Personal Data Protection (GDPR)·Last updated : September 18, 2026

Privacy Policy

Kaya is firmly committed to safeguarding the privacy of our customers and their end-users. Your proprietary software telemetry and prospect data are never used to train artificial intelligence models.

1. Core Guarantee: Zero AI Model Training

Key takeaway :Contractual guarantee: none of the customer data you submit or connect to Kaya is ever used to train or fine-tune AI foundation models (LLMs).

Protecting your strategic business data is our top priority. When Kaya inspects your web pages, analyzes conversion funnels, or audits Stripe telemetry, this information is utilized solely to deliver the service to your workspace.

We interface with Anthropic (Claude) and enterprise model providers under strict corporate zero-data-retention agreements with explicit exclusions from any model training or reinforcement learning sets.

2. Data We Collect

In the course of providing Marketing OS, we collect and process the following categories of data:

2.1 Account and Authentication Data

Full name, business email address, cryptographically hashed passwords (via Argon2id), and assigned organization roles.

2.2 Product Intelligence & Onboarding Telemetry

Public URLs of your software, text scraped during initial crawl, pricing models, ideal customer profiles (ICPs), and confirmed competitive positioning.

2.3 Billing & Revenue Analytics

Stripe transaction identifiers and aggregated subscription metrics (MRR, churn rates, customer lifetime value). No full payment card credentials are ever stored on our servers; payments are processed entirely by Stripe.

2.4 Technical & Governance Audit Logs

Connection IP addresses, request signatures, and tamper-proof audit trails for every automated action initiated by the agent (annotated with timestamps and risk classification R0-R4).

3. Purposes and Legal Bases for Processing

We process personal data strictly under valid legal grounds provided by the European General Data Protection Regulation (GDPR):

Applicable legal bases:

• Contractual Performance: to operate the software platform, run growth workflows, and execute approved campaigns.

• Legitimate Interest: to defend infrastructure, prevent security incidents, and mitigate prompt injection threats.

• Legal Compliance: to satisfy statutory tax, accounting, and invoice retention mandates.

• Explicit Consent: for non-essential communications or optional tracking preferences.

4. Authorized Sub-processors & International Transfers

Key takeaway :All sub-processors are bound by strict Data Processing Agreements guaranteeing GDPR-compliant protection standards.

Kaya collaborates with trusted infrastructure providers to deliver specialized system operations:

Key authorized sub-processors:

VendorService / RoleData LocationSafeguards
Neon Inc.Managed PostgreSQL DatabaseEU (Frankfurt, Germany)GDPR Compliant
Upstash Inc.Serverless Redis & Rate LimitingEU (Frankfurt, Germany)GDPR Compliant
Vercel Inc.Edge Compute & Frontend HostingEU (Frankfurt) / USAStandard Contractual Clauses (SCC)
Anthropic PBCEnterprise LLM Inference EngineUSA (Zero Data Retention API)SCC + Enterprise DPA
Stripe Inc.Payment Billing & SubscriptionsEU / USAPCI-DSS Level 1 + Enterprise DPA
Resend Inc.Transactional Email DeliveryEU / USAGDPR Compliant + SCC

5. Your GDPR Rights

Key takeaway :You retain absolute rights to access, rectify, export, and erase all personal and organizational data.

Under Articles 15 through 22 of the GDPR, you are entitled to the following rights:

• Right to access and receive an electronic copy of your processed personal data.

• Right to prompt rectification of inaccurate or outdated information.

• Right to erasure ('right to be forgotten') of your account and related telemetry.

• Right to restriction of processing and right to object.

• Right to data portability in an open, machine-readable format (JSON/CSV).

To exercise your rights, please reach out to our Data Protection Officer at privacy@kaya.ai. We commit to responding within 30 calendar days.

6. Security & Infrastructure Integrity

Kaya implements defense-in-depth architectural standards:

• Universal encryption in transit via TLS 1.3 and at rest via AES-256.

• Immutable PostgreSQL append-only triggers for the governance audit ledger.

• Strict internal SSRF network filtering when crawling customer web properties.