Legal
Privacy Policy
What Kairon collects, who it reaches, how long we keep it, and how to have it deleted.
1. Who we are
Kairon is a business-to-business tool, operated from Argentina under the name Kairon. Our customers are companies that run outreach on LinkedIn from their own LinkedIn accounts.
Questions about this policy, or any request under it, go to [email protected]. If you need a data processing agreement, write to us and we will put one in place.
2. Two different roles
This policy covers two kinds of people, and our responsibility is different for each.
Operators: the people who use Kairon. Our customers and their teams. For their data we are the controller: we decide what we collect and why.
Prospects: the people our customers reach out to. Our customer decides who to contact and what to say. For that data we are a processor acting on our customer’s instructions. If you are a prospect and want your data removed, write to [email protected]. We will act, and we will also tell the customer who targeted you so they can act on their side.
3. What we collect
From operators
- Account identity: name, email address, profile picture, and the organization you belong to. If you sign in with Google, we receive these from Google.
- Billing identity and subscription state.
- The credentials that connect your LinkedIn seat. They are encrypted at the field level and are never shown back to you or to anyone else.
- What you write inside the product: ICP definitions, campaign settings, message templates, writing guidelines, and instructions to the agent.
- Product usage: pages viewed, actions taken, errors encountered, and session replays in which form inputs are masked.
From prospects
- Public LinkedIn profile data, read through your own connected seat: name, headline, location, current and past positions, education, skills, follower and connection counts, profile picture, and public post activity.
- The content of LinkedIn conversations between your seat and that person, including what they wrote back.
- Data you upload yourself, for example a CSV of contacts.
- Publicly available web results about the person’s company, gathered during campaign research.
- If you connect your own Instantly workspace: business email addresses returned by that workspace’s enrichment.
We do not buy contact databases, and we do not sell prospect data.
4. Where prospect data comes from
Kairon has no LinkedIn access of its own. Every read and every message goes through your own LinkedIn account, connected by you. What Kairon can see is exactly what your own account can see. Daily ceilings and sending hours are enforced on our side, so automated use stays within a human pace and an agent cannot raise its own limits.
5. Why we process it, and on what legal basis
For operator data, where we are the controller:
- To perform our contract with you: running the product, your account, your seats, support, and billing.
- Our legitimate interests: keeping the service working and secure (error tracking, logs, traces, profiling), preventing abuse, and improving the product in aggregate.
- Your consent: non-essential cookies and marketing email, each withdrawable at any time.
- Legal obligation: accounting and tax records, and answering lawful requests.
For prospect data we are a processor: we act on our customer’s documented instructions, and the legal basis for contacting that person is the customer’s to establish, not ours. See section 6.
We do not use your data, or your prospects’ data, for advertising.
6. What you are responsible for
If you are a Kairon customer, you decide who gets contacted and what is said to them. That makes you the controller of that data, and it means you are responsible for:
- Having a lawful basis to contact each person, and to process their data, under the rules that apply where they are.
- Telling them what they are entitled to be told, and honouring their rights when they ask you directly.
- The content you send, and complying with LinkedIn’s own terms on the account you connected.
- Anything you upload, including contact lists you did not collect yourself.
When a prospect comes to us instead of to you, we honour the request and tell you it happened, so your own records stay correct.
7. Who we share it with
Only with the service providers below, each processing data on our behalf. This list is maintained in our engineering repository and updated in the same change that introduces a vendor.
| Provider | What it does | What reaches it | Where |
|---|---|---|---|
| Railway | Hosting: application, database, cache | All operator and prospect data, at rest and in transit | US |
| Unipile | LinkedIn access through your own seat | The credentials used to connect your seat, prospect LinkedIn identity and profile, and message content | France |
| Anthropic | Language models: drafting, qualification, reply classification | Prospect public profile text, your instructions, message bodies | US |
| Vercel AI Gateway | Routes our language model calls | The same text sent to the models | US |
| Langfuse | Model call tracing and prompt store | Prompt and completion text, tool arguments and results, keyed by operator and organization | US |
| PostHog | Product analytics, error tracking, feature flags, session replay | Operator identity and organization, error payloads, replays with form inputs masked | US / EU |
| Grafana Cloud | Logs, traces, metrics, profiling | Application telemetry, with personal data redacted before it is written | US |
| Inngest | Durable background workflows | Event payloads carrying record identifiers | US |
| Resend | Transactional email | Operator email address and message content | US |
| Cloudflare R2 | Media storage | LinkedIn profile pictures and company logos | US |
| TinyFish | Web research during the campaign research step | Prospect and company names and public URLs, used as search queries | US |
| Tavily | Web research during the campaign research step | Prospect and company names and public URLs, used as search queries | US |
| Commet | Billing | Operator and organization billing identity, subscription state | US |
| Sign-in, if you choose it | Your Google account identity | US | |
| Instantly | Email follow-up, only if you connect your own workspace | Prospect name, employer and domain sent for enrichment; the returned business email; email bodies and replies | US |
Two of these have a chain past them, and you should know about both.
- Unipile reaches LinkedIn through commercial proxy providers, which therefore carry the traffic of your connected seat. We link their policy rather than copying the names here, because the list is theirs to change and a stale copy would be worse than none: unipile.com/privacy-policy. It also states that Unipile does not store account credentials, though it does hold message content and settings for connected accounts until the account is removed, and that it hosts in France.
- Instantly, if you connect it, is your workspace and your contract, not ours. Its enrichment is fulfilled by its own data supplier, which therefore also processes those prospect identifiers; we hold no contract with that supplier and no visibility into which one serves a given lookup. Data held inside your Instantly workspace is deleted by you, in Instantly.
We also disclose data when the law requires it, and in a merger or acquisition, in which case this policy keeps applying until it is replaced.
8. International transfers
We operate from Argentina and most of our providers are in the United States. When personal data of people in the European Economic Area or the United Kingdom is transferred, we rely on the Standard Contractual Clauses or an equivalent lawful mechanism offered by the provider.
9. Language models
- Text is sent to language model providers to draft messages, qualify prospects and classify replies.
- We rely on those providers’ published API terms, under which customer data is excluded from model training by default. We do not enable any setting that would allow training on your data.
- We send only what the task needs. A prompt never carries message histories from unrelated prospects, billing data, or credentials.
10. How long we keep it
| What | How long |
|---|---|
| Operator account and organization data | While the account is active |
| Prospect profiles and conversations | While the account is active |
| Any of the above, after an erasure request | Hard-deleted within 30 days |
| Any of the above, after the account closes | Deleted within 90 days, unless the law requires otherwise |
| Billing and accounting records | 10 years, as tax law requires |
| Audit trail (record identifiers only, no personal data) | Kept indefinitely: it survives erasure without re-exposing it |
| Database backups | A rolling 7-day window |
| Logs and traces, with personal data already redacted | 30 days |
Deletion on request. Write to [email protected]. For a prospect, this removes the profile and the stored conversation. Deleting a record inside the product marks it as removed for operational purposes; that is not erasure, and the request above is what triggers erasure. Erased data ages out of backups within the seven-day window above.
Data inside your own LinkedIn account, and inside your own Instantly workspace, is not ours to delete. You control it there.
11. Your rights
Depending on where you live you may have the right to access, correct, delete or receive a copy of your personal data, to object to or restrict processing, to withdraw consent, and to complain to your data protection authority (in Argentina, the Agencia de Acceso a la Información Pública; in the European Union, the authority for the country you live in).
If you are in California or another US state with its own privacy law, the same requests apply, including the right to know what we collect and to have it deleted. We do not sell or share personal information for cross-context behavioural advertising.
Write to [email protected] and we will answer within 30 days. We may ask you to confirm your identity first, and we use that confirmation for nothing else. We do not charge for this, and we will not treat you differently for asking.
12. Security
- Encryption in transit and at rest.
- Credentials and other sensitive fields are additionally encrypted per field.
- Every request is scoped to one organization at the database layer, so one customer’s data cannot be read from another customer’s session.
- Personal data is redacted from logs and traces.
- Privileged actions are written to an append-only audit trail.
- We aim to notify affected customers within 72 hours of confirming a personal data breach.
No system is perfectly secure, and we do not claim otherwise.
13. Cookies
We use a cookie to keep you signed in and one to remember your language; the product does not work without them. Our analytics provider sets its own cookies to measure product usage, and our site records which page you first arrived on so a signup can be credited to it. We do not use advertising cookies inside the product.
14. Children
Kairon is not for anyone under 18, and we do not knowingly collect their data.
15. Changes
We update the date at the top whenever this policy changes. For a change that meaningfully affects your rights, we tell customers by email before it takes effect.
16. Contact
Kairon: [email protected]