1. Controller and contact
KYSTA, Dorpsweg 46A, 1697 KB Schellinkhout, the Netherlands, is the controller for personal data processed through the KYSTA service. KYSTA is registered with the Dutch Chamber of Commerce under number 89960017.
Privacy questions and requests can be sent to privacy@kysta.app. General product and account support is available at support@kysta.app.
2. Data KYSTA processes
- Identity and profile: device identity, display name, locale, timezone, profanity preference and optional verified email address.
- Tracking content: onboarding answers, selected goals, custom goals and activities, check-ins, measurements, daily reflections, notes, schedule choices and calculated progress.
- Potentially sensitive content: information you choose to record may reveal health, mental wellbeing, dependencies, sexuality, finances or other special-category information.
- Notifications: reminder preferences, timezone and web-push subscription details when notifications are enabled.
- Service and security: session identifiers, request and error metadata, IP address and user-agent data in security logs, support-access audit records, plan entitlement and voucher state, plus the version and time of your legal document acceptance.
- Billing and payment: billing country, verified account email, selected plan and billing period, Mollie customer, payment, mandate and subscription references, payment status, invoice number, amounts, VAT and service period. KYSTA does not receive or store your full bank or card details.
3. Purposes and legal bases
| Purpose | Legal basis |
|---|---|
| Provide identity, sync, goals, logging, receipts, exports and account controls | Performance of the service contract |
| Process sensitive information you deliberately choose to record | Explicit consent, which can be withdrawn |
| Send optional reminders and account email codes | Consent and performance of the requested service |
| Secure KYSTA, prevent abuse, diagnose failures and audit administrator support access | Legitimate interests in service security |
| Maintain legally required financial records | Legal obligation, where paid plans apply |
| Start, administer and cancel a paid Plus subscription and make invoices available | Performance of the subscription contract and legal obligations |
KYSTA does not use your tracking content for advertising and does not sell it. If consent is withdrawn, processing based on that consent stops; processing already performed lawfully is not retroactively invalidated.
4. Storage and retention
Profile and tracking data is retained while your KYSTA profile is active or until you delete it. Push subscription data is retained until notifications are disabled, the subscription expires, or the tracking profile is cleared. Expiring validation codes become unusable after their validity period.
Security and support audit records are retained only while needed to protect the service, investigate incidents, meet legal obligations or establish legal claims. Where immediate deletion from a backup is not technically possible, data is isolated from normal use and removed through the backup lifecycle.
Invoices, payment references and related financial administration are normally retained for seven years where Dutch tax law requires it, including after a tracking profile or subscription is ended. Failed or abandoned checkout records are retained only as long as needed for reconciliation, security and dispute handling.
5. Recipients and transfers
Data may be processed by infrastructure, database, email-delivery and web-push providers acting for KYSTA, by Mollie as the payment service provider for paid subscriptions, and by authorised support personnel where access is necessary and audited. Mollie receives the verified account email, amount, currency, billing country and KYSTA payment references needed to complete and administer the transaction. Only the data needed for each service is shared.
KYSTA prefers processing in the European Economic Area. If a provider processes data outside the EEA, KYSTA requires a lawful transfer mechanism such as an adequacy decision or approved contractual safeguards.
6. Cookies and device storage
The app uses strictly necessary session and CSRF protection mechanisms. It also keeps an effective-user-scoped offline working copy and an idempotent evidence outbox on your device so the app can remain useful through connection loss. Authentication secrets are not stored in browser storage.
The public landing page does not use advertising cookies, behavioural analytics or cross-site tracking. Hosting systems may process limited access logs for delivery and security.
7. Security
KYSTA uses HTTPS, scoped database access, audited administrator support sessions and field-level encryption for reflective notes and short-text context. No internet service can promise absolute security, so controls are reviewed and updated as the service changes.
8. Progress calculations and automated decisions
KYSTA automatically calculates progress, streaks, status messages and earned rewards from your saved evidence. These calculations are motivational product features; they do not make decisions that produce legal or similarly significant effects.
9. Your rights
Depending on the processing and applicable law, you may request access, correction, erasure, restriction, portability, or object to processing. You may withdraw consent at any time and lodge a complaint with the data protection authority where you live or work.
Profile details can be corrected in Profile. A machine-readable JSON backup and evidence CSV are available in Settings. The clear data control removes your tracking profile. You can also email privacy@kysta.app. Requests are handled without undue delay and normally within one month.
10. Children
KYSTA is not directed at children. Anyone below the digital-consent age that applies in their country should not use the service without valid parent or guardian authorisation.
11. Changes to this statement
Material changes will be dated and communicated in the app where appropriate. Earlier processing remains governed by the statement that applied at that time.
