Last updated: August 20, 2026
This privacy policy describes how Kairos Intelligence ("Kairos", "we", "us")
collects, uses, discloses and protects personal data in connection with the
kairosintelligence.fr web application ("the dashboard") and
the Kairos browser extension ("the extension"), together referred to as
"the Service".
Kairos is an artificial-intelligence governance tool for agencies and their
teams. Its design rests on a simple principle: the most sensitive data never
leaves your device. Privacy is built in from the start (privacy by design).
1. Who we are
Kairos Intelligence is a project currently being incorporated, based in
Montreal (Quebec), Canada, offering its service in the European Union.
For the processing described in this policy, Kairos acts as the controller
within the meaning of the General Data Protection Regulation (GDPR), except for
the governance data described in section 6, where Kairos acts as a processor
on behalf of your agency.
For any question regarding the protection of your data, to exercise your rights,
or to reach our data-protection point of contact, write to
confidentialite@kairosintelligence.fr.
2. The founding principle: PII detection is local
Kairos's PII guard feature analyzes your prompts entirely within your
browser, before they are sent to the AI service you are using (ChatGPT,
Claude, Gemini, Perplexity):
- Pass 1: local rules (emails, phone numbers, IBAN, SIRET, card numbers,
API keys, etc.);
- Pass 2: an entity-recognition model run locally (WebAssembly). The model
is downloaded once and then cached on your device; no data from your prompt
is transmitted for this analysis.
As a result, the content of your prompts and the personal data they contain
are never transmitted to Kairos's servers. The only exception is described in
section 4 (the "Improve" button).
Information you provide to us:
- Account: email address, name, password (stored in hashed form, never in
clear text), membership in an agency and workspaces, role. If you sign in via
Google, we receive your email address, your name and an account identifier.
- Library content: the templates, reusable blocks (snippets) and
frameworks (frameworks) created by agency administrators.
- Payment information (where applicable): processed by our payment provider.
Kairos does not store your card numbers.
Information collected automatically:
- AI usage data (anti-"shadow AI" feature): the extension records which
AI services are used and when, along with associated technical metadata —
but not the content of your prompts.
- Product telemetry: aggregated counters (number of assisted prompts, number
of PII items blocked, average quality score, Pass 2 deactivation rate). These
metrics contain no prompt content.
- Technical data: server logs, IP address, browser type, device or extension
identifier, timestamps — used for the security and proper operation of the
Service.
4. What we do not collect
- The content of your prompts is neither collected nor stored by Kairos
during PII analysis (see section 2).
- Exception — the "Improve" button: if, and only if, you click "Improve" in
the dashboard, the text of the relevant template is sent to Mistral AI
(European Union) in order to propose an optimized version. This action is
always triggered by you.
- to provide, maintain and secure the Service;
- to authenticate you and manage your account;
- to manage your agency's prompt library;
- to provide agency administrators with AI-usage governance dashboards (see
section 6);
- to improve the product based on aggregated metrics;
- to process payments, where applicable;
- to comply with our legal obligations and to prevent fraud and abuse.
We do not sell your personal data and do not use it for targeted
advertising.
5a. Legal bases for processing
In accordance with article 6 GDPR, our processing relies on:
- performance of the contract binding us to you or to your agency — creating
and managing your account, providing the Service, billing;
- our legitimate interest — securing the Service, preventing fraud and abuse,
improving the product from aggregated metrics;
- consent — only when you trigger an optional action such as the "Improve"
button, which you may never use;
- compliance with legal obligations — accounting retention, responding to
requests from authorities.
6. Governance data and your employer's role
When an agency deploys Kairos to its teams, it may consult dashboards on AI
usage by its employees. For this data, the agency is the controller and
Kairos acts as a processor, processing the data according to the agency's
instructions. If you are an employee of a client agency, direct your questions
about this governance to your agency first.
7. Disclosure to third parties and sub-processors
We disclose your data only to the providers strictly necessary for the operation
of the Service, bound by confidentiality commitments:
- Hetzner Online GmbH — hosting of the application server, the database and uploaded files — Helsinki (Finland);
- Scaleway — off-site retention of encrypted backups — Paris (France);
- Mistral AI — optimization of a prompt template from your library, only when you click "Improve" — European Union;
- Resend — sending transactional emails (verification, security) — United States;
- Stripe — payment processing, where billing is enabled — United States;
- Google — authentication, only if you choose to sign in with a Google account — United States;
- ImprovMX — routing of inbound mail addressed to our aliases, including your rights requests — United States;
- Microsoft — hosting of the mailbox that inbound mail is forwarded to — United States;
- Hugging Face — distribution of the PII detection model downloaded once by the extension; no prompt content passes through it — United States.
The current list, with each provider's role and location, is published on the
sub-processors page.
We may also disclose information if required by law, to enforce our terms, or in
the context of a corporate reorganization (in which case this policy would
continue to apply).
8. Hosting and transfers
- Account data, library content and uploaded files are hosted in the
European Union, with Hetzner Online GmbH, in
Helsinki (Finland). Encrypted backups are kept in
a data center located in France (Paris): they do not leave the European Union.
- Our application infrastructure is self-hosted on those servers: we do not
entrust your account data or your library to a third-party cloud platform.
- Processing by Mistral AI (the "Improve" button) takes place in the European
Union.
- Some ancillary providers (transactional email delivery, inbound mail routing,
payment processing, Google authentication, detection-model distribution) are
established in the United States. The data sent to them is limited to what
is strictly necessary for their function — an email address, billing data, and
the content of the messages you send us when you write to us — and never
includes the content of your library or of your prompts. Those transfers rely
on the standard contractual clauses adopted by the European Commission
(GDPR art. 46) or on an adequacy decision where one applies.
- As Kairos is based in Montreal (Quebec), Canada, day-to-day operation of
the Service (administration, support) entails access from Canada, which
constitutes a transfer within the meaning of GDPR chapter V. That access is
limited to the people who need it and never covers the content of your
prompts.
9. Retention period
We retain data only for as long as necessary for the purposes described, or as
required by law:
- Account: for the entire duration of the relationship, then for a limited
period after the account is closed;
- Library: until deleted by your agency;
- Session tokens: at most 20 days, renewed as you keep
using the Service;
- Technical logs and usage data: for a limited period, after which they are
deleted or anonymized.
10. Your rights
In the European Union (GDPR), you have the rights of access,
rectification, erasure, restriction of processing, objection and portability, as
well as the right to give directives on what becomes of your data after your
death. You may lodge a complaint with the Commission nationale de l'informatique et des libertés (CNIL)
(https://www.cnil.fr).
If you reside in Quebec or Canada, Law 25 and PIPEDA grant you equivalent
rights, including the right to file a complaint with the Commission d'accès à
l'information du Québec.
To exercise these rights, write to confidentialite@kairosintelligence.fr. We will respond
within the time limits set by applicable law. If your request concerns
governance data held on behalf of your agency, we will direct you to it (see
section 6).
11. Automated decisions
Kairos makes no decision based solely on automated processing that produces
legal effects or significantly affects you. PII detection and the quality score
are assistance tools: the final decision (send, anonymize, cancel) always
belongs to you.
11a. Artificial-intelligence transparency
Kairos embeds an entity-recognition model that runs locally in your browser
to detect personal data. For the sake of transparency, in the spirit of article
50 of Regulation (EU) 2024/1689 on artificial intelligence, we inform you that:
- this model is an AI system within the meaning of the Regulation, provided
by Kairos;
- its results are probabilistic: it may miss a piece of personal data or
flag one wrongly, and does not replace your own review;
- it generates no content and performs no emotion recognition and no biometric
categorisation;
- the prompt quality score is computed by deterministic rules, not by a
machine-learning model.
The content you then submit to third-party AI services (ChatGPT, Claude, Gemini,
Perplexity) is governed by those services' own terms and transparency
obligations, for which Kairos is not responsible.
12. Security
We implement reasonable security measures: encryption in transit (TLS), strict
data isolation between tenants (agencies and workspaces) enforced server-side on
every read and every write, authentication via signed tokens, one-way password
hashing and restricted staff access. As no method of transmission or storage is
perfectly secure, we cannot guarantee absolute security.
13. Cookies
We use only strictly necessary or preference cookies: maintaining your
authenticated session, remembering the language you chose and the state of the
interface. These cookies are exempt from prior consent; we use neither
advertising cookies nor third-party analytics.
14. Security incidents
In accordance with articles 33 and 34 GDPR, we document every personal data
breach. Where it is likely to result in a risk to your rights and freedoms, we
notify the Commission nationale de l'informatique et des libertés (CNIL) within 72 hours of becoming aware of
it, and we inform you directly where the risk is high.
The Service is a professional tool that is not intended for minors and is not
designed to knowingly collect information concerning persons under
15 years of age.
16. Changes
We may amend this policy. The update date appears at the top of the page; in the
event of a material change, we will inform you by an appropriate means.
Kairos Intelligence — Montreal (Quebec), Canada.
For any question regarding the protection of your data: confidentialite@kairosintelligence.fr.