Privacy Policy

Last updated: 16 May 2026

1. Who we are

Kodiac is operated by Kodiac AI Ltd (“Kodiac”, “we”, “us”). We provide AI Visibility & Representation Infrastructure for B2B brands. For the purpose of UK GDPR and EU GDPR, when you sign up as a customer we act as the data processor for personal data you submit (your team members, contacts you choose to track) and the data controller for personal data we collect directly about you (account details, usage telemetry).

2. What personal data we collect

  • Account data, name, email, hashed password, authentication factors (TOTP secret, WebAuthn credentials).
  • Usage telemetry, which screens you visit, which features you use, error reports. Only collected if you opted in via the cookie consent banner.
  • Customer-uploaded content, brand information, competitor lists, knowledge sources you connect, source-of-truth facts. You control what you upload.
  • Communication metadata, sign-in timestamps, IP addresses (for the IP allowlist + audit log), MFA challenge events.

3. How we use it

  • Operate the service you signed up for.
  • Authenticate you and protect your account (MFA, audit log).
  • Improve the product, only with analytics consent.
  • Send you service emails (invites, password resets, security alerts). We don't send marketing emails unless you opt in.
  • Comply with our legal obligations (tax, fraud prevention).

4. Lawful basis

Performance of a contract (your subscription), legitimate interests (security, fraud prevention, product improvement), legal obligation (tax records, GDPR record-keeping), and consent (analytics cookies, marketing communications).

5. Data retention

  • Active account data, kept for the lifetime of your account.
  • Deleted account data, soft-deleted immediately; hard-deleted after a 30-day retention window via our automated cleanup job. After that we keep only the minimum required by tax and accounting law (invoices, transaction records).
  • Audit log, retained per workspace tier (90 days Starter / 365 days Growth / 7 years Enterprise) for security and compliance investigations.
  • Backup snapshots, encrypted, retained up to 30 days, then automatically purged.

6. Where we process data

Primary processing region: London (eu-west-2), chosen as the UK/EU default for data residency. Workspaces on Enterprise tier can pin to alternative regions (Dublin, Virginia, Singapore) for residency requirements.

Sub-processors: Vercel (hosting), Neon (managed Postgres), Inngest (background workflows), Resend (transactional email), Stripe (payments), Anthropic / OpenAI / Google / Perplexity (AI providers you can selectively enable). A current sub-processor list is available on request; we'll notify Enterprise customers of any changes 30 days in advance.

7. International transfers

Where data crosses borders we rely on the UK International Data Transfer Agreement (IDTA) and EU Standard Contractual Clauses (SCCs) with our sub-processors. Enterprise customers can request a copy of the executed agreements.

8. Your rights

Under GDPR you have the right to:

  • Access the personal data we hold about you
  • Rectify inaccurate data
  • Erase your data (“right to be forgotten”), self-service via Settings → Account → Delete my account, with a 30-day recovery window before hard deletion
  • Restrict or object to processing
  • Portability of data you've given us
  • Withdraw consent at any time without affecting prior lawful processing
  • Lodge a complaint with the ICO (UK) or your local supervisory authority (EU)

9. Cookies

We use strictly necessary cookies for authentication and session security (always on) and optional cookies for analytics and marketing (consent-gated via the banner). You can change your cookie preferences any time by clearing the consent cookie or via a future Settings panel.

10. Security

All traffic is TLS 1.2+. Passwords are hashed with bcrypt. MFA (TOTP or WebAuthn) is available to every user; required for Admin+ on Enterprise. Database access is least-privilege, audited, and pinned to the workspace region. Row-level security policies enforce multi-tenant isolation at the database layer.

11. Contact

Data Protection Officer: dpo@kodiac.ai. For Enterprise customers, we'll execute a Data Processing Agreement (DPA) before processing begins, see our DPA page for the template.

12. Changes

Material changes will be notified by email to the workspace owner at least 30 days before they take effect. Non-material changes will be reflected here with an updated “Last updated” date.