Privaata legal policy
Privaata Privacy Policy
How Privaata handles account data, workspace content, integrations, AI processing, retention, and privacy rights.
Source document: Privaata Privacy Policy.docx
Privaata Privacy Policy
Effective Date: September 1, 2026 Last Updated: September 1, 2026
This Privacy Policy explains how Kinfolk Technologies Limited (“Kinfolk Technologies,” “we,” “us,” or “our”), as the operator of Privaata, collects, uses, discloses, stores and otherwise processes personal data in connection with the Privaata website, platform, accounts, customer support, billing, marketing and related services.
Privaata is a privacy management software platform designed to help organizations manage privacy records, evidence, system integrations, AI-assisted recommendations, data subject requests, Records of Processing Activities (“RoPAs”), Data Protection Impact Assessments (“DPIAs”), incidents, vendors, policies, training, reporting and regulatory readiness.
This Privacy Policy also explains the important distinction between personal data Kinfolk Technologies processes for its own purposes and information that customers place in, connect to or otherwise process through their Privaata workspaces.
1. Who We Are
Privaata is operated by:
Kinfolk Technologies Limited 18 Geranium Path Mona Heights Kingston 6 Jamaica
Privacy Email: privacy@kinfolktechnologies.comTelephone: (876) 298-4018
For information collected in connection with website visits, account administration, demo or sales requests, customer support, billing, marketing, security and our own business operations, Kinfolk Technologies Limited is generally responsible for determining how and why that information is processed.
For personal data contained within a customer’s Privaata workspace, Kinfolk Technologies Limited generally processes that information on behalf of and according to the instructions of the customer, subject to the applicable agreement and law.
2. Our Role and Our Customers’ Role
Privaata is designed primarily as a business-to-business service.
Organizations using Privaata remain responsible for the personal data they choose to enter, upload, connect, scan, import, approve, export or otherwise manage through their workspaces.
This may include information contained within:
RoPAs;
DPIAs;
data subject access requests and other data subject rights requests;
incident and breach records;
vendor and processor records;
policies and governance documents;
training records;
data maps;
assessments;
evidence;
notes;
reports;
audit records; and
information obtained through connected systems.
The customer determines what information is placed in its workspace, why that information is processed, which authorized users can access it, which integrations are connected, what actions are taken based on the information, and what legal or compliance decisions are ultimately made.
Where Kinfolk Technologies processes Customer Data solely to provide Privaata to the customer, Kinfolk Technologies generally acts as a processor or service provider on the customer’s behalf, while the customer generally acts as the data controller or equivalent responsible organization, unless applicable law or a written agreement provides otherwise.
Nothing about storing or processing Customer Data through Privaata transfers ownership of that data to Kinfolk Technologies.
3. Customer Data
For purposes of this Policy, “Customer Data” means information, records, documents, files, evidence, metadata, personal data and other content submitted to, stored in, connected to, generated within or otherwise processed through a customer’s Privaata workspace on the customer’s behalf.
Customers retain their rights and interests in their Customer Data.
Kinfolk Technologies does not claim ownership of Customer Data merely because that data is stored, analyzed or otherwise processed through Privaata.
We process Customer Data only as necessary to provide, maintain, secure and support Privaata; comply with the customer’s authorized instructions; meet applicable legal obligations; and exercise rights permitted under the applicable customer agreement and law.
4. Information We Collect
The information Privaata processes depends on how an individual or organization interacts with the service, the modules being used and the systems the customer chooses to connect.
4.1 Account and Identity Information
When an account is created or administered, we may collect information such as:
name;
email address;
organization name;
job title;
login and authentication information;
login provider;
authentication events;
workspace membership;
role and permissions; and
support contact information.
Passwords are used for authentication but should be stored using appropriate cryptographic password-protection mechanisms rather than as readable plaintext.
4.2 Organization and Workspace Information
We may process information relating to a customer’s organization and configuration, including:
organization name;
industry or organization type;
jurisdiction;
legal entities;
selected modules;
subscription plan;
workspace configuration;
users;
user roles and permissions;
privacy records;
task history;
workflow information;
audit decisions; and
reporting settings.
The precise information collected may vary according to the functionality selected and changes made to Privaata over time.
4.3 Privacy and Compliance Records
Customers may use Privaata to process information relating to:
processing activities;
personal data categories;
data subjects;
lawful bases;
data retention;
data sharing;
international transfers;
DPIAs;
DSARs and other rights requests;
incidents and potential breaches;
vendors and processors;
privacy policies;
compliance evidence;
training;
risks;
remedial actions; and
privacy governance activities.
Such records may themselves contain personal data.
Customers are responsible for determining what Customer Data is appropriate and lawful to place within Privaata.
4.4 Integration Information
Customers may voluntarily connect third-party systems to Privaata.
When an authorized administrator establishes an integration, Privaata may process information such as:
OAuth consent information;
connected provider;
connected administrator or account email;
authorization status;
integration configuration;
synchronization status;
directory information;
file or email metadata;
audit-log metadata;
scan results;
scan summaries;
evidence extracts;
system identifiers; and
other information necessary to provide the authorized integration functionality.
The particular information accessible to Privaata depends on the integration, permissions authorized by the customer and functionality being used.
4.5 AI-Related Information
When AI-assisted features are used, Privaata may process information such as:
user prompts;
relevant evidence snippets;
contextual workspace information;
generated recommendations;
generated classifications or summaries;
model and processing metadata;
confidence indicators where applicable;
human approvals or rejections;
modifications made by users; and
feedback concerning generated recommendations.
AI-related processing is described further below.
4.6 Technical and Security Information
We may automatically collect technical information necessary to operate, protect and troubleshoot Privaata, including:
IP addresses;
browser and device information;
operating-system information;
timestamps;
session information;
authentication logs;
application logs;
API events;
error reports;
rate-limit events;
security alerts; and
activity relevant to fraud, abuse and security investigations.
4.7 Billing and Commercial Information
We may process commercial information such as:
subscription plan;
billing cycle;
trial status;
subscription status;
invoices;
transaction references;
payment status;
renewal status;
coupon or discount information; and
billing contacts.
Payment transactions may be processed by authorized third-party payment providers.
Where Privaata uses a hosted payment environment, payment-card details may be entered directly into the payment provider’s environment rather than Privaata.
We do not need or intend to collect customers’ full payment-card numbers or card security codes through ordinary Privaata account functionality where the payment provider handles those credentials.
5. How We Use Information
Kinfolk Technologies may use information, as appropriate to our role and the circumstances, to:
provide and operate Privaata;
create and administer accounts;
authenticate users;
maintain tenant separation;
manage user permissions;
maintain audit logs;
run customer-authorized integrations;
process privacy and compliance workflows;
generate reports;
provide AI-assisted functionality;
respond to support requests;
troubleshoot errors;
monitor system reliability;
protect Privaata and its users;
detect and prevent fraud, abuse and unauthorized access;
administer subscriptions and trials;
process and reconcile payments;
communicate service and security information;
send marketing communications where appropriate;
improve platform reliability and performance;
comply with applicable legal obligations;
establish, exercise or defend legal rights; and
otherwise provide functionality requested or authorized by customers.
6. Aggregated and De-identified Information
Kinfolk Technologies may generate and use aggregated or de-identified information for legitimate operational purposes, including understanding system reliability, feature usage, platform performance and general product trends.
We will take reasonable steps designed to ensure that information treated as de-identified is not used to identify a particular individual.
Customer workspace content will not be converted into a means of commercially exploiting identifiable customer information contrary to the commitments in this Policy or an applicable customer agreement.
7. AI-Assisted Processing
Privaata uses artificial intelligence to support privacy-management activities.
Depending on the functionality being used, AI may assist users by identifying or suggesting:
likely personal data categories;
potential privacy risks;
legal-basis questions;
retention issues;
DPIA screening concerns;
potential DSAR search locations;
incident-triage considerations;
vendor risks;
missing governance evidence;
possible compliance gaps;
recommended follow-up actions; and
other privacy-management observations.
AI functionality is intended to provide decision support.
AI-generated recommendations are not legal advice and should not automatically replace professional, legal, compliance or organizational judgment.
Privaata is designed so that users can review relevant evidence and, where applicable, modify, approve or reject AI-generated outputs before relying on them as official privacy records or decisions.
8. Customer Data and AI Model Training
Kinfolk Technologies does not use Customer Data to train general-purpose or public AI models.
Customer information submitted to or accessed by Privaata’s AI functionality is processed only as necessary to provide authorized Privaata functionality, operate and secure the service, and otherwise act in accordance with applicable customer instructions and agreements.
Where Kinfolk Technologies uses a third-party AI provider to support Privaata functionality, we seek to configure and manage that processing consistently with these commitments.
We may implement measures such as data minimization, limiting the contextual information transmitted to an AI provider, redaction where appropriate, access controls, tenant-level AI controls, model metadata and decision trails.
If Kinfolk Technologies were to introduce a programme under which identifiable Customer Data could be used for broader model-training purposes, such use would require an appropriate separate arrangement and would not be implied merely by using Privaata.
9. Human Oversight of AI
Privaata’s AI functionality is intended to assist rather than silently make consequential privacy decisions on behalf of customers.
Where appropriate to the workflow, Privaata may maintain information showing:
what information was considered;
what recommendation was generated;
relevant model or processing metadata;
confidence information where available;
whether a human reviewed the recommendation;
whether the recommendation was approved, modified or rejected; and
what final action was recorded.
Customers remain responsible for determining whether an AI-assisted recommendation is appropriate for their circumstances.
10. Third-Party Integrations
Customers may choose to connect Privaata to third-party systems.
These may include productivity platforms, document repositories, email systems, collaboration platforms, human-resource systems, cloud services or other business applications supported by Privaata.
When an integration uses OAuth or a similar authorization mechanism, the customer or authorized administrator may be redirected to the relevant third-party provider to review requested permissions and approve or reject access.
Privaata will use integration access only for authorized platform purposes, which may include:
privacy discovery;
evidence indexing;
data identification;
search;
workflow suggestions;
reporting;
DSAR support;
compliance monitoring; and
other functionality selected or authorized by the customer.
Customers are responsible for ensuring that they have appropriate authority to connect a system and authorize Privaata to process information available through that system.
11. Integration Credentials and Tokens
Where integrations require access tokens, refresh tokens, secrets or similar credentials, Privaata is designed to protect such credentials using appropriate security controls.
Integration credentials should be used only for the purposes associated with the authorized connection and permissions.
Customers may disconnect supported integrations through their workspace where that functionality is available.
Disconnecting an integration may prevent future synchronization or collection from that system but may not automatically delete information previously imported into or generated within Privaata.
12. Analytics
Privaata uses Cloudflare Analytics to help understand website or service usage, performance, reliability and related operational information.
Analytics information may include technical and usage information such as requests, approximate network or geographic information, browser or device characteristics and other information generated when users interact with Privaata.
Analytics information is used for purposes such as understanding service usage, maintaining reliability, troubleshooting, protecting the service and improving performance.
Analytics information is not used by Kinfolk Technologies to sell Customer Data or create third-party advertising profiles from Customer Data.
13. Marketing Communications
Kinfolk Technologies may send marketing or product communications concerning Privaata, including information about:
new features;
product improvements;
educational material;
events;
promotions; and
related Kinfolk Technologies offerings.
Where required, recipients will be provided with a mechanism to unsubscribe from marketing communications.
Opting out of marketing does not necessarily prevent Kinfolk Technologies from sending essential non-marketing communications, such as:
account notices;
security alerts;
billing communications;
subscription notices;
service announcements;
changes affecting contractual or legal terms; and
responses to support requests.
14. We Do Not Sell Personal Data
Kinfolk Technologies does not sell Customer Data or personal data collected through Privaata.
We do not provide Customer Data to third parties in exchange for money for their independent marketing or advertising purposes.
We also do not use Customer Data for targeted third-party advertising.
Sharing information with service providers acting on our behalf to provide Privaata is not treated by Kinfolk Technologies as a sale of Customer Data.
15. Service Providers and Subprocessors
Kinfolk Technologies relies on third-party service providers to operate Privaata.
Depending on the services and functionality being used, these providers may support areas such as:
cloud hosting;
databases;
authentication;
object storage;
email delivery;
monitoring;
analytics;
customer support;
AI processing;
security; and
payment processing.
These providers may process information only to the extent necessary to provide the applicable service, subject to appropriate arrangements and applicable law.
Kinfolk Technologies intends to maintain a separate Subprocessor List identifying relevant subprocessors and their purposes.
Where required by an applicable contract or law, customers may receive notice of material changes to subprocessors.
16. Payment Processing
Payment information may be processed through authorized payment service providers and financial institutions.
Where payment-card information is collected through a hosted payment environment operated by a payment provider, Kinfolk Technologies does not need to receive the customer’s complete card number or security code to administer the Privaata subscription.
Kinfolk Technologies may nevertheless receive and retain transaction-related information such as:
transaction identifiers;
order identifiers;
payment status;
amount;
currency;
card type or limited card information where provided;
authorization information;
billing status; and
recurring-payment or token references.
Such information may be used for billing, reconciliation, refunds, dispute management, fraud prevention and accounting.
17. Security
Kinfolk Technologies uses administrative, technical and organizational measures designed to protect Privaata and information processed through the service.
Privaata’s security architecture may include measures such as:
tenant separation;
role-based access controls;
authentication controls;
audit logging;
secure OAuth handling;
encryption and secure management of secrets;
rate limiting;
backup and restoration procedures;
least-privilege access;
monitoring;
security logging; and
human oversight of AI-assisted privacy decisions.
No online system can guarantee absolute security.
Customers also play an important role in protecting their information. Customers should assign roles carefully, periodically review authorized users, protect login credentials, use available multi-factor authentication or single sign-on capabilities where appropriate, disconnect integrations that are no longer needed and avoid uploading unnecessary sensitive information.
18. Data Hosting
Privaata production data is hosted using infrastructure located in United States data centres.
As a result, information provided to Privaata by customers in Jamaica or other countries may be transferred to, stored in or otherwise processed in the United States.
Additional service providers supporting Privaata may process information in other jurisdictions depending on their infrastructure and the services being provided.
19. International Data Transfers
Because Privaata may serve customers in Jamaica, the wider Caribbean and other jurisdictions while using infrastructure or service providers located elsewhere, use of Privaata may involve international transfers of personal data.
Where required by applicable law, Kinfolk Technologies will seek to implement appropriate mechanisms and safeguards for such transfers.
Depending on the applicable jurisdiction and circumstances, safeguards may include:
contractual protections;
processor agreements;
transfer-related contractual clauses;
assessments of service providers;
security measures;
data minimization; and
other legally recognized transfer mechanisms.
Enterprise arrangements may address additional data-transfer or data-residency requirements where supported by Privaata and agreed in writing.
20. Retention of Customer Data
Customer Data is ordinarily retained while the customer maintains an active Privaata service, subject to customer configuration, deletion instructions, contractual requirements and applicable law.
Following termination or expiration of a customer subscription, Customer Data will ordinarily remain available or recoverable for up to 30 days, unless:
the customer requests earlier deletion and it can reasonably and lawfully be completed;
a different period is established by contract;
applicable law requires longer retention;
preservation is necessary in connection with a legal claim, investigation or dispute; or
limited information must be retained for legitimate security, fraud-prevention or legal purposes.
After the applicable retention period, Customer Data will be deleted or rendered inaccessible from active production systems in accordance with our applicable deletion procedures.
21. Backups
Privaata may maintain backups for disaster recovery, resilience, security and business-continuity purposes.
Information deleted from active production systems may remain temporarily within backup systems until the relevant backup is overwritten, expires or is otherwise securely deleted in accordance with Kinfolk Technologies’ backup-retention procedures.
Backup copies are not intended to be restored for ordinary business use after a valid deletion merely to continue processing deleted Customer Data.
Before publication, Kinfolk Technologies will verify and document the specific backup-retention period applicable to Privaata.
22. Retention of Other Information
Not all information associated with an account is necessarily deleted when a subscription ends.
Kinfolk Technologies may retain limited information for legitimate purposes, including:
invoices;
payment and accounting records;
security logs;
fraud-prevention information;
audit records;
support correspondence;
contractual records;
evidence concerning disputes; and
information required by applicable law.
Such information will be retained only for as long as reasonably necessary for the applicable purpose or legally required retention period.
23. Export and Deletion
Where supported by Privaata, customers may export relevant records from their workspace.
Customers may also request deletion of their workspace or Customer Data in accordance with their agreement and applicable law.
Customers should export information they wish to retain before the applicable post-termination retention period expires.
Deletion of a workspace may not immediately remove information from disaster-recovery backups, financial records, security logs or records that Kinfolk Technologies is legally entitled or required to retain.
24. Account Deletion
Individuals may request deletion of their Privaata account by contacting:
privacy@kinfolktechnologies.com
Kinfolk Technologies may take reasonable steps to verify the requester’s identity before acting on a deletion request.
Deletion requests remain subject to information we must or are legitimately entitled to retain for purposes such as:
legal compliance;
accounting;
taxation;
fraud prevention;
security;
contractual enforcement; and
dispute resolution.
Where an individual account forms part of an organization-controlled workspace, certain workspace records may be controlled by that organization rather than the individual user.
25. Data Subject Rights
Depending on applicable law and the circumstances, individuals may have rights concerning their personal data, including rights to:
request access;
request correction;
request deletion or erasure;
object to certain processing;
request restriction of processing;
request information concerning processing;
withdraw consent where processing relies on consent;
request portability or export where applicable; and
make a complaint to an appropriate supervisory or regulatory authority.
The precise rights available depend on the applicable jurisdiction and circumstances.
26. Requests Concerning Customer Workspace Data
If an individual’s personal data appears within a Privaata customer’s workspace, the relevant customer organization will ordinarily be the appropriate organization to contact regarding a data subject rights request.
For example, if an employer uses Privaata to manage an employee’s personal data, the employee should ordinarily direct the request to the employer rather than Kinfolk Technologies.
Where Kinfolk Technologies acts as processor for that Customer Data, we will provide reasonable assistance to the customer as required by applicable law and our contractual obligations.
We will not ordinarily make the customer’s substantive legal decisions concerning that individual’s request.
27. Requests Concerning Kinfolk Technologies’ Own Processing
Individuals may contact Kinfolk Technologies directly concerning personal data that we process for our own purposes, including information associated with:
Privaata accounts;
website interactions;
support;
billing;
marketing;
security; and
Kinfolk Technologies’ own business administration.
Privacy requests may be sent to:
privacy@kinfolktechnologies.com
We may request information reasonably necessary to verify identity and locate the relevant records before fulfilling a request.
28. Jamaica Data Protection Law
Kinfolk Technologies Limited is based in Jamaica and recognizes its responsibilities under applicable Jamaican data protection law, including the Data Protection Act, 2020, where applicable to its processing activities.
Our approach to personal data is intended to reflect core data-protection principles, including appropriate consideration of:
lawful and fair processing;
purpose limitation;
data minimization;
accuracy;
retention;
security;
transparency; and
accountability.
Where another privacy or data-protection law applies to a particular customer, individual or processing activity, additional requirements and rights may apply.
29. International Customers
Privaata may be made available to organizations outside Jamaica.
The applicability of a particular privacy law depends on factors including the customer’s location, the individuals whose data is processed, the nature of the processing and the relevant law’s territorial scope.
Customers remain responsible for determining the laws applicable to their own processing activities and configuring and using Privaata appropriately.
Privaata’s privacy-management functionality does not itself guarantee that a customer’s organization is legally compliant.
30. Children
Privaata is a business-oriented privacy management platform and is not directed at children.
Individuals under the age of 18 should not independently create Privaata accounts.
This restriction does not necessarily mean that Customer Data can never contain information concerning children. A customer organization may, depending on its lawful activities, use Privaata to manage privacy records involving minors.
In such circumstances, the customer remains responsible for ensuring that it has an appropriate legal basis and safeguards for processing that information.
If Kinfolk Technologies becomes aware that a child has independently created an account contrary to this Policy, we may take appropriate steps to investigate and remove the account.
31. Legal Requirements and Protection of Rights
Kinfolk Technologies may process, preserve or disclose information where reasonably necessary to:
comply with applicable law;
comply with a valid legal process;
respond to lawful requests from competent authorities;
protect the security and integrity of Privaata;
investigate fraud, abuse or security incidents;
enforce applicable agreements;
protect the rights, property or safety of Kinfolk Technologies, customers or others; or
establish, exercise or defend legal claims.
Where appropriate and legally permitted, we will seek to limit disclosures to information reasonably necessary for the relevant purpose.
32. Business Transactions
If Kinfolk Technologies Limited undergoes a merger, acquisition, financing, restructuring, sale of assets or similar corporate transaction, information associated with Privaata may be disclosed or transferred as part of that transaction where lawful and appropriate.
Any recipient of personal data would remain subject to applicable data-protection requirements and any commitments that continue to apply to the information.
33. Cookies and Similar Technologies
Privaata and its website may use cookies, local storage and similar technologies where necessary for functionality such as:
authentication;
session management;
security;
user preferences;
performance; and
analytics.
Where required by applicable law, Privaata will provide appropriate information or choices concerning non-essential cookies and similar technologies.
Additional details may be provided in Privaata’s Cookie Policy.
34. Changes to this Privacy Policy
Kinfolk Technologies may update this Privacy Policy as Privaata evolves, including when:
functionality changes;
new integrations are introduced;
subprocessors change;
AI functionality changes;
infrastructure changes;
legal requirements change; or
our privacy practices otherwise materially change.
When this Policy is updated, we will revise the “Last Updated” date.
Where required by law or contract, we will provide reasonable additional notice before material changes take effect.
35. Contact Us
Questions about this Privacy Policy or Kinfolk Technologies’ privacy practices may be directed to:
Kinfolk Technologies LimitedPrivaata18 Geranium PathMona HeightsKingston 6Jamaica
Privacy Email: privacy@kinfolktechnologies.comTelephone: (876) 298-4018
Individuals seeking to exercise applicable privacy rights concerning information for which Kinfolk Technologies is responsible may contact us using the privacy email above.
Requests concerning personal data controlled by a Privaata customer should ordinarily be directed to that customer organization.