Privacy Policy
Last updated: 2026-04-30
This policy is an engineering-drafted placeholder while final language is being prepared by counsel. The substantive provisions below reflect our current operating commitments, but the document will be revised before public launch. For any pre-launch questions, contact legal@kironyx.com.
1. Who we are
Kironyx is operated by Kironyx Inc. (the "Company", "we", "us"). This Privacy Policy describes how we collect, use, and share information about you when you use the Kironyx service.
2. What we collect
- Account data:your email address, name, company name, and industry, captured at sign-up and onboarding.
- Authentication data:credentials are managed by Amazon Cognito; we never store passwords directly.
- Subscription & billing data:handled by Paddle as merchant of record. We see only the customer ID, plan, and status; we never see your card details.
- Usage data:competitors you choose to track, the research and analyses we perform on your behalf, and your interactions with the dashboard.
- Operational logs:request metadata, IP address, and error context retained for security and debugging purposes.
3. Why we collect it (lawful basis under GDPR Art. 6)
- Contractual necessity:to provide the service you subscribed to.
- Legitimate interest:to operate, secure, and improve the service.
- Legal obligation:tax, sanctions screening, and accounting records.
- Consent:for any optional marketing communications, with the right to withdraw at any time.
4. AI processing disclosure
Kironyx uses Anthropic's Claude API to perform competitive research and analysis. Your competitors' names and URLs (which you provide) are sent to Anthropic to enable the research function. Anthropic does not use this data to train their models. See our sub-processor list for the full list of third parties that process data on our behalf.
5. Data retention
Research findings, change records, and competitor records are retained while your account is active. Upon account deletion (see Section 7), your personal data is erased within 30 days, except where retention is required for tax or legal obligations (typically up to 6 years for invoicing records).
6. International transfers
Our infrastructure is hosted in the United States (AWS us-east-1). Where we transfer personal data outside your jurisdiction (e.g., from the EU/UK to the US), we rely on Standard Contractual Clauses (SCCs) approved by the European Commission.
7. Your rights
- Right to access (GDPR Art. 15 / CCPA §1798.110): request a machine-readable export of your data via the dashboard or by emailing privacy@kironyx.com.
- Right to erasure (GDPR Art. 17 / CCPA §1798.105): delete your account from the settings page or by emailing us.
- Right to rectification (GDPR Art. 16): edit your profile fields directly in the dashboard.
- Right to portability (GDPR Art. 20): your data export is provided as JSON suitable for porting.
- Right to object / restriction:contact us at privacy@kironyx.com.
- Right to lodge a complaint:with the supervisory authority in your country of residence.
8. Cookies & storage
We use browser localStorage to keep you signed in. We do not set tracking cookies. See the storage notice on first visit for details.
9. Security
Data is encrypted in transit via TLS, encrypted at rest by AWS-managed keys, and access is restricted by role-based controls. We follow the security commitments described in our sub-processor list.
10. Children
Kironyx is a B2B service not intended for individuals under 16. If you believe a minor has created an account, contact us so we can erase the data.
11. Changes to this policy
Material changes will be communicated to active users by email at least 14 days before they take effect. Version history is published at the top of this document.
12. Contact
Privacy inquiries: privacy@kironyx.com. Data Protection Officer (for EU/UK data subjects): dpo@kironyx.com.