Privacy Policy

Pilot / Early-Access Version For Kairos Compliance Engine

Last Updated: January 2, 2026

1. Introduction

This Privacy Policy explains how Kairos Automata LLC (“Company,” “We,” “Us”) collects, uses, stores, and protects information within the Kairos Compliance Engine (“Service”).

By using the Service, you agree to this Policy.

2. Information We Collect

2.1. Account Information

We may collect:

  • Name
  • Email address
  • Organization name
  • Billing information

2.2. De-Identified Note Content

Users may submit de-identified clinical notes to generate outputs.

We do not store, use, or process PHI. Any submission containing PHI violates our Terms.

2.3. Usage Data

We collect usage analytics such as:

  • Number of processed notes
  • Timestamps of use
  • Feature usage
  • Interaction logs
  • Device/browser info

This helps us improve reliability and performance.

2.4. Cookies & Technical Data

We may use cookies or similar technologies for:

  • Authentication
  • Session management
  • Website performance

3. How We Use Information

We use information to:

  • Operate and improve the Service
  • Generate automated outputs
  • Maintain security
  • Troubleshoot issues
  • Analyze usage trends
  • Provide support
  • Process payments

We do not sell your data.

We do not use your data for advertising.

4. Data Security

We implement commercially reasonable safeguards to protect your data, including:

  • Encrypted storage
  • Encrypted communication (HTTPS)
  • Role-based access control
  • Limited access to internal systems

No system is 100% secure; users submit data at their own risk.

5. Data Retention

We may retain:

  • Account information while your account is active
  • Usage logs for operational and safety purposes
  • De-identified note content only when necessary to improve or debug the Service

You may request deletion at any time.

6. Third-Party Service Providers

We may use third-party vendors such as:

  • Hosting services
  • Database providers
  • Logging/analytics tools
  • Payment processors
  • AI model providers (e.g., OpenAI for de-identified text only)

These vendors may process your data solely to operate the Service.

We do not allow vendors to use your data for independent purposes.

7. No PHI Policy

We do not accept PHI and do not operate as a HIPAA Business Associate unless a separate written BAA is signed.

Any PHI submitted by the User is a violation of the Terms and may result in account termination.

8. User Rights

Users may:

  • Request access to stored data
  • Request deletion of de-identified content
  • Update account information
  • Request closure of their account

Contact us at austinzdarnold@gmail.com.

9. Children’s Privacy

The Service is not intended for individuals under 18.

10. Changes to Privacy Policy

We may update this Policy. Continued use constitutes acceptance.

11. Contact

Kairos Automata LLC austinzdarnold@gmail.com