The short version
We use information to provide and protect KasiLabs, carry out the work you approve and keep usage understandable. We do not sell personal information.
Who this policy covers
This policy applies worldwide when you visit KasiLabs, create an account, use a workspace, contact us or use an app operated through our service.
KasiLabs is the organisation responsible for account, website, billing and product-administration information. When a customer uses KasiLabs to handle information about its own staff, customers or partners, that customer decides why the information is used and KasiLabs normally processes it on the customer’s instructions.
Our role and your organisation’s role
For information about visitors, account holders, billing contacts and our own service operations, KasiLabs acts as a controller or business. For customer content processed inside a workspace or customer application, the customer normally acts as the controller or business and KasiLabs acts as its processor or service provider.
A written order, data-processing agreement or applicable law may describe these roles in more detail. If those documents conflict with this public policy for customer content, the signed document controls to the extent of the conflict.
Information we collect
We collect information you provide, information created while you use the product and limited information from your device or connected services.
- Account and contact details, including your name, email address and sign-in method.
- Workspace details, member roles, project descriptions and owner decisions.
- Files, documents, messages, prompts and other content you choose to submit.
- Usage, cost, payment and service records needed to provide the service and apply your limits.
- Approvals, important changes and security records used for review and support.
- Device, browser, approximate location, cookies and product-interaction information.
- Messages and information you provide when you contact us or respond to a survey.
Where information comes from
Most information comes directly from you or other people in your workspace. We may also receive limited information from sign-in providers, payment processors, connected services, security partners and publicly available business sources.
If a customer places another person’s information in a KasiLabs app, that customer is responsible for having a lawful reason and giving any notice the law requires.
Why we use information
We use personal information only for clear purposes: to perform our agreement, follow your instructions, protect the service, meet legal duties and improve KasiLabs in ways people reasonably expect.
- Create and manage accounts, workspaces, projects and access choices.
- Build, review and operate the apps and actions you approve.
- Measure usage, apply spending limits, prevent fraud and prepare accurate billing records.
- Protect accounts, investigate failures and keep important activity reviewable.
- Respond to support requests and send essential service messages.
- Improve product reliability and usability using limited analytics.
- Comply with law, enforce agreements and protect people’s rights.
Our legal grounds
Where a law requires a legal basis, we rely on the performance of a contract, compliance with a legal duty, our legitimate interests in operating and protecting the service, or consent. The basis depends on the information and why it is used.
You may withdraw consent at any time. This does not affect processing that already occurred or processing supported by another lawful basis.
When information is shared
We do not sell personal information. We also do not share it for cross-context behavioural advertising. We disclose only what is needed to authorised workspace members, service providers working for us, professional advisers, a buyer during a genuine business transaction, or authorities when law requires it.
Providers may host data, secure the product, carry out approved app actions, measure reliability, process payments or help us support customers. They must protect the information and use it only for the work they perform for us, subject to their legal duties.
AI and automated processing
When you request an AI-assisted action, the content needed for that action may be sent to a carefully selected service provider. We limit the information sent to what is reasonably needed, apply the workspace’s permissions and record usage for security and billing.
KasiLabs does not use private customer content to train a general-purpose model unless the customer has expressly agreed to that separate use. We do not make solely automated decisions about a person that create legal or similarly significant effects on behalf of KasiLabs.
International transfers
KasiLabs serves customers globally, so information may be processed in countries other than the one where you live. Privacy laws and government access rules can differ between countries.
Where required, we use recognised safeguards such as adequacy decisions, contractual protections, consent or another lawful transfer method. Workspace owners should also check whether their own use requires specific data-location choices.
How long we keep information
While an account, workspace or application remains active, we may retain the information and customer content submitted to it for as long as reasonably needed to provide, secure, maintain and improve the service requested by that customer. Workspace owners may delete content using available product controls, and applicable privacy law may require earlier deletion or restriction in some circumstances.
When an account is deleted or the service ends, we may keep submitted content in restricted systems for up to six months. This limited post-closure period allows us to complete secure deletion across backups, restore data after an accidental or disputed deletion, investigate fraud, abuse or security incidents, prevent repeated attacks, resolve billing or ownership disputes, enforce our agreements, establish or defend legal claims, and meet lawful requests from courts or regulators.
During that post-closure period, retained content is not used for advertising or new product features and access is limited to people who need it for those purposes. At the end of six months, we delete or irreversibly de-identify the content unless a legal hold, court order or specific legal duty requires longer retention.
Some records are kept separately for longer where reasonably necessary or legally required. These may include invoices, tax and payment records, consent records, contract records, abuse-prevention signals, security logs and evidence of important approvals. We keep only what the relevant purpose requires and apply access limits.
How we protect information
We use technical and organisational safeguards designed to limit access, keep important actions reviewable and reduce accidental loss or misuse. Access is based on roles, sensitive connections are kept away from browser code, and workspace owners can set practical boundaries.
No online service can promise perfect security. If we confirm a breach that creates a risk to people, we will respond and notify affected people or regulators when law requires it.
Your choices and rights
Depending on where you live, you may ask to be informed, access information, correct it, delete it, restrict or object to some uses, receive a portable copy, withdraw consent, or appeal a decision. You may also opt out of direct marketing and certain sale or sharing practices. KasiLabs does not discriminate against people for exercising privacy rights.
Some rights have legal limits. We may verify your identity and, when a customer controls the information, direct the request to that customer. You may complain to the privacy regulator where you live or work if you believe your rights were not respected.
Regional privacy notices
People in the European Economic Area, United Kingdom and Switzerland may have rights to access, correction, erasure, restriction, objection and portability, and may complain to their local supervisory authority. Where required, international transfers use an adequacy decision, approved contractual terms or another lawful safeguard.
Residents of California and other United States jurisdictions may have rights to know, access, correct, delete or obtain a copy of covered personal information and to opt out of certain sale, sharing or targeted advertising. KasiLabs does not sell personal information or share it for cross-context behavioural advertising, and does not discriminate for exercising a privacy right.
People in Kenya and other countries may have similar rights under local law. We honour every right that applies to the person and the processing, even if it is not listed word-for-word here.
How to make a request or complaint
Email privacy@kasilabs.com and describe the account, workspace and request. Do not send passwords, identity documents or sensitive content unless we ask through a secure channel. We may request proportionate information to verify identity and authority before disclosing or changing information.
We respond within the period required by applicable law. If we deny or limit a request, we will explain why and describe any available appeal or complaint route. You may also contact the data-protection or consumer authority where you live, work or believe a violation occurred.
Children
KasiLabs is built for organisations and working teams and is not directed to children. A person must be at least 18, or the age of legal majority where they live, to create an account. Do not submit a child’s personal information unless an authorised organisation has a lawful reason and appropriate safeguards.
Changes to this policy
We may update this policy when the product, our practices or the law changes. We will change the effective date and provide a clearer notice when an update materially changes how personal information is used.
