- Classification: Public Compliance Documentation
1. Overview and Scope
This Privacy Policy explains how Kainam Corporation ("Kainam", "we", "us", "our") collects, uses, shares, discloses, and protects the personal data of individuals who access or use the Kainam Platform, visit https://kainam.ai, or otherwise interact with Kainam (collectively, "Users" or "you").
- Applies regardless of whether access is direct, or through a reseller, OEM partner, or white-label partner.
- By accessing or using the Platform, Users acknowledge the collection and processing of their personal data as described here.
2. Information We Collect
Kainam collects information that identifies, relates to, describes, or could reasonably be linked, directly or indirectly, with a particular user or device ("Personal Data").
A. Information Provided Directly
- Account Registration Data: Name, business email address, corporate physical address, phone number, account credentials.
- Profile and Professional Data: Job title, department, company name.
- Communications: Information provided when contacting customer support, submitting security incidents, or writing to the legal team.
- Billing Information: Payment card information, bank routing details, and financial transaction history, processed securely via third-party payment gateways.
B. Information Automatically Collected via Platform Usage
- Device Metadata: IP address, operating system type and version, browser configuration, unique device identifiers, network connection properties.
- Log and Telemetry Data: System access timestamps, features utilized, API request volumes, error logs, user interaction pathways within the AI/ML suite.
- Cookies and Tracking Technologies: Session cookies and persistent analytics beacons to maintain authentication states and measure system performance.
C. Information Processed on Behalf of Customers
- Kainam may process enterprise datasets uploaded by corporate customers.
- The customer acts as Data Controller; Kainam acts as Data Processor.
- Such data is processed strictly per customer instructions and the applicable Data Processing Addendum (DPA).
3. How Personal Data Is Used
Personal Data is used exclusively for explicit, legitimate business purposes:
- Providing and maintaining the stability of the Platform.
- Processing transactions and managing enterprise customer accounts.
- Delivering technical support, system update notices, and administrative notifications.
- Investigating, detecting, and mitigating fraud, security vulnerabilities, or AUP violations.
- Compiling aggregated, non-identifying operational analytics to optimize AI models and user interfaces.
- Complying with mandatory legal obligations, financial audits, and lawful law enforcement requests.
4. Data Retention and Erasure
- Personal Data is retained only as long as necessary to fulfill the primary collection purposes, contractual commitments, or statutory retention rules (e.g., tax, audit, corporate record keeping).
- When no longer required, data is safely purged, anonymized, or cryptographically destroyed.
5. Data Protection Rights & Deletion Requests
Individuals have the right to access, rectify, restrict, or request permanent deletion of their personal data, in accordance with global frameworks (EU/UK GDPR, CCPA/CPRA, and other applicable regional laws).
A. Explicit Data Deletion Protocol
- Dedicated Email: privacy@kainam.ai
- Subject Line Requirement: `Data Deletion Request`
B. Validation and Identity Verification
- Identity is verified before executing any erasure.
- Requesters must provide full name, associated organization, and the explicit email addresses tied to the data in question.
C. Resolution Timeline and Processing
- Acknowledgment: Intake logged and initial acknowledgment sent within forty-eight (48) hours of receipt.
- Execution: Verified deletion requests completed across all active production databases and application systems within thirty (30) days from verification.
- Archival Off-sites: Data on isolated, encrypted backups is naturally overwritten per the standard disaster recovery cycle (maximum 90 days), remaining completely inaccessible during that period.
- Exemptions: Users are informed if certain data must be maintained due to explicit legal exemptions (e.g., historical financial transactions or active law enforcement investigations).
6. Third-Party Disclosures
Kainam does not sell, rent, or lease Personal Data to third-party brokers. Data is shared only with trusted categories of recipients necessary to run the infrastructure:
- Cloud Infrastructure Providers: Secure hosting and server environments.
- Enterprise Operations Tooling: CRM systems, ticketing platforms, billing gateways.
- Legal and Regulatory Entities: Where mandatory to protect rights, user safety, or respond to valid subpoenas.
7. Security Safeguards
Technical and organizational measures designed to protect personal data against unauthorized access, loss, modification, or exposure:
- End-to-end transport encryption (TLS 1.3)
- AES-256 encryption at rest
- Strict principle-of-least-privilege access permissions
- Routine automated vulnerability assessments
8. Amendments to this Policy
- Kainam may modify this Privacy Policy at any time; the active version is always at https://kainam.ai/privacy.
- Material modifications are flagged via customer dashboard alerts or clear email messaging at least thirty (30) days before taking effect.