
Privacy Policy – Kennys Mobile App
Last updated: 20 May 2026
This Privacy Policy applies exclusively to the mobile application „KENNYS Mobile“ (the “App”) for iOS and Android. A separate privacy policy applies to the website www.kennys.de.
The App is an internal business application distributed solely to employees and authorised business partners of KENNYS. GmbH through closed channels (Apple TestFlight / Apple Business Manager Custom App and Google Play Closed Testing).
1. Controller
KENNYS. GmbH
Im Eschle 1
78333 Stockach
Germany
Phone: +49 (0) 7771-876-0
E-mail: info@kennys.de
2. Data Protection Officer
Christoph Rank
machCon Deutschland GmbH
Robert-Bosch-Straße 1
78234 Engen, Germany
E-mail: datenschutz@kennys.de (forwarded to the DPO)
3. Data Processed and Purposes
3.1 Authentication data (Microsoft 365 / Azure AD)
The App uses Microsoft Entra ID (Azure AD) single sign-on via OAuth 2.0 / OpenID Connect.
- Data: Name, business e-mail address, User Principal Name (UPN), Azure AD Object ID, access and refresh tokens.
- Purpose: Authentication, authorisation, role-based access control.
- Legal basis: Art. 6(1)(b) GDPR (performance of the employment relationship) and Art. 88 GDPR in conjunction with § 26 BDSG.
3.2 API usage data (server-side)
Each request the App makes to our backend is logged.
- Data: IP address, timestamp, endpoint path, HTTP status, app version, OS version.
- Purpose: Operational security, troubleshooting, abuse prevention.
- Legal basis: Art. 6(1)(f) GDPR (legitimate interest in secure operation).
- Retention: 90 days, then automatic deletion.
3.3 Push notifications (Firebase Cloud Messaging)
The App uses Firebase Cloud Messaging (FCM) provided by Google Ireland Ltd. to deliver push notifications (e.g. work-related alerts, system notices).
- Data: FCM device token, device type, OS version, app instance ID.
- Purpose: Delivery of push messages in a business context.
- Legal basis: Art. 6(1)(a) GDPR (consent obtained via system dialog on first launch) and Art. 6(1)(b) GDPR for operationally necessary notifications.
- Withdrawal: Can be disabled at any time in device or app settings.
- Third-country transfer: Google LLC (USA). Basis: EU Standard Contractual Clauses and EU-U.S. Data Privacy Framework (EU Commission adequacy decision of 10 July 2023).
3.4 Analytics (Firebase Analytics / Google Analytics for Firebase)
To improve stability and usability, the App uses Firebase Analytics provided by Google Ireland Ltd.
- Data: Pseudonymous instance ID, events (e.g. screen views, crashes), device model, OS version, app version, approximate country-level location derived from IP (IP not stored). IP addresses are truncated by Firebase (IP anonymisation enabled).
- Purpose: Usage analytics, crash reporting, product improvement.
- Legal basis: Art. 6(1)(a) GDPR (consent obtained on first launch).
- Withdrawal: Can be revoked at any time in app settings.
- Retention: 14 months by default (Firebase retention); pseudonymous aggregate data may be retained longer.
- Third-country transfer: Google LLC (USA) under EU Standard Contractual Clauses and the EU-U.S. Data Privacy Framework.
3.5 No other data
The App does not collect location data (GPS), contacts, calendar, camera/microphone data, advertising identifiers (IDFA/GAID) or cookies.
4. Recipients
- Microsoft Ireland Operations Ltd. / Microsoft Corporation (USA) – Azure AD / Microsoft 365 authentication; data processing agreement pursuant to Art. 28 GDPR in place.
- Google Ireland Ltd. / Google LLC (USA) – Firebase Cloud Messaging and Firebase Analytics; data processing agreement in place.
- Apple Distribution International Ltd. (Ireland) / Apple Inc. (USA) – App distribution via App Store / TestFlight / Apple Business Manager; crash logs only with explicit consent.
- Own IT infrastructure – Kenny S. GmbH backend servers hosted within the EU.
Data is never sold for advertising purposes and is not shared with unrelated third parties.
5. Retention
| Data category | Retention |
|---|---|
| Azure AD identity mapping | Duration of employment, deactivated thereafter |
| Access / refresh tokens | Until expiry or sign-out |
| API logs | 90 days |
| Firebase Analytics | 14 months |
| FCM device token | Until uninstall or withdrawal |
6. Your Rights
Under the GDPR you have the following rights in particular:
- Access (Art. 15 GDPR)
- Rectification (Art. 16 GDPR)
- Erasure (Art. 17 GDPR)
- Restriction of processing (Art. 18 GDPR)
- Data portability (Art. 20 GDPR)
- Objection to processing based on legitimate interests (Art. 21 GDPR)
- Withdrawal of consent (Art. 7(3) GDPR) with effect for the future
- Complaint to a supervisory authority (Art. 77 GDPR), e.g. the Data Protection Commissioner of Baden-Württemberg
To exercise your rights, contact us at: info@kennys.de or our Data Protection Officer.
7. Security
- Encrypted transport (HTTPS / TLS 1.2+)
- Token storage in iOS Keychain / Android Keystore
- Role-based access control on the backend
- No password storage within the App
8. Minors
The App is intended exclusively for adult employees and authorised business partners. It is not designed for use by minors.
9. Changes to this Policy
We reserve the right to amend this Privacy Policy to reflect legal developments or changes to the App. The current version is available in the App and at www.kennys.de.