1 Identification of the data controller
The entity responsible for the KiHora platform is:
Hereinafter referred to as KIHORA.
KIHORA acts as the data controller for the data necessary for:
- creating and managing customer and business accounts;
- authenticating users;
- providing and operating the booking service;
- sending booking notifications;
- providing support;
- platform security;
- preventing fraud and misuse;
- maintaining technical and audit records;
- sending essential service communications;
- managing the contractual relationship with participating establishments.
When a participating establishment enters third-party personal data into the platform, including data of walk-in customers who do not have a KIHORA account, data of its professionals, or data contained in photographs, and determines the purposes for which that data is used, the establishment acts as the data controller.
In those situations, KIHORA acts as a data processor, processing data on behalf of the establishment and according to the requested features, under the applicable Data Processing Agreement.
When an establishment receives data from a customer registered with KIHORA and begins using it on its own initiative, it acts as an independent data controller, under section 6.
This distinction is consistent with the general legal framework for the protection of personal data of individuals in force in Cape Verde, approved by Law No. 133/V/2001 of 22 January, as amended by Law No. 41/VIII/2013 of 17 September and Law No. 121/IX/2021 of 17 March, which imposes separate obligations on both controllers and processors.
2 Who this Policy applies to
This Policy applies to:
- customers who create an account in the KiHora app;
- owners and representatives of establishments who create an account in the KiHora Business app;
- professionals and employees whose data is recorded by a participating establishment;
- walk-in customers whose data is recorded by a participating establishment without having an account on the platform;
- people who join the waiting lists for access to the apps;
- visitors to public pages on kihora.cv.
KIHORA provides two separate apps with separate accounts:
- KiHora, for customers looking for and booking services;
- KiHora Business, for people managing an establishment and its schedule.
A customer account and a business account are separate contexts, with their own data, permissions and identifiers, even when the same individual is behind both accounts.
3 Categories of personal data processed
KIHORA may process the categories of personal data described in the following sections.
3.1 Customer account data
The following may be processed:
- first name;
- last name;
- email address, obtained from the identity provider;
- country code and telephone number, optionally provided;
- gender, optionally provided;
- profile photograph, optionally provided;
- internal account identifier;
- account identifier held by the identity provider;
- account creation and last-update dates.
The email address is the login identity and cannot be edited through the app. The telephone number is optional and can be added, changed or removed by the customer at any time.
Gender and the profile photograph are optional, can be changed or removed at any time, and are made available to establishments where the customer books, under section 7.
3.2 Business account data
The following may be processed:
- first name;
- last name;
- email address, obtained from the identity provider;
- country code and telephone number;
- internal account identifier;
- account identifier held by the identity provider;
- record of acceptance of the applicable legal documents, under section 30;
- account creation and last-update dates.
3.3 Establishment data
When creating and managing an establishment, the following may be processed:
- trading name;
- contact email address;
- country code and contact telephone number;
- address;
- geographical latitude and longitude coordinates;
- city;
- establishment description;
- business categories;
- accepted payment methods, including cash, Visa and Vinti4;
- opening hours for each day of the week;
- service catalogue, including name, description, duration and price;
- profile and cover photographs;
- photographs associated with each service;
- establishment publication status.
When an establishment is operated by an individual, its data may also constitute personal data of that person.
Once published, the establishment is visible in the customer app and KIHORA may publish a public establishment page on kihora.cv, under section 26.
3.4 Professional and employee data
When an establishment registers the professionals who provide services there, the following may be processed:
- first name;
- last name;
- email address;
- country code and telephone number, optionally provided;
- photograph;
- services that each professional can perform;
- schedule, assigned bookings and blocked periods.
This data is entered by the establishment. The professional's first name and photograph are shown on the establishment page in the customer app when the establishment is published.
3.5 Walk-in customer data
When an establishment records a booking for a person who does not have an account on the platform, hereinafter referred to as a walk-in customer, the following may be processed:
- first name, required;
- last name, optional;
- country code and telephone number, optional;
- email address, optional;
- booking history at that establishment.
Walk-in customer data is associated exclusively with the establishment that recorded it and is not shared with other establishments.
A walk-in customer's email address is entered by the establishment, is not verified and is processed solely as contact data. KIHORA does not use it to identify, associate or automatically create customer accounts.
3.6 Booking history data
The following may be processed:
- establishment identification;
- service identification;
- professional identification;
- customer or walk-in customer identification;
- date, start time and end time;
- booking status, including pending, confirmed, cancelled and completed;
- booking origin, according to whether it was created by the customer or the establishment;
- record type, including booking or schedule block;
- reason, for schedule blocks;
- recurrence rule, where applicable;
- creation and last-update dates.
KIHORA may also record that an establishment has blocked a customer, so that the customer can no longer make bookings at that establishment. Identification of the establishment, identification of the customer and the date the block was created may be processed.
A block is specific to the establishment that created it. KIHORA does not create, show or provide any block, count, rating or attendance history shared between different establishments, and does not operate any list of customers to avoid.
Blocking is a decision taken by a person at the establishment, under section 14. Blocking a customer cancels that customer's future bookings at that establishment, and the customer is notified of those cancellations.
3.7 Reviews
The following may be processed:
- rating from one to five;
- optional free-text comment;
- indication that the review was submitted anonymously;
- submission date;
- link to the booking that generated the review.
The processing of reviews and the anonymity safeguards are described in section 10.
3.8 Favourites
The establishments that each customer marks as favourites and the date on which they were marked may be processed. This information is visible only to the customer.
3.9 Photographs
The following may be uploaded and stored:
- customer profile photograph;
- establishment profile photograph;
- establishment cover photographs;
- photographs of each service;
- photograph of each professional.
These photographs may contain personal data, including images of professionals, employees, customers or other identifiable people shown in them.
A customer's profile photograph is not shown on any public page. It is made available to the establishments where that customer books, under section 7. It is stored in the same way as the photographs above, so the access rules in section 9 apply to it equally.
KIHORA does not support uploading documents, invoices, contracts or files other than photographs.
The access rules for these photographs are described in section 9.
3.10 Notifications and device identifiers
The following may be processed:
- device identifier assigned by the notification service;
- device platform, Android or iOS;
- type and content of generated notifications, including title and text;
- booking and establishment identifiers associated with the notification;
- creation date, read date and delivery status;
- record of sending attempts, number of attempts and any errors.
Notification titles and text may contain the customer's first name, the establishment name, the service, and the booking date and time.
3.11 Location data
In the customer app, and only with permission granted by the user in the device operating system, the approximate or precise location of the device may be processed to sort and show establishments by proximity.
Location is used at the time of the search and is not persistently stored in KIHORA's database as a location history.
Refusing location permission does not prevent use of the app. In that case, searches are performed by city.
3.12 Waiting lists
The email address of people who sign up to access either app before its general availability, as well as the sign-up date, may be processed.
3.13 Technical, session and security data
The following may be processed:
- IP address of the request;
- date and time of access;
- request method, path and parameters;
- response code and request duration;
- user-agent information, including app, version and operating system;
- internal request-correlation identifier;
- profile and internal account identifier associated with the request;
- technical errors and exceptions;
- security incidents;
- information necessary to prevent fraud and misuse.
3.14 Usage analytics data
Both apps use a usage analytics service provided by Google.
In the KiHora Business app, the following may be processed:
- internal business-account identifier;
- login, registration, logout and screen-navigation events;
- authentication method used, Google or Apple;
- sharing of a booking reminder with a customer, including the channel chosen;
- technical device data collected by the service itself.
In the KiHora customer app, the following may be processed:
- internal customer-account identifier;
- login, registration, logout and screen-navigation events;
- authentication method used, Google or Apple;
- the terms typed when searching for establishments;
- establishments viewed, and the establishment and service identifiers associated with a booking started, confirmed or cancelled;
- establishments marked as favourites;
- the rating given when a review is submitted;
- opening an establishment's location in an external maps app;
- technical device data collected by the service itself, including a device identifier assigned by the service and the approximate location derived from the IP address.
Names, email addresses and telephone numbers are never transmitted to this service. The identifier used is the internal account identifier.
This service is not used for advertising, does not build marketing profiles and does not use the device's advertising identifier.
KIHORA does not currently use any crash or failure-diagnosis tool in either app. Technical errors are recorded on KIHORA's own servers, under section 3.13.
3.15 Support and communications data
When a user contacts KIHORA, the following may be processed:
- name;
- email;
- subject;
- message content;
- attachments;
- request history;
- technical data necessary to resolve the problem;
- record of exchanged communications.
4 Sources of data
Personal data may be obtained:
- directly from the data subject through the apps;
- from the identity provider chosen by the user when logging in;
- from the participating establishment that registers professionals, walk-in customers or photographs;
- through normal use of the apps;
- from the devices used;
- from technology providers necessary to provide the service;
- through waiting-list and contact forms.
When data is not entered by the data subject, the establishment that entered it is responsible for ensuring its lawfulness and informing the data subject, under section 8.
5 Purposes and legal bases
5.1 Account creation and management
Data is processed to create the account, identify the user, authenticate access, manage the profile, enable the features, and distinguish customer accounts from business accounts.
Legal basis: performance of the contract or taking steps at the request of the data subject before entering into a contract.
5.2 Establishment discovery and search
Data is processed to show published establishments, order results by proximity, rating or name, filter by city and category, show the establishment page and manage favourites.
Legal basis: performance of the contract and legitimate interest in providing and improving the service.
5.3 Booking management
Data is processed to calculate availability, create, confirm, cancel and complete bookings, prevent overlapping bookings for the same professional, manage schedule blocks and recurring bookings, show the schedule to the establishment, show booking history to the customer and record walk-in customer bookings.
Legal basis: performance of the contract and, for walk-in customers, performance of the contract between the data subject and the establishment, under the establishment's responsibility.
5.4 Contacting the customer about a booking
Contact data described in section 7 is processed to allow the establishment to contact the customer about a booking, including to confirm it, reschedule it or report a delay.
Legal basis: performance of the contract.
5.5 Establishment and team management
Data is processed to create and configure the establishment, manage the service catalogue, manage professionals and their association with services, manage schedules, manage photographs, publish and unpublish the establishment, and show activity indicators and the customer list.
Legal basis: performance of the contract and the establishment's legitimate interest in organising its activity.
5.6 Blocking a customer
Data is processed to allow an establishment to prevent a customer from making further bookings with it, and to cancel that customer's future bookings at that establishment, under section 3.6.
Legal basis: the establishment's legitimate interest in managing its schedule and in deciding whom it serves.
5.7 Booking notifications
Data is processed to inform customers and establishments of the creation, confirmation, cancellation and completion of bookings through in-app notifications and push notifications on the device.
Legal basis: performance of the contract.
5.8 Reviews
Data is processed to allow a customer to review a completed booking and to show those reviews on the establishment page in the app and to the establishment concerned.
Legal basis: performance of the contract and legitimate interest in transparency and service quality.
5.9 Security and fraud prevention
Data is processed to control access, verify that each request is made by an authorised person, protect accounts and establishments, prevent misuse, investigate incidents, detect fraud, protect the platform's integrity and availability, and maintain audit records.
Legal basis: legitimate interest and, where applicable, compliance with legal obligations.
5.10 Technical operation, monitoring and error correction
Data is processed to ensure the operation, availability and performance of the platform, detect errors and correct failures.
Legal basis: legitimate interest.
5.11 Usage analytics
Data is processed to understand in aggregate how the apps are used and to guide their development.
Legal basis: legitimate interest, without using direct identifiers and without advertising.
5.12 Support and assistance
Data is processed to respond to requests, investigate errors, solve problems, provide technical support and follow up on account-related requests.
Legal basis: performance of the contract and legitimate interest.
5.13 Compliance with legal obligations
Data may be processed and retained to comply with legal, tax, accounting, judicial, regulatory, fraud-prevention and information-security obligations.
Legal basis: compliance with a legal obligation.
5.14 Essential communications
KIHORA may send security notifications, operational alerts, confirmations, account messages and communications about material changes to the service or legal documents.
Legal basis: performance of the contract and legitimate interest.
5.15 Commercial communications
KIHORA may send promotional communications when the recipient has consented, when a previous contractual relationship permits this under the law, or when another valid legal basis exists.
The data subject may cancel these communications at any time.
Legal basis: consent or legitimate interest, where legally permitted.
6 Data received by the establishment and each entity's role
When a customer books at an establishment, the establishment can see in its app the data necessary to provide the service, including the customer's contact data, as described in section 7.
From that moment, there are two separate data controllers:
- KIHORA, for the processing it performs to operate the platform;
- the establishment, for its own use of that data, including contacting the customer, organising its activity or keeping its own records.
The establishment is not KIHORA's processor for that own use and is directly responsible to the data subject for it.
This has three practical consequences that are important to understand.
First. When the customer deletes their account, the establishment stops seeing that data in the app. This does not delete information that it has already seen, noted or stored in its own systems. These limits apply going forward and do not undo what was already known.
Second. The establishment must delete contact data it has kept in its own systems as soon as the related booking is completed, and in any event when the customer requests it.
Third. A deletion request addressed to the establishment must be answered by the establishment. KIHORA will provide reasonable assistance and forward the request, under section 23.
These documents prohibit the establishment from using contact data obtained through the platform for purposes unrelated to the booked service, including sending unsolicited advertising, or making acceptance of a booking conditional on authorisation to share additional data.
7 Data the establishment receives
When a customer books at an establishment, that establishment receives the customer's first name, last name, email address and telephone number, where the customer has provided them, together with the gender and profile photograph if the customer has set them.
This data is made available because the establishment cannot deliver the booked service without it. It identifies the person attending, allows the establishment to organise service, and allows it to contact the customer about that booking, including to confirm it, reschedule it or report a delay.
Legal basis: performance of the contract between the customer and the establishment. This is not consent, and there is no setting in the app that switches it off. A customer who does not want an establishment to hold these details should not book with that establishment.
An establishment receives this data only for customers who actually have a booking with it, and never for customers of other establishments.
What the establishment may then do with that data is limited, and it answers for that directly, under section 6. It may use the data to provide the booked service and for contact required by that service. It may not use it for advertising, promotions or any other unsolicited communication, and it may not make acceptance of a booking conditional on obtaining further data.
For bookings the establishment records itself for walk-in customers, this section does not apply: that data is collected and entered by the establishment under its own responsibility.
8 Establishment responsibility for data it enters
The participating establishment is responsible for ensuring that it has the authority and appropriate legal basis to:
- collect data from professionals, employees and walk-in customers;
- enter that data into the platform;
- store and use it;
- upload photographs showing identifiable people;
- grant access to that data to people operating the establishment account.
The establishment undertakes to:
- enter only lawfully obtained data;
- limit data to what is necessary for booking and providing the service;
- keep data accurate and up to date;
- inform data subjects, including professionals and walk-in customers, that their data is recorded in KIHORA;
- obtain a professional's consent before uploading their photograph and inform them of the rules in section 9;
- delete data that is no longer necessary;
- answer data-subject requests when acting as the data controller.
KIHORA retains its own legal obligations as controller or processor, depending on the processing involved.
The establishment's responsibility for data it enters does not exclude or limit KIHORA's own legal obligations.
9 Rules for access to photographs
Photographs uploaded to the platform are intended to be shown publicly on the establishment page and are therefore public content from the moment the establishment is published.
There are two aspects of this operation that must be understood because they do not follow simply from publication.
First, each photograph is accessible through a long, non-guessable direct link that does not require authentication. Anyone who knows or obtains that link can open the photograph outside the app, and KIHORA cannot make the link inoperative other than by deleting the photograph.
Second, as a consequence, the link continues to work after the establishment is unpublished or a professional is no longer associated with the establishment, while the photograph has not been deleted.
A customer's profile photograph is not published anywhere, but it is stored in the same way and is reachable through the same kind of direct link. Both points above apply to it equally.
Consequently:
- photographs should not be uploaded if the establishment or data subject would not accept them being accessible outside the app;
- photographs of identity documents, health data or any other sensitive information should not be uploaded;
- uploading photographs of third parties requires their consent;
- when a professional leaves the establishment, the establishment should delete that photograph if it wants it to stop being accessible.
When a photograph is deleted through the app, the file is removed from storage and its link stops working.
10 Reviews and anonymity
A review may be submitted only by the customer who made the booking, only once per booking, and is final. Reviews cannot be edited or deleted by their author through the app.
When submitting a review, the customer chooses whether it is anonymous. That choice is permanent and cannot be changed after submission.
When a review is not anonymous, the author's first name is shown in the app to other customers and to the establishment.
When a review is anonymous:
- the author's name is not shown to the establishment or other customers;
- the author's name is not even read from the database when the establishment's reviews are viewed;
- the establishment has no platform feature that allows it to identify the author.
In either case, the author can still see their reviews in their account history, marked as having been submitted anonymously.
Reviews are not shown on public pages at kihora.cv, under section 26.
The anonymity described here is a guarantee towards the establishment and other users. KIHORA, as platform operator, retains the technical link between the review and the booking that generated it, which is necessary to prevent duplicate reviews or reviews from people who did not use the service, and to respond to legal obligations or requests from a competent authority.
11 Push notifications
Push notifications are sent through a third-party messaging service identified in section 15.
To make delivery possible, the app registers a device identifier with that service. KIHORA stores the identifier and associates it with the account.
The message sent contains a title and text intended to be shown on the device, as well as internal booking and establishment identifiers used to open the relevant screen when the notification is tapped.
The user can disable notifications in the device operating-system settings. In that case, notifications continue to be shown inside the app.
When the messaging service reports that a device identifier is no longer valid, including because the app was uninstalled, KIHORA deletes that identifier from its systems.
12 Contact through messaging apps
The KiHora Business app may provide the establishment with a feature that prepares a pre-filled reminder message to be sent to a customer through a messaging app installed on the establishment's own device, such as WhatsApp.
It is important to be precise about who does what:
- the establishment sends the message from its own number and its own account in the messaging app;
- KIHORA does not send the message, communicate with the messaging app's servers or transmit any data to it;
- the messaging-app provider is not KIHORA's processor and is therefore not included in the list in section 15;
- processing performed by that provider is governed by the terms applying between the establishment and the provider and by the relationship between the establishment and the customer.
This feature is available only for customers whose telephone number the establishment lawfully holds: registered customers who provided a telephone number, which the establishment receives under section 7, and walk-in customers whose number the establishment collected itself.
The establishment is responsible for the lawfulness of the contact it makes, under section 6.
13 No payments on the platform
KIHORA does not process payments.
The platform allows each establishment to indicate which payment methods it accepts, including cash, Visa and Vinti4. This indication is purely informational.
Payment for the service is made directly between the customer and the establishment, outside the platform.
KIHORA does not collect, process or store card numbers, security codes, bank details or any other payment-method data.
14 No automated decisions or artificial intelligence
KIHORA does not use, in the features described in this Policy, optical character recognition, generative artificial-intelligence models, profiling for marketing purposes, or solely automated decisions that produce legal effects for data subjects or significantly affect them.
Uploaded photographs are not subjected to automated content analysis, facial recognition or information extraction.
A block described in section 3.6 is created by a person at the establishment. It is not the output of any automated evaluation of the customer, and accepting or refusing a booking is always an act of a person at the establishment.
If features involving solely automated decisions are introduced, this Policy will be updated in advance and data subjects will be informed under section 30.
15 Data sharing and processors
KIHORA uses the following providers to deliver the service:
- Google Ireland Limited and Google LLC, for user authentication, push notifications and usage analytics in both apps;
- Apple Inc. and Apple Distribution International Limited, for Sign in with Apple and distribution of the app on iOS;
- Microsoft Corporation and Microsoft Ireland Operations Limited, for photograph storage and development and operations support services;
- Hetzner Online GmbH, for hosting the application servers;
- Neon Inc., for the database service;
- Cloudflare Inc., for traffic protection, routing and distribution;
- Grafana Labs, for collecting technical logs and operating metrics;
- MapTiler AG, for supplying the maps shown in the customer app.
These providers should process data only to the extent necessary to provide their respective services and in accordance with the applicable contractual terms.
Google and Apple authentication. When a user chooses to sign in with a Google or Apple account, KIHORA receives the email address and, when provided, the name associated with that account from the relevant provider for authentication. This information is not used for any purpose other than identifying and authenticating the KIHORA account. Sign in with Apple allows the user to hide their real email address; in that case, KIHORA receives a forwarding address provided by Apple.
Maps. When a customer opens the map in the app, the device directly requests images for the viewed area from the map provider. That request reveals the device's IP address and the geographical area queried to the provider. KIHORA does not transmit the user's identity to that provider.
Technical logs. Access and application logs, which include the request IP address and the internal identifier of the associated account, are sent to the technical-log collection service identified above.
KIHORA may also disclose data when necessary to:
- comply with a legal obligation;
- respond to a judicial, administrative or regulatory authority;
- prevent fraud;
- investigate a security incident;
- protect KIHORA's rights;
- protect the rights or safety of third parties;
- carry out a user request;
- establish, exercise or defend rights in judicial or out-of-court proceedings.
KIHORA does not sell personal data or share it for third-party advertising.
16 International transfers
KIHORA provides the service in Cape Verde, but the technical infrastructure supporting the platform is located outside the national territory.
In particular:
- the application servers are located in Germany;
- the database is located in Germany;
- photograph storage is located in Western Europe;
- authentication, notification, usage analytics, failure diagnosis, technical-log, maps and traffic-distribution services are provided by international providers and may involve processing outside Cape Verde, including in the United States of America.
Processing personal data outside Cape Verde constitutes an international transfer of data subject to the general legal framework for personal-data protection and the involvement of the National Data Protection Commission.
KIHORA undertakes to:
- complete the formalities legally required with the National Data Protection Commission for processing and international transfers;
- appoint providers that offer appropriate protection guarantees;
- enter into the applicable contractual instruments with those providers, including standard contractual clauses when available;
- limit transfers to what is strictly necessary to provide the service;
- keep information about processing locations up to date.
The specific processing location may depend on the provider, service and configuration used.
17 Data retention
Data is retained for the period necessary for the purposes for which it was processed.
As a rule:
- account data is retained while the account is active;
- establishment data is retained while the establishment exists on the platform;
- professional data is retained while the professional is associated with the establishment;
- booking data is retained while necessary for the customer and establishment history and the defence of rights;
- walk-in customer data is retained while the establishment keeps it and does not request its deletion;
- reviews are retained while the establishment exists on the platform;
- photographs are retained until deleted through the app;
- device identifiers are retained while valid and deleted when the messaging service reports that they are no longer valid;
- notifications and their delivery records are retained while necessary for account history and investigation of delivery failures;
- waiting-list addresses are retained until the person is invited to the platform or requests removal;
- technical and access logs are retained in monitoring systems for approximately fourteen days;
- support requests are retained for the time necessary to resolve and document them and to defend rights;
- records of acceptance of legal documents are retained while the account exists and for the period necessary to prove the contractual relationship and comply with legal obligations.
KIHORA may retain certain data after an account is closed when necessary to comply with legal obligations, prevent fraud, investigate incidents, respond to authorities, resolve disputes, or exercise and defend rights.
18 Account deletion
The customer can delete their account from the app. The establishment can do the same, without prejudice to obligations undertaken towards customers with future bookings.
Deletion takes effect immediately, has no reversal period and cannot be undone.
Deletion does not indiscriminately erase all records. It removes the identity and disconnects the account while retaining records belonging to the establishment or that the law requires to be kept. Specifically:
- the first name, last name, email address, telephone number and photograph, where present, stop being associated with the account and are replaced or removed so that the person is no longer identifiable through the platform;
- the link to the identity provider is severed, so logging in no longer provides access to the former account;
- device identifiers, notifications, favourites and sharing preferences are deleted;
- bookings are retained without customer identification because they are part of the establishment's activity record;
- submitted reviews are retained and treated as anonymous, so the author's name is no longer shown even if the author chose to disclose it;
- the establishment's customer list keeps the corresponding line without identification, with its booking count.
Deleting a customer account does not affect data that an establishment received and retained on its own initiative, under section 6. For that data, the request must be addressed to the establishment.
Deleting an establishment entails removing its associated services, professionals, photographs and schedules, without prejudice to legal retention obligations and temporary persistence in the restoration history described in section 19.
Deletion of walk-in customer data may be requested by the data subject from KIHORA or the establishment that recorded it. When the request is addressed to KIHORA and it acts as processor, it will be forwarded and coordinated with the establishment, under section 23.
19 Backups
The database service used by KIHORA maintains its own history-retention mechanism that allows the database to be restored to an earlier point in time.
Under the currently contracted plan, this mechanism covers approximately seven days in production.
Photograph storage benefits from the redundancy and protection mechanisms provided by its provider.
Consequently:
- data deleted from active systems may continue to exist in the database restoration history for an approximate maximum of seven days;
- during that period, the data is not accessible through the apps, cannot be recovered by the user and is not used for other purposes;
- access to the restoration history is limited to authorised technical staff and should occur only in justified technical, security or legal circumstances.
Backups are intended to recover the platform after technical failures or serious incidents and are not an individual archive available to the user.
A restoration window of this size means that the platform does not replace the establishment's own records. Establishments are advised to keep their own records of schedules and customers.
20 Security
KIHORA applies technical and organisational measures intended to protect personal data, including:
- user authentication through external identity providers;
- server-side validation that each request is made by someone authorised to make it;
- resolving the user's identity from the authentication token, never from identifiers sent in the request;
- separating customer accounts from business accounts;
- separating establishments so that an establishment can access only its own establishment data;
- limiting an establishment's access to customers who actually have bookings at that establishment;
- encrypting communications through HTTPS;
- encrypted storage of session credentials on the device through the operating system's secure mechanisms;
- managing secrets in a dedicated vault;
- access and audit logs;
- monitoring errors, availability and incidents;
- restricting administrative access to the infrastructure.
No computer system is completely immune to failures, attacks or unlawful access.
21 Authentication and identity
Sign-in is performed exclusively through external identity providers, currently Google and Apple.
KIHORA does not set, receive or store users' passwords.
Each account corresponds to an individual. The identifier assigned by the identity provider is the account's identity key, not the email address, so changing the address with the provider does not cause the user to lose access to their history.
KIHORA does not provide its own two-factor authentication. Access security depends largely on the security of the Google or Apple account used, and the user is responsible for protecting it, including by enabling the two-step verification mechanisms provided by those providers.
Sharing credentials between people is prohibited.
22 Exceptional administrative access
By default, KIHORA staff do not view account data or booking content.
Access may occur when necessary to:
- provide requested support;
- resolve a technical failure;
- investigate fraud or unauthorised access;
- ensure security;
- recover or protect an account;
- comply with a legal obligation;
- respond to a competent authority.
Access must be limited to what is necessary, carried out by authorised staff, subject to confidentiality obligations, linked to a justified purpose and logged when technically applicable.
23 Data-subject rights
Under the law applicable in Cape Verde, data subjects may exercise, where applicable, the following rights:
- the right to information;
- the right of access;
- the right to rectification;
- the right to erasure or blocking of data;
- the right to object;
- the right to withdraw consent when processing is based on it;
- the right not to be subject to solely automated decisions.
These rights are not absolute and may be subject to legal conditions or limitations. For example, the right to erasure may not apply when retention is necessary to comply with a legal obligation or to exercise or defend rights.
Some of these rights can be exercised directly in the app, including correcting the profile, changing sharing preferences and deleting the account.
Other requests should be sent to: [email protected]
The request must clearly state:
- the applicant's identity;
- the right they wish to exercise;
- the data or processing concerned;
- information needed to locate the data, including the account email address or the establishment where the data was recorded.
KIHORA may request additional information strictly necessary to confirm the applicant's identity, so that data is not disclosed to anyone who is not the relevant data subject.
Exercising these rights is generally free of charge.
KIHORA will seek to respond within the legally applicable period or, where none applies, within a maximum of thirty days from receipt of a properly documented request.
When data was entered by a participating establishment, or when the request concerns the establishment's use of data received under section 6, KIHORA may forward or coordinate the request with that establishment as controller and inform the data subject of that referral.
24 Complaints to the supervisory authority
The data subject has the right to lodge a complaint with:
National Data Protection Commission of Cape Verde
Information about data-subject rights and complaint procedures is available on the website of the National Data Protection Commission at www.cnpd.cv.
25 Commercial communications
Commercial communications are separate from essential service communications and booking notifications.
Acceptance of the Terms of Use, acceptance of the Data Processing Agreement or acknowledgement of this Policy does not amount to consent to receive marketing.
When marketing depends on consent:
- consent will be requested separately;
- the option will not be preselected;
- refusal will not prevent normal use of the platform;
- consent may be withdrawn at any time.
Booking push notifications are not commercial communications and cannot be used for that purpose.
An establishment receiving a telephone number under section 7 may use it for contact about the booking only. It is not consent to receive advertising from that establishment.
26 Cookies, local storage and public pages
The KiHora and KiHora Business mobile apps do not use cookies.
The apps use local storage mechanisms on the device to:
- store the session credential in encrypted form;
- store the account identifier and profile elements needed to operate during a temporary loss of connection;
- store preferences, including the app theme;
- record whether location permission has already been requested.
These mechanisms are necessary for the service to operate.
KIHORA may publish public pages for published establishments on kihora.cv, containing the name, cover photograph, description, location and service catalogue. These pages are intended to be found through search engines.
These pages do not show reviews, customer names or any customer data, and do not use analytics, personalisation or advertising cookies.
If non-essential cookies are introduced on kihora.cv, consent will be requested where legally required and detailed information will be included in a separate Cookie Policy.
27 Children
The KiHora Business app is intended exclusively for people aged at least 18 who have capacity to enter into contracts and represent an establishment.
The KiHora app is intended for people aged at least 13. Users under 18 may use it only with the knowledge and authorisation of their legal representative.
KIHORA does not collect dates of birth and does not ask the user to declare their age, so it cannot verify either.
Creating an account requires a Google or Apple account, whose use is also subject to the age conditions set by those providers.
The data sharing described in section 7 applies to underage users in the same way. Their legal representative is responsible for monitoring their use of the app, including the submission of non-anonymous reviews, which show the author's first name.
When an establishment records a booking for a minor as a walk-in customer, the establishment is responsible for ensuring that it has the consent or authorisation of the legal representative and for limiting the recorded data to what is strictly necessary.
If improper processing of children's data is identified, KIHORA may limit processing, suspend access, request clarification and delete the data where legally applicable.
28 Platform development status
KIHORA is in an early operating phase, with a phased launch and a set of features that is still evolving.
The feature for exporting data from the app is not yet available and is provided on request under section 23.
This circumstance does not reduce data subjects' rights or KIHORA's legal obligations.
As these features become available, this Policy will be updated.
29 Personal-data breaches
In the event of a personal-data breach likely to pose a risk to data subjects' rights and freedoms, KIHORA will:
- document the incident;
- adopt appropriate containment and corrective measures;
- report the incident to the National Data Protection Commission as legally required;
- inform affected data subjects when the risk requires it;
- inform affected participating establishments when the incident concerns data processed on their behalf.
Any incident or suspected unauthorised access must be reported immediately to [email protected].
30 Acceptance and changes to the Policy
This Policy is acknowledged when an account is created and does not, by itself, constitute a request for consent.
For each account, KIHORA records which legal documents were accepted or acknowledged, in which version and on what date.
KIHORA may update this Policy whenever there are legal, regulatory, technical, contractual or operational changes, changes relating to providers, or changes relating to platform features.
The latest version will be made available on kihora.cv, with the version and effective date indicated.
When there are materially significant changes, users will be informed through the app, by email or by another appropriate means, and new acknowledgement may be requested before use continues.
Previously accepted or acknowledged versions are retained for evidentiary and audit purposes.
31 Contact
For questions about data protection, exercising rights or this Privacy Policy: