Privacy Policy
How Kavinora Technologies Ltd collects, uses, and protects personal data under UK GDPR, EU GDPR, and the Data Protection Act 2018.
Last updated: 30 July 2026
1. Who We Are
This website and the Kavinora platform ("Platform") are operated by Kavinora Technologies Ltd, a company registered in England and Wales. Our registered office is at 60 Tottenham Court Road, Office 1215, Fitzrovia, London, W1T 2EW, United Kingdom.
We are the data controller for personal data processed through this Platform. For questions about how we handle your data, contact us at: [email protected].
2. Legal Basis
This policy is issued under the UK General Data Protection Regulation (UK GDPR), the Data Protection Act 2018, and the EU General Data Protection Regulation (EU GDPR, Regulation 2016/679). We process personal data only where we have a valid lawful basis under Article 6 UK GDPR / Article 6 EU GDPR:
- Contractual necessity: to provide access to the Platform and services you have requested.
- Legitimate interests: to improve our services, maintain security, and prevent fraud.
- Consent: for optional communications such as product updates and newsletters (you may withdraw at any time).
- Legal obligation: where we must retain records to comply with applicable law.
3. What Data We Collect
- Account data: name, email address, hashed password, organisation name.
- Google OAuth data: if you sign in with Google, we receive your Google profile information (name, email address, profile picture URL, and Google account ID) as provided by Google's OAuth 2.0 service. We use this solely to create and authenticate your account. We do not access your Google Drive, Gmail, contacts, or any other Google services beyond the basic profile scope.
- Passkey / WebAuthn data: if you register a passkey for passwordless authentication, we store the public key material, credential ID, and device attestation metadata associated with your passkey. We never receive or store your private key or biometric data; these remain on your device and are never transmitted to our servers.
- Usage data: pages visited, features used, session duration, browser type, IP address (anonymised after 90 days).
- Chat & voice data: messages and transcribed voice input sent to the AI assistant during a session. Voice audio is processed in-memory and never stored unless you explicitly save a conversation.
- Business data you upload: files, documents, or structured data shared with AI agents inside the Platform. This data is scoped to your account and never used to train shared models.
- Payment data: handled by our payment processor. We do not store card numbers.
- Cookies: see our Cookie Policy for details.
4. How We Use Your Data
- Provide, maintain, and improve the Platform.
- Authenticate users via password, Google OAuth, or passkey/WebAuthn and enforce security controls.
- Personalise the AI assistant experience within your account.
- Send transactional emails (e.g. password resets, invoices).
- Send marketing emails only if you have opted in; unsubscribe at any time via the link in each email or by emailing [email protected].
- Comply with legal obligations including fraud prevention.
5. Data Sharing
We do not sell or rent your personal data. We may share it with:
- Cloud infrastructure providers (e.g. Google Cloud Platform) acting as data processors under appropriate data processing agreements.
- AI model providers: where your prompts are sent to third-party model APIs (e.g. Azure OpenAI, Anthropic), only the content of the prompt is transmitted; no persistent personal data is retained by those providers under our agreements.
- Google OAuth: when you sign in with Google, authentication tokens are exchanged with Google's servers. Google's use of your data is governed by the Google Privacy Policy.
- Payment processors: to handle billing transactions.
- Law enforcement / regulators: where legally required.
6. International Data Transfers
Your data may be processed outside the UK and the European Economic Area (EEA), including in the United States, via cloud infrastructure providers such as Google Cloud Platform and AI model providers.
Where data is transferred outside the UK, we rely on:
- UK adequacy regulations issued by the Secretary of State.
- International Data Transfer Agreements (IDTAs) approved by the ICO.
- The UK Extension to the EU-US Data Privacy Framework, where applicable.
Where data is transferred outside the EEA, we rely on:
- European Commission adequacy decisions under Article 45 EU GDPR.
- Standard Contractual Clauses (SCCs) adopted by the European Commission under Article 46(2)(c) EU GDPR.
- The EU-US Data Privacy Framework, where the recipient is a certified participant.
We conduct transfer impact assessments where required and implement supplementary measures (such as encryption in transit and at rest) to ensure your data receives an equivalent level of protection regardless of where it is processed.
7. EU GDPR Compliance
If you are located in the European Economic Area (EEA), the following additional provisions apply:
- Data controller: Kavinora Technologies Ltd, 60 Tottenham Court Road, Office 1215, Fitzrovia, London, W1T 2EW, United Kingdom.
- Representative in the EU: If required under Article 27 EU GDPR, details of our EU representative will be published on this page and can be requested by contacting [email protected].
- Lawful bases: the same lawful bases described in Section 2 apply under Article 6 EU GDPR.
- Your rights: EU data subjects have the same rights described in Section 9 below. You may also lodge a complaint with your local supervisory authority (a list is available at edpb.europa.eu).
- Data Protection Impact Assessments (DPIAs): we conduct DPIAs where processing is likely to result in a high risk to individuals, including for AI-powered profiling and large-scale processing of user data.
8. Data Retention
- Active accounts: data is retained for the duration of your subscription plus 30 days.
- Closed accounts: all personal data is deleted within 30 days of account closure, unless we are required to retain it by law.
- Google OAuth tokens: revoked and deleted upon account closure or when you disconnect Google sign-in from your account settings.
- Passkey credentials: deleted immediately upon account closure or when you remove a passkey from your account settings.
- Backups: purged within 90 days of the deletion request.
- Financial records: retained for 7 years as required by UK tax law.
9. Your Rights
Under UK GDPR and EU GDPR you have the right to:
- Access a copy of your personal data (Subject Access Request).
- Rectification of inaccurate data.
- Erasure ("right to be forgotten"): we will delete your data within 30 days unless retention is legally required.
- Restriction of processing in certain circumstances.
- Data portability: receive your data in a machine-readable format.
- Object to processing based on legitimate interests.
- Withdraw consent at any time where consent is the lawful basis.
- Not be subject to automated decision-making, including profiling, that produces legal or similarly significant effects, unless authorised by law or based on explicit consent.
To exercise any right, email [email protected]. We will respond within one calendar month (extendable by two further months for complex requests, in which case we will inform you within the first month).
UK residents: you may lodge a complaint with the Information Commissioner's Office (ICO) at ico.org.uk or call 0303 123 1113.
EU/EEA residents: you may lodge a complaint with your local data protection supervisory authority. A list of authorities is available at edpb.europa.eu.
10. Security
We implement appropriate technical and organisational measures including TLS encryption in transit, encrypted databases at rest, role-based access controls, and regular security reviews. No system is 100% secure; please notify us immediately at [email protected] if you discover a vulnerability.
11. Children
The Platform is intended for business use by persons aged 18 or over. We do not knowingly collect data from children under the age of 16 (or the applicable age of digital consent in your jurisdiction). If you believe a child has provided us with personal data, please contact us so we can delete it.
12. Changes to This Policy
We may update this policy from time to time. Material changes will be notified by email or prominent notice on the Platform at least 14 days before they take effect. Continued use after the effective date constitutes acceptance of the updated policy.
13. Contact
Kavinora Technologies Ltd
60 Tottenham Court Road, Office 1215
Fitzrovia, London, W1T 2EW
United Kingdom
General enquiries: [email protected]
Privacy enquiries: [email protected]
Policy enquiries: [email protected]