Skip to content
kimo.
The appPrivacyTerms
Contact us
Back to Kimo

KIMO · YOUR INFORMATION

Privacy Policy

What we handle, why we need it and the choices you have.

Last updated: 21 September 2026

ON THIS PAGE1. Who we are2. Information we handle3. Purposes and legal grounds4. Providers and sharing5. Storage and security6. Retention7. Your choices and rights8. Account and data deletion9. This website10. Young people11. Changes and contact
A privacy question?
info@periwin.com
The essentials

Kimo connects to your employer’s HR system. Your employer decides how employment records are used; Periwin provides the app and related services. The store-release app also uses Firebase Analytics and OneSignal. This policy explains those different activities rather than treating all of your information as one dataset.

1. Who we are and what this covers

Kimo is provided by Periwin Solutions Limited (“Periwin”, “we”, “us”), a UK company with its business contact address at 44a, Lowlands Road, Harrow, England, HA1 3AN, United Kingdom. Contact us at info@periwin.com.

This policy covers the Kimo iOS and Android app and kimo.periwin.com. It does not replace your employer’s employee privacy notice.

Your employer or the organisation that provides your Kimo account is normally the controller of its employment records: it decides why those records exist, what they contain, who may access them and how long they must be kept. Where Periwin hosts or handles those records on that organisation’s instructions, we act as its processor. We act as a controller for our own business enquiries, support administration, website operation and product analytics. These roles depend on the particular processing, not simply on who owns the app.

2. Information we handle

The information available in Kimo depends on your employer’s configuration, the permissions assigned to you and the features you use. We receive information from you, your employer’s connected HR system and the technical services described below.

  • Sign-in and account information: your company site address, sign-in identifier or email, employee identifier, role and session credentials. Your password is sent to your company’s system to authenticate you; the current app does not save that password for future sign-ins.
  • Employee information: name, contact details, photograph if supplied by your employer, company, department, job title, joining date and employment status. The app retrieves your employee record and the fields made available by the company’s system. Depending on that record, this can also include address, date of birth, emergency contacts, pay and contract information, tax identifiers, bank details or other custom HR fields. Not every organisation supplies every category.
  • Work and leave information: shift dates, times, work locations, breaks, availability, swap or cover requests, overtime records, leave entitlement, dates, duration, reasons and approval or withdrawal status. A named workplace is not a GPS reading.
  • Other enabled features: information entered into available expense, onboarding, directory, recruitment or performance functions, including amounts, descriptions, tasks and feedback. Some features currently store entries locally rather than submitting them to the employer’s server.
  • Communications: in-app notices and notifications, and information you choose to include when contacting support, such as your email, company site and a description of the problem.
  • Technical information: app and device identifiers, operating system and app version, usage events, notification subscription information and network information processed by the providers in section 4.

Sensitive information. Sickness leave, medical explanations or some employee fields may reveal health or other specially protected information. Your employer is responsible for determining the appropriate legal grounds and safeguards for its use of those records. Only include information necessary for the request; avoid sending medical documents, passwords or unnecessary sensitive details to our general support email.

The current app does not request access to precise device location, the camera, microphone, phone contacts or photo library. A profile photograph displayed from your employer’s system is different from access to your device’s photographs. The app contains no advertising display SDK and does not make automated employment decisions.

3. Why information is used and the legal grounds

Employment information is used to authenticate access, show permitted records, operate work and leave workflows, synchronise information and make relevant updates available. Your employer determines its lawful basis, which may include performing an employment contract, meeting legal obligations or legitimate interests in administering its workforce. It must also identify an additional legal condition when processing special-category information. Using Kimo is not, by itself, consent to all employment processing.

For activities where Periwin is the controller, the purposes and grounds are:

  • Enquiries and support: our legitimate interests in responding to people, resolving problems and administering our services; contractual necessity where we are taking steps at your request to enter into, or perform, a contract with you personally.
  • Website delivery, security and service administration: our legitimate interests in operating a reliable service, preventing abuse and maintaining business records, subject to your interests and rights.
  • Product measurement: understanding which screens are used and improving the service. Our interest in improving Kimo does not override rules requiring consent for non-exempt storage or access on a device. Where those rules apply, consent is required before that activity; a lawful exemption must meet its own conditions, including any required means of objection.
  • Legal compliance and claims: compliance with an applicable legal obligation, or legitimate interests in establishing, exercising or defending legal claims, as appropriate.

This policy is an explanation of processing, not a request for blanket consent. The current app does not provide an in-app analytics preference switch. See section 7 for how to raise an objection or ask about collection associated with your account.

4. Service providers and sharing

Information is shared with authorised people in your organisation and with providers needed to operate the relevant service. Your employer’s permissions and processes determine which managers, HR staff and administrators can access its records. We do not sell your personal information or use your HR records to serve advertisements.

Firebase Analytics — Google

The store-release app includes Google Analytics for Firebase. It records screen usage and automatically collected app events, with technical details such as app-instance identifiers, device or app information and engagement information. Kimo also sets a property identifying the company site host. Its analytics integration does not deliberately attach employee names, emails, leave reasons or pay records to analytics events. That does not make the SDK’s information anonymous: technical identifiers can distinguish an installation. Collection, including advertising-related identifiers where available, depends on platform permissions and the release and provider settings. See Firebase privacy information and Google’s app-data disclosure guidance.

OneSignal — notifications

OneSignal connects a notification subscription to your account using your company site and employee ID. The app also sends your email, company site, employee ID and role to OneSignal. Its SDK processes notification tokens, subscription and permission status, device and app details, session information and network information such as IP address. Notification content and delivery or interaction information may also be processed to deliver and manage messages. See OneSignal’s Privacy Policy and its SDK data information.

OneSignal delivers through Apple Push Notification service on iOS and Firebase Cloud Messaging on Android. Notification content can appear on your lock screen depending on device settings. Disabling notification display does not by itself delete your OneSignal record or necessarily stop all SDK processing.

Hosting, support and employer integrations

The company HR system, its hosting providers and authorised support providers process information needed to run and support it. Your employer may configure further integrations, including Microsoft Teams or email notifications. Those integrations can involve additional recipients and are subject to your employer’s configuration and privacy notice. They are not automatically present for every Kimo customer.

Cloudflare hosts and delivers this website. Our email provider processes messages you send to info@periwin.com. Apple and Google separately handle their stores, downloads and any platform-level diagnostics or analytics under their own notices. Store privacy settings do not necessarily control analytics inside Kimo.

Information may also be disclosed where legally required, to protect legal rights or security, or in a lawful business transfer with appropriate safeguards and notice where required. Provider privacy notices explain their practices; they do not remove Periwin’s responsibilities for the processing we determine.

5. Where information is stored and how it is protected

Customer HR records are stored on servers in London, England. Kimo connects to the company site supplied at sign-in. If your employer operates a separate environment, its privacy notice explains that environment’s arrangements.

London hosting of HR records does not mean every category of information stays in the UK. Google, OneSignal, Cloudflare and other service providers operate internationally and may process information in the United States or other countries. Applicable transfer arrangements depend on the provider, recipient and service configuration. UK transfers requiring safeguards must use an appropriate legal mechanism, such as an applicable adequacy arrangement or approved contractual safeguards. Contact us for information about the arrangements applying to your data and how to obtain relevant safeguards.

The app requires HTTPS for non-local company sign-in addresses. It keeps sign-in session credentials in platform secure storage and retains app settings and some work information in its local application database to support normal use and cached views. The local database is not given a separate app-managed encryption layer in the current implementation; it relies on the device’s application isolation and operating-system protections. We do not describe this as end-to-end encryption.

Use a device passcode, keep your device and app updated, and follow your employer’s rules for shared or managed devices. Networked services cannot be guaranteed free from every security risk. Report suspected account compromise or unauthorised disclosure to your employer and info@periwin.com.

6. How long information is kept

There is no single retention period for all Kimo information. The following criteria apply:

  • Employment records: your employer sets retention according to the employment relationship, statutory record-keeping duties, outstanding requests and legitimate legal or audit requirements. Ending app access does not automatically erase those records.
  • Device information: settings and cached work data can remain until replaced, removed through the operating system’s app-data controls or otherwise cleared. Sign-out clears the session credential but does not purge all cached records. Uninstalling is not a request to delete server records, and platform-protected storage or backups may be handled separately by the operating system.
  • Firebase and OneSignal: analytics, identifiers, subscriptions and message-related information are subject to the retention settings and lifecycle rules applying to our provider accounts. Criteria include the continuing need to measure service use or deliver notifications, account or subscription activity, provider cleanup rules and valid deletion requests. Some provider settings are configurable by Periwin; provider operation is not an exemption from our responsibilities. We have not specified a fixed number of months because the configured period differs by dataset. Ask us for the applicable settings. Google explains its controls in its data retention guidance.
  • Support correspondence: retained for handling the enquiry, follow-up and a necessary record of its resolution, and longer where a legal requirement or actual dispute requires it. The amount and sensitivity of information and whether the issue remains relevant are factors in deciding when it is no longer needed.
  • In-app diagnostics: the current app keeps up to 30 recent handled errors in memory for troubleshooting; sign-out clears that history. It does not automatically send this diagnostic history to a separate crash-reporting service. Logs on the company server and provider systems have their own applicable retention arrangements.

Deleting a current record may not remove copies immediately from backups or legally required records. Any continuing retention must have an appropriate purpose and applicable safeguards. Contact us if you need retention information for a particular record or service.

7. Your choices and rights

You can control notification display and lock-screen previews in your device settings. Notification permission is separate from the processing of an account or subscription identifier. Sign-out and an analytics reset are not the same as switching off future collection.

Depending on the applicable law and processing, you may have rights to access your information, correct it, request erasure, restrict its use or receive certain information in a portable form. Where processing relies on consent, you may withdraw that consent without affecting the lawfulness of earlier processing.

Your right to object

You may object to processing based on legitimate interests, including relevant product analytics, for reasons relating to your situation. Where information is used for direct marketing, you may object at any time. Email info@periwin.com to raise an objection.

Contact your employer’s HR or privacy team for employment records. You may also contact Periwin; we will handle requests concerning processing we control and help route requests concerning your employer’s records. We may need proportionate information to verify identity or identify the relevant account. Rights are subject to lawful exceptions, and we will explain the response rather than promise that every record can be erased.

You can complain to the UK Information Commissioner’s Office through ico.org.uk/make-a-complaint, or to another relevant supervisory authority. You do not need our permission to do so.

8. Account access and data deletion requests

Kimo currently uses employer-provided accounts and has no public self-service sign-up or in-app account-deletion button. Your employer administers access to its HR system.

  1. To request account closure or deletion of personal information, contact your employer’s HR/privacy team or email info@periwin.com with the subject “Kimo account and data deletion request”.
  2. Identify your company site, the email associated with your account and whether your request concerns employer records, notification/analytics information or both. Do not send your password or identity documents unless we have arranged an appropriate verification method.
  3. We will identify the responsible organisation and the scope of the request. Where we control the processing, we will assess deletion and contact relevant providers as appropriate. Where the employer controls it, we will refer or assist with the request under its instructions.

We respond within the period required by applicable data-protection law and explain any lawful extension, refusal or information that must be retained. Employment, tax, payroll, security and legal-claim records may need to be retained for a valid reason. Removing an app or disabling notifications alone does not carry out this process.

Request help with your data

9. This website

The website uses locally hosted fonts and images. Its own frontend does not set analytics or advertising cookies and does not load Firebase or OneSignal. Cloudflare may process request metadata, including IP addresses, URLs, timestamps and browser information, to deliver the site and protect it. Any infrastructure security cookies or processing are described in Cloudflare’s Privacy Policy.

Contact links open your email application. Clicking “copy email” writes only our contact address to your clipboard; it does not read your clipboard. There is no website registration or contact-form database. If you send an email, we receive the information in that message through our email service.

10. Young people

Kimo is a workplace service, not a service directed at children. Employers are responsible for providing accounts only where lawful and for applying appropriate safeguards to young workers. If you believe a child’s information has been provided without an appropriate basis, contact us and the relevant employer.

11. Changes and contact

We may update this notice when Kimo’s features, providers or data practices change. The date at the top identifies the latest revision. Material changes will be communicated in a way appropriate to their effect, and any legally required permission must be obtained separately.

Periwin Solutions Limited
44a, Lowlands Road
Harrow, England, HA1 3AN
United Kingdom
info@periwin.com
kimo.

A Periwin Solutions Limited product.

© 2026 Periwin Solutions Limited.
Privacy PolicyTerms & Conditions
Back to top