Back to home

PRIVACY POLICY

Pivotaltasks.com

Last updated: February 15, 2026


1. INTRODUCTION

This Privacy Policy aims to inform you about how KIMIND (hereinafter "we", "our" or "Kimind") collects, uses, shares and protects your personal data in connection with the use of the Pivotaltasks.com service (hereinafter "the Service" or "the Platform").

Kimind attaches great importance to the protection of your personal data and undertakes to process it in compliance with:

  • The General Data Protection Regulation (GDPR - Regulation EU 2016/679)
  • The French Data Protection Act of January 6, 1978, as amended
  • Any other applicable data protection regulations

2. DATA CONTROLLER

The data controller for your personal data is:

KIMIND
Registered office: 17 rue du Colisée, 75008 Paris, France
Email: legal@kimind.com
Phone: +33 1 75 43 82 33

Data Protection Officer (DPO):
Email: rgpd@kimind.com


3. DATA COLLECTED

3.1 Identification and contact data

When creating your account, we collect:

  • Email address (required for authentication and communications)
  • Username (if provided)
  • Profile information (if voluntarily provided)

3.2 Content data

As part of using the Service, we collect and store:

  • Tasks: title, description, status, dates, priority
  • Projects: name, description, settings
  • Assignments: assignment of tasks to team members
  • Any other content that you create, import or share via the Service

3.3 Technical and connection data

Automatically collected during your use of the Service:

  • Connection data: IP address, browser type, operating system
  • Usage data: pages viewed, features used, date and time of connection
  • Cookies and technical identifiers: see section 6

3.4 Payment data

For paid subscriptions:

  • Billing information: name, billing address
  • Banking data: processed directly by our payment provider (we do not store your complete banking data)

4. PURPOSES AND LEGAL BASES OF PROCESSING

We process your personal data for the following purposes:

Purpose Legal basis Data concerned
Account creation and management Contract performance Email, credentials
Service provision Contract performance All content data
Subscription and payment management Contract performance Billing data
Customer support Contract performance / Legitimate interest Email, account data
Service improvement Legitimate interest Usage data
Anonymized statistics Legitimate interest Anonymized usage data
Compliance with legal obligations Legal obligation Billing data, logs
Security and fraud prevention Legitimate interest Connection data, logs

5. DATA RECIPIENTS

Your personal data is processed by:

5.1 Authorized Kimind staff

Only Kimind staff members who need access to your data in the course of their duties have access to it.

5.2 Host

Lovable.dev (Lovable Labs Sweden AB, Tunnelgatan 5, 11137 Stockholm, Sweden): Platform and data hosting

5.3 Service providers

We use subcontractors for:

  • Payment processing (PCI-DSS compliant payment processor)
  • Sending transactional emails
  • Statistical analysis (anonymized data only)

All our subcontractors are carefully selected and contractually required to comply with GDPR.

5.4 Third-party integrations

If you choose to integrate your account with Linear.com, certain data may be shared with this service according to your integration settings. This integration is carried out under your responsibility. We invite you to consult Linear.com's privacy policy.

5.5 Legal authorities

We may be required to communicate your data to competent authorities if required by law or to protect our legal rights.


6. COOKIES AND SIMILAR TECHNOLOGIES

6.1 Cookies used

The Service uses the following types of cookies:

Technical cookies (strictly necessary):

  • Authentication and session management
  • Service security
  • Language and interface preferences

Statistical cookies:

  • Audience and usage measurement (anonymized data)
  • User experience improvement

6.2 Cookies NOT used

Kimind does NOT use any:

  • Advertising cookies
  • Behavioral tracking cookies for commercial purposes
  • Third-party social media cookies
  • Invasive profiling mechanisms

6.3 Cookie management

You can manage your cookie preferences (except strictly necessary cookies) via:

  • Your account settings
  • Your browser settings

Refusing technical cookies may prevent the use of certain Service features.


7. DATA RETENTION PERIOD

We retain your personal data for the following periods:

Type of data Retention period
Active account data As long as the account is active
Content data (tasks, projects) Until the user deletes them
Data after account deletion 30 days (recovery period) then permanent deletion
Billing data 10 years (legal accounting obligation)
Connection and security logs 12 months maximum

At the expiration of these periods, your data is either permanently deleted or irreversibly anonymized.


8. DATA SECURITY

Kimind implements appropriate technical and organizational measures to protect your personal data against:

  • Accidental loss
  • Unauthorized access
  • Fraudulent use
  • Unauthorized modification or disclosure

These measures include:

  • Encryption of data in transit (HTTPS/TLS)
  • Encryption of data at rest
  • Secure authentication
  • Strict access control
  • Regular security monitoring and audits
  • Backup procedures

Despite these measures, no data transmission over the Internet can be guaranteed as completely secure. You are responsible for the confidentiality of your login credentials.


9. DATA TRANSFERS OUTSIDE THE EU

Your personal data is hosted and processed within the European Union.

In case of transfer outside the EU (particularly via subcontractors), we ensure that:

  • Appropriate safeguards are in place (EU Commission standard contractual clauses, adequacy decisions, etc.)
  • The level of protection of your data is equivalent to that of GDPR

10. YOUR RIGHTS

In accordance with GDPR and the French Data Protection Act, you have the following rights:

10.1 Right of access

You can obtain confirmation that your data is being processed and access that data.

10.2 Right of rectification

You can request correction of your inaccurate or incomplete data.

10.3 Right to erasure ("right to be forgotten")

You can request deletion of your data in certain cases (withdrawal of consent, objection to processing, unlawfully processed data, etc.).

10.4 Right to restriction of processing

You can request restriction of processing of your data in certain circumstances.

10.5 Right to data portability

You can receive your data in a structured and commonly used format, and transmit it to another data controller.

10.6 Right to object

You can object to the processing of your data for legitimate reasons, particularly for processing based on legitimate interest.

10.7 Right to withdraw consent

Where processing is based on your consent, you can withdraw it at any time.

10.8 Right to define post-mortem directives

You can define directives regarding the fate of your data after your death.

10.9 Exercising your rights

To exercise your rights, contact us:

  • By email: rgpd@kimind.com
  • By mail: KIMIND - DPO, 17 rue du Colisée, 75008 Paris, France

We undertake to respond within a maximum period of one month from receipt of your request. This period may be extended by two months in case of complexity, in which case you will be informed.

Proof of identity may be requested to secure your request.

10.10 Right to lodge a complaint

You have the right to lodge a complaint with the French National Commission for Information Technology and Civil Liberties (CNIL):

  • Website: www.cnil.fr
  • Address: 3 Place de Fontenoy - TSA 80715 - 75334 PARIS CEDEX 07
  • Phone: +33 1 53 73 22 22

11. PROCESSING PRINCIPLES

In accordance with GDPR, we undertake to:

  • Lawfulness, fairness, transparency: process your data lawfully, fairly and transparently
  • Purpose limitation: collect your data for determined, explicit and legitimate purposes
  • Data minimization: collect only adequate, relevant and necessary data
  • Accuracy: keep your data accurate and up to date
  • Storage limitation: retain your data only as long as necessary
  • Integrity and confidentiality: guarantee the security of your data

12. NO-RESALE COMMITMENT

Kimind formally undertakes to:

  • Never sell your personal data to third parties
  • Never rent your personal data to third parties
  • Never share your data for third-party advertising or marketing purposes
  • Only collect data strictly necessary for the operation of the Service

Your data is used exclusively to provide you with the Service and improve it.


13. MINORS

The Service is not intended for minors under 16 years of age. We do not knowingly collect personal data from minors. If you are a parent or legal guardian and discover that your child has provided us with personal data, contact us at rgpd@kimind.com so we can delete it.


14. PRIVACY POLICY MODIFICATIONS

We may modify this Privacy Policy at any time to reflect:

  • Service developments
  • Legal or regulatory changes
  • Improvements to our data protection practices

Any substantial modification will be notified to you by email and/or via the Service at least 30 days before it takes effect. The date of last update is indicated at the top of this document.

We encourage you to regularly consult this Privacy Policy.


15. CONTACT

For any questions regarding this Privacy Policy or the processing of your personal data:

Data Protection Officer:
Email: rgpd@kimind.com

KIMIND
17 rue du Colisée
75008 Paris, France
Email: legal@kimind.com
Phone: +33 1 75 43 82 33


16. TRANSPARENCY AND GDPR COMPLIANCE

Kimind is committed to complete transparency regarding the processing of your personal data. This Privacy Policy aims to inform you clearly and accessibly about:

  • The data we collect
  • The reasons for this collection
  • Who has access to your data
  • Your rights and how to exercise them

We regularly conduct GDPR compliance audits and update our practices to ensure the highest level of protection for your personal data.


Last updated: February 15, 2026