Privacy Policy
Kairos One PMIS Privacy Policy
Effective date: July 3, 2026
This Privacy Policy explains how Kairos One Inc. ("Kairos") collects, uses, protects, retains, and shares information in connection with the Kairos One PMIS platform ("Service"). Kairos generally acts as a service provider/processor handling information on behalf of its customer organizations, under their instructions and the applicable agreement. It is designed to align with the safeguards and breach-notification expectations of laws such as the New York SHIELD Act and the New Jersey data-breach statute (N.J.S.A. 56:8-161 et seq.).
1. Information We Collect
Account information: name, business email address, role, organization/company, authentication activity, and login metadata including IP address and timestamps used for security and audit purposes.
Project information submitted to the Service: schedules, documents, reports, action items, comments, attachments, approvals, and audit history.
Limited technical/usage information needed to operate and secure the Service. Kairos does not intentionally collect Social Security numbers, payment-card data, or special categories of personal information through the Service.
2. How We Use Information
To provide secure access, operate platform features and dashboards, generate schedule and portfolio insights, maintain records and audit trails, and support customer operations.
To protect the Service — detecting, investigating, and preventing unauthorized access, fraud, and abuse — and to meet legal and contractual obligations. Aggregated or de-identified data may be used to monitor and improve reliability.
AI and automated processing: when AI features are enabled, the Service sends the specific content you submit to an AI feature to a third-party large-language-model provider (currently Google (Gemini); the current provider is listed in the Sub-processor List in our Trust Center and may change with advance notice) to generate summaries, schedule and risk analysis, and Copilot responses. The provider receives Customer Data only to return a response, in the United States, on terms that do not permit training on it. AI outputs are decision-support only and are reviewed by a person before any consequential action (a human stays in the loop). Kairos does not use Customer Data to train any model unless the customer specifically opts in. See our Responsible AI Statement for details.
3. Sharing and Disclosure
Kairos does not sell personal information or Customer Data. Information is accessible to authorized users in accordance with the customer’s configured permissions and project assignments.
Information may be shared with vetted service providers (sub-processors) acting on Kairos’s behalf under contractual confidentiality and security obligations, with customer-approved integrations, or where required by law or legal process.
4. Information Security
Kairos maintains administrative, technical, and physical safeguards designed to protect personal information, consistent with the "reasonable safeguards" standard of the NY SHIELD Act.
Technical safeguards include encryption of data in transit (TLS) and encryption of data at rest (storage-level encryption of the database and file storage via AWS RDS and S3 server-side encryption), role-based access control with least-privilege scoping, authentication controls, audit logging of access and data changes, rate limiting, and secure development and change-management practices. Administrative safeguards include access reviews and assignment of security responsibility.
5. Data Breach Notification
Kairos maintains an incident-response process to detect, assess, and respond to security incidents. In the event of a breach of private information, Kairos will notify the affected customer without unreasonable delay and will cooperate with the customer’s notification obligations to affected individuals and regulators, including those under the NY SHIELD Act and N.J.S.A. 56:8-163, in the most expedient time possible and without unreasonable delay.
6. Data Retention and Deletion
Kairos retains personal information and Customer Data for as long as needed to provide the Service and as required to meet security, audit, dispute-resolution, and legal-compliance obligations, after which it is deleted or de-identified.
Customers and their administrators may request access, correction, deletion, or export of personal information, subject to the applicable agreement and legal retention requirements. Requests can be made using the contact below.
7. Data Location and Sub-processors
Customer Data is hosted on Amazon Web Services (AWS) in the United States. A current list of sub-processors (including AI providers and their regions) is published as the Sub-processor List in our Trust Center, and Kairos commits to advance notice of changes as set out in the Data Processing Agreement. Where a government customer requires that data be stored or processed within a specific jurisdiction (for example, within the United States), Kairos will configure the deployment accordingly.
Where any support or development services are performed outside the United States, Kairos will disclose this to government customers as required (including under applicable state offshore-services disclosure requirements) and will honor onshore-handling requirements specified in the contract.
8. Your Rights and Requests
Depending on applicable law and the customer agreement, individuals may have rights to access, correct, delete, or obtain a copy of their personal information. Because Kairos typically processes information on behalf of a customer, such requests are generally directed to and coordinated with the relevant customer organization.
9. Children’s Privacy
The Service is intended for business and government use and is not directed to children. Kairos does not knowingly collect personal information from children.
10. Changes to This Policy
Kairos may update this Privacy Policy. Material changes will be posted here with an updated effective date and, for active customers, communicated to the customer administrator.
Contact Kairos
Kairos One Inc.
Schedule Control Intelligence for capital portfolios
Email: legal@kairosonegroup.com