or restrict a deletion request and will explain any available appeal or complaint process unless prohibited by law.
14. YOUR PRIVACY RIGHTS AND CHOICES
Subject to applicable law, you may have the right to:
- know whether and how we process your Personal Information;
- access or obtain a copy of Personal Information;
- correct inaccurate or incomplete information;
- delete Personal Information;
- withdraw consent for future processing;
- object to or restrict certain processing;
- obtain certain information in a portable, machine-readable format;
- opt out of marketing, targeted advertising, sale, or sharing where applicable;
- request information about or human review of certain automated decisions;
- appeal a refusal of a privacy request where applicable; and
- complain to a privacy or data-protection regulator.
You may manage many choices in account, notification, Connected Account, device, cookie, and feature-specific AI permission controls. Additional instructions are available at https://kamu.ca/privacy/choices/.
To exercise a right that is not available in the Services, contact privacy@razif.ca. Describe the request and identify the Kamu account or interaction involved. We may request information reasonably necessary to verify identity, authority, jurisdiction, and the scope of the request. An authorized agent may submit a request where law permits, but we may require proof of authority and direct identity verification.
We will respond within the time required by applicable law. We do not discriminate against a person for exercising a privacy right. A request may be limited or refused where law permits, including where it would disclose another person's information, interfere with legal privilege, compromise security, conflict with a legal obligation, or cannot be verified. We will provide an explanation and appeal information where required.
14.1 Canadian residents
Canadian residents may request access to and correction of Personal Information, withdraw consent subject to legal or contractual restrictions and reasonable notice, and challenge our compliance with applicable federal or provincial privacy law. We may retain information where permitted or required by law despite withdrawal or deletion.
14.2 European Economic Area, United Kingdom, and Switzerland
Where the General Data Protection Regulation, United Kingdom GDPR, Swiss data-protection law, or a similar law applies, you may have rights of access, rectification, erasure, restriction, objection, portability, and withdrawal of consent. You may also complain to the supervisory authority where you reside, work, or believe an infringement occurred.
14.3 California and other United States residents
Where applicable United States state law grants privacy rights, you may request confirmation, access, correction, deletion, or portability and may appeal certain decisions. Kamu does not sell Personal Information or share it for cross-context behavioural advertising. We do not use or disclose sensitive Personal Information for purposes that require a statutory right to limit under California law. We will recognize legally required browser or device opt-out signals if we begin processing subject to such a signal.
14.4 Marketing, notifications, and device choices
- Use the unsubscribe link in a marketing email or the stated reply method for a commercial text message.
- Change push-notification preferences in Kamu or device settings.
- Change microphone, camera, photo, and location permissions in device settings.
- Disconnect an optional Connected Account in Kamu or the third party's settings.
- Withdraw future optional AI permission through the in-product control available with the AI feature or by contacting privacy@razif.ca.
15. INTERNATIONAL PROCESSING AND TRANSFERS
Kamu is based in Canada. We and our vendors may process Personal Information in Canada, the United States, and other countries where Kamu, Razif Holdings Ltd., Marketplace participants, or service providers operate. The laws in those countries may differ from the laws where you live, and information may be accessible to courts, law-enforcement authorities, or national-security authorities under local law.
Where required, Kamu uses an approved transfer mechanism, contractual data-protection clauses, adequacy decision, risk assessment, consent, or another lawful basis for an international transfer. We also require appropriate confidentiality, security, and data-use restrictions from vendors. You may contact privacy@razif.ca for information about applicable transfer safeguards.
16. CHILDREN AND MINORS
The Services are not directed to children. You must be at least 18 years old and have the legal capacity required where you live to create an independent Kamu account or offer services as a Marketplace Provider. An organization-managed program for a younger participant may be offered only under a separate arrangement that addresses authorization, supervision, and applicable child-privacy law.
Kamu does not knowingly collect Personal Information from a child through the general Services. If you believe a child has provided Personal Information without valid authorization, contact privacy@razif.ca. We will investigate and delete or otherwise address the information as required by law.
17. THIRD-PARTY SERVICES AND EXTERNAL LINKS
The Services may link to or interoperate with a third-party website, application, map, identity provider, AI provider, payment processor, communication service, or Marketplace Provider. A third party may collect information directly from you and may receive information you authorize Kamu to disclose. Its own terms and privacy policy apply to its independent processing.
Review the third party's privacy information before using the service. Kamu is not responsible for a third party's independent privacy practices, but this does not limit any responsibility Kamu has for selecting and supervising a vendor that processes Personal Information on our behalf.
18. CONTACT, COMPLAINTS, AND REGULATORY RIGHTS
Questions, privacy requests, and complaints may be directed to:
Privacy Officer
Kamu Administration Ltd.
Kamu, a Razif company
1322 Avenue G N
Saskatoon, Saskatchewan S7L 2A7
Canada
Email: privacy@razif.ca
Website: https://kamu.ca/privacy/choices/
Legal notices that are not privacy requests may be sent to legal@razif.ca. Security reports may be sent to security@razif.ca. Customer-support matters may be sent to support@kamu.ca.
We will investigate a privacy complaint and explain our findings and any responsive action. If you are not satisfied, you may complain to the privacy or data-protection authority with jurisdiction, including the Office of the Privacy Commissioner of Canada or an applicable provincial, state, national, or regional authority.
19. CHANGES TO THIS POLICY
We may amend this Policy to reflect changes in the Services, technology, law, vendors, or our processing practices. The "Last Updated" date identifies the current version. We will post the revised Policy at https://kamu.ca/privacy/ and provide additional notice, or obtain consent, where required by law.
If a change materially affects how we use Personal Information already collected, we will not apply the materially different use retroactively without a lawful basis and any required notice or consent.
20. ACCESSIBILITY AND PRECEDENCE
You may request this Policy in an accessible format by contacting privacy@razif.ca. If this Policy is translated, the English version governs to the extent permitted by law in the event of an inconsistency, except where applicable law requires another version to prevail.
Kamu Administration Ltd.
Kamu, a Razif company
© 2026 Kamu Administration Ltd. All rights reserved.
