Privacy Policy
Last updated: 12 September 2025
1. Introduction and Key Information
1.1 About This Policy
This Privacy Policy explains how Kai Technology Labs Ltd ("Kai", "we", "us", or "our") collects, uses, shares, and protects your personal information when you use our intelligent task management service ("Service") available at https://hellok.ai and related applications.
We are committed to protecting your privacy and handling your data transparently in accordance with the UK General Data Protection Regulation (UK GDPR) and other applicable data protection laws. We implement Privacy by Design principles, ensuring data protection is built into our systems from the ground up.
We will only disclose user data in response to a valid and legally binding request, and we will notify the user unless prohibited by law.
1.2 Policy at a Glance
The following has been provided for quick reference only and does not replace the full Privacy Policy. Please read the full policy for complete details.
- We never use your content (emails, messages) to train AI models.
- We only collect the data we need to make Kai work.
- You control your integrations and can disconnect them at any time.
- We prioritize using data centers located in the EU.
- You have full rights to access, amend, or delete your data.
1.3 ICO Registration
We are registered with the ICO as a data controller under number ZB982461. You can verify our registration on the ICO public register.
1.4 Data Protection Officer
We have not appointed a formal Data Protection Officer (DPO) as we do not engage in large-scale systematic monitoring or process special category data as a core activity. However, our data protection lead can be contacted at support@hellok.ai for any privacy-related queries.
1.5 Data Controller Information
Company Name: Kai Technology Labs Ltd
Company Registration Number: 16618112
Registered in: England and Wales
Registered Office: 85 Great Portland Street, First Floor, London, England, W1W 7LT
Contact Email: support@hellok.ai
Website: https://hellok.ai
For privacy-related inquiries, please contact us at support@hellok.ai.
2. Information We Collect
2.1 Data Minimization Principle
We only collect data that is necessary for providing our Service. Here's why we need each type:
| Data Type | Purpose | Necessity |
|---|---|---|
| Email Address | Account creation, authentication, communication | Essential for service |
| Name | Personalization, support | Required for user identification |
| Integration Data | Task creation from emails/messages | Core service functionality |
| Usage Analytics | Service improvement, debugging | Legitimate business need |
| Payment Information | Subscription processing | Required for paid features |
2.2 Special Category Data
Consumer Accounts. For individual consumer accounts, Kai acts as the controller only of your own account data. You must not use the Service to process special category data belonging to third parties. If such data is ingested incidentally, it is processed solely under your instructions, for the purpose of delivering the Service you requested. You are responsible for obtaining any necessary consents from third parties.
2.3 Account Information
When you create an account, we collect:
- Email address (required)
- First and last name (required)
- Authentication credentials (OAuth tokens, Passkeys, or Magic Link tokens)
2.4 Integration Data
When you connect third-party services, we process:
- Gmail Integration: Email content, metadata, sender information, attachments
- Slack Integration: Messages, channel information, sender details
- Connected account identifiers and OAuth tokens
2.5 Usage and Analytics Data
We automatically collect:
- Service usage patterns and feature interactions
- Task creation and management data
- IP address and device information
- Browser type and operating system
- Session recordings (only with explicit opt-in consent)
- Performance metrics and error reports
2.6 Payment Information
For paid subscriptions, we collect:
- Billing name and address
- Payment method details (processed by Stripe)
- Transaction history and subscription status
2.7 Support and Communication Data
When you contact us:
- Support ticket content and metadata
- Email communications
- Feedback and survey responses
2.8 Cookies and Tracking Technologies
Please refer to our Cookie Policy for detailed information on cookies we use and how to manage your preferences.
3. Legal Basis for Processing
3.1 Legal Basis Mapping
We process your data under specific legal bases:
| Processing Activity | Data Categories | Legal Basis | Explanation |
|---|---|---|---|
| Account Creation | Email, Name | Contract | Necessary to provide service |
| Authentication | OAuth tokens, Passkeys | Contract | Required for secure access |
| Gmail/Slack Processing | Messages, Emails | Contract | Explicit opt-in when connecting |
| AI Task Creation | Communication content | Contract | Part of integration consent |
| Payment Processing | Billing information | Contract | Required for subscriptions |
| Service Analytics | Usage data | Legitimate Interests | Improving service quality |
| Security Monitoring | IP, Device info | Legitimate Interests | Preventing fraud and abuse |
| Marketing Emails | Email address | Consent | Explicit opt-in required |
| Session Recording | User interactions | Consent | Explicit opt-in required |
| Support Tickets | Communication data | Contract | Providing customer support |
We process your personal data based on the following legal grounds:
3.2 Contract Performance
We process personal data where it is necessary to perform our contract with you. This includes:
- Creating and managing your account
- Providing the core features of the Service (such as task extraction, summaries, and prioritization)
- Processing subscription payments
- Delivering customer support
3.3 Consent
We rely on your consent for processing that is not strictly necessary for the Service. This includes:
- Sending marketing communications
- Enabling session recording and replay
- Tracking email opens and clicks
You may withdraw consent at any time by updating your preferences, disconnecting integrations, or using the unsubscribe links provided.
3.4 Legitimate Interests
We process some data where it is necessary for our legitimate interests, provided these are not overridden by your rights and interests. This includes:
- Basic product analytics to improve usability and features
- Security monitoring and fraud prevention
- Service performance monitoring and debugging
3.5 Special Category Data
If you choose to connect integrations (such as Gmail or Slack), messages may contain special category data under UK GDPR. We will only process such data with your explicit consent at the point of connection, and solely to provide the Service.
For business customers, your organization is the controller and is responsible for ensuring a valid condition for processing such data (e.g., obtaining explicit consent where required).
For consumer users, you should avoid connecting accounts containing special category data from third parties, as we cannot rely on your consent on their behalf.
4. Consent Management
You have granular control over your consents:
4.1 Integration Consents
- Gmail: Connect/disconnect anytime
- Slack: Connect/disconnect anytime
- Future integrations: Separate consent for each
4.2 Processing Consents
- AI Processing: Required for core service (can delete account to stop)
- Session Recording: Optional, off by default
- Email Tracking: Optional, can disable
4.3 Communication Consents
- Marketing emails: Opt-in required (unchecked by default)
- Service emails: Cannot opt-out (essential for service)
- Product updates: Separate consent option
5. AI Processing and Automated Decision-Making
5.1 How AI Processing Works
Our Service uses artificial intelligence for, but not limited to:
- Analyze emails and messages to identify tasks
- Generate summaries and insights
- Suggest task priorities and deadlines
- Create contextual connections between items
As described in our Terms of Service, our AI Processing is not intended for high-risk use cases, including but not limited to medical, financial, safety-critical, or other sensitive personal data processing where errors could cause significant harm. You must not use the Service in these contexts.
5.2 AI Safeguards
- No Training: Your data is NEVER used to train AI models
- No Retention: Configured for no-training and ZDR where available; otherwise up to ~30 days of limited logs.
- Encryption: All data sent to AI providers is encrypted
- EU Processing: We prioritize EU-based AI processing where available
5.3 AI Limitations and Risks
Important: AI processing may:
- Misinterpret context or meaning
- Generate inaccurate summaries
- Miss important nuances
- Process sensitive information you haven't identified
Always review AI-generated content before relying on it.
5.4 Profiling Disclosure
Our AI analysis may constitute limited profiling under GDPR:
- We analyze patterns in your communications
- We do NOT make decisions that legally or significantly affect you
- You can object to profiling by disconnecting integrations
- No automated decision-making affects your access to services
6. How We Use Your Information
We use your personal data to:
- Provide and maintain the Service
- Process and analyze your emails and messages to create tasks
- Generate AI-powered summaries and insights
- Authenticate and secure your account
- Process payments and manage subscriptions
- Respond to support requests
- Send service and marketing communications (with consent)
- Improve and develop new features
- Comply with legal obligations
- Protect against fraud and abuse
7. Data Retention
7.1 Retention Periods
| Data Category | Retention Period | Justification |
|---|---|---|
| Account Data | Duration of account + 30 days | Service provision |
| Inactive Accounts | 2 years then auto-deleted | Data minimization |
| Deleted Account Data | 30 days grace period | Recovery option |
| Integration Data | While integration connected | User control |
| Payment Records | 7 years | Legal requirement |
| Support Tickets | 2 years | Service improvement |
| Security Logs | 90 days | Security monitoring |
| Analytics Data | 13 months | Trend analysis |
| Backups | 7-day rotation | Disaster recovery |
| Marketing Preferences | Until withdrawn | Consent management |
7.2 Backup Deletion Process
When you request deletion:
- Primary data deleted immediately
- Marked for deletion in all systems
- Backups overwritten within 7-day cycle
- Confirmation sent after complete deletion
8. Data Sharing and Sub-Processors
We share your data only as described below:
8.1 Infrastructure Providers
- Temporal Cloud: Workflow orchestration (EU) - encrypted operational data only
- Google Cloud Platform (GCP): Infrastructure hosting (EU)
- Cloudflare: CDN and security services (Global)
8.2 Service Providers
- Clerk: Authentication services (EU/US)
- Stripe: Payment processing (EU/US)
- SendGrid: Email delivery (EU/US)
8.3 AI Processing Services
Note: AI providers process data only for service provision, configured for no-training and ZDR where available; otherwise up to ~30 days of limited logs. Limited security logs may be retained by providers as required for abuse detection and compliance.
- Google Vertex AI (Gemini): AI processing (EU)
- OpenAI: AI processing (US with EU processing)
- Anthropic: AI processing (US with EU processing)
8.4 Analytics and Support
- DataDog: Monitoring and session replay (EU)
- Usersnap: Support and feedback (EU)
- Google Analytics: Marketing site analytics (EU/US)
- PostHog: Marketing Site analytics (EU/US)
- GetLaunchList: Waitlist management
8.5 Google
When you connect Google services, we access Google user data only to provide the requested features; we do not sell or use Google user data for ads, and we request the minimum scopes needed. Our use complies with Google's API Services User Data Policy (Limited Use).
8.6 Other Disclosures
We may share your information:
- With your consent or at your direction
- To comply with legal obligations or valid legal requests
- In connection with a merger, acquisition, or sale of assets
- To protect our rights, property, or safety
We maintain a current list of sub-processors and will notify you of any changes.
9. Data Security
9.1 Security Measures
We implement appropriate technical and organizational measures to protect your personal data:
- Encryption in transit (TLS/HTTPS) and at rest (AES-256)
- Modern authentication (Passkeys, OAuth, Magic Links - no passwords)
- Access controls and authentication
- Regular security updates and monitoring
- 7-day backup retention with encryption
- Incident response procedures
While we strive to protect your data, no method of transmission or storage is 100% secure.
9.2 Data Breach Response
In the event of a personal data breach:
- We will notify the ICO within 72 hours of awareness
- We will notify affected users if high risk to rights and freedoms
- We will document all breaches and remediation steps
- We will implement measures to prevent recurrence
9.3 Your Security Responsibilities
- Keep your authentication credentials secure
- Use strong, unique passwords for connected accounts
- Report any suspicious activity immediately
- Ensure you have authority to connect work accounts
10. Your Rights
10.1 Summary of Rights
Under UK GDPR, you have the following rights:
10.2 Access
Request a copy of your personal data we hold.
10.3 Rectification
Request correction of inaccurate or incomplete data.
10.4 Erasure
Request deletion of your personal data ("right to be forgotten").
10.5 Restriction
Request limiting processing of your data.
10.6 Data Portability
Receive your data in a structured, commonly used format (JSON/CSV).
10.7 Objection
Object to processing based on legitimate interests or for direct marketing.
10.8 Automated Decision-Making
We do not engage in automated decision-making or profiling that significantly affects you.
10.9 Consent Withdrawal
Withdraw consent at any time where processing is based on consent.
10.10 How to Exercise Your Rights
To exercise these rights:
- Email: support@hellok.ai
- Include proof of identity
- Specify which rights you're exercising
- We will respond within 30 days
- No fee for first request (may charge for repeated requests)
10.11 Complaints
You have the right to lodge a complaint with the Information Commissioner's Office:
- Website: https://ico.org.uk
- Phone: 0303 123 1113
- Address: Wycliffe House, Water Lane, Wilmslow, SK9 5AF
11. Children's Privacy
The Service is not intended for users under 18 years of age. We do not knowingly collect personal data from children. If you believe we have collected data from someone under 18, please contact us immediately.
12. Third-Party Services
12.1 Work Account Authorization
Important: By connecting work accounts, you represent and warrant that:
- You have explicit authorization from your employer
- You comply with your organization's data policies
- You accept responsibility for any policy violations
- Your employer may have rights to this data
- You will indemnify us for unauthorized connections
12.2 Integration Risks
When you connect Gmail or Slack:
- You warrant you have authority to connect these accounts
- We access only data necessary for task management
- You can disconnect integrations at any time
- Third-party services have their own privacy policies
13. Marketing Communications
We send marketing emails only with your consent:
- Opt-in checkbox (unchecked by default) during signup
- Unsubscribe link in every marketing email
- Manage preferences in account settings
- Transactional emails sent regardless of marketing preferences
14. International Transfers
Where we transfer personal data outside the UK/EEA, we use appropriate safeguards, including:
- The EU Standard Contractual Clauses (2021/914) and the UK International Data Transfer Addendum (or the UK IDTA), and
- Transfer risk assessments.
If an adequacy decision applies, we may rely on it instead.
15. Changes to This Policy
15.1 Notification of Changes
We may update this Privacy Policy to reflect changes in our practices or legal requirements. We will notify you of material changes via email or Service notification. Continued use after changes constitutes acceptance.
16. Contact Information
For privacy questions or concerns:
- Email: support@hellok.ai
- Post: 85 Great Portland Street, First Floor, London, England, W1W 7LT
16.1 How to Reach Us
For privacy questions, requests, or complaints:
- Email: support@hellok.ai (preferred)
- Post: 85 Great Portland Street, First Floor, London, W1W 7LT
- Response Time: Within 30 days for formal requests
16.2 Supervisory Authority
You may also contact the Information Commissioner's Office:
- Website: https://ico.org.uk/make-a-complaint
- Phone: 0303 123 1113
- LiveChat: Available on ICO website
- Post: Information Commissioner's Office, Wycliffe House, Water Lane, Wilmslow, Cheshire, SK9 5AF
We encourage you to contact us first to resolve any concerns.
© 2025 Kai Technology Labs Ltd. All rights reserved.