Privacy Policy

Last updated:

1. Overview

KONDWIT Inc. ("we", "us", or "our") operates the KONDWIT platform. This policy describes how we collect, use, and protect your information when you use our Service.

2. Information We Collect

Account Information

When you create an account, we collect your name, email address, and organization. If you sign in via Microsoft Entra ID, we receive your profile information from your identity provider.

Usage Data

We collect information about how you use the Service, including pages visited, searches performed, and features used. This helps us improve the product.

Content You Create

Research sessions, memos, collections, and other content you create within the Service is stored in our database to provide the Service to you.

AI Assistant Connector Data (MCP & Copilot)

When you connect an AI assistant — Claude, ChatGPT, Cursor, VS Code, Goose, or Microsoft Copilot — to KONDWIT through our Model Context Protocol (MCP) server or the Microsoft Copilot agent, we process and log the following so we can answer the request and maintain a compliance-grade audit trail:

  • Tool requests and responses — the inputs you (or your assistant on your behalf) send to a KONDWIT tool, and the regulatory content we return. These are written to a hash-chained, append-only audit log, because the compliance use case needs a record of what guidance was retrieved and when. Each row carries the hash of its predecessor, so an altered row breaks the chain; read that as tamper-evidence within the platform. Chain heads are signed with our own key and recorded as anchor rows in the same database. They are not timestamped by a trusted timestamp authority, and no copy of the anchor is held outside the platform. See our Trust Center security page for the measured anchor coverage and what is not in place.
  • Identity from the connector's OAuth flow — the account identifier the assistant authenticates with, bound to your KONDWIT user.
  • Microsoft Graph delegated tokens (Copilot only) — received transiently to act on your behalf for the current request; used in-memory andnot stored.
  • Adaptive Card interaction payloads (Copilot only) — the fields you submit when you act on a KONDWIT card inside Copilot.

Your tool inputs and outputs are never used to train any AI model, ours or a third party's.

3. How We Use Your Information

  • Provide, maintain, and improve the Service
  • Process billing and subscription management
  • Send transactional emails (account, billing, compliance alerts)
  • Respond to support requests
  • Analyze usage patterns to improve the product

We do not sell your personal information to third parties.

3a. What We Do NOT Collect

  • Procedure documents and other content you upload for regulatory analysis are processed transiently; we do not retain that analysis input unless you explicitly pin the result to a Canvas Session.
  • No third-party advertising or cross-site tracking.
  • No biometric data and no special-category / sensitive PII beyond the authentication identity your identity provider supplies.

4. Data Storage, Residency, and Security

Your data is hosted on Microsoft Azure infrastructure in the United States, in the Central US region. Every resource that stores customer data — the database, the cache, the key vault, the application containers — is in that single region. EU residency is on the roadmap and is not available today. We use encryption in transit (TLS) and at rest. Access to production systems is restricted to authorized personnel.

Database backups are performed automatically with point-in-time recovery across a 35-day window. Backups are stored in the same region as the database; there is no cross-region copy. See our Trust Center security page for the full posture, including what is not in place.

5. Third-Party Services and Sub-processors

Third parties that process customer data on our behalf are disclosed in one place: our sub-processor list, which names each processor, the purpose, the data categories involved, the processing location, and the applicable data processing agreement. Any addition or material change to that list triggers a 30-day advance notification to subscribed customers. Model providers on that list process your queries to answer them; your content is not used to train any AI model, ours or a third party's.

5a. YouTube API Services

KONDWIT uses YouTube API Services to display public video metadata — title, description excerpt, duration, channel, and thumbnail — in the pipeline-safety news lane. We request read-only public metadata only; no video or audio content is downloaded, proxied, or stored. No customer or personal data is sent to YouTube; outbound requests carry only KONDWIT's own search terms, built from public pipeline-incident facts. Video thumbnails are loaded directly from Google's servers, so when a thumbnail is displayed your browser or mail client contacts Google and, as with any request to a third-party server, discloses your IP address and User-Agent to it. Where video content is displayed, you are also bound by the YouTube Terms of Service. Google's handling of any data it collects through these services is governed by the Google Privacy Policy.

6. Data Retention

We retain your account data for as long as your account is active. If you delete your account, we will delete your personal data within 30 days, except where retention is required by law.

  • Customer business data — lifetime of the subscription, plus 30 days after cancellation.
  • Compliance audit chain — because KONDWIT serves a regulatory audit-trail use case, the hash-chained record of tool requests and the regulatory content returned is not deleted. Seven years is our retention policy target; today the only copy lives in the primary database, within its 35-day point-in-time restore window, and no archive enforces a seven-year floor.
  • LLM prompts and completions — processed by our model providers subject to their own retention terms (see the sub-processor list). We do not currently operate a separate prompt-level observability store; if one is enabled, its retention will be disclosed here first.
  • Operational logs (IP, request timing, error traces) — 365 days.
  • Transient processing data, including Microsoft Graph delegated tokens — cleared at the end of the request or session.

7. Your Rights

You have the right to:

  • Access the personal data we hold about you
  • Request correction of inaccurate data
  • Request deletion of your data
  • Export your data in a portable format
  • Withdraw consent for optional data processing

Where the GDPR applies, those rights are served as follows:

  • Right of access (Article 15) — an asynchronous per-user data export, returned as gzipped JSONL with a SHA-256 integrity hash.
  • Right to erasure (Article 17) — a 7-day cancelable grace window, then a cascade delete across all org-scoped data per documented cascade rules. Audit chain entries are preserved with the actor anonymized, under the Article 17(3)(b) legitimate-interest exemption.
  • Records of processing (Article 30) — the hash-chained audit log, exportable in OCSF v1.1.

To exercise these rights, contact us at privacy@kondwit.com.

8. Data Processing Agreement (DPA)

Our DPA template is the foundation for the customer-facing data processing terms. Enterprise customers execute the DPA as part of contract signature; the live template covers GDPR Article 28 plus Standard Contractual Clauses for EU transfers.

Request the DPA template

9. Breach Notification

72-hour notification under GDPR Article 33. Our breach notification procedure documents the operational flow.

10. Cookies

We use essential cookies for authentication and session management. We do not use third-party advertising or tracking cookies. Analytics, when enabled, use privacy-focused tools that do not track individual users across sites.

11. Changes to This Policy

We may update this policy from time to time. Material changes will be communicated via email at least 14 days before they take effect.

12. Contact

Questions about privacy? Contact us at privacy@kondwit.com.

Terms·Privacy·© 2026 KONDWIT
Privacy Policy — KONDWIT