Privacy Policy
Last updated 31 July 2026. This page is maintained by Kynesis to explain how personal data is handled across the Kynesis website and application.
1. Who we are
Kynesis provides an AI quality assurance platform that scores conversations, documents and other content against customer-defined scorecards. This policy explains how we handle personal data on our website (kynesis.ai) and in the Kynesis application (app.kynesis.ai).
For personal data we collect about website visitors, prospects and account holders, Kynesis acts as the data controller. For content that a customer submits to be assessed, Kynesis acts as a data processor on that customer's instructions, under a data processing agreement (DPA).
Privacy contact: privacy@kynesis.ai. You can also reach us through the contact form.
2. Personal data we collect
| Category | Examples | Source |
|---|---|---|
| Contact data | Name, email address, company, message content | You, via our contact form |
| Account data | Email address, authentication identifiers, account settings, roles | You, at sign-up |
| Assessment content | Transcripts, chats, emails, tickets, documents, audio, images you submit for scoring, which may contain personal data about your customers or staff | You or your integrations |
| Usage data | Pages viewed, referrer, approximate country, device type, product events | Automatic, via analytics |
| Technical data | IP address, browser and OS information, request logs | Automatic, via hosting and security logs |
| Email engagement | Delivery, bounce, unsubscribe and suppression status | Our email infrastructure |
3. Why we use it and our legal bases (GDPR Art. 6)
| Purpose | Legal basis |
|---|---|
| Responding to enquiries and providing demos | Contract / pre-contractual steps (Art. 6(1)(b)) and legitimate interests (Art. 6(1)(f)) |
| Creating and operating your account, delivering the platform | Contract (Art. 6(1)(b)) |
| Processing assessment content on a customer’s behalf | The customer’s legal basis; we process on documented instructions (Art. 28) |
| Product analytics, reliability and improvement | Legitimate interests (Art. 6(1)(f)), or consent where required for non-essential cookies |
| Security, fraud prevention, abuse and rate limiting | Legitimate interests (Art. 6(1)(f)) and legal obligation (Art. 6(1)(c)) |
| Product and marketing emails | Consent (Art. 6(1)(a)) or soft opt-in legitimate interests; withdrawable at any time |
| Accounting, tax and legal compliance | Legal obligation (Art. 6(1)(c)) |
4. AI processing and model training
Assessment content is processed by large language models to produce scores, evidence quotes and coaching feedback. We do not use customer assessment content to train our own foundation models, and we contract with model providers on terms that exclude the use of submitted content for training their models.
Automated scoring can inform coaching and performance conversations. Because a human reviewer can always view, override, calibrate and dispute any score, Kynesis is not designed to produce decisions based solely on automated processing within the meaning of GDPR Art. 22. Customers remain responsible for how they use scores in employment decisions and for informing their staff.
5. Sharing and subprocessors
We do not sell personal data. We share it only with service providers acting under contract, and with authorities where legally required. Current categories of subprocessor:
| Provider role | Purpose |
|---|---|
| Cloud hosting and database (Supabase, EU region options) | Application hosting, authentication, database and storage |
| Application platform / CDN | Serving the website and application |
| AI model providers | Generating assessments, insights and summaries |
| Email delivery provider | Transactional and notification email |
| Product analytics (Amplitude, EU data centre) | Usage measurement and product improvement |
An up-to-date subprocessor list is available on request at privacy@kynesis.ai.
6. International transfers
We prefer EU/EEA processing and offer EU-hosted processing options. Where personal data is transferred outside the EEA or UK, we rely on an adequacy decision or on the European Commission’s Standard Contractual Clauses (plus the UK Addendum where relevant), together with a transfer risk assessment and technical measures such as encryption in transit and at rest. Copies of the relevant safeguards are available on request.
7. Retention
| Data | Retention |
|---|---|
| Contact form submissions | Up to 24 months after last contact, then deleted |
| Account data | For the life of the account, then deleted or anonymised within 90 days of closure |
| Assessment content and results | For the contracted retention period configured by the customer; deleted on instruction or within 30 days of contract end |
| Analytics and technical logs | Typically 12 months or less, in aggregated or pseudonymised form where possible |
| Email suppression records | Kept indefinitely so we do not email you again after you unsubscribe |
8. Security
Technical and organisational measures include encryption in transit (TLS) and at rest, row-level security so each account can only reach its own records, role-based permissions, least-privilege service credentials, secrets held outside source code, authentication with optional SSO and 2FA, audit logging, and regular dependency and security scanning.
These are the controls we operate today; this page is not a certification and does not assert an independent audit outcome. If you require details of a specific certification or audit report, contact us and we will tell you what is available.
9. Your rights
Where GDPR or UK GDPR applies, you have the right to access your data, to rectification, to erasure, to restriction of processing, to data portability, to object to processing based on legitimate interests, and to withdraw consent at any time. You can exercise these rights by emailing privacy@kynesis.ai. We respond within one month and may ask for information to verify your identity.
If Kynesis processes your data on behalf of one of our customers (for example, you are a support agent whose calls were assessed), please direct your request to that organisation; we will assist them in responding.
You may lodge a complaint with your local supervisory authority. Residents of California and other US states with comprehensive privacy laws may also request disclosure, deletion and correction, and may opt out of any sale or sharing of personal information — we do not sell or share personal information for cross-context behavioural advertising.
11. Children
Kynesis is a business tool and is not directed at children. We do not knowingly collect personal data from anyone under 16.
12. Incident notification
If a personal data breach affects your data, we notify the relevant supervisory authority within 72 hours where the GDPR requires it, and inform affected customers without undue delay with the information available at that point. Report a suspected security issue or vulnerability to privacy@kynesis.ai.
13. Changes to this policy
We may update this policy as the product and legal landscape change. The date at the top shows the current version, and we will tell account holders by email about material changes before they take effect.