1. Data Controller
The data controller under this privacy policy is Kontextio.
You may submit all requests regarding your personal data through the following contact channels:
- Email: info@kontextio.com
- Website: kontextio.com
2. Scope of This Policy
This policy applies when you:
- Visit the kontextio.com website
- Complete early access, demo, or contact forms
- Subscribe to or use Kontextio services
- Contact us by email, support channels, or other communication methods
Kontextio may also act as a data processor on behalf of enterprise customers when providing its AI access and security platform. In that case, processing activities are governed by the data processing agreement (DPA) signed with the customer and applicable law.
3. Personal Data We Collect
The personal data we collect depends on how you use our services.
3.1. Website Visitors
- IP address, browser type and version, operating system
- Pages visited, session duration, and referral source
- Device information and approximate geographic location (city/country level)
- Usage data collected through cookies and similar technologies
3.2. Early Access and Contact Forms
- First and last name (if provided)
- Corporate email address
- Company or organization name and job title (if provided)
- Message or request content submitted through the form
3.3. Platform Users (During Service Use)
- Account information (name, email, organization details)
- Authentication and session records
- Roles and access permissions
- Platform usage logs and audit records
- Support requests and correspondence history
Kontextio processes enterprise data connected by customer organizations only to deliver the service and in accordance with customer instructions. Ownership of that data remains with the customer.
4. Purposes of Processing
We process your personal data for the following purposes:
- Operating, securing, and improving website performance
- Receiving, evaluating, and responding to early access requests
- Providing, managing, and supporting the Kontextio platform
- Running authentication, authorization, and access control processes
- Ensuring compliance with GDPR and applicable regulations
- Measuring service quality and improving user experience
- Detecting, preventing, and responding to security incidents
- Fulfilling legal obligations and handling legal proceedings
- Marketing and informational communication where you have given consent
5. Legal Basis
Under GDPR Articles 6 and 9, we process personal data on the following legal bases:
- Contract performance: Fulfilling your service request and platform use
- Legal obligation: Retention and reporting duties required by law
- Legitimate interests: Security, fraud prevention, and service improvement activities
- Consent: Marketing communications and non-essential cookies
6. Sharing and International Transfers
We do not sell, rent, or commercially transfer your personal data to third parties.
Your data may be shared only in the following circumstances:
- Service providers: Hosting, email delivery, analytics, and security vendors acting as processors under confidentiality obligations
- Legal requirements: Courts, regulators, or public authorities when required by law
- Corporate transactions: Mergers, acquisitions, or asset transfers, subject to legal requirements and appropriate notice
When personal data is transferred outside the European Economic Area, we implement appropriate safeguards such as Standard Contractual Clauses, adequacy decisions, or other mechanisms permitted under GDPR Chapter V.
7. Data Security
We apply the following technical and organizational measures to protect personal data:
- TLS/SSL encryption for data in transit
- Access control, role-based authorization, and multi-factor authentication options
- Audit logs and anomaly detection
- Regular security assessments and updates
- Employee privacy and security awareness training
- Data minimization and retention limited to what is necessary
No system is 100% secure, but we are committed to protecting your data using industry-standard measures.
8. Retention Periods
We retain personal data only for as long as necessary for the processing purpose and applicable legal retention requirements:
- Early access records: Up to 2 years after the request is closed, or until deletion is requested
- Platform account data: For the duration of service and applicable post-contract retention periods
- Website logs: Generally 12 months for security purposes
- Support correspondence: 3 years after the request is resolved
When retention periods expire, data is securely deleted, destroyed, or anonymized.
9. Cookies and Similar Technologies
Our website may use cookies for essential functionality, security, and — with your consent — analytics purposes.
Cookie types may include:
- Strictly necessary cookies: Required for the site to function
- Performance cookies: Anonymous analysis of visitor behavior
- Preference cookies: Remembering language and display preferences
You can manage or disable cookies through your browser settings. Disabling essential cookies may affect some site functionality.
10. Your Rights Under GDPR
Depending on your location, you may have the following rights:
- Right of access to your personal data
- Right to rectification of inaccurate or incomplete data
- Right to erasure in certain circumstances
- Right to restriction of processing
- Right to data portability
- Right to object to processing based on legitimate interests
- Right to withdraw consent at any time where processing is consent-based
- Right not to be subject to solely automated decision-making with legal or similarly significant effects
To exercise your rights, contact info@kontextio.com with information sufficient to verify your identity. We respond within one month, unless an extension is permitted under GDPR. You also have the right to lodge a complaint with your local supervisory authority.
11. Children's Privacy
Kontextio services are not directed at individuals under 18, and we do not knowingly collect personal data from children. If we become aware that data from a person under 18 has been collected, we will delete it promptly.
12. Changes to This Policy
We may update this privacy policy from time to time. When material changes are made, we will publish the updated policy on this page and, where appropriate, notify registered users by email. The current version is always available on this page.
13. Contact
For questions about this privacy policy or how your personal data is processed, contact us at info@kontextio.com.