kaia
ProductUse casesIntegrations
Log inSign up
← Back to Kaia

Privacy Policy

This policy explains what information Kaia handles, why we handle it, and the choices available to you.

Last updated: 20 July 2026

Contents

01Who we are and scope02Information we collect03Connected services04How we use information05Legal bases06AI processing07Sharing and providers08Cookies and analytics09Data retention10Security11International transfers12Your rights13Children14Changes to this policy15Contact and complaints
01

Who we are and scope

Kaia Technologies ("Kaia", "we", "us" or "our"), ABN 46 603 121 960, is based in Tasmania, Australia. We provide AI agents and workflow automation tools for businesses.

This Privacy Policy applies to personal information handled through our websites, applications, customer support, and related services (together, the "Services"). It does not govern third-party products you choose to connect to Kaia, which remain subject to their own privacy policies.

If an organisation provides you access to a Kaia workspace, that organisation may control the workspace and the information within it. In that context, Kaia generally processes personal information on the organisation's instructions, and questions about its use of your information should first be directed to that organisation.

02

Information we collect

Information you provide

  • Account details, such as your name, email address, profile image, login method, and organisation.
  • Workspace details, team membership, roles, permissions, and invitations.
  • Prompts, conversations, agent instructions, uploaded files, approvals, and other content you submit.
  • Support requests, product feedback, and other communications with us.
  • Billing contact and subscription details. Payment card data is handled by our payment provider rather than stored directly by Kaia.

Information collected automatically

  • Device, browser, operating system, IP address, language, and approximate location derived from IP.
  • Pages viewed, features used, actions taken, referring URLs, timestamps, and diagnostic events.
  • Security, authentication, audit, and error logs.
  • Cookie and similar technology identifiers, subject to your browser settings and applicable consent requirements.
03

Connected services and customer content

You may authorise Kaia to connect to services such as email, calendars, CRM, documents, spreadsheets, analytics, accounting, messaging, inventory, or advertising platforms. Depending on the connection and permissions you choose, Kaia may read, create, update, send, or otherwise process data in those services to carry out your requests.

Connected data may include messages, contacts, events, files, records, transactions, reports, and metadata. Kaia only seeks access scopes needed for the enabled connection, but workspace owners and users are responsible for choosing appropriate permissions and ensuring they have authority to provide the data to Kaia.

You can disconnect an integration through the Services or the third-party provider. Disconnecting stops future access but does not automatically remove information already incorporated into conversations, outputs, audit records, or other stored Service data.

04

How we use information

We use personal information to:

  • Provide, operate, maintain, and personalise the Services.
  • Authenticate users, administer workspaces, and enforce roles and permissions.
  • Run AI agents, retrieve relevant context, generate outputs, and perform actions you authorise.
  • Process subscriptions, measure usage, and manage billing.
  • Respond to support requests and send service, security, and administrative messages.
  • Monitor reliability, troubleshoot errors, prevent abuse, and protect users and the Services.
  • Understand feature use and improve the performance and design of the Services.
  • Comply with law, enforce our terms, and establish or defend legal claims.
  • Send marketing communications where permitted. You may unsubscribe from marketing messages at any time.
05

Legal bases for processing

Where the GDPR, UK GDPR, or another law requires a legal basis, we rely on one or more of the following: performance of a contract; our legitimate interests in operating, securing, and improving the Services; your consent; and compliance with legal obligations. Where we rely on consent, you may withdraw it at any time without affecting processing already carried out.

For customer content processed on behalf of a workspace customer, that customer determines the applicable purpose and legal basis. Kaia acts as a processor or service provider to the extent required by applicable law.

06

AI processing

Kaia sends relevant prompts, instructions, files, connected-service data, and conversation context to AI service providers to generate responses and planned actions. Outputs may be stored with conversation and audit history so you can review what an agent did and why.

Kaia does not sell customer content or use it to train a general-purpose AI model. AI providers process content under their business or API terms. Automated outputs can be incomplete or incorrect, so users should review outputs and approvals before relying on them for material decisions or external communications.

07

How we share information

We do not sell personal information. We disclose information only as described below:

  • Service providers. Vendors that provide infrastructure, authentication, AI processing, integrations, billing, analytics, observability, and background processing.
  • Connected services. Third parties you direct Kaia to interact with, including when an agent sends, creates, or updates information.
  • Your workspace. Workspace owners and authorised members may access workspace content, activity, and audit history according to their permissions.
  • Legal and safety reasons. Authorities or other parties where reasonably necessary to comply with law, protect rights and safety, investigate abuse, or enforce agreements.
  • Business transfers. A buyer, investor, adviser, or successor in connection with a financing, reorganisation, sale, or transfer, subject to appropriate confidentiality safeguards.
Core service-provider categories currently used by Kaia
ProviderPurpose
VercelWebsite and application hosting, delivery, and performance monitoring
SupabaseDatabase, authentication, and file storage infrastructure
OpenAIAI model processing
NangoAuthorisation and connectivity for third-party integrations
Trigger.devBackground and scheduled workflow processing
StripeSubscription billing and payment processing
PostHogProduct analytics and diagnostics, where enabled
LangfuseAI observability and diagnostics, where enabled

Providers and product features may change. We require providers to handle information for the contracted purpose and subject to appropriate confidentiality and security terms.

08

Cookies and analytics

Kaia uses essential cookies and local storage for authentication, security, preferences, and core functionality. Where enabled, analytics technologies help us understand product use, diagnose problems, and improve the Services. We do not use personal information for cross-context behavioural advertising or sell it through advertising cookies.

You can control cookies through your browser. Blocking essential storage may prevent sign-in or other parts of the Services from working. Where law requires consent for non-essential cookies, we will request it before setting them.

09

Data retention

We retain account and customer content while needed to provide the Services, for the period directed by the workspace customer, and afterward only as reasonably necessary for legitimate business, security, backup, dispute-resolution, and legal purposes. Retention varies by data type, workspace settings, contractual commitments, and legal requirements.

You may request deletion of your account or personal information. Some information may remain for a limited period in backups or be retained where required by law, to prevent fraud or abuse, collect fees, resolve disputes, or enforce agreements. Deleting Kaia data does not delete copies held in a connected third-party service. See our Data Deletion Instructions for request steps, including for data received through Facebook or Instagram.

10

Security

We use reasonable technical and organisational safeguards designed to protect information, including access controls, encryption in transit, provider security controls, and logging. No system is completely secure, and we cannot guarantee that information will never be accessed, disclosed, altered, or lost.

You are responsible for keeping your account and devices secure, using appropriate workspace permissions, reviewing agent approvals, and notifying us promptly if you suspect unauthorised access.

11

International data transfers

Kaia is operated from Australia, and our providers may process information in Australia, the United States, the European Union, and other countries. These countries may have different privacy laws from your country.

Where required, we use recognised safeguards for international transfers, such as data processing agreements and standard contractual clauses, and take reasonable steps to ensure overseas recipients handle personal information consistently with applicable law.

12

Your privacy rights

Depending on where you live, you may have rights to access, correct, delete, restrict, or object to processing of your personal information; receive a portable copy; withdraw consent; or complain to a regulator. Australian users may request access and correction under applicable Australian privacy law. EEA and UK users may also object to processing based on legitimate interests and lodge a complaint with their local supervisory authority.

California residents may have rights to know, correct, delete, and obtain a copy of personal information, and to receive equal service when exercising those rights. Kaia does not sell personal information or share it for cross-context behavioural advertising.

Email elliott@usekaia.com to make a request, or follow our Data Deletion Instructions. We may need to verify your identity and authority. If your information belongs to a customer-managed workspace, we may direct the request to that customer.

13

Children

The Services are intended for business users aged 18 or older. We do not knowingly collect personal information from children. If you believe a child has provided information to Kaia, contact us so we can investigate and take appropriate action.

14

Changes to this policy

We may update this policy as our Services, providers, or legal obligations change. We will post the revised version here and update the date above. If a change materially affects your rights, we will provide additional notice where reasonably practicable or required by law.

15

Contact and complaints

For privacy questions, requests, or complaints, contact:

Kaia Technologies
ABN 46 603 121 960
Tasmania, Australia
elliott@usekaia.com

We will investigate privacy complaints and respond within a reasonable period. If you are not satisfied with our response, you may contact the Office of the Australian Information Commissioner or another regulator available in your jurisdiction.

kaia

AI agents for the work that keeps your business moving.

ProductUse casesIntegrationsPrivacyTermsData deletion
© 2026 Kaia Technologies