Privacy Policy

Last updated: 12 September 2025

1. Introduction and Key Information

1.1 About This Policy

This Privacy Policy explains how Kai Technology Labs Ltd ("Kai", "we", "us", or "our") collects, uses, shares, and protects your personal information when you use our intelligent task management service ("Service") available at https://hellok.ai and related applications.

We are committed to protecting your privacy and handling your data transparently in accordance with the UK General Data Protection Regulation (UK GDPR) and other applicable data protection laws. We implement Privacy by Design principles, ensuring data protection is built into our systems from the ground up.

We will only disclose user data in response to a valid and legally binding request, and we will notify the user unless prohibited by law.

1.2 Policy at a Glance

The following has been provided for quick reference only and does not replace the full Privacy Policy. Please read the full policy for complete details.

  • We never use your content (emails, messages) to train AI models.
  • We only collect the data we need to make Kai work.
  • You control your integrations and can disconnect them at any time.
  • We prioritize using data centers located in the EU.
  • You have full rights to access, amend, or delete your data.

1.3 ICO Registration

We are registered with the ICO as a data controller under number ZB982461. You can verify our registration on the ICO public register.

1.4 Data Protection Officer

We have not appointed a formal Data Protection Officer (DPO) as we do not engage in large-scale systematic monitoring or process special category data as a core activity. However, our data protection lead can be contacted at support@hellok.ai for any privacy-related queries.

1.5 Data Controller Information

Company Name: Kai Technology Labs Ltd
Company Registration Number: 16618112
Registered in: England and Wales
Registered Office: 85 Great Portland Street, First Floor, London, England, W1W 7LT
Contact Email: support@hellok.ai
Website: https://hellok.ai

For privacy-related inquiries, please contact us at support@hellok.ai.

2. Information We Collect

2.1 Data Minimization Principle

We only collect data that is necessary for providing our Service. Here's why we need each type:

Data Type Purpose Necessity
Email Address Account creation, authentication, communication Essential for service
Name Personalization, support Required for user identification
Integration Data Task creation from emails/messages Core service functionality
Usage Analytics Service improvement, debugging Legitimate business need
Payment Information Subscription processing Required for paid features

2.2 Special Category Data

Consumer Accounts. For individual consumer accounts, Kai acts as the controller only of your own account data. You must not use the Service to process special category data belonging to third parties. If such data is ingested incidentally, it is processed solely under your instructions, for the purpose of delivering the Service you requested. You are responsible for obtaining any necessary consents from third parties.

2.3 Account Information

When you create an account, we collect:

  • Email address (required)
  • First and last name (required)
  • Authentication credentials (OAuth tokens, Passkeys, or Magic Link tokens)

2.4 Integration Data

When you connect third-party services, we process:

  • Gmail Integration: Email content, metadata, sender information, attachments
  • Slack Integration: Messages, channel information, sender details
  • Connected account identifiers and OAuth tokens

2.5 Usage and Analytics Data

We automatically collect:

  • Service usage patterns and feature interactions
  • Task creation and management data
  • IP address and device information
  • Browser type and operating system
  • Session recordings (only with explicit opt-in consent)
  • Performance metrics and error reports

2.6 Payment Information

For paid subscriptions, we collect:

  • Billing name and address
  • Payment method details (processed by Stripe)
  • Transaction history and subscription status

2.7 Support and Communication Data

When you contact us:

  • Support ticket content and metadata
  • Email communications
  • Feedback and survey responses

2.8 Cookies and Tracking Technologies

Please refer to our Cookie Policy for detailed information on cookies we use and how to manage your preferences.

3. Legal Basis for Processing

3.1 Legal Basis Mapping

We process your data under specific legal bases:

Processing Activity Data Categories Legal Basis Explanation
Account Creation Email, Name Contract Necessary to provide service
Authentication OAuth tokens, Passkeys Contract Required for secure access
Gmail/Slack Processing Messages, Emails Contract Explicit opt-in when connecting
AI Task Creation Communication content Contract Part of integration consent
Payment Processing Billing information Contract Required for subscriptions
Service Analytics Usage data Legitimate Interests Improving service quality
Security Monitoring IP, Device info Legitimate Interests Preventing fraud and abuse
Marketing Emails Email address Consent Explicit opt-in required
Session Recording User interactions Consent Explicit opt-in required
Support Tickets Communication data Contract Providing customer support

We process your personal data based on the following legal grounds:

3.2 Contract Performance

We process personal data where it is necessary to perform our contract with you. This includes:

  • Creating and managing your account
  • Providing the core features of the Service (such as task extraction, summaries, and prioritization)
  • Processing subscription payments
  • Delivering customer support

3.3 Consent

We rely on your consent for processing that is not strictly necessary for the Service. This includes:

  • Sending marketing communications
  • Enabling session recording and replay
  • Tracking email opens and clicks

You may withdraw consent at any time by updating your preferences, disconnecting integrations, or using the unsubscribe links provided.

3.4 Legitimate Interests

We process some data where it is necessary for our legitimate interests, provided these are not overridden by your rights and interests. This includes:

  • Basic product analytics to improve usability and features
  • Security monitoring and fraud prevention
  • Service performance monitoring and debugging

3.5 Special Category Data

If you choose to connect integrations (such as Gmail or Slack), messages may contain special category data under UK GDPR. We will only process such data with your explicit consent at the point of connection, and solely to provide the Service.

For business customers, your organization is the controller and is responsible for ensuring a valid condition for processing such data (e.g., obtaining explicit consent where required).

For consumer users, you should avoid connecting accounts containing special category data from third parties, as we cannot rely on your consent on their behalf.

4. Consent Management

You have granular control over your consents:

4.1 Integration Consents

  • Gmail: Connect/disconnect anytime
  • Slack: Connect/disconnect anytime
  • Future integrations: Separate consent for each

4.2 Processing Consents

  • AI Processing: Required for core service (can delete account to stop)
  • Session Recording: Optional, off by default
  • Email Tracking: Optional, can disable

4.3 Communication Consents

  • Marketing emails: Opt-in required (unchecked by default)
  • Service emails: Cannot opt-out (essential for service)
  • Product updates: Separate consent option

5. AI Processing and Automated Decision-Making

5.1 How AI Processing Works

Our Service uses artificial intelligence for, but not limited to:

  • Analyze emails and messages to identify tasks
  • Generate summaries and insights
  • Suggest task priorities and deadlines
  • Create contextual connections between items

As described in our Terms of Service, our AI Processing is not intended for high-risk use cases, including but not limited to medical, financial, safety-critical, or other sensitive personal data processing where errors could cause significant harm. You must not use the Service in these contexts.

5.2 AI Safeguards

  • No Training: Your data is NEVER used to train AI models
  • No Retention: Configured for no-training and ZDR where available; otherwise up to ~30 days of limited logs.
  • Encryption: All data sent to AI providers is encrypted
  • EU Processing: We prioritize EU-based AI processing where available

5.3 AI Limitations and Risks

Important: AI processing may:

  • Misinterpret context or meaning
  • Generate inaccurate summaries
  • Miss important nuances
  • Process sensitive information you haven't identified

Always review AI-generated content before relying on it.

5.4 Profiling Disclosure

Our AI analysis may constitute limited profiling under GDPR:

  • We analyze patterns in your communications
  • We do NOT make decisions that legally or significantly affect you
  • You can object to profiling by disconnecting integrations
  • No automated decision-making affects your access to services

6. How We Use Your Information

We use your personal data to:

  • Provide and maintain the Service
  • Process and analyze your emails and messages to create tasks
  • Generate AI-powered summaries and insights
  • Authenticate and secure your account
  • Process payments and manage subscriptions
  • Respond to support requests
  • Send service and marketing communications (with consent)
  • Improve and develop new features
  • Comply with legal obligations
  • Protect against fraud and abuse

7. Data Retention

7.1 Retention Periods

Data Category Retention Period Justification
Account Data Duration of account + 30 days Service provision
Inactive Accounts 2 years then auto-deleted Data minimization
Deleted Account Data 30 days grace period Recovery option
Integration Data While integration connected User control
Payment Records 7 years Legal requirement
Support Tickets 2 years Service improvement
Security Logs 90 days Security monitoring
Analytics Data 13 months Trend analysis
Backups 7-day rotation Disaster recovery
Marketing Preferences Until withdrawn Consent management

7.2 Backup Deletion Process

When you request deletion:

  1. Primary data deleted immediately
  2. Marked for deletion in all systems
  3. Backups overwritten within 7-day cycle
  4. Confirmation sent after complete deletion

8. Data Sharing and Sub-Processors

We share your data only as described below:

8.1 Infrastructure Providers

  • Temporal Cloud: Workflow orchestration (EU) - encrypted operational data only
  • Google Cloud Platform (GCP): Infrastructure hosting (EU)
  • Cloudflare: CDN and security services (Global)

8.2 Service Providers

  • Clerk: Authentication services (EU/US)
  • Stripe: Payment processing (EU/US)
  • SendGrid: Email delivery (EU/US)

8.3 AI Processing Services

Note: AI providers process data only for service provision, configured for no-training and ZDR where available; otherwise up to ~30 days of limited logs. Limited security logs may be retained by providers as required for abuse detection and compliance.

  • Google Vertex AI (Gemini): AI processing (EU)
  • OpenAI: AI processing (US with EU processing)
  • Anthropic: AI processing (US with EU processing)

8.4 Analytics and Support

  • DataDog: Monitoring and session replay (EU)
  • Usersnap: Support and feedback (EU)
  • Google Analytics: Marketing site analytics (EU/US)
  • PostHog: Marketing Site analytics (EU/US)
  • GetLaunchList: Waitlist management

8.5 Google

When you connect Google services, we access Google user data only to provide the requested features; we do not sell or use Google user data for ads, and we request the minimum scopes needed. Our use complies with Google's API Services User Data Policy (Limited Use).

8.6 Other Disclosures

We may share your information:

  • With your consent or at your direction
  • To comply with legal obligations or valid legal requests
  • In connection with a merger, acquisition, or sale of assets
  • To protect our rights, property, or safety

We maintain a current list of sub-processors and will notify you of any changes.

9. Data Security

9.1 Security Measures

We implement appropriate technical and organizational measures to protect your personal data:

  • Encryption in transit (TLS/HTTPS) and at rest (AES-256)
  • Modern authentication (Passkeys, OAuth, Magic Links - no passwords)
  • Access controls and authentication
  • Regular security updates and monitoring
  • 7-day backup retention with encryption
  • Incident response procedures

While we strive to protect your data, no method of transmission or storage is 100% secure.

9.2 Data Breach Response

In the event of a personal data breach:

  1. We will notify the ICO within 72 hours of awareness
  2. We will notify affected users if high risk to rights and freedoms
  3. We will document all breaches and remediation steps
  4. We will implement measures to prevent recurrence

9.3 Your Security Responsibilities

  • Keep your authentication credentials secure
  • Use strong, unique passwords for connected accounts
  • Report any suspicious activity immediately
  • Ensure you have authority to connect work accounts

10. Your Rights

10.1 Summary of Rights

Under UK GDPR, you have the following rights:

10.2 Access

Request a copy of your personal data we hold.

10.3 Rectification

Request correction of inaccurate or incomplete data.

10.4 Erasure

Request deletion of your personal data ("right to be forgotten").

10.5 Restriction

Request limiting processing of your data.

10.6 Data Portability

Receive your data in a structured, commonly used format (JSON/CSV).

10.7 Objection

Object to processing based on legitimate interests or for direct marketing.

10.8 Automated Decision-Making

We do not engage in automated decision-making or profiling that significantly affects you.

10.9 Consent Withdrawal

Withdraw consent at any time where processing is based on consent.

10.10 How to Exercise Your Rights

To exercise these rights:

  1. Email: support@hellok.ai
  2. Include proof of identity
  3. Specify which rights you're exercising
  4. We will respond within 30 days
  5. No fee for first request (may charge for repeated requests)

10.11 Complaints

You have the right to lodge a complaint with the Information Commissioner's Office:

  • Website: https://ico.org.uk
  • Phone: 0303 123 1113
  • Address: Wycliffe House, Water Lane, Wilmslow, SK9 5AF

11. Children's Privacy

The Service is not intended for users under 18 years of age. We do not knowingly collect personal data from children. If you believe we have collected data from someone under 18, please contact us immediately.

12. Third-Party Services

12.1 Work Account Authorization

Important: By connecting work accounts, you represent and warrant that:

  • You have explicit authorization from your employer
  • You comply with your organization's data policies
  • You accept responsibility for any policy violations
  • Your employer may have rights to this data
  • You will indemnify us for unauthorized connections

12.2 Integration Risks

When you connect Gmail or Slack:

  • You warrant you have authority to connect these accounts
  • We access only data necessary for task management
  • You can disconnect integrations at any time
  • Third-party services have their own privacy policies

13. Marketing Communications

We send marketing emails only with your consent:

  • Opt-in checkbox (unchecked by default) during signup
  • Unsubscribe link in every marketing email
  • Manage preferences in account settings
  • Transactional emails sent regardless of marketing preferences

14. International Transfers

Where we transfer personal data outside the UK/EEA, we use appropriate safeguards, including:

  • The EU Standard Contractual Clauses (2021/914) and the UK International Data Transfer Addendum (or the UK IDTA), and
  • Transfer risk assessments.

If an adequacy decision applies, we may rely on it instead.

15. Changes to This Policy

15.1 Notification of Changes

We may update this Privacy Policy to reflect changes in our practices or legal requirements. We will notify you of material changes via email or Service notification. Continued use after changes constitutes acceptance.

16. Contact Information

For privacy questions or concerns:

  • Email: support@hellok.ai
  • Post: 85 Great Portland Street, First Floor, London, England, W1W 7LT

16.1 How to Reach Us

For privacy questions, requests, or complaints:

  • Email: support@hellok.ai (preferred)
  • Post: 85 Great Portland Street, First Floor, London, W1W 7LT
  • Response Time: Within 30 days for formal requests

16.2 Supervisory Authority

You may also contact the Information Commissioner's Office:

  • Website: https://ico.org.uk/make-a-complaint
  • Phone: 0303 123 1113
  • LiveChat: Available on ICO website
  • Post: Information Commissioner's Office, Wycliffe House, Water Lane, Wilmslow, Cheshire, SK9 5AF

We encourage you to contact us first to resolve any concerns.

© 2025 Kai Technology Labs Ltd. All rights reserved.