Legal

Privacy Policy

Your privacy is a fundamental right. This policy explains what MKH Suite collects, why we collect it, and how you stay in control of your account and workspace data.

Version 1.0Effective July 7, 2026GDPR alignedBusiness platform
1

Who We Are

MKH Suite is operated by Muhammad Kabir Hussain ("we", "us", "our"). We provide an AI-powered CRM and project management platform for freelancers and tech companies — including leads, deals, clients, projects, inbox sync, booking pages, and AI writing tools. We are the data controller for personal data processed through the platform.

Privacy & GDPR requests

General support

Security vulnerabilities

Legal inquiries

2

Scope

This Privacy Policy applies to:

  • Workspace owners and team members on company or individual accounts
  • Visitors to mkhsuite.com, app.mkhsuite.com, company workspaces (*.mkhsuite.com), and admin.mkhsuite.com
  • Prospects who interact with your booking pages or inbox conversations
  • Anyone contacting us for support, billing, or partnership inquiries

Third-party services you connect — Anthropic, your SMTP/IMAP provider, Paddle, Calendly — are governed by their own policies. We only process data through them when you enable an integration.

3

Data We Collect

Account & identity

DataPurpose
Full nameAccount identification and personalization
Email addressAuthentication, notifications, and support
Workspace slug / usernameTenant routing and workspace identity
Account type (company or individual)Feature access and URL routing
Profile photo (optional)UI personalization
Password (hashed — never plain text)Authentication
Timezone and localeScheduling, bookings, and display

Billing & payment

DataPurpose
Subscription plan and tierService delivery and feature limits
Invoice and transaction historyBilling records and tax compliance
Payment method (tokenized via Paddle)Payment processing — we never store card numbers
Paddle customer and subscription IDsBilling reconciliation and portal access

Workspace & CRM

DataPurpose
Leads, deals, and clientsCRM and pipeline management
Sent and received emails, attachmentsInbox sync and conversation history
Email events (opens, clicks, bounces)Deliverability and conversation analytics
Booking pages and appointmentsScheduling and calendar sync
Projects, files, and knowledge baseClient delivery and AI context

Integration credentials

DataPurpose
SMTP / IMAP credentialsSend and receive email on your behalf
Anthropic API keyAI writing and agent responses
Calendly or booking webhook URLsAppointment sync
Integration secrets are stored server-side only. They are never returned to the browser or exposed in client-side code.

Technical & usage

DataPurpose
IP addressSecurity, rate limiting, and abuse prevention
Browser and device metadataCompatibility and debugging
API and error logsService reliability
Feature usage metricsProduct improvement (aggregated where possible)
4

How We Collect Data

  • Directly from you — registration, workspace setup, CRM records, uploads, and support messages
  • Automatically — session cookies, server logs, and usage metrics
  • From integrations — IMAP messages, Calendly events
  • From Paddle — transaction confirmations when paid billing is active
  • From booking forms — appointment submissions on your public pages
6

How We Use Your Data

  • Operate the workspace — store leads, deals, clients, projects, sync inbox, power AI agents
  • Process billing — manage subscriptions through Paddle when paid plans are active
  • Provide support — respond to tickets and troubleshoot account issues
  • Secure the platform — detect abuse and unauthorized access
  • Improve the product — analyze aggregated, anonymized usage patterns
What we do not do: We do not sell your CRM data. We do not use your workspace content or AI prompts to train third-party models without your explicit written consent. We do not run advertising based on your workspace data.
7

Data Sharing & Third Parties

We share data only when necessary to provide the Service.

AI providers

ProviderData sharedPurpose
Anthropic (Claude)Prompts, templates, and agent context you submitAI writing and agent responses

Email infrastructure

ProviderData sharedPurpose
Your SMTP / IMAP providerEmail content and credentials you configureSend and receive mail

Platform infrastructure

We host on Cloudflare (Workers, D1 database, R2 storage). Cloudflare processes data under our instructions as a sub-processor.

Payments

Paid subscriptions are processed by Paddle.com Market Limited as Merchant of Record. See our Terms of Service for billing terms.

Legal disclosures

We may disclose data when required by law or court order. Where legally permitted, we will notify you before complying.

8

AI Data Processing

When you use AI agents, your prompts and context are sent to configured AI providers (typically Anthropic). Providers process inputs under their own policies once data leaves our servers.

  • Inputs and outputs are stored in your workspace history
  • You can delete AI-generated content from agent sessions
  • Do not include highly sensitive personal data in prompts unless necessary
9

Email & Messaging

When you connect a mailbox, we sync and store messages so you can manage client conversations in your workspace. You are responsible for lawful basis and consent under applicable privacy and anti-spam rules for any messages you send.

10

International Data Transfers

Your data may be processed outside your home jurisdiction through Cloudflare and connected providers. We rely on appropriate safeguards including processor agreements and standard contractual clauses where required.

To request details of safeguards in place, email privacy@mkhsuite.com.

11

Cookies & Tracking

We use essential session cookies to keep you signed in. For the full inventory, see our Cookie Policy.

TypePurposeOpt out?
EssentialAuthentication and securityNo — required for the Service
FunctionalTheme and UI preferencesYes
AnalyticsAggregated usage (server-side where possible)Limited

We do not use advertising, retargeting, or social media tracking cookies.

12

Your Privacy Rights

RightDescriptionHow to exercise
AccessReceive a copy of personal data we holdEmail us or Settings → Account
RectificationCorrect inaccurate dataSettings → Profile
ErasureRequest deletion of personal dataData Deletion Policy
PortabilityExport data in machine-readable formatEmail us before account deletion
Restriction / objectionPause or object to certain processingprivacy@mkhsuite.com
Withdraw consentWhere processing is consent-basedprivacy@mkhsuite.com

We respond within 30 days. Complex requests may take up to 60 days with notice. Identity verification may be required.

13

Data Security

Encryption in transit

TLS 1.2+ for all browser-server communication

Server-side secrets

Integration keys never exposed to the browser

Access controls

Role-based workspace access for team accounts

Session hardening

HttpOnly and Secure cookies in production

Rate limiting

API abuse detection and throttling

Audit logging

Sensitive workspace actions are logged

Data breach notification: If a breach affects your data, we will notify affected users and relevant authorities as required by applicable law. Report vulnerabilities to security@mkhsuite.com.
14

Children's Privacy

MKH Suite is not directed at individuals under 18. We do not knowingly collect personal data from minors. If you believe a minor has provided data, contact us and we will delete it promptly.

15

Data Retention

See our Data Retention Policy for full schedules. Key periods:

Data typeRetention
Account dataActive account + 30 days after deletion request
CRM and inbox dataUntil deleted by you or workspace removal
Billing records7 years (legal requirement)
Technical logs90 days
16

Changes to This Policy

We may update this policy as features evolve. Material changes will be communicated via email or in-app notice. Previous versions are available on request.

17

Contact Us

Privacy requests

Security issues

General support

Response time: within 30 days for privacy requests.

Related policies

MKH Suite is operated by Muhammad Kabir Hussain. These policies describe how we handle data for the platform at mkhsuite.com. For jurisdiction-specific legal advice, consult a qualified attorney.