Who we are and scope
Kaia Technologies ("Kaia", "we", "us" or "our"), ABN 46 603 121 960, is based in Tasmania, Australia. We provide AI agents and workflow automation tools for businesses.
This Privacy Policy applies to personal information handled through our websites, applications, customer support, and related services (together, the "Services"). It does not govern third-party products you choose to connect to Kaia, which remain subject to their own privacy policies.
If an organisation provides you access to a Kaia workspace, that organisation may control the workspace and the information within it. In that context, Kaia generally processes personal information on the organisation's instructions, and questions about its use of your information should first be directed to that organisation.
Information we collect
Information you provide
- Account details, such as your name, email address, profile image, login method, and organisation.
- Workspace details, team membership, roles, permissions, and invitations.
- Prompts, conversations, agent instructions, uploaded files, approvals, and other content you submit.
- Support requests, product feedback, and other communications with us.
- Billing contact and subscription details. Payment card data is handled by our payment provider rather than stored directly by Kaia.
Information collected automatically
- Device, browser, operating system, IP address, language, and approximate location derived from IP.
- Pages viewed, features used, actions taken, referring URLs, timestamps, and diagnostic events.
- Security, authentication, audit, and error logs.
- Cookie and similar technology identifiers, subject to your browser settings and applicable consent requirements.
Connected services and customer content
You may authorise Kaia to connect to services such as email, calendars, CRM, documents, spreadsheets, analytics, accounting, messaging, inventory, or advertising platforms. Depending on the connection and permissions you choose, Kaia may read, create, update, send, or otherwise process data in those services to carry out your requests.
Each service is connected separately. Kaia requests only the access scopes needed for the connection you are enabling, at the time you enable it, and shows you the permissions before you approve them. Workspace owners and users are responsible for choosing appropriate permissions and ensuring they have authority to provide the data to Kaia.
Connected data may include messages, contacts, events, files, records, transactions, reports, and metadata. For Google services, the exact categories, uses, and limits are set out in Google user data below.
You can disconnect an integration through the Services or the third-party provider. Disconnecting stops future access and causes Kaia to delete the stored credentials and connection records for that integration. See Data Deletion Instructions for how to remove content that has already been incorporated into conversations or audit records.
Shopify data
When a merchant connects a Shopify store, Kaia receives data from that merchant's Shopify Admin API connection. Depending on the scopes granted by the merchant and Shopify's protected-customer-data approval, this may include:
- the store's Shopify identifier, domain, settings, and account metadata;
- products, variants, inventory items and quantities, locations, and fulfillment locations;
- orders, line items, fulfillment orders, fulfillments, tracking information, and order reports;
- customer identifiers, names, email addresses, phone numbers, postal addresses, order history, spending summaries, and related customer records; and
- other records or store-credit information exposed by a scope that the merchant has approved.
Kaia uses Shopify data only to carry out the merchant's request, return a report or result in the Kaia workspace, prepare or perform an action that the merchant has approved, secure and operate the connection, and comply with law. Kaia does not sell Shopify data, use it for advertising or marketing profiles, or use it to train or improve a general-purpose AI model.
Kaia requests only the Shopify scopes needed for the enabled actions. Shopify may require additional approval for customer contact, address, order-history, fulfillment-destination, or analytics fields. The merchant controls whether to grant those permissions and can disconnect the store at any time.
Kaia uses Nango to complete Shopify OAuth and transport requests to Shopify. Shopify data may also be processed by the infrastructure, database, AI, background-job, and observability providers described in section 8, only to provide and secure the Services.
Google user data
This section describes exactly what Kaia accesses through Google APIs, why, where it goes, how long it is kept, and what we will never do with it. It applies in addition to the rest of this policy, and prevails over any more general statement here if the two conflict.
What Kaia accesses, and why
Google services are connected individually. Connecting one Google service does not grant Kaia access to any other. Kaia only accesses the services listed below, and only after you complete Google's consent screen for that service.
| Google service | Information Kaia can access | What Kaia does with it |
|---|---|---|
| Gmail | Message and thread contents, subject lines, senders and recipients, dates, attachments, labels, and drafts in the mailbox you connect. | Searches, reads and summarises mail you ask about; applies or removes labels; creates drafts; and sends messages you have asked it to send. |
| Google Calendar | The list of calendars you subscribe to, calendar metadata such as name, description and time zone, free/busy availability, and event details including title, description, time, location, attendees and conferencing links. | Lists your calendars, reads calendar settings, checks availability, and reads, creates, updates and deletes events on calendars you can access — including calendars shared with you by other people. |
| Google Sheets | Structure, sheet names and cell values of spreadsheets you identify by link or ID in a conversation, and of spreadsheets Kaia creates for you. | Reads and analyses spreadsheet data; writes, updates and clears values; adds, renames and removes sheets; and creates new spreadsheets when you ask. |
| Google Analytics | Your GA4 account, property and data stream list, and aggregated report data such as sessions, users, traffic sources, events and conversions. | Read-only. Finds the right property and runs the reports you ask for. Kaia does not request any Analytics write access. |
| Google Ads | Account structure, campaigns, ad groups, ads, keywords, budgets and performance reports for the accounts you connect. | Reports on performance, and creates or updates campaigns, ads, keywords and experiments. Changes to your account require your approval before they run. |
| YouTube | Channel details, video metadata, captions, playlists and comments for the channel you connect. | Reads channel and video information and captions; creates and modifies playlists; and updates video details and comments at your direction. |
Kaia uses Google user data only to carry out the request you made in your workspace: to answer your question, produce a summary or report, or perform an action you asked for. Kaia does not build advertising or marketing profiles from it, and does not create aggregated or anonymised datasets from Google user data.
Kaia requests the narrowest scope that supports the features above. Where a broader scope is unavoidable, it is because the narrower alternative cannot perform a function you rely on — for example, read-only calendar scopes cannot create or update an event on a calendar shared with you, and file-picker-only Drive access cannot open a spreadsheet you paste into a conversation as a link.
Limited Use
Kaia's use and transfer of information received from Google APIs to any other app will adhere to the Google API Services User Data Policy, including the Limited Use requirements.
What Kaia never does with Google user data
The commitments below apply to raw Google user data and to anything derived, aggregated or anonymised from it.
- We do not sell it.
- We do not transfer, license or disclose it to advertisers, advertising networks, data brokers, information resellers, or any other party for their own purposes.
- We do not use it for advertising of any kind, including targeted, retargeted, personalised or cross-context behavioural advertising.
- We do not use it for credit, lending, insurance, tenancy or employment eligibility decisions.
- We do not use it to develop, train, retrain, fine-tune or improve generalised artificial intelligence or machine learning models, whether our own or a third party's.
- We do not use it to build or improve products or services unrelated to the Kaia workspace through which you connected it.
- We do not allow humans to read it, except: with your explicit consent for a specific message or file; where necessary for security purposes such as investigating abuse or a suspected incident; to comply with applicable law; or where the data has been aggregated and anonymised and is used for internal operations. Kaia does not currently produce aggregated or anonymised datasets from Google user data.
- In a merger, acquisition, financing or sale of assets, Google user data is transferred only where we have obtained your explicit prior consent, as the Limited Use requirements demand. The general business-transfer disclosure in section 8 does not override this.
Where Google user data goes
Google user data is processed by the following providers, solely to deliver the Services to you and under contractual confidentiality and security terms:
- Nango — authorises the connection and carries API requests to and from Google.
- Vercel — hosts and runs the application that processes your request.
- Supabase — stores the conversations, outputs and audit records that may contain Google content.
- OpenAI — processes the content needed to answer your request, under its business/API terms, which do not permit use of API content to train its models.
- Trigger.dev — runs scheduled and background jobs you have configured.
- Langfuse — receives diagnostic traces of agent runs, where enabled, under a short retention period.
PostHog receives product-event metadata only — such as which feature was used and when — and does not receive Google message, file, event, or report content. Stripe never receives Google user data. Google user data is not transferred to any other third party except where you direct Kaia to send it, or as required by law.
Retention and deletion of Google user data
- Kaia revalidates your authorisation with Google at least every 30 days. Google user data that Kaia has stored is refreshed from Google or deleted within 30 days.
- When you disconnect a Google integration in Kaia, or revoke Kaia's access from your Google security settings, Kaia deletes the stored credentials, connection records and associated Google user data within 7 days.
- Google content that has already been incorporated into a conversation or audit record is deleted when you delete that conversation, or when your account or workspace is deleted. See Data Deletion Instructions.
YouTube API Services
Kaia's YouTube features use YouTube API Services. By using them you agree to be bound by the YouTube Terms of Service. Google's handling of your information is described in the Google Privacy Policy.
You can revoke Kaia's access to your YouTube data at any time through the Google security settings page. Kaia deletes stored YouTube API data within 7 days of that revocation, and otherwise refreshes or deletes stored YouTube API data at least every 30 days. Kaia does not use YouTube data for advertising, does not artificially inflate views, likes, subscriptions or other metrics, and does not combine YouTube data with data from other services to build a profile of you.
Google Data Portability APIs
Not applicable. Kaia does not request, access or use any Google Data Portability API scope.
How we use information
We use personal information to:
- Provide, operate, maintain, and personalise the Services.
- Authenticate users, administer workspaces, and enforce roles and permissions.
- Run AI agents, retrieve relevant context, generate outputs, and perform actions you authorise.
- Process subscriptions, measure usage, and manage billing.
- Respond to support requests and send service, security, and administrative messages.
- Monitor reliability, troubleshoot errors, prevent abuse, and protect users and the Services.
- Understand feature use and improve the performance and design of the Services.
- Comply with law, enforce our terms, and establish or defend legal claims.
- Send marketing communications where permitted. You may unsubscribe from marketing messages at any time.
Connected-service content, including Google user data, is used only for the first three purposes above and for the security and legal-compliance purposes described. It is not used for marketing, and it is not used to improve the Services beyond operating them for you.
Legal bases for processing
Where the GDPR, UK GDPR, or another law requires a legal basis, we rely on one or more of the following: performance of a contract; our legitimate interests in operating, securing, and improving the Services; your consent; and compliance with legal obligations. Where we rely on consent, you may withdraw it at any time without affecting processing already carried out.
For customer content processed on behalf of a workspace customer, that customer determines the applicable purpose and legal basis. Kaia acts as a processor or service provider to the extent required by applicable law.
AI processing
Kaia sends relevant prompts, instructions, files, connected-service data, and conversation context to AI service providers to generate responses and planned actions. Outputs may be stored with conversation and audit history so you can review what an agent did and why.
Kaia does not sell customer content and does not use it to develop, train, retrain, fine-tune or improve any generalised AI or machine learning model. This applies to raw customer content and to derived, aggregated or anonymised versions of it. Our AI providers process content under business or API terms that do not permit training on it, and we disable any provider setting that would allow content to be used for model improvement.
AI providers may retain request and response state for a limited period under their standard API controls in order to operate the service and monitor for abuse — currently up to 30 days. That state is deleted on expiry, and we request deletion of associated provider state when you delete your account.
Automated outputs can be incomplete or incorrect, so users should review outputs and approvals before relying on them for material decisions or external communications.
Data retention
We retain information only as long as needed for the purpose it was collected, then delete or de-identify it. The periods below apply unless a longer period is required by law, or is necessary to prevent fraud or abuse, resolve a dispute, or enforce our agreements.
| Data type | Retention |
|---|---|
| Account and workspace records | While the account is active. Deleted within 30 days of a verified account or workspace deletion request. |
| Conversations, agent outputs, uploaded files | Until you delete them, or within 30 days of account or workspace deletion. |
| Connected-service content held for a connection | Refreshed from the source or deleted within 30 days. |
| OAuth credentials and connection records | Deleted within 7 days of disconnection or revocation. |
| Shopify OAuth credentials and local Shopify connection records | Deleted promptly, and no later than 7 days, after disconnection, revocation, app uninstall, or a Shopify shop-redaction request. Nango credentials are revoked through Nango. |
| Shopify customer, order, fulfillment, product, inventory, location, and report data in conversations, action history, or audit records | Retained only under the applicable conversation, action-history, and audit retention periods in this policy, or until a verified Shopify customer or shop deletion request is completed, whichever is earlier. |
| Security, authentication, and agent-action audit logs | 12 months. |
| AI observability traces, where enabled | 30 days. |
| AI provider request and response state | Up to 30 days under the provider's standard API retention controls. |
| Product analytics events (metadata only) | 12 months. |
| Encrypted backups | Rolling. Overwritten or deleted within 90 days. |
Shopify sends Kaia mandatory privacy requests for customer access, customer deletion, and shop deletion. Kaia verifies the request, records the compliance event without retaining the raw webhook body, and completes the applicable export, redaction, or deletion across Shopify-linked Kaia records within the period required by law and Shopify. Data that remains in Shopify is governed by the merchant's and Shopify's own policies.
You may request deletion of your account or personal information at any time. Deleting Kaia data does not delete copies held in a connected third-party service. See our Data Deletion Instructions for request steps, including for data received through Google, Facebook, Instagram, or Shopify.
Security
We use technical and organisational safeguards designed to protect information, including:
- Encryption of data in transit over TLS, and encryption at rest in our database, file storage, and backups.
- OAuth credentials held by our integration provider and in encrypted storage, never exposed to browser clients or included in AI prompts.
- Workspace-scoped authorisation, with roles and permissions enforced on every request.
- Least-privilege scope requests, made per connection at the time you enable it.
- Manual approval by default for actions that write to a connected service on a new connection.
- Authentication, access, and agent-action audit logging.
- Staff access limited to personnel who need it for support or operations, under confidentiality obligations.
- Vendor review and data processing agreements with providers that handle customer content.
- A documented incident response process, including assessment and notification where required by law.
No system is completely secure, and we cannot guarantee that information will never be accessed, disclosed, altered, or lost. You are responsible for keeping your account and devices secure, using appropriate workspace permissions, reviewing agent approvals, and notifying us promptly if you suspect unauthorised access.
International data transfers
Kaia is operated from Australia, and our providers may process information in Australia, the United States, the European Union, and other countries. These countries may have different privacy laws from your country.
Where required, we use recognised safeguards for international transfers, such as data processing agreements and standard contractual clauses, and take reasonable steps to ensure overseas recipients handle personal information consistently with applicable law.
Your privacy rights
Depending on where you live, you may have rights to access, correct, delete, restrict, or object to processing of your personal information; receive a portable copy; withdraw consent; or complain to a regulator. Australian users may request access and correction under applicable Australian privacy law. EEA and UK users may also object to processing based on legitimate interests and lodge a complaint with their local supervisory authority.
California residents may have rights to know, correct, delete, and obtain a copy of personal information, and to receive equal service when exercising those rights. Kaia does not sell personal information or share it for cross-context behavioural advertising.
Shopify customer requests
A Shopify merchant or an authorised data subject may request access to or deletion of Shopify-derived personal information held by Kaia by emailing elliott@usekaia.comwith the store domain, the Shopify customer ID when available, and the relevant email address, phone number, or order IDs. We verify the requester and authority before acting. Do not send a Shopify access token or other credential by email. We will respond within the period required by applicable law and Shopify's compliance requirements. The request may cover Shopify-derived data in Kaia conversations, action history, audit records, and stored connection data; it does not delete the source record held by Shopify.
Email elliott@usekaia.com to make a request, or follow our Data Deletion Instructions. We may need to verify your identity and authority. If your information belongs to a customer-managed workspace, we may direct the request to that customer.
Children
The Services are intended for business users aged 18 or older. We do not knowingly collect personal information from children. If you believe a child has provided information to Kaia, contact us so we can investigate and take appropriate action.
Changes to this policy
We may update this policy as our Services, providers, or legal obligations change. We will post the revised version here and update the date above. If a change materially affects your rights, we will provide additional notice where reasonably practicable or required by law.
Contact and complaints
For privacy questions, requests, or complaints, contact:
Kaia TechnologiesABN 46 603 121 960
Tasmania, Australia
elliott@usekaia.com
We will investigate privacy complaints and respond within a reasonable period. If you are not satisfied with our response, you may contact the Office of the Australian Information Commissioner or another regulator available in your jurisdiction.