Legal
Privacy Policy
Your privacy is a fundamental right. This policy explains what MKH Suite collects, why we collect it, and how you stay in control of your account and workspace data.
Who We Are
MKH Suite is operated by Muhammad Kabir Hussain ("we", "us", "our"). We provide an AI-powered CRM and project management platform for freelancers and tech companies — including leads, deals, clients, projects, inbox sync, booking pages, and AI writing tools. We are the data controller for personal data processed through the platform.
Privacy & GDPR requests
General support
Security vulnerabilities
Legal inquiries
Scope
This Privacy Policy applies to:
- Workspace owners and team members on company or individual accounts
- Visitors to mkhsuite.com, app.mkhsuite.com, company workspaces (*.mkhsuite.com), and admin.mkhsuite.com
- Prospects who interact with your booking pages or inbox conversations
- Anyone contacting us for support, billing, or partnership inquiries
Third-party services you connect — Anthropic, your SMTP/IMAP provider, Paddle, Calendly — are governed by their own policies. We only process data through them when you enable an integration.
Data We Collect
Account & identity
| Data | Purpose |
|---|---|
| Full name | Account identification and personalization |
| Email address | Authentication, notifications, and support |
| Workspace slug / username | Tenant routing and workspace identity |
| Account type (company or individual) | Feature access and URL routing |
| Profile photo (optional) | UI personalization |
| Password (hashed — never plain text) | Authentication |
| Timezone and locale | Scheduling, bookings, and display |
Billing & payment
| Data | Purpose |
|---|---|
| Subscription plan and tier | Service delivery and feature limits |
| Invoice and transaction history | Billing records and tax compliance |
| Payment method (tokenized via Paddle) | Payment processing — we never store card numbers |
| Paddle customer and subscription IDs | Billing reconciliation and portal access |
Workspace & CRM
| Data | Purpose |
|---|---|
| Leads, deals, and clients | CRM and pipeline management |
| Sent and received emails, attachments | Inbox sync and conversation history |
| Email events (opens, clicks, bounces) | Deliverability and conversation analytics |
| Booking pages and appointments | Scheduling and calendar sync |
| Projects, files, and knowledge base | Client delivery and AI context |
Integration credentials
| Data | Purpose |
|---|---|
| SMTP / IMAP credentials | Send and receive email on your behalf |
| Anthropic API key | AI writing and agent responses |
| Calendly or booking webhook URLs | Appointment sync |
Technical & usage
| Data | Purpose |
|---|---|
| IP address | Security, rate limiting, and abuse prevention |
| Browser and device metadata | Compatibility and debugging |
| API and error logs | Service reliability |
| Feature usage metrics | Product improvement (aggregated where possible) |
How We Collect Data
- Directly from you — registration, workspace setup, CRM records, uploads, and support messages
- Automatically — session cookies, server logs, and usage metrics
- From integrations — IMAP messages, Calendly events
- From Paddle — transaction confirmations when paid billing is active
- From booking forms — appointment submissions on your public pages
Legal Basis for Processing (GDPR)
| Activity | Legal basis |
|---|---|
| Account registration and authentication | Contract performance |
| Outbound service delivery | Contract performance |
| Billing and invoicing | Contract performance + legal obligation |
| Security monitoring and fraud prevention | Legitimate interests |
| Product analytics (aggregated) | Legitimate interests |
| Marketing emails (if opted in) | Consent |
| Legal compliance and record keeping | Legal obligation |
How We Use Your Data
- Operate the workspace — store leads, deals, clients, projects, sync inbox, power AI agents
- Process billing — manage subscriptions through Paddle when paid plans are active
- Provide support — respond to tickets and troubleshoot account issues
- Secure the platform — detect abuse and unauthorized access
- Improve the product — analyze aggregated, anonymized usage patterns
Data Sharing & Third Parties
We share data only when necessary to provide the Service.
AI providers
| Provider | Data shared | Purpose |
|---|---|---|
| Anthropic (Claude) | Prompts, templates, and agent context you submit | AI writing and agent responses |
Email infrastructure
| Provider | Data shared | Purpose |
|---|---|---|
| Your SMTP / IMAP provider | Email content and credentials you configure | Send and receive mail |
Platform infrastructure
We host on Cloudflare (Workers, D1 database, R2 storage). Cloudflare processes data under our instructions as a sub-processor.
Payments
Paid subscriptions are processed by Paddle.com Market Limited as Merchant of Record. See our Terms of Service for billing terms.
Legal disclosures
We may disclose data when required by law or court order. Where legally permitted, we will notify you before complying.
AI Data Processing
When you use AI agents, your prompts and context are sent to configured AI providers (typically Anthropic). Providers process inputs under their own policies once data leaves our servers.
- Inputs and outputs are stored in your workspace history
- You can delete AI-generated content from agent sessions
- Do not include highly sensitive personal data in prompts unless necessary
Email & Messaging
When you connect a mailbox, we sync and store messages so you can manage client conversations in your workspace. You are responsible for lawful basis and consent under applicable privacy and anti-spam rules for any messages you send.
International Data Transfers
Your data may be processed outside your home jurisdiction through Cloudflare and connected providers. We rely on appropriate safeguards including processor agreements and standard contractual clauses where required.
To request details of safeguards in place, email privacy@mkhsuite.com.
Your Privacy Rights
| Right | Description | How to exercise |
|---|---|---|
| Access | Receive a copy of personal data we hold | Email us or Settings → Account |
| Rectification | Correct inaccurate data | Settings → Profile |
| Erasure | Request deletion of personal data | Data Deletion Policy |
| Portability | Export data in machine-readable format | Email us before account deletion |
| Restriction / objection | Pause or object to certain processing | privacy@mkhsuite.com |
| Withdraw consent | Where processing is consent-based | privacy@mkhsuite.com |
We respond within 30 days. Complex requests may take up to 60 days with notice. Identity verification may be required.
Data Security
Encryption in transit
TLS 1.2+ for all browser-server communication
Server-side secrets
Integration keys never exposed to the browser
Access controls
Role-based workspace access for team accounts
Session hardening
HttpOnly and Secure cookies in production
Rate limiting
API abuse detection and throttling
Audit logging
Sensitive workspace actions are logged
Children's Privacy
MKH Suite is not directed at individuals under 18. We do not knowingly collect personal data from minors. If you believe a minor has provided data, contact us and we will delete it promptly.
Data Retention
See our Data Retention Policy for full schedules. Key periods:
| Data type | Retention |
|---|---|
| Account data | Active account + 30 days after deletion request |
| CRM and inbox data | Until deleted by you or workspace removal |
| Billing records | 7 years (legal requirement) |
| Technical logs | 90 days |
Changes to This Policy
We may update this policy as features evolve. Material changes will be communicated via email or in-app notice. Previous versions are available on request.
Contact Us
Privacy requests
Security issues
General support
Response time: within 30 days for privacy requests.
Related policies
MKH Suite is operated by Muhammad Kabir Hussain. These policies describe how we handle data for the platform at mkhsuite.com. For jurisdiction-specific legal advice, consult a qualified attorney.