An important note on which part applies to you.
Part 1 covers personal data Karez collects for its own purposes — website visitors, prospects, people who email us, and account administrators. For that data Karez is a controller.
Part 2 covers the business records Karez processes on behalf of a customer, from the systems of record that customer connects and authorizes. For that data Karez is a processor (a "service provider" under California law), acting only on the customer's documented instructions. If you are an employee, contractor, supplier, or customer of an organization that uses Karez, Part 2 is the part that concerns you — and your rights run through that organization, which is the controller.
Contents
1. Part 1 — Website and prospect data
For the data described in this Part, Karez determines the purposes and means of processing and is therefore a controller.
1.1 What we collect
- Contact details you give us — name, business email, company, role, and anything you write in an email or a pilot request.
- Site usage data — pages viewed, referrer, approximate location derived from IP, device and browser type. [Confirm what analytics, if any, are actually deployed. If none, say "we do not use third-party analytics" — that is a genuine differentiator and it is free.]
- Server logs — IP address, timestamp, request path, retained for [period] for security and abuse prevention.
- Recruiting data, if you apply for a role. [Delete this bullet if not applicable.]
1.2 Why we use it
To respond to your enquiry, to run and secure the website, to arrange and deliver pilots, and to send you information you asked for. Our lawful bases under GDPR are performance of a contract or steps taken at your request, our legitimate interests in operating and securing the site and in business-to-business outreach, and consent where required (for example, non-essential cookies).
1.3 Cookies
[State exactly what is set. If the site sets only strictly necessary cookies and no third-party trackers, say so plainly — it is short, true, and better than a generic cookie policy. If a consent banner is required, link it here.]
1.4 Retention
Enquiry and prospect records: [period]. Server logs: [period]. We delete or anonymize data when it is no longer needed for the purpose it was collected for.
2. Part 2 — Customer data
When an organization uses Karez, Karez processes records from the systems that organization connects. For all such data Karez is a processor under GDPR and a service provider under the CCPA. The customer is the controller and determines what is processed and why. Karez acts only on the customer's documented instructions, set out in our Data Processing Addendum.
Where a customer's records concern that customer's own customers or suppliers, Karez acts as a sub-processor.
2.1 What we connect to
Karez connects only to the systems of record the customer selects and authorizes, using credentials and permission scopes the customer grants. Typical sources include data warehouses, ERP and TMS systems, ticketing and workflow tools, and document stores. The customer chooses which; Karez does not connect to anything the customer has not enabled.
2.2 What we read, derive, and retain
Karez reads the records those systems already hold, and builds from them an operational memory — an index of how work moves through the organization. The personal data typically present in those records includes names, business contact details, user and employee identifiers, role and organizational unit, action timestamps, approval and authorship metadata, and free-text content in tickets and documents that may itself contain further personal data.
We call the artifacts Karez builds Derived Artifacts: embeddings, vector indexes, extracted entity and process graphs, operational memory, cached model context, and prompt and completion logs.
2.3 Deletion reaches the derived artifacts
Most vendors' deletion commitments cover "customer data" and say nothing about what happens to the indexes and embeddings built from it. Ours reaches both. When a customer deletes data or terminates, Karez deletes the underlying records and purges the Derived Artifacts built from them, within [N] days, with written confirmation on request.
[BLOCKING: do not publish this paragraph until the capability exists and has been tested. An unmet commitment here is worse than no commitment.]
2.4 We do not train on customer data
Karez does not use Customer Data to train, fine-tune, or evaluate its own models; to build cross-customer benchmarks or analytics products; or to improve the product outside the individual customer's own tenant. This is a contractual commitment in our platform agreement and Data Processing Addendum, not a policy statement we can change unilaterally.
We do not define aggregated or anonymized derivatives out of "Customer Data" in order to create an exception to the above.
2.5 Tenant isolation
[State the actual model, and specifically whether operational memory, embeddings, and model context are isolated per tenant, and that no customer's data influences another customer's outputs. "Multi-tenant with logical isolation" will not satisfy a security reviewer — be specific. See trust.html.]
3. What Karez does not do
Karez reads from the systems of record you connect and authorize. Karez does not:
- record or transcribe calls;
- ingest chat or messaging content for monitoring purposes;
- capture screens or keystrokes;
- collect biometric identifiers — including voice, face, gait, or keystroke biometrics;
- produce individual employee performance scores or rankings.
[Every line above must be verified true before publishing, and edited to match reality. The entire value of this section is its accuracy — one false line converts it from a trust asset into a misrepresentation.]
4. Subprocessors
Karez uses subprocessors to deliver the platform, including infrastructure providers and AI model providers. Our current list is maintained at karez.ai/trust, with — for each entry — the entity, the service provided, data categories, region, transfer mechanism, and that provider's retention and training posture for our data.
Customers may subscribe to change notifications at [email protected]. We give [30] days' advance notice by email to the customer's designated contact before adding a subprocessor, and customers may object. If we cannot offer a reasonable workaround, the customer may terminate the affected service with a pro-rata refund of prepaid fees.
We remain fully liable for our subprocessors' performance.
5. International transfers
Karez is a US company. Where personal data is transferred from the EEA, UK, or Switzerland, we rely on the European Commission's Standard Contractual Clauses (Modules 2 and 3 as applicable), the UK International Data Transfer Addendum, and the Swiss addendum, together with supplementary measures where required. Copies are available in our DPA.
[If an EU representative is appointed under Art. 27, name them here. If not applicable because Karez acts only as a processor for EU-established controllers, state that instead — do not claim to be a controller subject to GDPR when you are not.]
6. Your rights
For Part 1 data (website and prospect data), you may request access, correction, deletion, restriction, portability, or object to processing. Contact [email protected]. You may also complain to your local supervisory authority.
For Part 2 data (customer data), your rights run through the organization that uses Karez — it is the controller. If you contact us directly about Part 2 data, we will refer you to that organization and support them in responding, as our DPA requires. We will not act on such a request without the controller's instruction.
7. US state privacy law
Karez acts as a service provider (California) and processor (Virginia, Colorado, Connecticut, Texas, and other US state comprehensive privacy laws) for Customer Data. We process it only for the specific business purposes set out in our written agreement with the customer, and we do not sell or share personal information, or use it for cross-context behavioral advertising.
Karez does not claim a business-to-business or employment exemption, and applies the same protections to business-context personal data regardless of whether an exemption would be available. California, notably, has no such exemption.
8. AI-specific disclosures
- Model providers. Karez selects the models it uses; they are listed as subprocessors, with their retention and training posture stated. We contract for zero-retention and no-training terms where available. [Confirm per provider before publishing.]
- AI interaction disclosure. Where a Karez agent communicates directly with a person — for example by posting a comment or sending a message — it is identified as an AI system.
- Automated decision-making. [This is a product decision that must be made deliberately and stated honestly. If Karez agents do not allocate work to named individuals and do not evaluate individual performance, say so explicitly — it is the single most valuable sentence on this page. If they do, this section needs to describe the human review available, and the product likely falls in scope of the EU AI Act Annex III(4)(b) and CCPA ADMT rules. See legal/02-privacy-dpa-proposal.md §8.]
- Human oversight. Customers configure which agent actions require human approval, and can suspend any agent at any time. Every agent action is logged and exportable.
9. Contact
Privacy questions and rights requests: [email protected]
Security: [email protected]
General: [email protected]
[Karez legal entity name]
[registered address]