Legal

    Privacy Policy

    Last updated 31 July 2026. This page is maintained by Kynesis to explain how personal data is handled across the Kynesis website and application.

    1. Who we are

    Kynesis provides an AI quality assurance platform that scores conversations, documents and other content against customer-defined scorecards. This policy explains how we handle personal data on our website (kynesis.ai) and in the Kynesis application (app.kynesis.ai).

    For personal data we collect about website visitors, prospects and account holders, Kynesis acts as the data controller. For content that a customer submits to be assessed, Kynesis acts as a data processor on that customer's instructions, under a data processing agreement (DPA).

    Privacy contact: privacy@kynesis.ai. You can also reach us through the contact form.

    2. Personal data we collect

    CategoryExamplesSource
    Contact dataName, email address, company, message contentYou, via our contact form
    Account dataEmail address, authentication identifiers, account settings, rolesYou, at sign-up
    Assessment contentTranscripts, chats, emails, tickets, documents, audio, images you submit for scoring, which may contain personal data about your customers or staffYou or your integrations
    Usage dataPages viewed, referrer, approximate country, device type, product eventsAutomatic, via analytics
    Technical dataIP address, browser and OS information, request logsAutomatic, via hosting and security logs
    Email engagementDelivery, bounce, unsubscribe and suppression statusOur email infrastructure

    3. Why we use it and our legal bases (GDPR Art. 6)

    PurposeLegal basis
    Responding to enquiries and providing demosContract / pre-contractual steps (Art. 6(1)(b)) and legitimate interests (Art. 6(1)(f))
    Creating and operating your account, delivering the platformContract (Art. 6(1)(b))
    Processing assessment content on a customer’s behalfThe customer’s legal basis; we process on documented instructions (Art. 28)
    Product analytics, reliability and improvementLegitimate interests (Art. 6(1)(f)), or consent where required for non-essential cookies
    Security, fraud prevention, abuse and rate limitingLegitimate interests (Art. 6(1)(f)) and legal obligation (Art. 6(1)(c))
    Product and marketing emailsConsent (Art. 6(1)(a)) or soft opt-in legitimate interests; withdrawable at any time
    Accounting, tax and legal complianceLegal obligation (Art. 6(1)(c))

    4. AI processing and model training

    Assessment content is processed by large language models to produce scores, evidence quotes and coaching feedback. We do not use customer assessment content to train our own foundation models, and we contract with model providers on terms that exclude the use of submitted content for training their models.

    Automated scoring can inform coaching and performance conversations. Because a human reviewer can always view, override, calibrate and dispute any score, Kynesis is not designed to produce decisions based solely on automated processing within the meaning of GDPR Art. 22. Customers remain responsible for how they use scores in employment decisions and for informing their staff.

    5. Sharing and subprocessors

    We do not sell personal data. We share it only with service providers acting under contract, and with authorities where legally required. Current categories of subprocessor:

    Provider rolePurpose
    Cloud hosting and database (Supabase, EU region options)Application hosting, authentication, database and storage
    Application platform / CDNServing the website and application
    AI model providersGenerating assessments, insights and summaries
    Email delivery providerTransactional and notification email
    Product analytics (Amplitude, EU data centre)Usage measurement and product improvement

    An up-to-date subprocessor list is available on request at privacy@kynesis.ai.

    6. International transfers

    We prefer EU/EEA processing and offer EU-hosted processing options. Where personal data is transferred outside the EEA or UK, we rely on an adequacy decision or on the European Commission’s Standard Contractual Clauses (plus the UK Addendum where relevant), together with a transfer risk assessment and technical measures such as encryption in transit and at rest. Copies of the relevant safeguards are available on request.

    7. Retention

    DataRetention
    Contact form submissionsUp to 24 months after last contact, then deleted
    Account dataFor the life of the account, then deleted or anonymised within 90 days of closure
    Assessment content and resultsFor the contracted retention period configured by the customer; deleted on instruction or within 30 days of contract end
    Analytics and technical logsTypically 12 months or less, in aggregated or pseudonymised form where possible
    Email suppression recordsKept indefinitely so we do not email you again after you unsubscribe

    8. Security

    Technical and organisational measures include encryption in transit (TLS) and at rest, row-level security so each account can only reach its own records, role-based permissions, least-privilege service credentials, secrets held outside source code, authentication with optional SSO and 2FA, audit logging, and regular dependency and security scanning.

    These are the controls we operate today; this page is not a certification and does not assert an independent audit outcome. If you require details of a specific certification or audit report, contact us and we will tell you what is available.

    9. Your rights

    Where GDPR or UK GDPR applies, you have the right to access your data, to rectification, to erasure, to restriction of processing, to data portability, to object to processing based on legitimate interests, and to withdraw consent at any time. You can exercise these rights by emailing privacy@kynesis.ai. We respond within one month and may ask for information to verify your identity.

    If Kynesis processes your data on behalf of one of our customers (for example, you are a support agent whose calls were assessed), please direct your request to that organisation; we will assist them in responding.

    You may lodge a complaint with your local supervisory authority. Residents of California and other US states with comprehensive privacy laws may also request disclosure, deletion and correction, and may opt out of any sale or sharing of personal information — we do not sell or share personal information for cross-context behavioural advertising.

    10. Cookies and analytics

    We use strictly necessary cookies and local storage to keep you signed in and to remember interface preferences such as light or dark mode. We use privacy-focused, aggregate website analytics and product analytics configured in the EU to understand which pages and features are used. We do not run advertising or cross-site tracking pixels. You can block or delete cookies in your browser, though sign-in will not work without the necessary ones.

    11. Children

    Kynesis is a business tool and is not directed at children. We do not knowingly collect personal data from anyone under 16.

    12. Incident notification

    If a personal data breach affects your data, we notify the relevant supervisory authority within 72 hours where the GDPR requires it, and inform affected customers without undue delay with the information available at that point. Report a suspected security issue or vulnerability to privacy@kynesis.ai.

    13. Changes to this policy

    We may update this policy as the product and legal landscape change. The date at the top shows the current version, and we will tell account holders by email about material changes before they take effect.