Owner-approved version 1, approved 2026-10-01. Customer acceptance and live sales remain disabled until the controlled release checks pass.
1. Who controls your personal data
KXRA GROUP LTD, company number 17435511, registered at 66 Paul Street, London, England, United Kingdom, EC2A 4NA, is the controller for account, relationship, billing, security, enquiry and business-contact data described in this notice.
Contact KXRA about privacy at info@kxra-group.com. KXRA has not appointed a data protection officer because the current processing does not require one.
2. Data we collect
We may collect identity and work-contact data, organisation and role information, account and authentication records, project and task activity, files and content you submit, support and privacy requests, billing identifiers and subscription state, consent and agreement evidence, security and audit records, device and bounded network information, and correspondence.
We receive data directly from you, your organisation's administrator, invited partners, service providers used to operate the platform, and public sources that a governed project is authorised to research.
3. Why we use data and our lawful bases
We use account, project, subscription and support data to perform a contract or take requested pre-contract steps. We use security, audit, fraud-prevention, service-improvement and business-administration data for our legitimate interests in operating a secure and accountable service, balanced against individual rights.
We use data to meet legal obligations, including tax, accounting, sanctions, law-enforcement and data-protection duties. Where consent is the appropriate basis, including non-essential cookies or optional marketing, consent can be withdrawn at any time.
4. AI and authorised context
KXRA retrieves project context only after server and database permissions are checked. A model does not decide access. AI output is logged with bounded run evidence so authorised users can inspect how work was produced.
External model processing remains disabled unless KXRA has approved the provider, purpose, region, retention, data terms and spend controls. When enabled, the applicable provider and transfer information will be added before customer data is sent.
5. Sharing and service providers
We share data only as needed with infrastructure and service providers, professional advisers, authorities where legally required, and people authorised by the relevant organisation. Current launch providers include Vercel for application hosting, Supabase for authentication and database services, Resend for transactional email, and Stripe for billing.
Stripe acts under its own privacy terms for payment information. KXRA does not store full card details. Providers that are not activated for customer processing are not treated as active recipients merely because they appear in the technical roadmap.
6. International transfers
Some providers may process data outside the United Kingdom. Where UK adequacy regulations do not apply, we require an appropriate transfer mechanism such as the UK International Data Transfer Agreement, the UK Addendum to approved standard contractual clauses, or another lawful safeguard. You may request information about the applicable safeguard.
7. Retention
Active account and project data is kept while needed to provide the service. Following workspace closure, ordinary customer content is scheduled for deletion or irreversible anonymisation within 90 days, with encrypted backups expiring within a further 35 days unless a legal hold applies.
Enquiries that do not become customers are normally kept for 12 months. Security and audit evidence is normally kept for 12 months. Contract, payment, invoice and tax records may be kept for six years after the relevant financial year or longer where law or a dispute requires. Agreement and consent evidence is retained for the relationship and six years afterwards.
8. Security
We use access controls, row-level database policies, multi-factor authentication for privileged accounts, encryption in transit, restricted service roles, logging, backups and review gates. No system is completely secure, and users must protect their credentials and report suspected compromise promptly.
9. Your rights
Depending on the circumstances, you may have rights to access, correct, erase or restrict personal data, object to processing, receive portable data, and withdraw consent. The right to object to direct marketing applies at any time.
Send a request to info@kxra-group.com. We may need to verify identity and authority before acting. Some rights are limited where we must retain data or another lawful exemption applies.
10. Automated decisions
KXRA does not use personal data to make solely automated decisions that produce legal or similarly significant effects. AI-assisted suggestions remain subject to authorised human review.
11. Complaints
Please contact KXRA first so we can investigate. You may also complain to the UK Information Commissioner's Office at ico.org.uk or by using the contact details published by the ICO.
12. Changes
We will update this notice when processing, providers or legal requirements materially change. The current version and effective date will be shown on this page, and material changes will be notified where appropriate.
Related documents: customer document index.