01Who we are and what this covers
Keyveve, Inc. (“Keyveve,” “we,” “us”), a Delaware corporation headquartered in Austin, Texas, provides a platform that accounting, tax, advisory, and other professional services firms use to manage client work: documents, client portals, workflows, messaging, e-signatures, and connections to the other systems those firms already use.
This policy explains how we handle information through the Keyveve application (including the staff and client portals and the desktop app) and through this website. When a firm uses Keyveve for its clients, the firm decides what information goes into Keyveve and why; we process that information on the firm's behalf and under our agreement with the firm.
02Information we collect
Account information
Names, email addresses, phone numbers, roles, and firm details for the people who use Keyveve, and sign-in records.
Client work content
Documents, files, messages, questionnaires, signatures, notes, and other records that firms and their clients upload or create. This can include financial records, tax documents, and tax identification numbers.
Data from connected systems
When a firm or its client chooses to connect another system, such as QuickBooks Online, Xero, Microsoft 365, Google Drive, Dropbox, or a bank through Plaid, we receive the information that connection allows and that the person approved. For accounting systems this can include the chart of accounts, transactions, balances, reports, vendors and customers, and attached documents.
Usage and device information
Log and diagnostic data such as IP address, browser and device type, pages and features used, and error reports.
Website visitors
Basic analytics about visits to this website, and anything you send us, such as a demo request.
03How we use information
- To provide, secure, and support Keyveve and the features a firm turns on.
- To sync and display data from systems a firm or client has connected, and to carry out changes a person at the firm has reviewed and approved.
- To run AI-assisted features (such as document classification, extraction, and research) for the firm that requested them.
- To send service messages, such as sign-in, security, and account notices.
- To monitor, troubleshoot, and improve reliability and security.
- To meet legal obligations and enforce our agreements.
04Artificial intelligence and your data
AI features run on Microsoft Azure services that Keyveve controls. Customer content sent to them is used only to answer the request or provide the feature, and stays tied to the firm it belongs to.
We do not use customer content to train AI models, and we do not allow our providers to. AI output is there to assist people; firms review consequential accounting, tax, legal, and signature decisions before they take effect.
05Data from accounting and other connected systems
Connecting a system such as QuickBooks Online is always a choice made by a person at the firm or its client, on that system's own sign-in page. Keyveve never sees the password for it.
- What we read. Only the data needed for the features the firm uses, for the purposes recorded when the connection was made.
- What we change. Nothing, unless a person at the firm reviews the exact change and approves it first.
- How we store it. Encrypted, in the firm's own separate space. Sign-in tokens for connected systems receive an additional layer of encryption.
- Who sees it. Only people at the firm with access to that client or source. We do not sell it or share it with other firms.
- Disconnecting. Firms can disconnect a system at any time from Keyveve, and can also remove Keyveve's access from within that system. After disconnecting, we stop reading from it and delete or return the stored data under our agreement with the firm and the retention periods below.
Our use of data from each connected system also follows that provider's own developer terms.
07How we protect information
- Data is encrypted in transit (TLS 1.2 or later) and at rest.
- Each firm's data is kept separate, enforced in the application and again in the database.
- Access within Keyveve follows firm, role, client, and document permissions, and important actions are recorded in audit logs.
- Staff access to production systems requires multi-factor authentication and is limited to what each role needs.
- We test backups and recovery, review vulnerabilities, and maintain an incident response plan. We are working toward a SOC 2 examination.
08How long we keep information
We keep customer content for as long as the firm's account is active and as the firm's own retention settings require. When a firm deletes content or closes its account, we delete it from our systems, including stored copies and derived data, within a reasonable period, except where the law or a legal hold requires us to keep it. Security logs are kept for at least 12 months.
09Your choices and rights
If you are a firm's client, the firm controls your information in Keyveve; contact the firm first, and we will help it respond. Anyone may ask us to access, correct, or delete personal information we hold about them, or ask how it is used, by writing to info@keyveve.com or by mail to Keyveve, Inc., 8300 Bluff Springs Road, Unit 1131, Austin, TX 78744. We will respond as the law where you live requires, and we will not treat you differently for asking.
10Children
Keyveve is a business service. It is not directed to children under 13, and we do not knowingly collect their information.
11Changes to this policy
We may update this policy as Keyveve changes. We will post the new version here with a new effective date and, for significant changes, let firms know in advance.
Questions about this page? Write to info@keyveve.com or call (317) 478-1212, or send mail to Keyveve, Inc., 8300 Bluff Springs Road, Unit 1131, Austin, TX 78744.