Introduction & Scope
KEENL (“we”, “us”, “our”, or the “Company”) operates the website located at keenl.com (the “Site”), the KEENL AI website builder platform (the “Service”), and related subdomains, applications, and tools that link to this Privacy Policy.
This Privacy Policy applies to all visitors, users, prospective customers, Site Credit holders, and anyone who otherwise interacts with KEENL online or offline. It describes the personal information we collect, how we use it, with whom we share it, and the rights you have over your data.
If anything in this policy is unclear, write to support@keenl.com and a real human on our team will reply within two business days with a clear answer — no legalese, no runaround.
By accessing or using KEENL, you confirm that you have read and understood this Privacy Policy. If you do not agree with its terms, please discontinue use of the Service and contact us so we can address your concerns.
Information We Collect
We collect a minimal amount of information — only what we need to build, host, and support your website, and to communicate with you about it. The data we collect falls into three categories.
2.1 · Information you give us directly
- Account information: name, email address, password (hashed & salted), phone number (optional, only if you request a call-back), and the country you operate in.
- Billing information: payment method details processed by our PCI-DSS compliant payment processor. We never see or store your full card number, CVV, or bank credentials on KEENL servers.
- Business information you submit to the AI builder: business name, industry, address, hours, contact details, brand colors, logos, photos, written copy, products, services, and any prompts you provide during the AI generation step.
- Domain registration data: if we register a domain on your behalf, the registrar requires your name, address, email, and phone number (WHOIS data). This is required by ICANN policy.
- Support correspondence: emails, chat messages, screen recordings, design briefs, and feedback you share with our design and engineering team.
2.2 · Information we collect automatically
- Device & log data: IP address, browser type and version, operating system, device identifiers, referring/exit pages, pages visited, and timestamps.
- Usage analytics: aggregated behavior on our marketing site and dashboard (pages visited, features used, time on page) via privacy-respecting analytics tools.
- Cookies and similar technologies: as described in detail in Section 04 — Cookies & Tracking .
- Performance data: for the websites we host on your behalf, aggregated traffic and uptime logs to maintain service quality and diagnose issues.
2.3 · Information from third parties
- Payment processors: confirmation of successful payments, refunds, and fraud-screening signals.
- Identity verification providers: when required for high-value transactions or to comply with anti-fraud regulations.
- Marketing partners: if you arrive at KEENL via an affiliate link, paid ad, or referral, we receive the referring source and any campaign identifier (without revealing your identity to the partner).
We do not collect special categories of data (race, religion, health, sexual orientation, biometric data, government IDs) unless you voluntarily provide it in your website content. We do not buy data from data brokers. We do not track you across unrelated third-party websites for advertising.
How We Use Your Data
We process your personal information for the following purposes, on the following legal bases:
| Purpose | Data used | Legal basis |
|---|---|---|
| Create and manage your KEENL account | Account info, email | Contract performance |
| Generate your website using AI | Business inputs, brand assets, prompts | Contract performance |
| Process Site Credit purchases and refunds | Billing data, transaction history | Contract performance, legal obligation |
| Register and renew your domain name | WHOIS contact data | Contract performance, legal obligation |
| Provide lifetime human support | Account, support correspondence, design assets | Contract performance, legitimate interest |
| Detect and prevent fraud, abuse, security incidents | IP, device, log data, behavior signals | Legitimate interest, legal obligation |
| Send service announcements (outages, policy updates) | Email, account status | Contract performance, legitimate interest |
| Send marketing emails (only with consent) | Email, behavioral data | Consent (you can opt out anytime) |
| Improve the platform through aggregated analytics | Anonymized usage data | Legitimate interest |
| Comply with tax, accounting, and legal obligations | Billing records, transaction history | Legal obligation |
Under the EU General Data Protection Regulation (GDPR), our “legitimate interests” are always balanced against your fundamental rights, and we perform a documented assessment (LIA) before relying on this basis. You can request a copy of any LIA by emailing support@keenl.com .
Cookies & Tracking
Cookies are small text files placed on your device when you visit a website. KEENL uses cookies and similar technologies (local storage, pixels, SDKs) for the purposes described below. You can manage your cookie preferences at any time via our in-app Cookie Preferences panel or your browser settings.
4.1 · Categories of cookies we use
4.2 · Cookies set on the websites we build for you
Websites created on KEENL may use their own cookies depending on the features you enable — for example, an analytics integration, a contact form, an appointment booking widget, or a shopping cart. These cookies are governed by your own privacy policy that you publish on the site, not by this Privacy Policy. You are the controller of any personal data collected through your KEENL site; we act as a processor on your behalf.
4.3 · Do Not Track & Global Privacy Control
KEENL honors the Global Privacy Control (GPC) signal and the “Do Not Track” setting in your browser. When we detect either signal, we automatically opt you out of non-essential cookies and the sale or sharing of personal information (for the purposes of California law).
Third-Party Services
To run KEENL reliably, we rely on a small number of carefully selected third-party processors. Each has signed a Data Processing Agreement (DPA) with us that complies with GDPR Article 28 and equivalent standards. Below is the current list — we update this page whenever a change is made.
| Provider | Purpose | Location | Data shared |
|---|---|---|---|
| Freemius | Payment processing, fraud screening, tax handling | EU | Name, email, billing address, last 4 digits of card, IP |
| Cloudflare | DNS, CDN, DDoS protection, security | Global (edge network) | IP, request metadata, TLS fingerprint |
| Amazon Web Services | Website & database hosting, file storage | US East / EU West (configurable) | Customer site content, account data, uploaded files |
| OpenAI & Anthropic | AI website generation, copy assistance | United States | Business prompts, generated content (no account identifiers sent) |
| Resend / Postmark | Transactional & marketing email delivery | United States / EU | Email address, name, message content |
| Namecheap / Cloudflare Registrar | Domain registration & DNS | United States | WHOIS contact data (name, address, phone, email) |
Sharing & Disclosure
We do not sell, rent, lease, or trade your personal information to third parties for their own marketing purposes. Full stop. We only share data in the following limited circumstances:
- With service providers that process data on our behalf under written agreements (listed in Section 05).
- With your consent when you explicitly direct us to share information — for example, when you transfer a Site Credit to another person.
- For legal reasons when we believe in good faith that disclosure is necessary to (a) comply with a valid subpoena, court order, or applicable law, (b) detect or prevent fraud, security incidents, or illegal activity, or (c) protect the safety, rights, or property of KEENL, our users, or the public.
- In a business transaction if KEENL is acquired, merged, or sells substantially all of its assets. You will receive advance notice by email and on this page.
- Aggregated, de-identified data that cannot reasonably be used to identify you — for example, “30% of KEENL sites are in the wellness industry.” This is not personal information.
Even though some privacy laws only restrict “selling” in a narrow sense, we extend the same protection to all forms of paid data sharing. The only money that changes hands around your data is the $119 you pay us for a Site Credit — and even then, your data is not part of the transaction.
Data Security
We take the security of your data seriously and have implemented technical and organizational measures aligned with SOC 2 and ISO 27001 standards. These include:
- Encryption in transit: all data is transmitted over TLS 1.3 or higher.
- Encryption at rest: all databases and file storage are encrypted using AES-256.
- Password hashing: passwords are hashed with Argon2id and never stored in plaintext.
- Access control: principle of least privilege, role-based access, mandatory MFA for all staff, and audited access logs.
- Network security: Web Application Firewall (WAF), DDoS mitigation, IP allow-listing for administrative tasks, and segregated production environments.
- Backups: encrypted, geographically redundant daily backups with point-in-time recovery, tested quarterly.
- Vendor management: every third-party processor is vetted for security posture and bound by a DPA.
- Incident response: a documented breach response plan with notification commitments of 72 hours to authorities and affected users when legally required.
- Employee training: all KEENL staff complete mandatory privacy and security training upon hire and annually thereafter.
That said, no method of transmission over the internet or electronic storage is 100% secure. While we strive to protect your personal information, we cannot guarantee absolute security. You are responsible for maintaining the confidentiality of your account password and for any activity on your account.
Data Retention
We keep your personal data only as long as necessary to provide the Service, comply with our legal obligations, resolve disputes, and enforce our agreements. Specific retention periods are:
| Data category | Retention period | Reason |
|---|---|---|
| Active account & site content | While your account is active + 30 days after deletion | Service operation, recovery window |
| Billing & transaction records | 7 years after last transaction | Tax, accounting, anti-fraud law |
| WHOIS / domain contact data | Duration of registration + required retention period | ICANN policy |
| Support correspondence | 3 years after last contact | Continuity of lifetime support |
| Server logs & security logs | 90 days | Security investigation window |
| Analytics data | Aggregated: indefinite · Raw: 90 days | Product improvement |
| Marketing email engagement | Until you unsubscribe + 30 days | Suppression list management |
| Backups | 30 days rolling | Disaster recovery |
When the retention period expires, we either delete the data irreversibly or anonymize it so it can no longer be associated with you. If immediate deletion is not possible (for example, because the data is stored in an immutable backup), we isolate the data and delete it as soon as the backup cycle permits.
Your Rights & Choices
You have meaningful control over your personal information. Depending on where you live, you may have some or all of the following rights:
Right to access
Request a copy of the personal data we hold about you, in a portable format.
Right to rectification
Ask us to correct any information that is inaccurate or incomplete.
Right to deletion
Request that we erase your personal data, subject to legal exceptions.
Right to restrict processing
Ask us to pause processing while a complaint is investigated.
Right to data portability
Receive your data in a structured, machine-readable format (JSON / CSV).
Right to object
Object to processing based on legitimate interest or for direct marketing.
Right to opt out of sale
Even though we never sell your data, California residents can formally opt out.
Right to withdraw consent
Where processing is consent-based, withdraw it at any time without retaliation.
Right to lodge a complaint
File a complaint with your local data protection authority if unsatisfied.
Right to non-discrimination
We will never penalize you for exercising your privacy rights.
9.1 · How to exercise your rights
You can exercise most of these rights directly from your account dashboard (Settings → Privacy) or by emailing support@keenl.com . We respond to verified requests within 30 days , free of charge. If your request is complex, we may extend the response time by up to two further months and will inform you of the reason and the new timeline.
International Data Transfers
KEENL operates globally. When you use our Service from outside the United States, your data will be transferred to and processed in the United States and the European Union, where our primary infrastructure is located. We protect these transfers using the following safeguards:
- Standard Contractual Clauses (SCCs): approved by the European Commission in June 2021, integrated into all our Data Processing Agreements.
- UK International Data Transfer Agreement (IDTA): for transfers from the United Kingdom.
- Data Privacy Framework (DPF): where applicable, we rely on the EU-US Data Privacy Framework for certified recipients.
- Regional storage options: enterprise customers can elect to have their site and data hosted exclusively in the EU region.
- Transparency reports: we publish an annual report on government access requests and publish our policies on responding to such requests.
If you would like a copy of the SCCs or more information about specific transfer mechanisms, contact support@keenl.com .
Children’s Privacy
KEENL is a B2B service intended for adults operating legitimate businesses. The Service is not directed to children under the age of 16 (or such higher age as required by local law), and we do not knowingly collect personal information from children.
If you are a parent or guardian and believe your child has provided personal information to KEENL, please contact us at support@keenl.com and we will promptly delete the information. If you operate a KEENL-built website that knowingly collects data from minors (for example, an educational service), you are responsible for obtaining verifiable parental consent under applicable laws such as COPPA, GDPR-K, or PIPL.
AI & Automated Decisions
KEENL uses artificial intelligence to generate your website content, suggest layouts, and assist our human support team. We want to be transparent about how this works and the choices we have made.
- Your input is your data. Any business information, brand assets, or prompts you submit to the AI builder are used solely to generate your website and to refine it through your direct feedback. We do not use your private inputs to train foundation models.
- No fully automated decisions with legal effect. We do not subject you to any decision based solely on automated processing that produces legal effects concerning you (Article 22 GDPR).
- Human-in-the-loop. Every KEENL-built site is reviewed and approved by a human (you) before launch. Our support team — not a bot — handles all design and editing requests.
- Model providers. We use OpenAI and Anthropic as sub-processors. Both providers have committed to not retaining or training on API inputs, and we have entered into zero-data-retention agreements where available.
- Bias & accuracy. AI-generated copy is a starting draft. We encourage you to review, edit, and approve all content before publishing. KEENL does not guarantee the factual accuracy of AI-generated content.
Changes to This Policy
We may update this Privacy Policy from time to time to reflect changes in our practices, the Service, or applicable law. The “Last updated” date at the top of this page reflects when the most recent revision took effect.
For material changes — such as a new purpose of processing, a new category of recipient, or a change that affects your rights — we will provide at least 30 days’ advance notice by email and by a prominent in-app banner. We will not reduce your rights under this Privacy Policy without your explicit consent.
Previous versions of this Privacy Policy are archived and available on request.