KS-Merge emblem KS-Merge Merge and share — be in control.

Version 2 · effective 31 Jul 2026

Privacy Policy

Effective date: 31 July 2026 This policy explains how KS-Merge (Kokoro Solutions Ltd., Jamaica) processes personal data. We process personal data in accordance with the Jamaica Data Protection Act, 2020 ("DPA 2020") and, where a customer or its users are in those regions, the EU/UK General Data Protection Regulation. For documents you upload to a workspace, your firm is the data controller and KS-Merge is a data processor acting under the Data Processing Agreement.

1. Data we process

Category Examples Lawful basis
Account data name, email, role, password hash, 2FA settings performance of a contract
Uploaded documents & rendered bundles may contain sensitive personal data processed on the controller's instructions
Delivery metadata recipients, share access times, IP addresses contract; legitimate interests (security, chain of custody)
Billing data plan, seats, invoices, payment references contract; legal obligation
Telemetry & logs audit events, error logs, device/browser info legitimate interests (security, abuse prevention)

2. What we use data for

Providing and securing the service; rendering, certifying and delivering bundles at your direction; billing; abuse prevention (trial rate limits, scan quarantine); legally required record-keeping; and service communications. We do not sell personal data or use your documents for advertising or AI training. On file inspection: we automatically scan uploads for security purposes only — checking file structure, format integrity, embedded active content, and malware signatures. This is automated and does not involve reviewing the substance of your documents. We do not read, analyse, or use document content for any purpose beyond providing the service you requested, except where a security signal requires investigation or the law compels disclosure. See the Terms of Service §4a for how we track and act against malicious files and the division of security responsibility.

3. Retention and erasure

4. Your rights

Subject to law, you may request access (within 72 h, in-app export), rectification (immediate), erasure (within 30 days), restriction, portability (ZIP of JSON + originals) and objection, and you may withdraw consent where processing relies on it. Contact dpo@kokorosolutions.com. You may lodge a complaint with the Office of the Information Commissioner (Jamaica) or, if you are in the EEA/UK, your local supervisory authority.

5. Sub-processors and international transfers

We use a small number of trusted service providers to operate the service — including cloud hosting and object storage, our payment processor, our email provider, and an independent time-stamp authority for certified signing — each bound by a data-processing agreement. The current list is available to workspace customers on request (dpo@kokorosolutions.com); we give 30 days' notice of changes. Some of these providers process data outside Jamaica (including in the United States and the European Union). Where the DPA 2020 requires it, such transfers are made only where the destination ensures an adequate level of protection or appropriate contractual safeguards are in place; for EEA/UK personal data we additionally rely on the 2021 EU Standard Contractual Clauses or an adequacy decision.

6. Customer-elected external storage (Google Drive)

A workspace may choose to connect its own Google Drive so that new uploads and finished bundles are stored in the customer's Google account instead of KS-Merge storage. If you enable this, those files are held under your relationship with Google, subject to Google's terms — Google acts as your provider, not our sub-processor — and they leave KS-Merge's infrastructure. We record each file's fingerprint so we can detect tampering, but we cannot control, retain, or delete files that live in your Google Drive. You are responsible for that account and its retention.

7. Security

Your files are kept private to your workspace, encrypted in transit and at rest, protected by strong passwords and recommended two-factor sign-in, scanned for malicious content on upload, and covered by a tamper-evident activity log. We notify the Office of the Information Commissioner within 72 hours of becoming aware of a personal-data breach that meets the DPA 2020 threshold, and we notify affected data subjects without undue delay.

8. Cookies

We use only strictly necessary cookies (session, CSRF). No advertising or cross-site tracking cookies.

9. Contact

Data Protection Officer · Kokoro Solutions Ltd. · dpo@kokorosolutions.com