Legal center

Privaata legal policy

Privaata Terms of Service

The rules for using Privaata, including subscriptions, workspace responsibilities, AI review, security, exports, and support.

Source document: Privaata Terms of Service.docx

Privaata Terms of Service

Effective Date: September 1, 2026 Last Updated: September 1, 2026

These Terms of Service (“Terms”) govern access to and use of Privaata, a privacy management software-as-a-service platform operated by Kinfolk Technologies Limited (“Kinfolk Technologies,” “we,” “us,” or “our”).

By creating a Privaata account, starting a trial, purchasing a subscription, accessing a Privaata workspace, or otherwise using the service, you agree to these Terms.

If you use Privaata on behalf of a company, institution, government entity, nonprofit organization, church, association or other organization (“Customer”), you represent that you have authority to accept these Terms on that organization’s behalf. In that case, references to “you” or “Customer” include that organization where appropriate.

If you do not agree to these Terms, you must not use Privaata.

1. About Privaata

Privaata is privacy management software designed to help organizations manage privacy and data-protection activities, including:

Records of Processing Activities (“RoPAs”);

Data Protection Impact Assessments (“DPIAs”);

data subject access requests and other data subject rights requests (“DSARs”);

privacy incidents and breaches;

vendors and processors;

policies and governance records;

privacy training;

evidence and audit records;

data mapping;

system integrations;

AI-assisted recommendations;

reporting;

compliance workflows; and

regulatory readiness.

Features may vary according to the Customer’s subscription plan, configuration, jurisdiction, usage allowances and any separately agreed order or enterprise agreement.

2. Business and Professional Use

Privaata is primarily a business-to-business service.

It is intended for organizations and individuals using the service in a professional, organizational or business capacity. Privaata is not intended primarily as a consumer privacy application for personal or household use.

A Customer may authorize employees, contractors, advisers and other appropriate personnel to use its workspace in accordance with these Terms.

3. Eligibility and Minimum Age

You must be at least 18 years old to independently create a Privaata account.

By creating an account, you represent that you satisfy this requirement and have legal capacity to enter into these Terms.

4. Authority to Act for an Organization

If you create, configure, purchase or administer a Privaata workspace on behalf of an organization, you represent that you are authorized to do so.

The Customer is responsible for maintaining accurate information concerning its:

organization profile;

legal entities;

jurisdiction settings;

billing contacts;

authorized users;

user roles and permissions; and

integration approvals.

Kinfolk Technologies may reasonably rely on instructions provided by authorized Customer administrators.

5. Accounts, Users and Workspaces

Each Customer receives access to one or more Privaata workspaces according to its subscription and configuration.

Workspace administrators control who is authorized to access the workspace and what those users may do.

Customers are responsible for:

inviting appropriate users;

removing users who should no longer have access;

assigning appropriate roles;

reviewing access periodically;

maintaining accurate account information; and

supervising use of the workspace by authorized users.

Actions taken through an authorized Customer account may be treated as actions of the Customer, subject to applicable law and security considerations.

6. Account Security

Each individual user must use their own account.

Users must not knowingly share passwords or other individual authentication credentials in a manner that allows another person to impersonate them or bypass Privaata’s user controls.

Customers and users are responsible for taking reasonable measures to protect their accounts and credentials.

Users should promptly notify their workspace administrator and Kinfolk Technologies if they reasonably suspect:

unauthorized access;

compromised credentials;

account takeover;

suspicious activity; or

another security incident involving their Privaata account.

Where multi-factor authentication, single sign-on or other enhanced authentication features are available, Customers should use them where appropriate to their risk environment.

7. Subscription Plans

Privaata may offer different subscription plans.

Plans may differ according to matters such as:

features;

modules;

number of users;

number of legal entities;

integrations;

storage;

AI usage;

automation allowances;

support levels;

reporting functionality; and

other usage limits.

The features and limits applicable to a Customer will ordinarily be displayed during purchase, within Privaata, in an order form, or in a separately negotiated agreement.

8. Free Trials

Eligible Customers may receive a seven-day free trial.

A valid payment method is required to begin the trial.

Unless the Customer cancels before the trial expires, the trial will automatically convert to the selected paid monthly or annual subscription and the applicable payment method will be charged.

The applicable price, billing frequency and automatic conversion should be disclosed before the Customer starts the trial.

Kinfolk Technologies may restrict, suspend or terminate trial access where reasonably necessary to prevent fraud, abuse, security threats or misuse.

9. Subscription Billing and Automatic Renewal

Privaata offers monthly and annual subscriptions.

Unless otherwise stated:

subscriptions are billed in advance;

monthly subscriptions renew monthly;

annual subscriptions renew annually; and

subscriptions automatically renew until cancelled.

By purchasing a recurring subscription, the Customer authorizes Kinfolk Technologies and its authorized payment providers to process recurring charges associated with the subscription.

Applicable taxes may be added where required.

10. Cancellation and Refunds

Customers may cancel a subscription at any time.

Cancellation ordinarily prevents the next renewal rather than immediately terminating the already-paid subscription period.

Unless otherwise provided by law or written agreement, Customers ordinarily retain access through the end of their current paid subscription period.

Privaata does not provide a general money-back guarantee, and unused portions of paid subscription periods are ordinarily not prorated.

Refunds, accidental renewals, billing errors, duplicate transactions, service outages and related matters are governed by the separate Privaata Refund & Cancellation Policy, which forms part of the contractual terms applicable to subscriptions.

11. Upgrades and Downgrades

Where supported, Customers may change subscription plans.

An upgrade may take effect immediately and may result in an appropriate prorated charge for the remainder of the current billing period.

A downgrade will generally take effect at the next renewal date unless otherwise stated.

Downgrading may result in the loss or restriction of features, usage allowances, integrations, AI capacity, storage or other functionality.

Customers are responsible for reviewing the consequences of a downgrade before confirming it.

12. Payment Processing

Payments may be processed by authorized third-party payment providers, acquiring banks and payment networks.

Where a hosted payment environment is used, Customers may enter payment-card information directly into the payment provider’s environment.

Kinfolk Technologies may receive transaction information necessary to administer subscriptions without receiving or storing the complete payment-card number or card security code.

Use of third-party payment services may also be subject to applicable terms imposed by those providers.

13. Customer Data

“Customer Data” means information, records, documents, files, evidence, metadata, personal data and other content that a Customer enters, uploads, connects, scans, imports, generates, approves, stores or otherwise processes through its Privaata workspace.

Customers retain ownership of their Customer Data.

Using Privaata does not transfer ownership of Customer Data to Kinfolk Technologies.

14. Limited Rights Necessary to Provide Privaata

The Customer grants Kinfolk Technologies a limited, non-exclusive right to host, copy, transmit, process, analyze, display and otherwise handle Customer Data only as reasonably necessary to:

provide Privaata;

perform Customer-authorized functions;

operate integrations;

provide AI-assisted functionality;

generate Customer-requested reports and workflows;

maintain and secure the service;

provide support;

comply with lawful Customer instructions;

meet applicable legal obligations; and

exercise rights permitted under these Terms and applicable agreements.

This permission exists only to the extent reasonably necessary for those purposes and does not transfer ownership of Customer Data.

15. Customer Responsibility for Data

Customers are responsible for the Customer Data they place in or make accessible to Privaata.

The Customer represents that it has the rights, authority, permissions and, where required, appropriate legal basis necessary to:

collect the relevant information;

place it in Privaata;

authorize Privaata to process it;

connect relevant third-party systems;

permit authorized users to access it; and

instruct Kinfolk Technologies to process it as contemplated by the service.

Customers must not knowingly use Privaata to process information they have no lawful authority to process.

16. Data Protection Roles

Where Kinfolk Technologies processes personal data contained within Customer Data solely to provide Privaata according to the Customer’s instructions, Kinfolk Technologies will generally act as a processor or service provider, while the Customer will generally act as the controller or equivalent responsible organization, unless applicable law or a written agreement provides otherwise.

Where appropriate, these responsibilities may be further governed by a separate Data Processing Agreement (“DPA”).

Kinfolk Technologies may separately act as controller for personal data it processes for its own legitimate business purposes, including account administration, billing, security, support and its own business communications.

17. AI-Assisted Features

Privaata may use artificial intelligence to support privacy-management activities.

AI functionality may, for example, suggest:

privacy risks;

potential RoPA fields;

personal data classifications;

DPIA screening considerations;

DSAR actions or search locations;

retention concerns;

vendor risks;

breach or incident triage considerations;

governance gaps;

recommended actions; and

other compliance observations.

These outputs are designed to assist users rather than replace qualified human judgment.

18. AI Outputs Are Not Legal Advice

Privaata’s AI-generated recommendations and other automated outputs are not legal advice.

Kinfolk Technologies is a technology provider and is not acting as the Customer’s law firm merely by providing Privaata.

AI systems can produce information that is inaccurate, incomplete, outdated, ambiguous or inappropriate for a particular circumstance.

Customers must exercise appropriate professional judgment and should review relevant evidence before relying on an AI-generated recommendation.

Where appropriate, a qualified human should accept, modify or reject the recommendation before it becomes part of an official privacy or compliance decision.

19. No Guarantee of Legal Compliance

Privaata is designed to help organizations organize, automate and improve privacy-management activities.

However, using Privaata does not itself guarantee compliance with any law or regulatory requirement, including Jamaica’s Data Protection Act, the GDPR or other privacy, cybersecurity, employment, sectoral or data-protection laws.

Legal compliance depends on factors outside Kinfolk Technologies’ control, including:

Customer conduct;

organizational policies;

actual processing activities;

jurisdiction;

legal interpretation;

configuration;

accuracy of Customer Data;

implementation of recommendations; and

changes in law.

Customers remain responsible for their legal conclusions and compliance decisions.

Customers should obtain qualified legal advice for important regulatory submissions, contracts, incidents, breach notifications or other matters requiring legal interpretation.

20. AI and Customer Data

Kinfolk Technologies will not use Customer Data to train general-purpose or public AI models merely because the Customer uses Privaata.

Where third-party AI providers support Privaata functionality, Kinfolk Technologies may transmit information reasonably necessary to perform the authorized function, subject to applicable safeguards, agreements and the Privaata Privacy Policy.

21. Integrations

Customers may connect Privaata to supported third-party systems, including productivity suites, email systems, document repositories and other business applications.

By connecting a system, the Customer authorizes Privaata to request and use approved permissions for supported purposes, which may include:

privacy discovery;

evidence indexing;

data identification;

workflow generation;

DSAR support;

reporting;

compliance monitoring; and

related privacy-management operations.

The Customer is responsible for ensuring that the person authorizing an integration has authority to grant the relevant access.

22. Third-Party Services

Third-party services integrated with Privaata are operated by third parties.

Kinfolk Technologies does not control those providers and cannot guarantee that a third-party integration will remain available indefinitely or continue operating in exactly the same manner.

A third-party provider may:

modify its API;

modify permissions;

impose usage restrictions;

change pricing;

discontinue functionality;

suspend Customer access; or

discontinue its service.

Kinfolk Technologies may modify or discontinue an integration where reasonably necessary because of third-party changes, security concerns, legal requirements or technical limitations.

23. Acceptable Use

Customers and users must not use Privaata to:

violate applicable law;

infringe another person’s rights;

process personal data without appropriate authority;

gain unauthorized access to systems or information;

upload or distribute malware or malicious code;

interfere with Privaata’s security or operation;

bypass access controls;

circumvent subscription or usage restrictions;

conduct unauthorized scraping;

perform unauthorized vulnerability testing or attacks;

overwhelm the service with abusive automated requests;

impersonate another person;

misrepresent authority;

harass, threaten or harm another person;

conceal or falsify material privacy or compliance evidence;

deliberately misuse AI functionality;

facilitate fraudulent activity; or

use Privaata to violate another person’s privacy or data-protection rights.

Additional requirements may be contained in a separate Acceptable Use Policy.

24. Restrictions on the Software

Except where applicable law expressly prevents such restrictions, Customers must not:

copy Privaata except as permitted through normal use;

reproduce substantial proprietary portions of the platform;

modify or create unauthorized derivative versions;

reverse engineer, decompile or disassemble Privaata;

attempt to discover proprietary source code;

circumvent technical restrictions;

resell or sublicense access without authorization;

remove proprietary notices; or

use Kinfolk Technologies’ intellectual property outside the rights granted under these Terms.

Nothing in this section restricts rights that cannot lawfully be restricted.

25. Security Responsibilities

Kinfolk Technologies will maintain reasonable technical and organizational safeguards appropriate to the nature of the service.

Customers are responsible for reasonable security practices within their control, including:

assigning roles appropriately;

periodically reviewing access;

protecting credentials;

using SSO or MFA where available and appropriate;

promptly removing former users;

avoiding unnecessary sensitive-data uploads;

managing connected systems appropriately; and

reporting suspected unauthorized access promptly.

No online service can guarantee absolute security.

26. Support Access

Where Kinfolk Technologies personnel require access to Customer systems or Customer Data to provide technical support or investigate a security issue, access should be limited to what is reasonably necessary for the relevant purpose.

Kinfolk Technologies may implement controlled support procedures involving authorization, restricted privileges, logging and time-limited access where appropriate.

Support personnel must not use Customer Data accessed through support processes for unrelated purposes.

27. Audit Logs and Records

Privaata may maintain audit records concerning activity performed within the platform.

Audit records may assist Customers with governance, accountability, security investigations and regulatory readiness.

Customers remain responsible for determining which records they are legally or operationally required to retain and for how long.

28. Export, Backup and Retention

Privaata may provide export, backup, audit-log, restoration or related functionality.

Customers should maintain appropriate exports of information that is critical to their organization where necessary.

Following termination or expiration of a subscription, Customer Data will ordinarily be retained for up to 30 days, subject to applicable law, contractual requirements, backup-retention processes and the Privaata Privacy Policy.

Customers should export information they wish to retain before applicable deletion periods expire.

29. Intellectual Property

Privaata and its underlying intellectual property are owned by Kinfolk Technologies Limited or its licensors.

This includes, as applicable:

software;

source code;

object code;

interfaces;

designs;

branding;

trademarks;

logos;

workflows;

templates;

documentation;

product materials;

proprietary methodologies; and

other platform intellectual property.

Except for the limited right to use Privaata under these Terms, no ownership rights in Privaata are transferred to the Customer.

Customers retain ownership of their Customer Data.

30. Feedback

If a Customer voluntarily provides ideas, suggestions or feedback about improving Privaata, Kinfolk Technologies may use that feedback to develop and improve the service without owing compensation, provided doing so does not transfer ownership of the Customer’s Customer Data or confidential information.

31. Service Availability

Kinfolk Technologies will use commercially reasonable efforts to operate Privaata reliably.

However, Privaata may occasionally be unavailable because of:

planned maintenance;

emergency maintenance;

software updates;

infrastructure failures;

third-party provider failures;

internet or network problems;

cybersecurity incidents;

events outside Kinfolk Technologies’ reasonable control; or

other technical circumstances.

Standard subscriptions do not include a guarantee of 100% uptime.

Separate enterprise agreements may establish specific service-level commitments.

32. Changes to the Service

Kinfolk Technologies may improve, modify, replace or discontinue features as Privaata evolves.

Where a change materially reduces core paid functionality, Kinfolk Technologies will seek to provide reasonable notice where practicable and appropriate.

Changes may sometimes be required without advance notice for security, legal, regulatory or urgent technical reasons.

33. Suspension

Kinfolk Technologies may suspend or restrict access where reasonably necessary because of:

unpaid fees;

fraud;

unlawful activity;

material breach of these Terms;

abuse of the service;

serious security risk;

compromised accounts;

threats to other Customers or Privaata infrastructure;

legal or regulatory requirements; or

activity reasonably believed to create substantial risk.

Where reasonably practicable, Kinfolk Technologies will provide notice and an opportunity to resolve the issue.

Immediate suspension may occur where urgent action is reasonably necessary to protect the service, Customers, third parties or Kinfolk Technologies, or to comply with law.

34. Termination by the Customer

Customers may cancel their subscription according to the Privaata Refund & Cancellation Policy.

Cancellation ordinarily takes effect at the end of the current paid subscription period.

The Customer should export necessary Customer Data before its applicable access and retention periods expire.

35. Termination by Kinfolk Technologies

Kinfolk Technologies may terminate a Customer’s access for a material breach of these Terms.

Where the breach can reasonably be corrected, Kinfolk Technologies will ordinarily provide notice and a reasonable opportunity to remedy it before termination.

Kinfolk Technologies may terminate or take immediate protective action without a cure period where reasonably necessary because of:

fraud;

serious unlawful activity;

deliberate security attacks;

severe abuse;

material threats to Privaata or other Customers; or

circumstances where continued service would itself violate applicable law.

36. Effect of Termination

Upon termination:

the Customer’s right to use Privaata ends at the applicable termination time;

integrations may stop synchronizing;

authorized users may lose access;

unpaid amounts properly due remain payable;

Customer Data enters the applicable retention and deletion process; and

provisions intended by their nature to survive termination will continue to apply.

Where practical and lawful, Customers should be provided a reasonable opportunity to export appropriate Customer Data before final deletion.

37. Disclaimers

To the extent permitted by applicable law, Privaata is provided on an “as available” basis.

Kinfolk Technologies does not warrant that:

the service will be uninterrupted or error-free;

every defect will be corrected immediately;

every third-party integration will remain available;

AI outputs will always be accurate;

Privaata will identify every privacy or compliance issue; or

using Privaata will guarantee regulatory compliance.

Nothing in these Terms excludes warranties or rights that applicable law does not permit the parties to exclude.

38. Limitation of Liability

To the maximum extent permitted by applicable law, Kinfolk Technologies Limited’s aggregate liability arising out of or relating to Privaata, these Terms or the applicable subscription will generally not exceed the fees paid or payable by the affected Customer for Privaata during the twelve (12) months immediately preceding the event giving rise to the claim.

Where the Customer has used Privaata for less than twelve months, the relevant amount will be the fees paid or payable during that shorter period.

To the extent permitted by applicable law, Kinfolk Technologies will not be liable for indirect, incidental, special, exemplary, punitive or consequential losses, or for loss of profits, revenue, goodwill or business opportunities, arising from use of Privaata.

These limitations do not apply to liability that applicable law prohibits Kinfolk Technologies from excluding or limiting.

39. Customer Responsibility for Consequential Decisions

Customers remain responsible for decisions they make using information obtained through Privaata.

This includes decisions concerning:

regulatory notifications;

breach reporting;

responses to data subjects;

legal bases;

retention;

employment matters;

vendor decisions;

international transfers;

DPIAs;

compliance conclusions; and

implementation of AI-generated recommendations.

Privaata provides technology and decision support; it does not assume the Customer’s statutory responsibilities merely because the Customer uses the platform.

40. Indemnification

To the extent permitted by applicable law, the Customer agrees to indemnify and hold harmless Kinfolk Technologies Limited from third-party claims, losses, liabilities and reasonable costs arising from:

Customer Data that the Customer had no right or authority to process through Privaata;

unlawful use of the service;

the Customer’s material breach of these Terms; or

infringement of a third party’s rights through content or activity controlled by the Customer.

This provision does not require the Customer to indemnify Kinfolk Technologies for losses caused by Kinfolk Technologies’ own conduct where such indemnification would be prohibited by law.

41. Confidentiality

Each party may receive non-public information belonging to the other in connection with the service.

Each party should use reasonable measures to protect confidential information and use it only for purposes connected with the relationship, except where disclosure is:

authorized;

required by law;

necessary to professional advisers subject to confidentiality obligations; or

otherwise permitted by an applicable written agreement.

More detailed confidentiality provisions may be contained in enterprise agreements or a DPA.

42. Changes to These Terms

Kinfolk Technologies may update these Terms as Privaata, applicable laws or our business practices evolve.

The “Last Updated” date will identify the latest version.

Where a change materially affects Customers’ contractual rights, Kinfolk Technologies will provide reasonable notice where required by applicable law or agreement.

Changes will not be applied retroactively where doing so would be unlawful.

43. Enterprise and Negotiated Agreements

Enterprise Customers may enter into separate written agreements with Kinfolk Technologies.

Those agreements may contain different provisions concerning:

pricing;

minimum commitments;

payment;

renewals;

service levels;

support;

security;

data protection;

retention;

liability;

indemnification;

termination; and

other commercial terms.

Where a valid signed agreement expressly conflicts with these standard Terms, the signed agreement governs the conflict.

44. Governing Law

These Terms and the relationship between the Customer and Kinfolk Technologies Limited are governed by the laws of Jamaica, without regard to conflict-of-law principles, except where mandatory applicable law requires otherwise.

45. Disputes and Jurisdiction

The parties should first attempt in good faith to resolve disputes arising from Privaata through reasonable business discussions.

If a dispute cannot be resolved, it will ordinarily be subject to the jurisdiction of the competent courts of Jamaica, unless a separate written agreement provides another lawful dispute-resolution procedure or mandatory applicable law requires otherwise.

46. Force Majeure

Neither party will be responsible for delay or failure to perform obligations caused by circumstances beyond its reasonable control, except that this does not excuse payment obligations already properly due.

Such circumstances may include natural disasters, widespread telecommunications failures, major infrastructure outages, war, civil unrest, governmental actions, labour disruptions, epidemics, cyberattacks of extraordinary scope or failures of critical third-party infrastructure outside reasonable control.

47. Assignment

Customers may not assign or transfer their rights or obligations under these Terms without Kinfolk Technologies’ prior written consent, except where applicable law provides otherwise.

Kinfolk Technologies may assign these Terms in connection with a merger, corporate reorganization, financing, acquisition or sale of substantially all relevant business or assets, subject to applicable law and continuing data-protection obligations.

48. Severability

If any provision of these Terms is found invalid or unenforceable, the remaining provisions will continue in effect to the extent permitted by law.

The invalid provision should be interpreted or modified, where legally permissible, to most closely reflect its intended lawful effect.

49. No Waiver

Failure by either party to enforce a provision of these Terms on one occasion does not necessarily waive the right to enforce that provision later.

50. Entire Agreement

These Terms, together with applicable incorporated policies, order forms, DPAs and other written agreements expressly governing the Customer’s use of Privaata, constitute the agreement concerning the matters they address.

Applicable documents may include:

the Privaata Privacy Policy;

the Privaata Refund & Cancellation Policy;

the Privaata Acceptable Use Policy;

the Privaata Subscription & Billing Policy;

an applicable Data Processing Agreement; and

an applicable enterprise order or agreement.

Where documents conflict, a separately executed agreement may specify the applicable order of precedence.

51. Contact Information

Questions concerning these Terms may be directed to:

Kinfolk Technologies LimitedPrivaata18 Geranium PathMona HeightsKingston 6Jamaica

Telephone: (876) 298-4018

For privacy matters:privacy@kinfolktechnologies.com

For billing matters:billing@kinfolktechnologies.com