Terms & Conditions

Last updated: 9 September 2026

Please read these Terms & Conditions carefully. By starting to use the Services, you confirm that you have read and accepted these Terms & Conditions.

They govern access to and use of the Kanbanchi Services and form a binding agreement between the Customer and Kanbanchi Ltd. If you accept these Terms on behalf of an organisation, you confirm that you have authority to bind that organisation. By creating an Account, accepting an Order Form, purchasing a Subscription, or otherwise using the Services, you agree to these Terms.

Kanbanchi Ltd. is a company registered in England and Wales under company number 10478311, with registered office at C K R House, 70 East Hill, Dartford, England, DA1 1RZ (the “Provider”, “Kanbanchi”, “we”, “us” or “our”).

  1. Definitions
    1. In these Terms & Conditions, unless the context requires otherwise:

      Account” means the account used by a Customer or End User to access the Services, together with associated profile, authentication and administrative information;

      Affiliate” means an entity that controls, is controlled by, or is under common control with a party;

      Agreement” means the agreement between the Customer and the Provider comprising these Terms & Conditions, any applicable Order Form, and any other document expressly incorporated into the agreement;

      Charges” means Subscription fees and any other amounts the Customer agrees to pay the Provider, including agreed charges for Customisations, training or other professional services;

      Customer” means an individual acting for business or professional purposes, or a legal entity, educational institution or other organisation, that enters into the Agreement, creates or controls an Account, purchases a Subscription or otherwise uses the Services;

      Customer Content” means content, files, text, comments, board information, attachments, communications and other materials submitted, created, uploaded, linked or made available by or for the Customer or its End Users through the Services;

      Customer Data” means Customer Content together with other data relating to the Customer or its use of the Services that is processed to provide, administer, secure or support the Services;

      Customer Personal Data” means Personal Data that the Provider processes on behalf of the Customer in connection with the Services where the Customer acts as Controller and the Provider acts as Processor;

      Customer Confidential Information” means Customer Data, Customer Personal Data and any other non-public information disclosed by or on behalf of the Customer to the Provider in connection with the Agreement that is marked as confidential or that a reasonable person would understand to be confidential given its nature and the circumstances of disclosure;

      Customer-Controlled Storage” means the Customer’s connected Google Drive, Microsoft OneDrive or other customer-controlled storage environment supported by the Services;

      Customisation” means a custom development, configuration, integration or other adaptation of the Services agreed between the Provider and the Customer;

      Data Protection Laws” means all privacy and data protection laws applicable to the relevant processing, including the UK GDPR and Data Protection Act 2018, the EU GDPR where applicable, and other applicable national or state privacy laws, in each case as amended or replaced from time to time;

      Data Processing Agreement (DPA)” means a data processing agreement entered into between the Customer and the Provider in connection with the processing of Personal Data under the Services;

      End User” means an individual whom the Customer authorises to access or use the Services under the Customer’s Account or Subscription;

      Force Majeure Event” means an event beyond a party’s reasonable control, including failure of public telecommunications or internet infrastructure, widespread cloud or utility failure, cyberattack not caused by that party’s breach of the Agreement, natural disaster, fire, flood, epidemic, war, terrorism, civil unrest, industrial dispute affecting a third party, or a change in law that prevents performance;

      Free Plan” means any no-charge version of the Services made available by the Provider from time to time, subject to the functionality and usage limits stated at the time;

      Intellectual Property Rights” means patents, rights to inventions, copyright and related rights, database rights, trade marks, service marks, business and domain names, rights in get-up and trade dress, goodwill, rights in designs, software rights, rights in confidential information and trade secrets, and all similar or equivalent rights anywhere in the world, whether registered or unregistered;

      Maintenance Services” means maintenance, updates, patches and technical changes applied to the Services by the Provider;

      Order Form” means a quotation, proposal, order form, online checkout confirmation or other written commercial document accepted by the Customer and the Provider that specifies a Subscription, Charges, Subscription Period or other service-specific terms;

      Personal Data” has the meaning given to “personal data” or an equivalent term under the applicable Data Protection Laws;

      Plan” means a level or edition of the Services offered by the Provider from time to time;

      Provider” means Kanbanchi Ltd.;

      Services” means the Kanbanchi cloud application and related web-based functionality, integrations, APIs, documentation, websites and support services made available by the Provider, excluding Third Party Services;

      Subscription” means paid access to a Plan for a specified Subscription Period, including any seats or usage rights included in that Plan or Order Form;

      Subscription Period” means the monthly, annual or other period for which a Subscription is purchased or renewed;

      Support Services” means support relating to use of the Services and identification and resolution of errors, excluding consulting, training and Customisations unless expressly included in the applicable Plan or Order Form;

      Term” means the term of the Agreement, commencing in accordance with Clause 2.1 and ending in accordance with Clause 2.2;

      Third Party Services” means products, applications, identity providers, storage services, platforms or other services provided by third parties that interoperate with the Services or are selected or connected by the Customer;

      Trial” means a time-limited trial of the Services made available without charge or at a promotional charge;

      UK GDPR” means the United Kingdom General Data Protection Regulation as it forms part of UK law, as amended from time to time.

    2. References to a “Controller”, “Processor”, “Subprocessor”, “Data Subject”, “processing” or “Personal Data Breach” have the meanings given to the corresponding concepts under applicable Data Protection Laws.
    3. References to “writing” include email and other electronic communications capable of being retained as a record. References to a Clause are to a clause of these Terms & Conditions.
    4. Headings are for convenience only. Words in the singular include the plural and vice versa. “Including” means “including without limitation”.
  2. Term
    1. The Agreement comes into force when the Customer first accepts these Terms, creates an Account, accepts an Order Form, purchases a Subscription or begins using the Services, whichever occurs first.
    2. The Agreement continues until terminated in accordance with Clause 17. A paid Subscription continues for its applicable Subscription Period and renews in accordance with Clause 10 unless cancelled.
    3. The Provider may update these Terms from time to time to reflect changes in law, the Services, security requirements or business practices. Where an update materially affects the Customer’s rights or obligations, the Provider will give reasonable notice before the change takes effect, unless a change is required sooner by law or for urgent security reasons. For paid Subscriptions, material commercial changes will normally apply from the next renewal unless otherwise agreed or required by law.
  3. Services
    1. Subject to the Agreement and, for paid Plans, payment of the applicable Charges, the Provider grants the Customer a limited, non-exclusive, non-transferable right during the Term to access and use the Services for the Customer’s internal business, professional, educational or organisational purposes, as permitted by the applicable Plan or Order Form.
    2. The Customer may permit End Users to use the Services within the scope of the Customer’s Plan. The Customer is responsible for administering its Account, assigning seats and permissions, and for End Users’ compliance with the Agreement to the extent permitted by law.
    3. The Customer must maintain reasonable security over its Account and must not knowingly permit unauthorised access. The Customer must promptly notify the Provider if it becomes aware of compromised credentials, unauthorised access or misuse of its Account.
    4. The Customer must not, except to the extent expressly permitted by applicable law: copy or reproduce the Services other than through normal use; sell, resell, rent or sublicense the Services; reverse engineer, decompile or attempt to derive source code; bypass usage limits or security controls; or access the Services for the purpose of building or benchmarking a competing service in a manner that violates applicable law or the Provider’s rights.
    5. The Provider may update, improve, modify or replace features of the Services. The functionality available to the Customer is determined by the applicable Plan and may change over time. The Provider will not intentionally make a material reduction to the core functionality of a prepaid Plan during the current paid Subscription Period without reasonable justification, except where required for security, legal compliance or Third Party Services.
    6. Trials and Free Plans may be subject to additional functionality, capacity, card, storage, seat or other limits displayed in the Services or on the Provider’s pricing pages. At the end of a Trial, the Customer may be moved to a Free Plan with limited functionality unless it purchases a paid Subscription. The Provider may change or discontinue a Free Plan on reasonable notice where practicable.
    7. Acceptable Use and Prohibited Conduct. The Customer and End Users must use the Services lawfully and must not use the Services to:
      1. damage, disable, overload, impair or interfere with the Services or another user’s use of the Services;
      2. gain or attempt to gain unauthorised access to accounts, systems, networks, data or security controls, or conduct unauthorised penetration testing, scanning or probing;
      3. introduce malware, malicious code, destructive content or other material designed to compromise systems or data;
      4. send spam, unsolicited bulk communications, fraudulent communications, or impersonate another person or organisation;
      5. infringe Intellectual Property Rights, privacy rights, confidentiality obligations or other rights of any person;
      6. upload, store, publish, transmit or distribute content that is unlawful, fraudulent, defamatory, threatening, harassing, hateful, discriminatory or designed to facilitate unlawful harm;
      7. upload, store, publish, transmit or distribute child sexual abuse material, content that sexually exploits or endangers minors, sexually explicit or pornographic content, or content primarily intended for sexual arousal;
      8. upload, store, publish, transmit or distribute gratuitously graphic violence, gore, cruelty or material reasonably inappropriate for a professional or educational collaboration service; or
      9. use the Services in any other manner that violates applicable law or materially threatens the security, integrity or reputation of the Services or other users.
    8. The Provider may investigate suspected violations of Clause 3.7 and may remove or restrict access to content, suspend Accounts or take other proportionate action where the Provider reasonably believes this is necessary to enforce the Agreement, protect users or systems, or comply with law. Where practicable and legally permitted, the Provider will notify the affected Customer. Serious or urgent violations may result in immediate suspension or termination.
    9. Customers may report suspected prohibited content or misuse to team@kanbanchi.com.
    10. Children and educational use. Kanbanchi is not directed to children under 13 as a standalone service and the Provider does not seek to contract directly with children under 13. Educational institutions and other organisations may authorise student or minor use under their direction. The Customer is responsible for determining which child-privacy or education laws apply to its use, managing access, obtaining any permissions or consents required of the Customer, and configuring the Services appropriately. The Provider will process Customer Personal Data in accordance with Clause 12 and applicable contractual obligations.
    11. If the Customer uses the Services for regulated or sensitive information, including health, financial, education or special-category data, the Customer is responsible for determining whether additional legal or contractual requirements apply and for obtaining any agreement required for that use before submitting the relevant data. The Services are not intended to require special-category Personal Data as part of ordinary use.
  4. Customisations
    1. The Provider and the Customer may agree that the Provider shall design, develop and implement Customisation(s) at an additional cost.
    2. Unless the parties expressly agree otherwise in writing, all Intellectual Property Rights in Customisations and any underlying or reusable tools, code, methods, know-how and components remain the property of the Provider or its licensors. The Customer retains ownership of Customer Content supplied for use in a Customisation.
    3. Once a Customisation is delivered or enabled, it forms part of the Services for the Customer and is subject to the Agreement.
    4. The Provider may reuse general ideas, know-how, methods, code and non-Customer-specific elements developed in connection with a Customisation, provided it does not disclose Customer Confidential Information.
  5. Maintenance Services
    1. The Provider will provide Maintenance Services during the Term and may deploy updates, patches, security fixes and other changes as reasonably necessary to maintain, secure or improve the Services.
    2. The Provider may temporarily suspend or restrict access to all or part of the Services for planned maintenance, emergency maintenance, security reasons or circumstances outside the Provider’s reasonable control. Where reasonably practicable, the Provider will provide advance notice of planned material interruptions.
  6. Support Services
    1. The Provider will provide Support Services appropriate to the Customer’s Plan during the Term.
    2. Additional support, onboarding or other support-related services may be available under certain Plans or as expressly agreed in an Order Form.
    3. Unless expressly agreed in an Order Form or separate written agreement, the Services are not subject to a customer-specific service level agreement (SLA), including contractual uptime, support-response or resolution-time commitments. Kanbanchi maintains internal business continuity, disaster recovery and service recovery objectives in accordance with its security and operational policies. Such internal objectives do not constitute contractual service levels unless expressly incorporated into an Order Form or other written agreement.
    4. The Provider may suspend Support Services where undisputed Charges are overdue, provided that the Provider will not use this right in a manner that prevents the Customer from reporting an urgent security or privacy issue.
  7. Customer Data
    1. As between the parties, the Customer retains all right, title and interest in Customer Content and Customer Data, except for rights in the Services or Provider technology. No ownership of Customer Content is transferred to the Provider by these Terms.
    2. The Customer grants the Provider and its authorised service providers a non-exclusive, worldwide, royalty-free licence during the Term, and for any limited post-Term retention permitted by the Agreement, to host, copy, transmit, access, display, adapt, process and otherwise use Customer Data only to the extent reasonably necessary to provide, secure, maintain and support the Services, operate Customer-requested functionality and integrations, comply with the Customer’s instructions, enforce the Agreement, or comply with law. Any processing of Personal Data under this licence remains subject to Clause 12. This licence does not permit the Provider to sell Customer Content.
    3. The Provider may create and use aggregated or irreversibly anonymised information that does not identify the Customer or any individual for security, analytics, service operation, capacity planning, research and improvement of the Services.
    4. The Customer represents and warrants that it has all rights, permissions and lawful bases necessary to submit Customer Data to the Services and to instruct the Provider to process it in accordance with the Agreement. The Customer must not instruct the Provider to process data in a manner that would violate applicable law.
    5. The Customer is responsible for the accuracy, quality and legality of Customer Content and for obtaining appropriate permissions from End Users, collaborators and other persons whose data the Customer places in the Services.
    6. The Customer grants the Provider a non-exclusive, royalty-free right to use the Customer’s name and logo to identify the Customer as a Kanbanchi customer in customer lists, case studies and marketing materials. The Provider will not disclose Customer Confidential Information or imply endorsement without permission. The Customer may request removal at any time by written notice, after which the Provider will cease new use and remove the relevant material from Provider-controlled online materials within a reasonable period.
  8. Integrations with Third Party Services
    1. The Services may interoperate with Third Party Services, including Google Workspace, Google Drive, Microsoft 365 and Microsoft OneDrive. Some integrations are selected, authorised or configured by the Customer and may require the Customer to accept the third party’s own terms and privacy practices.
    2. When the Customer enables or uses a Third Party Service integration, the Customer instructs the Provider to exchange the Customer Data reasonably necessary to operate that integration, subject to Clause 12. The Customer is responsible for permissions, tenant configuration and access settings within Customer-Controlled Storage and other Customer-selected Third Party Services.
    3. The Provider may add, change, suspend or discontinue integrations where reasonably necessary because of changes to Third Party Services, security, law, technical compatibility, commercial availability or product development. The Provider will use reasonable efforts to avoid unnecessary disruption to material paid functionality.
    4. Third Party Services are controlled by their respective providers. Except for the Provider’s obligations relating to its own authorised Subprocessors under Clause 12, the Provider does not warrant the availability, functionality, security or continued operation of a Third Party Service and is not responsible for acts or omissions of a third-party provider outside the Provider’s reasonable control.
  9. No assignment of Intellectual Property Rights
    1. Except for the limited rights expressly granted in the Agreement, nothing in these Terms assigns or transfers Intellectual Property Rights from the Provider to the Customer or from the Customer to the Provider.
    2. The Provider and its licensors retain all Intellectual Property Rights in the Services, software, documentation, designs, interfaces, templates, methods, know-how and Provider materials, including updates and improvements.
    3. If the Customer voluntarily provides feedback, suggestions or ideas about the Services, the Provider may use them without restriction or payment, provided that any Customer Confidential Information included in such feedback remains subject to Clause 11.
  10. Charges, Subscriptions, Renewals and Refunds
    1. The Customer must pay the Charges applicable to its selected Plan, Subscription, seats, Customisations and other agreed services.
    2. Paid Subscriptions may be offered on monthly, annual or other billing periods. Unless cancelled before the applicable renewal date, a paid Subscription automatically renews at the end of each Subscription Period for a further Subscription Period of the same length at the then-current applicable price, unless an Order Form states otherwise. The Customer’s supported payment method will be charged at purchase and on each renewal. Invoice or bank-transfer payment may be available where arranged with the Provider.
    3. The Customer may cancel automatic renewal through the subscription-management interface where available or by contacting the Provider’s Support team. Cancellation does not normally terminate access immediately. The Customer may continue to use the paid Subscription until the end of the current paid Subscription Period, after which the Account may revert to a Free Plan or otherwise be limited unless a new Subscription is purchased.
    4. The Customer may add, remove or reallocate seats through the interface or with the Provider’s Support team where the applicable Plan permits. Charges for seat changes during a billing period may be prorated in accordance with the Provider’s current billing rules or the applicable Order Form.
    5. Annual paid Subscriptions are covered by a 30-day 100% money-back guarantee. Refund requests must be submitted to the Provider’s Support team within the applicable 30-day period.
    6. Monthly paid Subscriptions are covered by a 10-day 100% money-back guarantee. Refund requests must be submitted to the Provider’s Support team within the applicable 10-day period.
    7. Unless stated otherwise, Charges are exclusive of taxes that the Provider is required to charge. The Customer is responsible for applicable sales, use, value-added or similar taxes associated with its purchase, except taxes based on the Provider’s net income. Where the Customer is legally entitled to an exemption, it must provide valid supporting documentation.
    8. Trials do not automatically create a paid Subscription unless the Customer affirmatively selects or accepts a paid Subscription. At the end of a Trial, the Account may move to the then-current Free Plan with limited functionality unless the Customer upgrades. Expiry of a Trial does not, by itself, trigger deletion of Customer Data; Customer Data remains subject to the normal retention and deletion rules in Clauses 12 and 18. Trial and Free Plan features and limits are described in the Services or on the Provider’s pricing pages.
    9. Educational institutions and other eligible organisations may receive discounts under the Provider’s then-current education or non-profit programme. Eligibility, discount level, billing requirements and included Plans are governed by the offer stated at the time of purchase or in an Order Form. Current education information is available at https://www.kanbanchi.com/kanbanchi-for-education.
    10. The Provider may change pricing for future Subscription Periods. A price change does not alter Charges already paid for the current prepaid Subscription Period.
    11. If an undisputed payment is overdue, the Provider may, after reasonable notice where practicable, suspend paid functionality until payment is made. The Customer remains responsible for Charges properly due before suspension or termination.
  11. Confidentiality obligations
    1. Each party may receive Confidential Information from the other. “Confidential Information” means any non-public information disclosed by or on behalf of a party in connection with the Agreement that is marked or identified as confidential, or that a reasonable person would understand to be confidential given its nature and the circumstances of disclosure. Customer Confidential Information constitutes Confidential Information of the Customer whether or not marked as confidential. The Provider’s Confidential Information includes non-public information concerning the Services, software, technology, security, architecture, commercial terms and business operations.
    2. Each receiving party must protect the other party’s Confidential Information using at least reasonable care, use it only to perform its obligations or exercise its rights under the Agreement, and disclose it only to its personnel, Affiliates, professional advisers, insurers, auditors, subcontractors and service providers who need to know it for that purpose and are subject to appropriate confidentiality obligations.
    3. Confidential Information does not include information that the receiving party can demonstrate:
      1. was lawfully known to it without restriction before disclosure;
      2. becomes publicly available without breach of the Agreement;
      3. is lawfully received from a third party without a confidentiality obligation; or
      4. is independently developed without use of the disclosing party’s Confidential Information.
    4. A receiving party may disclose Confidential Information to the extent required by applicable law, court order or competent authority, provided that, where legally permitted, it gives the disclosing party reasonable prior notice and reasonable assistance to seek protective treatment.
    5. Upon termination of the Agreement, each party must cease using the other party’s Confidential Information except to the extent retention is permitted or required by the Agreement, applicable law, a documented retention requirement, backup lifecycle, or for the establishment, exercise or defence of legal rights. Any retained Confidential Information remains protected by this Clause. Customer Data and Customer Personal Data are returned, retained or deleted in accordance with Clauses 12 and 18.
    6. The obligations in this Clause continue after termination for as long as the information remains confidential. Trade secrets remain protected for as long as they qualify as trade secrets under applicable law.
  12. Data protection
    1. General compliance and roles. Each party must comply with the Data Protection Laws applicable to its own processing. The Provider acts as a Controller for Personal Data it processes for its own account administration, billing, security, legal compliance, sales and marketing purposes where it determines the purposes and means of that processing. Where the Provider processes Customer Personal Data solely on behalf of the Customer in delivering the Services, the Customer acts as Controller and the Provider acts as Processor, unless applicable law or a separate agreement establishes a different role.
    2. Processing particulars. Where the Provider acts as Processor for Customer Personal Data, the following processing particulars apply unless an applicable Order Form or DPA states otherwise:
      1. Subject matter: provision, operation, maintenance, support, security, backup, recovery and deletion of Customer workspace and collaboration functionality within the Kanbanchi Services.
      2. Duration: for the Term and thereafter only for the limited period necessary to complete deletion, return, lawful retention or backup expiration in accordance with the Agreement and applicable law.
      3. Nature and purpose: collection, recording, organisation, structuring, storage, retrieval, consultation, use, transmission, alignment, restriction, erasure and destruction necessary to provide SaaS project/task management, boards, lists, cards, comments, collaboration, authentication, integrations, support, troubleshooting, maintenance, security, backup/recovery and deletion.
      4. Types of Personal Data: identifiers and account information; name and email; profile and authentication-related information; user-generated board, list, card, task and comment content; attachment references and metadata and, where accessed to provide the Services, information contained in linked files; collaboration and activity data; support communications; IP address, device/browser data and security/audit logs; and other Personal Data the Customer or its End Users choose to submit.
      5. Categories of Data Subjects: Customer administrators, End Users, employees and contractors of Customer organisations, collaborators, support contacts, and other individuals whose Personal Data the Customer or its End Users submit or make accessible through the Services.
      6. Customer rights and obligations: the Customer determines the purposes for which Customer Personal Data is submitted to the Services, configures access and permissions, provides lawful documented instructions, responds to Data Subjects as Controller, and may exercise the rights set out in this Agreement.
    3. Documented instructions. The Provider will process Customer Personal Data only on the Customer’s documented instructions, including instructions arising from the Customer’s configuration and use of the Services, Order Forms, support requests and other written directions, unless applicable law requires otherwise. If law requires processing outside the Customer’s instructions, the Provider will inform the Customer before processing unless the law prohibits that notice. The Provider will promptly inform the Customer if, in the Provider’s reasonable opinion, an instruction infringes applicable Data Protection Laws.
    4. Customer responsibilities. The Customer is responsible for ensuring that instructions, collection and use of Customer Personal Data have an appropriate lawful basis and comply with applicable Data Protection Laws. The Customer must provide required privacy information to its own Data Subjects and must not instruct the Provider to process special-category or other regulated data unless the Customer has established all conditions and safeguards required by law.
    5. Confidentiality and security. The Provider will ensure that persons authorised to process Customer Personal Data are subject to appropriate confidentiality obligations and will maintain technical and organisational measures appropriate to the risks of the processing. These measures include, as applicable to the Services, encryption in transit, provider-managed encryption at rest for Google Cloud Platform (GCP)-hosted application data, identity and access controls, role-based access and least privilege, logging and monitoring, vulnerability management, secure development, incident response, backup/recovery controls, personnel security measures and vendor risk management. Current security and assurance information is available through https://www.kanbanchi.com/security and the Kanbanchi Trust Center at https://trust.kanbanchi.com/.
    6. Subprocessors. The Customer gives the Provider general written authorisation to engage Subprocessors necessary to provide and secure the Services. The Provider will maintain a current list of relevant Subprocessors through its Trust Center or another reasonably accessible location. The Provider will impose data-protection obligations on Subprocessors that provide a level of protection appropriate to the processing and, where Article 28 or equivalent law applies, obligations no less protective than those required for the relevant processing. The Provider remains responsible for its Subprocessors to the extent required by applicable law. Where advance notice of a new Subprocessor is required by applicable law or an applicable DPA, the Provider will provide such notice by reasonable means and will consider reasonable objections based on legitimate data-protection grounds.
    7. International transfers. Where an international transfer of Customer Personal Data requires additional safeguards under applicable Data Protection Laws, the Provider will use an applicable lawful transfer mechanism, such as an adequacy decision, Standard Contractual Clauses, the UK International Data Transfer Agreement or UK Addendum, the EU-US Data Privacy Framework or UK Extension where the relevant recipient and transfer are eligible, or another lawful jurisdiction-specific mechanism. The exact mechanism depends on the relevant data flow, recipient, destination, roles and applicable law. The parties will reasonably cooperate to implement any additional customer-specific transfer documentation required by applicable law.
    8. Data Subject rights and assistance. Taking into account the nature of processing, the Provider will provide reasonable assistance to the Customer with responding to requests to exercise Data Subject rights relating to Customer Personal Data. If the Provider receives a request relating to Customer Personal Data for which the Customer is Controller, the Provider may refer the requester to the Customer unless law requires the Provider to respond directly.
    9. Compliance assistance and Personal Data Breaches. Taking into account the nature of processing and information available to the Provider, the Provider will provide reasonable assistance with the Customer’s applicable security, breach-notification, data protection impact assessment (DPIA) and supervisory-authority consultation obligations. The Provider will notify the Customer without undue delay after becoming aware of a Personal Data Breach affecting Customer Personal Data and will provide information reasonably available to support the Customer’s assessment and notification obligations.
    10. Deletion and return. During the Term, the Customer should export or preserve Customer Data it wishes to retain using available functionality or Customer-Controlled Storage. Upon termination or a valid deletion instruction, the Provider will delete or, where applicable and technically available, enable return or export of Customer Personal Data in accordance with the Agreement, including Clause 18, the Customer’s instructions and applicable law. Customer Personal Data may remain for the limited retention, deletion and backup lifecycles described in Clause 18. Any retained data remains protected and is not used beyond the applicable retention purpose.
    11. Data location and backup distinction. The parties acknowledge the following current architecture model:
      1. Kanbanchi-controlled application and board data is processed in the Provider’s Google Cloud Platform environment; the Provider’s current documented primary application data location is the United States, US Central region.
      2. Underlying files attached to Kanbanchi boards remain stored in the Customer’s connected Google Drive or Microsoft OneDrive, depending on the integration. The Provider processes the references, metadata and access information necessary to provide board and attachment functionality.
      3. Customer-created or scheduled Kanbanchi board backups are stored in the Customer’s connected Google Drive for Google customers or Microsoft OneDrive for Microsoft customers. These copies are customer-controlled, and their retention and disposal follow the Customer’s settings and the applicable provider lifecycle.
      4. Separately, the Provider maintains scheduled daily backups of its production GCP database for recovery purposes. These Provider-controlled recovery copies are retained for seven days from creation. Deletion from live systems does not immediately remove data already contained in an existing backup; such data is placed beyond normal operational use and expires through the seven-day rotation. If a backup is restored, applicable deletion requests, account-status changes and retention controls are reapplied before return to normal production use.
    12. Audits and assurance. The Provider will make available information reasonably necessary to demonstrate compliance with its Processor obligations, including relevant security and privacy documentation and, where available and appropriate, independent assurance such as ISO 27001 and SOC 2 materials through the Trust Center access process. Where a direct audit or inspection is required by applicable Data Protection Laws and the information already provided is insufficient, the Provider will permit and contribute to a reasonable audit by the Customer or an independent auditor appointed by the Customer, subject to reasonable notice, confidentiality, security, scope and scheduling controls that do not prevent the Customer from meeting its legal obligations. Audits must not compromise other customers’ data or the security of the Services and should avoid unnecessary duplication. Unless the audit identifies material non-compliance by the Provider, the Customer bears its own audit costs and any reasonable incremental Provider costs agreed in advance.
    13. Separate DPA. Clause 12 is intended to provide binding data-processing terms for Customer Personal Data where the Provider acts as Processor. Where applicable law requires a separate Data Processing Agreement, the parties will enter into an appropriate DPA. Where a separate DPA is requested for procurement purposes or otherwise agreed between the parties, the parties may execute one. A signed DPA prevails over these Terms to the extent of a conflict concerning the processing of Personal Data.
    14. Controller processing. Personal Data for which the Provider acts as Controller is governed by applicable Data Protection Laws and the Provider’s Privacy Policy at https://www.kanbanchi.com/privacy-policy. The Privacy Policy may be updated separately from these Terms to reflect the Provider’s Controller processing activities.
  13. Warranties
    1. The Provider warrants that it has the legal right and authority to enter into and perform the Agreement and will provide the Services with reasonable skill and care.
    2. The Provider will comply with laws applicable to the Provider’s performance of its obligations under the Agreement.
    3. The Customer warrants that it has authority to enter into the Agreement, and that its use of the Services and instructions to the Provider will comply with applicable law and the rights of third parties.
    4. Nothing in the Agreement excludes or restricts any statutory guarantee, remedy or right that cannot lawfully be excluded or restricted.
  14. Acknowledgements and Warranty Limitations
    1. The Customer acknowledges that cloud software may contain defects, errors or vulnerabilities and that availability can depend on internet, cloud, identity, storage and other Third Party Services outside the Provider’s direct control. The Provider does not warrant that the Services will be uninterrupted, error-free or completely secure.
    2. The Provider does not warrant that the Services will be compatible with every third-party product, configuration or Customer environment, or that the Services will meet every particular business, legal or regulatory requirement of the Customer unless expressly agreed in writing.
    3. Any uptime figures, response targets, roadmap statements, beta features or estimated delivery dates communicated outside an applicable Order Form or other signed written agreement are informational only and do not constitute contractual commitments. Service level commitments are governed by Clause 6.3.
    4. The Services do not constitute legal, financial, accounting, tax, medical or other professional advice. The Customer is responsible for determining whether the Services and its configuration are appropriate for the Customer’s intended use and regulatory obligations.
    5. Descriptions, screenshots and feature comparisons on the Provider’s websites are intended to explain the Services. Minor differences or changes do not constitute a breach where the Services remain materially consistent with the applicable paid Plan or Order Form.
    6. This Clause is subject to Clause 13.4 and Clause 15.1.
  15. Limitations and Exclusions of Liability
    1. Nothing in the Agreement excludes or limits liability for death or personal injury caused by negligence; fraud or fraudulent misrepresentation; or any other liability to the extent that it cannot lawfully be excluded or limited.
    2. Neither party is liable to the other for indirect or consequential loss, or for loss of profits, revenue, anticipated savings, business opportunity, goodwill or reputation, arising out of or in connection with the Agreement, except to the extent such loss forms part of a third-party claim for which liability cannot lawfully be excluded.
    3. The Provider is not liable for loss caused by: the Customer’s or an End User’s breach of the Agreement; Customer-controlled permissions or configuration; Customer’s failure to maintain appropriate copies of data within Customer-Controlled Storage; unauthorised or unsupported integrations; or acts or omissions of Third Party Services outside the Provider’s reasonable control, except to the extent the loss is caused by the Provider’s breach of its own obligations.
    4. The Provider’s aggregate liability arising out of or in connection with the Agreement, whether in contract, tort (including negligence), breach of statutory duty or otherwise, will not exceed the total Charges paid or payable by the Customer for the affected Services during the 12 months immediately preceding the event giving rise to the first claim. If the Customer has been a paid Customer for less than 12 months, the cap is the Charges paid or payable for the paid period up to that event. If the affected Service was provided to the Customer without Charge, the Provider’s aggregate liability for that Service will not exceed £100.
    5. The limitations in Clause 15.4 do not reduce the Customer’s obligation to pay Charges properly due under the Agreement.
  16. Force Majeure Event
    1. A party is not liable for failure or delay in performing an obligation to the extent caused by a Force Majeure Event, except for payment obligations already due for Services supplied before the event.
    2. The affected party must, where reasonably practicable, notify the other party of the Force Majeure Event and take reasonable steps to mitigate its effects and resume performance.
    3. If a Force Majeure Event materially prevents the Provider from supplying a paid Service for a prolonged period, either party may terminate the affected paid Subscription on reasonable notice. Any refund required by applicable law or expressly agreed in an Order Form will be provided.
  17. Termination
    1. Subscription cancellation and termination of the Agreement are different actions. Cancelling automatic renewal under Clause 10.3 normally allows the Customer to use the paid Subscription until the end of the current Subscription Period. Deleting an Account or requesting immediate termination may make Customer Data inaccessible sooner.
    2. The Customer may terminate the Agreement by deleting its Account through the Services where available or by giving written notice to the Provider. The Customer should export any Customer Data it wishes to retain before deletion or termination.
    3. The Provider may suspend or restrict access immediately where reasonably necessary to address an urgent security risk, prohibited content, suspected fraud, unlawful use, a legal requirement, material risk to other customers, or non-payment after applicable notice. The Provider will use proportionate measures and, where practicable and legally permitted, explain the reason for suspension.
    4. Either party may terminate the Agreement for a material breach by the other party that is incapable of remedy, or if a remediable material breach is not remedied within 14 days after written notice specifying the breach. The Provider may terminate immediately for serious violations of Clause 3.7, fraud, deliberate security abuse or other conduct that reasonably requires immediate action.
    5. The Provider may discontinue the Services or cease offering them in a particular jurisdiction where continued provision is no longer legally, technically or commercially practicable. For a prepaid paid Subscription terminated by the Provider for this reason and not because of the Customer’s breach, the Provider will refund the prepaid Charges attributable to the unused portion of the affected Subscription Period, unless a different lawful remedy applies.
    6. If the Provider terminates for the Customer’s material breach, the Customer is not entitled to a refund of Charges already paid, except to the extent required by mandatory law.
    7. On termination: the Customer’s right to use the Services ends as specified in the termination notice or, for a cancelled renewal, at the end of the current Subscription Period; Customer Data is handled under Clauses 12 and 18; outstanding Charges properly accrued remain payable; and provisions intended by their nature to survive termination continue in force, including confidentiality, Intellectual Property Rights, liability, data protection for retained data, governing law and payment obligations.
  18. Data Retention and Account Deletion
    1. The Provider retains Customer Data only for as long as necessary for the applicable service, security, support, legal or contractual purpose and in accordance with its documented retention and deletion procedures. Different data categories may have different retention periods.
    2. Active account data is retained while required for the active Account or customer relationship. An Account that remains inactive for 365 consecutive days and has no active Subscription may be subject to automatic deletion after advance notification in accordance with the Provider’s deletion procedures.
    3. The Customer may request Account and Personal Data deletion through available functionality or by contacting the Provider. Following validation, the Provider will delete or irreversibly anonymise data from active systems without undue delay, except for information that must be retained for a documented lawful purpose or that remains temporarily in restricted recovery copies or provider-controlled deletion lifecycles.
    4. When a board is deleted through the Services, the board and associated customer-controlled files may be moved to the trash or recycle area of the Customer’s connected Google Drive or Microsoft OneDrive, depending on the integration and current product configuration. The current documented product configuration permits restoration for up to 30 days. Related board/application data in Kanbanchi active systems may remain for operational and recovery purposes for up to 365 days if the board is not restored, after which it is securely deleted from active systems unless a lawful retention exception applies.
    5. Provider-controlled scheduled production database backups are separate from Customer-created board backups. The Provider creates scheduled daily GCP database backups and retains each for seven days. Deleting data from live systems does not immediately remove versions already contained in an existing backup. Such residual data is placed beyond normal use and expires automatically through the seven-day rotation. If a backup is restored, applicable deletion requests and retention controls are reapplied before return to normal production use.
    6. Customer-created or scheduled Kanbanchi board backups are stored in the Customer’s connected Google Drive for Google customers or Microsoft OneDrive for Microsoft customers. These backups are controlled by the Customer; the Provider does not define their retention period or disposal lifecycle. The Customer’s settings and the applicable Google Drive or Microsoft OneDrive lifecycle govern their retention and deletion.
    7. The Provider may retain minimum records where necessary for legal, tax, accounting, fraud-prevention, security, audit, dispute-resolution, contractual or regulatory purposes, or where a legal or investigation hold applies. Such records are access-restricted, used only for the applicable purpose and deleted or anonymised when the retention requirement ends.
  19. Notices
    1. Notices under the Agreement may be sent by email, through the Services, through the Provider’s online contact or support facilities, or by post or courier where a physical notice is appropriate.
    2. The Provider may send notices to the email address associated with the Customer’s Account or to an administrative or billing contact supplied by the Customer. The Customer is responsible for keeping those contact details current.
    3. Legal notices to the Provider may be sent to team@kanbanchi.com or to Kanbanchi Ltd., C K R House, 70 East Hill, Dartford, England, DA1 1RZ.
    4. A notice sent by email is deemed received when it is delivered without a bounce or delivery-failure notice, subject to evidence to the contrary. A notice posted within the Services or on the Provider’s website is effective when displayed where that method is appropriate for the type of notice and permitted by law.
  20. Assignment
    1. The Customer may not assign, transfer or otherwise dispose of its rights or obligations under the Agreement without the Provider’s prior written consent, not to be unreasonably withheld where the proposed assignee is able to perform the Customer’s obligations.
    2. The Provider may assign or transfer the Agreement to an Affiliate or in connection with a merger, reorganisation, sale of business or substantially all relevant assets, provided that the assignee assumes the Provider’s material obligations under the Agreement. The Provider will give notice where required by law or reasonably practicable.
  21. No Waivers
    1. A failure or delay by either party to exercise a right or remedy does not waive that right or remedy. A waiver is effective only if given in writing and only for the specific circumstance for which it is given.
  22. Severability
    1. If any provision of the Agreement is found unlawful, invalid or unenforceable, the remaining provisions continue in effect.
    2. If an unlawful, invalid or unenforceable provision would be enforceable if part of it were deleted or modified, the provision will apply with the minimum deletion or modification necessary to make it enforceable, to the extent permitted by law.
  23. Third Party Rights
    1. Except as expressly stated in an applicable Order Form or DPA, a person who is not a party to the Agreement has no right under the Contracts (Rights of Third Parties) Act 1999 to enforce any term of the Agreement.
    2. The parties may vary, suspend, terminate or rescind the Agreement without the consent of any third party, subject to applicable law.
  24. Entire Agreement and Order of Precedence
    1. The Agreement constitutes the entire agreement between the parties relating to its subject matter and supersedes prior discussions, proposals and representations concerning the same subject matter, except for fraud or fraudulent misrepresentation and except for documents expressly incorporated into the Agreement.
    2. If there is a conflict between documents forming the Agreement, a signed DPA prevails for Personal Data processing matters; an applicable Order Form or statement of work prevails for service-specific and commercial matters; and these Terms & Conditions apply otherwise. A document prevails only to the extent of the relevant conflict.
    3. The Provider’s Privacy Policy and Cookie Policy govern the Provider’s Controller processing and use of cookies, respectively, but do not override a signed DPA or the Processor obligations in Clause 12.
  25. Governing Law and Jurisdiction
    1. The Agreement and any non-contractual obligations arising out of or in connection with it are governed by the laws of England and Wales.
    2. The courts of England and Wales have exclusive jurisdiction over disputes arising out of or in connection with the Agreement, unless the parties agree otherwise in writing or applicable law requires otherwise.
  26. Links to Provider Websites and Third-Party Websites
    1. The Services and Provider websites may contain links to third-party websites or resources. Unless expressly stated otherwise, those websites are not controlled by the Provider. The Provider is not responsible for third-party content, availability or practices, and inclusion of a link does not by itself constitute endorsement.
    2. The Customer may link to the Provider’s public website in a fair and lawful manner that does not damage the Provider’s reputation or falsely imply sponsorship, approval or association.
  27. Privacy and Cookies
    1. The Provider’s processing of Personal Data for which it acts as Controller is described in its Privacy Policy at https://www.kanbanchi.com/privacy-policy. The Provider may update that policy from time to time in accordance with applicable Data Protection Laws.
    2. The use of cookies and similar technologies on the Provider’s websites is described in the Cookie Policy at https://www.kanbanchi.com/cookie-policy and in the applicable consent-management interface.
    3. Security, compliance and current Subprocessor information is available through the Provider’s Security page at https://www.kanbanchi.com/security and Trust Center at https://trust.kanbanchi.com/.
 
Kanbanchi is GDPR compliant
Privacy Overview

This website uses cookies so that we can provide you with the best user experience possible. Cookie information is stored in your browser and performs functions such as recognising you when you return to our website and helping our team to understand which sections of the website you find most interesting and useful.