Legal
Privacy Policy
Last updated: 29 July 2026 · Version 2.4
1. Who we are
The Ken is operated by TheKen Ltd, a company registered in England and Wales (company number 17136686). We ("us", "our") are the data controller for personal data processed through our device, admin portal and mobile app. Contact: hello@theken.uk.
2. What data we collect
| Data | Purpose | Basis |
|---|---|---|
| Name, email, phone number | Account creation and portal access | Contract |
| Password (hashed + salted) | Authentication | Contract |
| Device ID | Linking your account to a Ken device | Contract |
| Contact names, photos, phone numbers | Displaying contacts on the device | Legitimate interest |
| Messages (text) | Delivering messages between portal and device | Contract |
| Video-mails (video/audio recordings) | Allowing family to leave messages | Consent |
| Call history (times, duration) | Showing recent calls in the portal | Legitimate interest |
| Medical records (GP, medications, allergies, conditions) | Care coordination and emergency access | Vital interests / Explicit consent |
| Care notes and medication logs | Safeguarding and care continuity | Legitimate interest (safeguarding) |
| Device heartbeat (online/offline status) | Monitoring device connectivity | Legitimate interest |
| Settings and preferences | Syncing device configuration | Contract |
| Audit log (who changed what setting, when) | Accountability and transparency | Legitimate interest |
| Photos (uploaded by family) | Photo carousel on the device | Consent |
| Consent records (what you agreed to, when) | Demonstrating lawful basis for processing | Legal obligation |
| Push notification tokens (mobile app) | Delivering alerts for messages, calls and reminders | Consent |
| Device platform and OS version (mobile app) | Ensuring app compatibility and debugging | Legitimate interest |
3. How and where we store your data
The Ken is operated from the United Kingdom by TheKen Ltd. Your data is stored and processed on infrastructure provided by Cloudflare, Inc. (headquartered in the USA) across their global network, including our primary database (Cloudflare D1), key-value stores (Cloudflare KV), media storage (Cloudflare R2) and real-time signalling (Cloudflare Durable Objects). Cloudflare is certified under ISO 27001 and SOC 2 Type II. Video call relay, when a direct peer-to-peer connection is not possible, is handled by TURN servers hosted by Hetzner Online GmbH in Germany. Data is encrypted in transit (TLS 1.3) and at rest.
International transfers. Because Cloudflare operates a global network, some processing may take place outside the UK and the European Economic Area. Where this occurs, transfers are protected by the UK International Data Transfer Addendum to the EU Standard Contractual Clauses, incorporated into our processors' Data Processing Agreements. Hetzner processing takes place within the EEA (Germany), which benefits from a UK adequacy decision.
We apply additional layers of protection:
- Passwords are salted and hashed using PBKDF2 with 100,000 iterations of SHA-256 - never stored in plain text
- Sensitive medical data (GP details, medications, allergies, conditions, NHS number, next of kin, key-safe code and the patient's date of birth) is encrypted at the field level using AES-256-GCM before storage. A care note saved through the older medical screen carries that same encryption
- Held as ordinary text in the database: the care-notes diary the portal writes to today and the older history behind it, the detail of a medication reminder (its label, the medicine's name, the dose, the instructions and any photo), and the rest of the patient record (patient number, full name, where they live, preferred hospital, communication notes and mobility level)
- MFA backup codes are individually hashed - we cannot read them
- Deleted user data is tokenised and the identity mapping is encrypted with a separate key in an isolated data store (see Section 6)
4. Who has access to your data
- Device users can see contacts, receive messages and calls on the physical device
- Contact users can see their own messages, calls and voicemails via the portal
- Admin users can manage contacts, messages, settings, medication reminders, and view the audit log
- Healthcare professional users can access care notes, medical records, medication management, and check-in schedules for devices they are assigned to
- HQ administrators can view all devices, manage user roles, and - with documented justification - resolve tokenised identity records for legal or safeguarding purposes. Every such access is audit-logged
- The Ken team may access data for technical support or to resolve issues, only when necessary
- We do not sell, rent or share your personal data with third parties for marketing purposes
5. Third-party services (sub-processors)
We use the following third-party services to operate The Ken. Each acts as our data processor under a written Data Processing Agreement:
- Cloudflare, Inc. (USA / global network) - API hosting, D1 database, KV stores, R2 media storage, Durable Objects signalling, and video call signalling (privacy policy)
- Hetzner Online GmbH (Germany) - TURN relay servers for video calls when peer-to-peer is not possible (privacy policy)
- Cloudflare Workers Static Assets (USA / global network) - marketing website and admin portal hosting (privacy policy)
- Resend (USA) - transactional email delivery. The activity email about a new message carries the sender's name and the first 100 characters of what they wrote (privacy policy)
- Apple Inc. (Apple Push Notification service), Google LLC (Firebase Cloud Messaging) and Expo (USA) - delivering push notifications to the mobile app. A push carries the caller's name, the Ken's name, the group name, whether the call is voice or video and, for an offline alert, how many minutes the Ken has been off. No message text is sent in a push (privacy policy)
- Stripe Payments Europe, Ltd. - card payment and subscription billing. We never see or store your card number (privacy policy)
- Backblaze, Inc. (USA) - off-site cold storage of the nightly database backup (privacy policy)
- Better Stack (Czech Republic) - operational logging, which includes device identifiers and account identifiers (privacy policy)
- Anthropic PBC (USA) - answering questions typed into our support chat. The text you type and the recent conversation are sent (privacy policy)
- Cloudflare Workers AI (global network) - transcribing voicemail audio into text so it can be read as well as heard. The audio itself is sent (privacy policy)
- Google LLC (public STUN servers) - helping two devices find a direct route to each other at the start of a call. The public IP address of each end is seen (privacy policy)
- Cloudflare RealtimeKit (global network) - carries the sound and picture of a group call, which does not run directly between the people on it (privacy policy)
- Tailscale Inc. (USA) - the private network our support team uses to reach a Ken. Device names, the address each Ken is given on that network and when it was last seen are held there (privacy policy)
- Twilio Inc. (USA / Ireland) - our support telephone line. The number you call from is processed so the call can be put through (privacy policy)
- Google LLC (connectivity check) - the Ken asks a Google address whether its internet connection is working, and opens the plain page at neverssl.com to bring up a hotel or cafe sign-in screen. The Ken's IP address is seen by both (privacy policy)
- PostHog (EU hosting) - cookieless website analytics (privacy policy)
A call between two people runs straight between the two ends wherever the network allows, and is relayed through our TURN servers at Hetzner in Germany when it cannot. A group call is different: its sound and picture always pass through Cloudflare RealtimeKit. A live call is never recorded or stored. A voicemail or video message is a recording somebody chooses to leave, and is stored as described in section 6.
We do not sell, rent or share your personal data with third parties for marketing purposes.
6. Data retention and deletion
While your account is active:
- Account data is retained for the lifetime of your account
- The portal and the device show the most recent 100 messages per device
- Voicemails and video messages are retained for 3 months by default, or longer if you have an extended storage plan
- The audit log shows the most recent 500 entries per device. Every entry is kept in the database for 12 months from the day it was written
- We may retain voicemail and video message data in our secure cloud infrastructure for a limited period beyond your visible retention window, to allow for service recovery, dispute resolution, or in case you choose to extend your storage plan. This data is not accessible to users during this period. The sweep that erases it runs once a day and does delete, and we will also erase it by hand if you ask us to
When your account is deleted, we use a tokenisation process to protect your identity while retaining records we are legally required to keep:
- Your personal identifiable information (name, email, phone number) is replaced with a random token across all records
- The mapping between your token and your real identity is encrypted with a separate key and stored in an isolated, access-controlled data store
- Only HQ administrators can resolve a token back to a real identity, and only with a documented reason - every lookup is audit-logged
- The token mapping is deleted when the retention period ends, and once it is gone nobody can work back from a record to a person
Post-deletion retention periods:
| Data type | Retention period | Justification |
|---|---|---|
| Audit log entries in our database | 12 months from the day each entry was written | Legal and regulatory compliance |
| Medical records, care notes and the token that links them to you | 3 years | UK safeguarding obligations |
| The token that links a retained audit record to you | 6 years | Legal and regulatory compliance |
| Messages, and the token that links them to you | 1 year | Dispute resolution |
| Everything else, including voicemails, contacts and call history | 90 days | Recovery, dispute resolution and operational cleanup |
Two sweeps sit behind that table and both of them delete. The one that erases the tokens and the retained records at the end of each period above runs once a day. The one that erases the account's own remaining records, once the date in the table has passed, runs every hour. If you want your data erased sooner than that, email us and we will run the erasure by hand. Once the token mapping is deleted, the retained records are effectively anonymous and cannot be linked back to any individual.
7. Your rights (UK GDPR)
You have the right to:
- Access - request a copy of all personal data we hold about you (Subject Access Request). We will provide this within 30 days in a machine-readable format
- Rectification - correct inaccurate data via your profile settings or by contacting us
- Erasure - request deletion of your data ("right to be forgotten"). We will tokenise your identity and delete your account. Certain records may be retained in tokenised form where we have a legal obligation (see Section 6)
- Portability - receive your data in JSON format via the portal's data export feature (available to Admin and HQ users)
- Object - object to processing based on legitimate interest
- Restrict processing - request that we limit how we use your data
- Withdraw consent - for data processed on the basis of consent (e.g. voicemails, photos, marketing communications). You can manage your consent preferences at any time via the portal's subscription settings
To submit a Subject Access Request or exercise any of these rights, email hello@theken.uk. We will respond within 30 days. HQ administrators can also process Subject Access Requests via the portal's HQ Admin panel.
8. Consent
When you create an account, you are asked to confirm that you have read and agree to this privacy policy and our Terms & Conditions. This consent is recorded with a timestamp and the policy version number in your account record.
You can manage your communication and data preferences at any time via the Subscriptions section in your profile settings. Each preference records when it was last changed. The following are individually configurable:
- Email notifications (messages, voicemails, missed calls, medication alerts)
- Birthday reminders
- Product updates and announcements
Withdrawing consent for optional features will not affect the core functionality of your Ken device.
9. Children's data
The Ken service is not intended for use by children under 13. We do not knowingly collect data from children. Contact photos of children (e.g. grandchildren) uploaded by family members are stored solely for display on the device.
10. Security
- All data in transit is encrypted using TLS 1.3
- Passwords are individually salted and hashed - never stored in plain text
- Sensitive medical fields are encrypted at rest using AES-256-GCM
- Deleted user identity mappings are encrypted with a separate key in an isolated data store
- Session tokens expire after 30 days and are HttpOnly + Secure
- Optional two-factor authentication (TOTP) is available
- Rate limiting is applied to authentication, password reset, and sensitive endpoints
- CSRF tokens are checked on state-changing requests made from a browser session
- Content Security Policy headers restrict script execution
- The audit log records changes to medical, care and account data, and every export of data out of the portal. Reads of a medical or care record are not recorded
- Bulk data exports are recorded in the audit log
- Failed sign-ins, failed password resets, failed email verifications and failed authenticator codes are counted for the lock-out, and a run of them is watched for automatically. Where the pattern looks like an attack, whether from one source or from many at once, an alert row naming the source and the number of attempts is written to the audit log and kept for 12 months
11. Data breach notification
In the event of a personal data breach that poses a risk to your rights and freedoms, we will:
- Notify the Information Commissioner's Office (ICO) within 72 hours of becoming aware of the breach, as required by Article 33 of UK GDPR
- Notify affected individuals without undue delay where the breach is likely to result in a high risk, as required by Article 34
- Document the breach, its effects, and the remedial actions taken in our internal audit log
Every resolution of a token back to a real identity is recorded with the reason given, and every export of data out of the portal is written to the audit log, so a breach can be reconstructed from those records.
12. Changes to this policy
We may update this policy from time to time. Changes will be posted on this page with an updated date. For material changes, we will notify you via email. If a policy change affects how we process your data, we may ask you to re-confirm your consent.
Policy version: 2.4
13. Contact
For privacy-related questions or to exercise your rights, contact us at hello@theken.uk or call +44 1236 801234.
If you are unsatisfied with our response, you have the right to lodge a complaint with the Information Commissioner's Office (ICO) at ico.org.uk.