TRUST, SAFETY & TRANSPARENCY

Privacy, clearly explained.

How KIIMO collects, uses and protects personal data across the mobile application and delivery network.

KIIMO Mobile Application Privacy Policy

We created the KIIMO mobile application to enable fast parcel delivery across the city and to let community members earn by completing deliveries near routes they already travel. This policy explains how personal data is protected while the service is used.

1. Controller

Under the Law on Personal Data Protection, the controller is KIIMO TECHNOLOGIES DOOEL Skopje, Dame Gruev St. 7/4-4, Centar, Skopje. Telephone: +389 70 894 436. Email: david.pavlovski@kiimo.me. Website: https://kiimo.me.

2. Data Protection Officer

Address: Dame Gruev St. 7/4-4, Centar, Skopje. Telephone: +389 70 894 436. Email: david.pavlovski@kiimo.me. Website: https://kiimo.me.

3. Definitions

This policy uses the terms from the Law on Personal Data Protection. Personal data means any information relating to an identified or identifiable natural person. A data subject is the person whose personal data is processed. Processing means any operation performed on personal data, including collection, recording, organisation, structuring, storage, adaptation, retrieval, consultation, use, disclosure, combination, restriction, erasure or destruction.

A controller determines the purposes and means of processing. A processor processes personal data on behalf of the controller. A user is a natural or legal person using KIIMO. A third party is a person or organisation other than the data subject, controller, processor or an authorised person. Consent is a freely given, specific, informed and unambiguous indication of the data subject’s wishes.

4. Personal data protection principles

Personal data is collected and processed lawfully, fairly and transparently, only for the purposes of using the KIIMO mobile application. It is not further processed for incompatible purposes without an appropriate assessment.

Processing is limited to the data necessary for the stated purposes. KIIMO takes reasonable steps to keep data accurate, enables users to correct, supplement or erase data, retains it only for the period required by this policy, and applies technical and organisational safeguards against unauthorised access, unlawful disclosure, loss or destruction.

5. What personal data do we collect and process?

KIIMO processes personal data disclosed by users of the application, whether they request delivery services as Senders and Recipients or provide delivery as Kiimsters.

Registration data includes name and surname, mobile phone number and email address. Users may also add pickup and delivery addresses. Identity verification requires an identification-document image and is performed through Didit; verification data is handled under Didit’s privacy policy.

When using KIIMO, the service may process order and delivery details, delivery history, basket items, payment-card details, a Kiimster’s real-time location and rating.

  • Name and surname
  • Mobile phone number
  • Email address
  • Pickup and delivery addresses
  • Identity-document image for verification
  • Order, delivery, basket and payment details
  • Real-time location and rating for Kiimsters

6. Why do we collect and process your personal data?

We process personal data to provide access to the delivery platform, connect Senders and Recipients with independent delivery partners, publish delivery requests, match requests with available Kiimsters based on location and rating, process payments, track deliveries and enable communication between the parties.

If additional processing becomes necessary, we will inform you and, where required, request consent before that processing begins.

7. Legal basis for processing

Consent is the legal basis for optional and required registration data. When a user arranges a delivery, processing is also necessary to perform the agreement between the user and KIIMO and the accepted terms of use.

8. Automated decision-making and direct-marketing profiling

KIIMO provides the described matching functionality but does not perform automated user-to-user linking that produces legal or similarly significant effects, and it does not currently provide profiling functionality. If this changes, KIIMO will conduct a prior analysis and, where necessary, obtain consent.

9. How do we protect your personal data?

KIIMO uses two-step identification when access to the application begins: registration data and verification through a code received by SMS. Communications within KIIMO are encrypted. KIIMO also applies appropriate technical and organisational safeguards designed to protect personal data from unauthorised access, disclosure, alteration or loss.

10. How long do we keep your personal data?

KIIMO keeps your personal data while you actively use the service. If you withdraw consent for processing for the purposes of using KIIMO, KIIMO will erase your personal data, subject to any lawful retention obligations.

11. How do we limit processing?

Personal data is processed and stored only for as long as necessary to achieve the purpose for which it was collected and processed.

12. Is your data transferred to another country or shared with anyone?

KIIMO is hosted on servers in the Federal Republic of Germany. Information about the server provider’s privacy practices is available at https://contabo.com/en/legal/privacy/.

KIIMO may disclose data to contracted service providers for archiving, storage and communication services, under agreements requiring an appropriate level of protection. Data may also be disclosed to competent public authorities where required by law. Any future transfer or disclosure not covered by this policy will be communicated in advance and consent will be requested where necessary.

13. Links to other websites

KIIMO may display links to third-party applications or websites that we do not operate. If you follow such a link, you will be directed to that third party. We recommend reviewing the privacy policy of every external site you visit. KIIMO does not control and is not responsible for third-party content, policies or privacy practices.

14. Protection of personal data during electronic payment

KIIMO TECHNOLOGIES cooperates with Komercijalna Banka. Its e-commerce payment module enables secure card payments and includes 3D Secure, Pay by Link and transaction reporting. Supported security protocols include Mastercard Identity Check and Visa Secure.

Further information is available through Komercijalna Banka at https://www.kb.mk/e-commerce.nspx and https://www.kb.mk/Content/Politika-na-privatnost-na-KB-2022-12.pdf.

15. Your rights as a data subject

You have the right to request access to the personal data processed about you and information about why it is processed, the categories involved, its sources, recipients, retention period and any automated decision-making.

You may request correction of inaccurate or incomplete data; erasure where the data is no longer required, consent is withdrawn, processing is unlawful or another legal ground applies; restriction where accuracy or lawfulness is disputed; and a structured, commonly used and machine-readable copy for portability. You may withdraw consent at any time without affecting processing carried out before withdrawal.

  • Right of access
  • Right to rectification
  • Right to erasure
  • Right to restrict processing
  • Right to data portability
  • Right to withdraw consent

16. Is there an age limit for using KIIMO?

KIIMO is not intended for children under 18. If a parent or guardian learns that a child under 18 has disclosed personal data to KIIMO without consent, they should contact the Data Protection Officer. If KIIMO discovers an account belonging to a person under 18, it will take steps to erase the data and delete the account.

17. Changes to this Privacy Policy

KIIMO TECHNOLOGIES may periodically update this policy as the service develops and user experience changes. We encourage users to review updates so they remain informed about the protection and processing of their personal data.

18. Right to submit a request to the Personal Data Protection Agency

If you believe that your personal data is not being processed in accordance with the Law on Personal Data Protection, you may contact the Personal Data Protection Agency, Goce Delchev Blvd. 18, Skopje, at https://www.dzlp.mk/ or info@privacy.mk.