KINDRED

Privacy Policy

DocumentKindred Privacy Policy
Version1.0 (v0.0.1)
Release coveredKindred v0.0.1 — First Release
Effective dateJuly 24, 2024
Last updatedJuly 24, 2024
Operator / Data ControllerMelco Technology PLC
ProductKindred
Websitewww.melcotechnology.com
Privacy contactprivacy@melcotechnology.com
Governing lawFederal Democratic Republic of Ethiopia
Supervisory authorityEthiopian Communications Authority (ECA)

This document is clearly labelled as a Privacy Policy. It names Melco Technology PLC as the operator of the Kindred application and describes how personal data is handled in the first release of Kindred (v0.0.1).

It describes only the features that are actually available in this release so that it matches the app and its Google Play Data Safety declaration.

It is written to satisfy the requirements of the Google Play Console (User Data policy and Data Safety), the Personal Data Protection Proclamation No. 1321/2024 of Ethiopia, and international data-protection best practice.


Document Overview & Key Details

DetailValue
DocumentKindred Privacy Policy
Version1.0 (v0.0.1)
Release coveredKindred v0.0.1 — First Release
Effective dateJuly 24, 2024
Last updatedJuly 24, 2024
Operator / Data ControllerMelco Technology PLC
ProductKindred
Websitewww.melcotechnology.com
Privacy contactprivacy@melcotechnology.com
Governing lawFederal Democratic Republic of Ethiopia
Supervisory authorityEthiopian Communications Authority (ECA)

This Privacy Policy describes how Melco Technology PLC handles personal data in Kindred. It is written to satisfy the requirements of the Google Play Console, the Personal Data Protection Proclamation No. 1321/2024 of Ethiopia (PDPP 2024), and international data-protection best practices.


1. Introduction

Kindred is a digital professional-identity and contact-management application that helps people create, manage, share, and exchange professional contact information. Kindred is developed and operated by Melco Technology PLC (“Melco”, “Kindred”, “we”, “us”, or “our”), a company established in Addis Ababa, Ethiopia.

This Privacy Policy explains what personal data we collect, why we collect it, the legal basis on which we rely, how we use, store, protect, and share it, and the rights you have over it. Kindred is built around a simple principle:

Your identity belongs to you. You decide what professional information you share, and with whom.

We comply with the Personal Data Protection Proclamation No. 1321/2024 of the Federal Democratic Republic of Ethiopia (the “Proclamation” or “PDPP 2024”), which entered into force on 24 July 2024, together with other applicable Ethiopian laws concerning electronic transactions, cybersecurity, computer crime, and consumer protection. Where our users are located outside Ethiopia, we also apply the core principles of leading international frameworks such as the EU General Data Protection Regulation (GDPR) as a matter of best practice.

This Policy is written for the first release of Kindred (v0.0.1). As Kindred introduces new features that involve new or materially different processing of personal data, we will update this Policy first, and we will not describe planned features as if they were already operational.


2. Who We Are and Scope of This Policy

  • Data Controller: For the purposes of the Proclamation, Melco Technology PLC is the data controller that determines the purposes and means of processing personal data through Kindred. Our contact details are set out in the “How to Contact Us” section.
  • Applicability: This Policy applies to individuals who create, verify, or log into a Kindred account; complete onboarding; create, manage, or share a Kindred Card; create and manage contacts; use the limited scanning feature where available; adjust app settings; or otherwise communicate with Kindred.
  • Third-Party Services: This Policy does not govern third-party services you may reach through information contained in a Kindred Card (for example, external social-media platforms, websites, or email services). Those services operate independently under their own privacy policies.

3. What Kindred Does in This Release

The first release of Kindred focuses on digital professional identity and contact management. The features available in this release are:

Available Features

  • Onboarding: A short guided setup, including selecting your preferred language.
  • Account creation and authentication: Registering, verifying your email, receiving one-time passwords (OTPs), logging in, resetting your password, and accepting the applicable legal terms.
  • Kindred Card: Creating, editing, and managing a digital professional card containing information you choose to provide.
  • Card sharing: Sharing your Kindred Card through supported channels: QR code, shareable link, text, email, and add-to-wallet.
  • Contacts: Creating, viewing, editing, filtering, and managing your professional contacts.
  • Settings: Managing your theme, language/locale, and account and profile preferences.

Limited Features Being Finalised in This Release

  • Card scanning: A scanner is present but is not yet part of the full end-to-end flow (see Section 9).
  • Receiving and importing contacts: Sharing your own card is available; receiving/importing and deeper device-contact integration are still being completed.
  • Subscriptions and plans: Plan options and an upgrade prompt exist, but the full paid-subscription flow is not yet routed (see Section 11).

Not Included in This Release

Features that form part of Kindred’s longer-term vision — such as professional notes, community and opportunities, events, enterprise identity, proximity/radar or location-based discovery, and NFC tap-to-share — are not operational in v0.0.1 and are not covered as active services by this Policy. They will receive privacy review before launch.


4. Personal Data We Collect

We collect only the personal data necessary to provide, secure, and improve Kindred, in line with the principle of data minimisation. What we collect depends on the features you use and the information you choose to provide.

CategoryExamplesSource
Account & authentication dataEmail address (required), account identifier, OTP and authentication records, account and verification status, record that you accepted the legal terms, security logsYou / Generated by the service
Profile & Kindred Card dataName, profile photo, professional title, occupation, company, phone, professional email, website, social links, and a location field — as you choose to includeYou
Contacts dataNames, phone numbers, emails, company, and professional details of contacts you create or manageYou
Preferences dataLanguage/locale and theme settingsYou / Settings
Technical & device dataIP address, device type, operating system, app version, device or installation identifiers, timestamps, crash and error logsAutomatically collected
Usage & security dataRegistration, verification, login, card creation/updates, sharing actions, contact actions, and setting changesAutomatically collected
Subscription data (limited)Selected plan and entitlement/subscription status — no payment credentialsYou / Generated

4.1 Email Address — Use Your Professional Email

An email address is required to create and verify a Kindred account. We use it to identify your account, send OTPs, authenticate access, support recovery and security, and send essential account and security communications.

Recommendation: We strongly recommend that you use your professional (work or business) email address — not a personal email — both when you create and verify your Kindred account and when you add an email to your Kindred Card. Kindred is a professional-identity tool: using a professional email keeps your professional presence consistent, presents you well to the people you connect with, and keeps your personal email out of the app and out of your professional exchanges. Using a personal email is not required and is discouraged. If you do not yet have a professional email, you may use another address, but we encourage you to switch to a professional one.

Your account (login) email is not automatically shown on your Kindred Card. If you choose to display an email on your Card, we recommend that it also be your professional email. Whatever you choose, your login email does not become public simply because you created an account.

4.2 Sensitive Personal Data and Identity Documents

Under the Proclamation, sensitive personal data includes information revealing racial or ethnic origin, political opinions, religious or philosophical beliefs, health, genetic and biometric data, and sexual orientation. This release of Kindred is not designed to collect sensitive personal data, and it does not collect government-issued identification documents or perform identity/KYC verification. If a future feature ever requires such processing, we will assess the applicable legal requirements — including any prior approval of the ECA — before introducing it, and update this Policy.


5. App Permissions and Why We Request Them

Kindred requests device permissions only where a feature needs them, and only for the purpose described below. You can grant or deny each permission in your device settings; denying a permission may limit the related feature.

PermissionWhy Kindred Requests It
CameraTo operate the card-scanning feature, where available — to read a business card or QR code so you can save or connect a contact. This feature is limited in this release (see Section 9).
Photos / MediaTo let you add a profile photo, company logo, or cover banner to your Kindred Card.
Internet / NetworkTo operate the service, authenticate you, and sync your card, contacts, and settings.

We limit the access, collection, use, and sharing of personal data to what is necessary for the purposes disclosed in this Policy and promoted in our Google Play listing.


6. How We Use Personal Data and Our Legal Bases

We process personal data only for specific, lawful purposes, and only where a lawful basis under the Proclamation applies. The lawful bases we rely on are: your consent; performance of a contract with you; compliance with a legal obligation; protection of vital interests; and our legitimate interests, where not overridden by your rights.

PurposeLegal Basis
Complete onboarding and create and maintain your accountPerformance of a contract
Verify your email and authenticate you (OTP)Performance of a contract; Legitimate interests (security)
Record your acceptance of the legal termsLegal obligation; Performance of a contract
Create, display, manage, and share your Kindred Card as you instructPerformance of a contract; Consent
Create and manage your contactsPerformance of a contract; Consent
Apply your language, locale, and theme preferencesPerformance of a contract; Legitimate interests
Provide the limited scanning feature, where availablePerformance of a contract; Consent
Offer plans and maintain subscription status (where available)Performance of a contract
Protect accounts; detect and prevent fraud, impersonation, and abuseLegitimate interests; Legal obligation
Respond to support requestsPerformance of a contract; Legitimate interests
Comply with law and lawful requests from authoritiesLegal obligation

Where we rely on consent, you may withdraw it at any time; withdrawal does not affect the lawfulness of processing carried out before withdrawal. We do not carry out automated decision-making that produces legal or similarly significant effects on you. If we ever introduce such processing, we will comply with the Proclamation and provide you the right to human review.


7. Your Kindred Card Is Different From Your Private Account Data

Creating a Kindred account does not make all account information visible to other users. Your required account email is used to verify and authenticate your account; that does not automatically mean another user can see the email you use to log in. Information becomes available to another person only when you choose to place it on a card intended for sharing, or otherwise share it through an available Kindred function. This separation is fundamental to how Kindred protects your privacy.


8. Information You Choose to Share

When you share your Kindred Card, the information on that card may become available to the recipient. In this release you can share your own card through the supported channels (QR, link, text, email, wallet). Features for receiving or importing other people’s cards are still being completed. Where Kindred provides a visibility or sharing control, you determine whether the applicable information is shared, and any action that requires your confirmation proceeds only on your affirmative action.

Once you provide information to another person, we cannot control what they do with it outside Kindred (for example, saving your number, taking a screenshot, or exporting it). Changing a visibility setting affects future sharing through Kindred but cannot remove information a recipient has already saved or retained independently.

Professional email when exchanging cards. Because your Kindred Card represents you professionally, we encourage you — including the first time you set up and share your card — to include your professional (work or business) email rather than a personal one. This keeps every exchange professional and protects your personal email.


9. Card Scanning (Limited in This Release)

Kindred includes a card-scanning capability that is still being finalised. In this release it is available only in a limited form and is not yet part of the standard end-to-end flow. Where scanning is used, it accesses your device camera to read a business card or Kindred Card so that you can save a contact; Kindred does not use information read from a card for unrelated marketing or profiling. Because the feature is not yet complete, you should not rely on it for processing important or sensitive information. When the full scanning flow is released, we will review and, if needed, update this Policy.


10. Information Collected Automatically

When you use Kindred, we automatically collect certain technical and security information (see Section 4). We use it to operate and secure the service, authenticate users, detect technical problems, prevent abuse, investigate security incidents, improve reliability, and protect our infrastructure.


11. Subscriptions and Plans (Being Introduced)

Kindred is introducing paid subscription plans. In this release, plan options and an upgrade prompt exist, but the full paid-subscription flow is not yet complete. Where subscriptions become available, payment is processed by an authorised third-party payment provider, and Kindred does not collect or store your bank-card numbers, card security codes, mobile-money PINs, bank passwords, or equivalent payment credentials. We may receive limited information such as selected plan, payment status, transaction reference, and subscription status for account administration. The payment provider processes payment information under its own privacy policy and legal obligations.


12. How We Share and Disclose Personal Data

Notice: We do not sell your personal data.

We share personal data only as described below, and only to the extent necessary:

  • Service providers (processors): Trusted providers of cloud hosting, databases, email and OTP delivery, authentication, analytics, crash reporting, security, customer support, and (where subscriptions are available) payment processing, who act on our instructions under confidentiality and security obligations.
  • Other users: Only the information you choose to share by sharing your Kindred Card, as described in Section 8.
  • Legal and safety: Where necessary to comply with law, respond to lawful requests from competent authorities, enforce our Terms, or detect, prevent, and address fraud, security, or technical issues.
  • Business transfers: If Melco is involved in a merger, acquisition, or asset sale, personal data may be transferred to the successor under equivalent privacy protections, and we will notify you as required.
  • With your consent: Any other sharing will be done transparently and only with your permission.

13. International Data Transfers

Some of our technology providers may operate infrastructure located outside Ethiopia, which means personal data may be stored or processed abroad. Under the Proclamation, cross-border transfers are permitted only where the ECA has determined that the recipient country provides an adequate level of protection, or where appropriate safeguards are in place — such as standard contractual clauses approved by the ECA, binding corporate rules, or your explicit consent after being informed of the risks — or where the transfer is otherwise necessary or permitted by law.

Where the Proclamation designates certain categories as critical personal data that must be processed on servers or data centres located in Ethiopia, we will comply with that requirement. Any cross-border transfer of sensitive personal data will be made only with the prior approval of the ECA where such approval is required. We apply the same standard of protection to your data wherever it is processed.


14. Data Retention

We retain personal data only for as long as reasonably necessary for the purpose for which it was collected, or as required or permitted by law. Different data types have different retention periods:

  • Account information: Retained while your account remains active.
  • OTP information: Retained only for the period reasonably necessary for authentication and security.
  • Subscription and transaction records: Retained as required for accounting and legal purposes.
  • Security records: Retained for a defined period necessary to protect the service.
  • Backups: Deleted information may remain briefly in secure backups before permanent deletion.

When information is no longer required, we take reasonable steps to delete, securely dispose of, or anonymise it.


15. Account Deletion and Data Deletion

You can delete your Kindred account and associated personal data. In line with Google Play requirements, we provide a deletion route both inside the app and on the web:

  • In the app: Open SettingsAccountDelete Account, and confirm.
  • On the web: Submit a deletion request at https://www.melcotechnology.com/kindred/delete-account (to be published) or email privacy@melcotechnology.com.

When your account is deleted, we take reasonable steps to delete or anonymise the personal data associated with it, including your profile, Kindred Card, and contacts you created. Some information may be retained where required for legal obligations, fraud prevention, security investigations, unresolved disputes, accounting, or the establishment or defence of legal claims, and residual copies may persist temporarily in secure backups before permanent deletion. Deleting your account does not delete information that another person has already received and independently saved outside Kindred.


16. Data Security and Breach Notification

We implement reasonable technical and organisational measures designed to protect personal data against unauthorised access, disclosure, alteration, loss, destruction, misuse, and unlawful processing. These may include secure authentication, encryption in transit and at rest where appropriate, access controls, restricted administrative access, security logging and monitoring, backups, security updates, vulnerability management, and incident-response procedures.

No online service can guarantee absolute security. If we become aware of a personal-data breach that is likely to present a risk, we will act to contain and remedy it and will notify the Ethiopian Communications Authority, and affected data subjects where required, within the timeframes set by law — which, under the Proclamation, is within 72 hours of becoming aware where notification is required. Never share your Kindred OTP or password with anyone.


17. Your Rights

Subject to the Proclamation and applicable limitations, you have the right to:

  • Be informed about how your personal data is processed;
  • Access the personal data we hold about you;
  • Request correction of inaccurate or incomplete data;
  • Request erasure of your data where legally applicable;
  • Restrict certain processing;
  • Object to certain processing, including direct marketing;
  • Receive your data in a portable, machine-readable format where technically feasible;
  • Withdraw consent where processing is based on consent;
  • Not be subject to a decision based solely on automated processing that produces legal or similarly significant effects; and
  • Lodge a complaint with the Ethiopian Communications Authority (ECA).

Rights after death: Under the Proclamation, privacy rights survive the death of a data subject for ten (10) years, and a lawful heir may invoke those rights during that period.

17.1 How to Exercise Your Rights

To exercise any right, contact us using the details in Section 21. We may need to verify your identity before acting on a request, to prevent someone else from obtaining your information. We will respond within the time required by applicable law. Many profile fields can also be corrected directly in the app through your account settings.


18. Children and Minors

Kindred is intended for professional use by adults and is not directed at children. Under the Proclamation, a minor is a person under 16 years of age. We do not knowingly process the personal data of a minor without the consent of a parent or guardian, and we make reasonable efforts to verify age and consent using available technology. The Proclamation prohibits processing a minor’s personal data for marketing, profiling, or the merging of profiles, and Kindred does not do so. If we learn that we have collected a minor’s data without the required consent, we will take reasonable steps to delete it.


19. Cookies and Similar Technologies

Where Kindred’s website or infrastructure uses cookies, device identifiers, local storage, or similar technologies, they may be used to maintain login sessions, authenticate users, provide security, remember preferences, support technical performance and diagnostics, and improve the service. Where applicable law requires consent for particular technologies, we will provide an appropriate choice.


20. Governing Law and Supervisory Authority

This Policy is governed by and interpreted in accordance with the laws of the Federal Democratic Republic of Ethiopia, including the Personal Data Protection Proclamation No. 1321/2024. The independent supervisory authority responsible for enforcing the Proclamation is the Ethiopian Communications Authority (ECA). As data controllers and processors are required to register with the ECA, Melco Technology PLC maintains, or is undertaking, the registration applicable to its processing activities. Nothing in this Policy removes or reduces any mandatory right or protection provided to you under applicable law. Where we serve users outside Ethiopia, we additionally apply the core principles of leading international frameworks such as the GDPR as a matter of best practice.


21. How to Contact Us

If you have a privacy question, concern, complaint, or request, please contact:

Role / ChannelContact Information
Legal entityMelco Technology PLC
Privacy contactprivacy@melcotechnology.com (to be confirmed)
General emailmelcotechno@gmail.com
Telephone+251 953 843 507
AddressKolfekeraniyo, Addis Ababa, Ethiopia
Websitewww.melcotechnology.com
Supervisory authorityEthiopian Communications Authority (ECA), Addis Ababa, Ethiopia

Please provide enough information for us to identify and understand your request. Do not send copies of identification documents or other sensitive information by ordinary email unless we specifically request them through a secure process.


22. Changes to This Privacy Policy

We may update this Policy when the law changes, the service changes, a new feature introduces new processing, a third-party service changes, or we improve our privacy or security practices. We will not describe future features as though they are already operational. Where a material change significantly affects how we process personal data, we will provide appropriate notice and obtain consent where required by law. The Version, Effective date, and Last updated fields identify the applicable version.