1. Core Guarantee: Zero AI Model Training
Protecting your strategic business data is our top priority. When Kaya inspects your web pages, analyzes conversion funnels, or audits Stripe telemetry, this information is utilized solely to deliver the service to your workspace.
We interface with Anthropic (Claude) and enterprise model providers under strict corporate zero-data-retention agreements with explicit exclusions from any model training or reinforcement learning sets.
2. Data We Collect
In the course of providing Marketing OS, we collect and process the following categories of data:
2.1 Account and Authentication Data
Full name, business email address, cryptographically hashed passwords (via Argon2id), and assigned organization roles.
2.2 Product Intelligence & Onboarding Telemetry
Public URLs of your software, text scraped during initial crawl, pricing models, ideal customer profiles (ICPs), and confirmed competitive positioning.
2.3 Billing & Revenue Analytics
Stripe transaction identifiers and aggregated subscription metrics (MRR, churn rates, customer lifetime value). No full payment card credentials are ever stored on our servers; payments are processed entirely by Stripe.
2.4 Technical & Governance Audit Logs
Connection IP addresses, request signatures, and tamper-proof audit trails for every automated action initiated by the agent (annotated with timestamps and risk classification R0-R4).
3. Purposes and Legal Bases for Processing
We process personal data strictly under valid legal grounds provided by the European General Data Protection Regulation (GDPR):
Applicable legal bases:
• Contractual Performance: to operate the software platform, run growth workflows, and execute approved campaigns.
• Legitimate Interest: to defend infrastructure, prevent security incidents, and mitigate prompt injection threats.
• Legal Compliance: to satisfy statutory tax, accounting, and invoice retention mandates.
• Explicit Consent: for non-essential communications or optional tracking preferences.
4. Authorized Sub-processors & International Transfers
Kaya collaborates with trusted infrastructure providers to deliver specialized system operations:
Key authorized sub-processors:
| Vendor | Service / Role | Data Location | Safeguards |
|---|---|---|---|
| Neon Inc. | Managed PostgreSQL Database | EU (Frankfurt, Germany) | GDPR Compliant |
| Upstash Inc. | Serverless Redis & Rate Limiting | EU (Frankfurt, Germany) | GDPR Compliant |
| Vercel Inc. | Edge Compute & Frontend Hosting | EU (Frankfurt) / USA | Standard Contractual Clauses (SCC) |
| Anthropic PBC | Enterprise LLM Inference Engine | USA (Zero Data Retention API) | SCC + Enterprise DPA |
| Stripe Inc. | Payment Billing & Subscriptions | EU / USA | PCI-DSS Level 1 + Enterprise DPA |
| Resend Inc. | Transactional Email Delivery | EU / USA | GDPR Compliant + SCC |
5. Your GDPR Rights
Under Articles 15 through 22 of the GDPR, you are entitled to the following rights:
• Right to access and receive an electronic copy of your processed personal data.
• Right to prompt rectification of inaccurate or outdated information.
• Right to erasure ('right to be forgotten') of your account and related telemetry.
• Right to restriction of processing and right to object.
• Right to data portability in an open, machine-readable format (JSON/CSV).
To exercise your rights, please reach out to our Data Protection Officer at privacy@kaya.ai. We commit to responding within 30 calendar days.
6. Security & Infrastructure Integrity
Kaya implements defense-in-depth architectural standards:
• Universal encryption in transit via TLS 1.3 and at rest via AES-256.
• Immutable PostgreSQL append-only triggers for the governance audit ledger.
• Strict internal SSRF network filtering when crawling customer web properties.