Privacy Policy

Last updated: August 20, 2026

This privacy policy describes how Kairos Intelligence ("Kairos", "we", "us") collects, uses, discloses and protects personal data in connection with the kairosintelligence.fr web application ("the dashboard") and the Kairos browser extension ("the extension"), together referred to as "the Service".

Kairos is an artificial-intelligence governance tool for agencies and their teams. Its design rests on a simple principle: the most sensitive data never leaves your device. Privacy is built in from the start (privacy by design).

1. Who we are

Kairos Intelligence is a project currently being incorporated, based in Montreal (Quebec), Canada, offering its service in the European Union.

For the processing described in this policy, Kairos acts as the controller within the meaning of the General Data Protection Regulation (GDPR), except for the governance data described in section 6, where Kairos acts as a processor on behalf of your agency.

For any question regarding the protection of your data, to exercise your rights, or to reach our data-protection point of contact, write to confidentialite@kairosintelligence.fr.

2. The founding principle: PII detection is local

Kairos's PII guard feature analyzes your prompts entirely within your browser, before they are sent to the AI service you are using (ChatGPT, Claude, Gemini, Perplexity):

  • Pass 1: local rules (emails, phone numbers, IBAN, SIRET, card numbers, API keys, etc.);
  • Pass 2: an entity-recognition model run locally (WebAssembly). The model is downloaded once and then cached on your device; no data from your prompt is transmitted for this analysis.

As a result, the content of your prompts and the personal data they contain are never transmitted to Kairos's servers. The only exception is described in section 4 (the "Improve" button).

3. Information we collect

Information you provide to us:

  • Account: email address, name, password (stored in hashed form, never in clear text), membership in an agency and workspaces, role. If you sign in via Google, we receive your email address, your name and an account identifier.
  • Library content: the templates, reusable blocks (snippets) and frameworks (frameworks) created by agency administrators.
  • Payment information (where applicable): processed by our payment provider. Kairos does not store your card numbers.

Information collected automatically:

  • AI usage data (anti-"shadow AI" feature): the extension records which AI services are used and when, along with associated technical metadata — but not the content of your prompts.
  • Product telemetry: aggregated counters (number of assisted prompts, number of PII items blocked, average quality score, Pass 2 deactivation rate). These metrics contain no prompt content.
  • Technical data: server logs, IP address, browser type, device or extension identifier, timestamps — used for the security and proper operation of the Service.

4. What we do not collect

  • The content of your prompts is neither collected nor stored by Kairos during PII analysis (see section 2).
  • Exception — the "Improve" button: if, and only if, you click "Improve" in the dashboard, the text of the relevant template is sent to Mistral AI (European Union) in order to propose an optimized version. This action is always triggered by you.

5. The purposes for which we use this information

  • to provide, maintain and secure the Service;
  • to authenticate you and manage your account;
  • to manage your agency's prompt library;
  • to provide agency administrators with AI-usage governance dashboards (see section 6);
  • to improve the product based on aggregated metrics;
  • to process payments, where applicable;
  • to comply with our legal obligations and to prevent fraud and abuse.

We do not sell your personal data and do not use it for targeted advertising.

In accordance with article 6 GDPR, our processing relies on:

  • performance of the contract binding us to you or to your agency — creating and managing your account, providing the Service, billing;
  • our legitimate interest — securing the Service, preventing fraud and abuse, improving the product from aggregated metrics;
  • consent — only when you trigger an optional action such as the "Improve" button, which you may never use;
  • compliance with legal obligations — accounting retention, responding to requests from authorities.

6. Governance data and your employer's role

When an agency deploys Kairos to its teams, it may consult dashboards on AI usage by its employees. For this data, the agency is the controller and Kairos acts as a processor, processing the data according to the agency's instructions. If you are an employee of a client agency, direct your questions about this governance to your agency first.

7. Disclosure to third parties and sub-processors

We disclose your data only to the providers strictly necessary for the operation of the Service, bound by confidentiality commitments:

  • Hetzner Online GmbH — hosting of the application server, the database and uploaded files — Helsinki (Finland);
  • Scaleway — off-site retention of encrypted backups — Paris (France);
  • Mistral AI — optimization of a prompt template from your library, only when you click "Improve" — European Union;
  • Resend — sending transactional emails (verification, security) — United States;
  • Stripe — payment processing, where billing is enabled — United States;
  • Google — authentication, only if you choose to sign in with a Google account — United States;
  • ImprovMX — routing of inbound mail addressed to our aliases, including your rights requests — United States;
  • Microsoft — hosting of the mailbox that inbound mail is forwarded to — United States;
  • Hugging Face — distribution of the PII detection model downloaded once by the extension; no prompt content passes through it — United States.

The current list, with each provider's role and location, is published on the sub-processors page.

We may also disclose information if required by law, to enforce our terms, or in the context of a corporate reorganization (in which case this policy would continue to apply).

8. Hosting and transfers

  • Account data, library content and uploaded files are hosted in the European Union, with Hetzner Online GmbH, in Helsinki (Finland). Encrypted backups are kept in a data center located in France (Paris): they do not leave the European Union.
  • Our application infrastructure is self-hosted on those servers: we do not entrust your account data or your library to a third-party cloud platform.
  • Processing by Mistral AI (the "Improve" button) takes place in the European Union.
  • Some ancillary providers (transactional email delivery, inbound mail routing, payment processing, Google authentication, detection-model distribution) are established in the United States. The data sent to them is limited to what is strictly necessary for their function — an email address, billing data, and the content of the messages you send us when you write to us — and never includes the content of your library or of your prompts. Those transfers rely on the standard contractual clauses adopted by the European Commission (GDPR art. 46) or on an adequacy decision where one applies.
  • As Kairos is based in Montreal (Quebec), Canada, day-to-day operation of the Service (administration, support) entails access from Canada, which constitutes a transfer within the meaning of GDPR chapter V. That access is limited to the people who need it and never covers the content of your prompts.

9. Retention period

We retain data only for as long as necessary for the purposes described, or as required by law:

  • Account: for the entire duration of the relationship, then for a limited period after the account is closed;
  • Library: until deleted by your agency;
  • Session tokens: at most 20 days, renewed as you keep using the Service;
  • Technical logs and usage data: for a limited period, after which they are deleted or anonymized.

10. Your rights

In the European Union (GDPR), you have the rights of access, rectification, erasure, restriction of processing, objection and portability, as well as the right to give directives on what becomes of your data after your death. You may lodge a complaint with the Commission nationale de l'informatique et des libertés (CNIL) (https://www.cnil.fr).

If you reside in Quebec or Canada, Law 25 and PIPEDA grant you equivalent rights, including the right to file a complaint with the Commission d'accès à l'information du Québec.

To exercise these rights, write to confidentialite@kairosintelligence.fr. We will respond within the time limits set by applicable law. If your request concerns governance data held on behalf of your agency, we will direct you to it (see section 6).

11. Automated decisions

Kairos makes no decision based solely on automated processing that produces legal effects or significantly affects you. PII detection and the quality score are assistance tools: the final decision (send, anonymize, cancel) always belongs to you.

11a. Artificial-intelligence transparency

Kairos embeds an entity-recognition model that runs locally in your browser to detect personal data. For the sake of transparency, in the spirit of article 50 of Regulation (EU) 2024/1689 on artificial intelligence, we inform you that:

  • this model is an AI system within the meaning of the Regulation, provided by Kairos;
  • its results are probabilistic: it may miss a piece of personal data or flag one wrongly, and does not replace your own review;
  • it generates no content and performs no emotion recognition and no biometric categorisation;
  • the prompt quality score is computed by deterministic rules, not by a machine-learning model.

The content you then submit to third-party AI services (ChatGPT, Claude, Gemini, Perplexity) is governed by those services' own terms and transparency obligations, for which Kairos is not responsible.

12. Security

We implement reasonable security measures: encryption in transit (TLS), strict data isolation between tenants (agencies and workspaces) enforced server-side on every read and every write, authentication via signed tokens, one-way password hashing and restricted staff access. As no method of transmission or storage is perfectly secure, we cannot guarantee absolute security.

13. Cookies

We use only strictly necessary or preference cookies: maintaining your authenticated session, remembering the language you chose and the state of the interface. These cookies are exempt from prior consent; we use neither advertising cookies nor third-party analytics.

14. Security incidents

In accordance with articles 33 and 34 GDPR, we document every personal data breach. Where it is likely to result in a risk to your rights and freedoms, we notify the Commission nationale de l'informatique et des libertés (CNIL) within 72 hours of becoming aware of it, and we inform you directly where the risk is high.

15. Information concerning minors

The Service is a professional tool that is not intended for minors and is not designed to knowingly collect information concerning persons under 15 years of age.

16. Changes

We may amend this policy. The update date appears at the top of the page; in the event of a material change, we will inform you by an appropriate means.

17. Contact us

Kairos Intelligence — Montreal (Quebec), Canada. For any question regarding the protection of your data: confidentialite@kairosintelligence.fr.