KoComplyAgentic Compliance
Back to KoComply
Legal

Privacy Policy

This policy describes how we handle personal data across our website, workspaces, AI agents, integrations and connected compliance workflows.

Effective and last updated: 6 October 2026

01

Scope and our role

This Privacy Policy explains how Kocomply Technologies ("KoComply", "we", "us" or "our") handles personal data when you visit kocomply.com, create or use a KoComply workspace, communicate with us, or connect third-party systems to our agentic compliance platform.

For website, account, sales and relationship data, KoComply generally acts as a data controller. For information a customer submits, imports or makes available through integrations for processing within its workspace ("Customer Data"), KoComply generally acts as a processor or service provider on the customer's instructions. The customer remains responsible for its own privacy notices, legal bases and instructions to us. A data processing addendum may supplement this Policy.

02

Information we collect

Depending on how you use KoComply, we may collect:

  • Account and identity data: name, work email, employer, role, authentication identifiers, workspace membership, profile details and sign-in events, including information received from Google or an enterprise identity provider when you choose single sign-on.
  • Commercial and contact data: company, website, team size, phone number, frameworks, interests, timeline, preferred meeting time, messages, demo requests, application details, order forms and billing or subscription status.
  • Customer Data and compliance content: policies, evidence, controls, risks, vendor records, questionnaires, audit materials, system descriptions, framework selections, comments, approvals, reports and files you upload or generate.
  • Integration data: system metadata and evidence made available by connected cloud, source control, identity, HR, device, ticketing, communication, CRM or other services. The exact fields depend on the connector and permissions you approve.
  • AI and support content: prompts, instructions, chats, feedback and generated outputs. Advisor chats may be stored with a session identifier and, if provided, your contact details, and may be shared with authorised KoComply personnel by email for follow-up.
  • Technical and usage data: IP address, device and browser information, pages viewed, timestamps, referring URLs, diagnostics, security events, cookie choices and interaction data.

Please do not submit special-category or highly sensitive data unless it is necessary for an agreed service and you are authorised to do so.

03

Sources of information

We collect data directly from you and your organisation; from authorised workspace administrators and users; from systems you connect; from public company websites and trust centres when an agent is asked to assess publicly available posture; from authentication, analytics and communications providers; and through automated use of the Service. If you provide data about another person, you confirm that you are authorised to do so.

05

AI agents and automated processing

KoComply uses AI models to analyse user-provided context and connected-system evidence and to draft policies, assessments, questionnaire responses, risk registers, readiness plans and other compliance materials. Relevant prompts, Customer Data and instructions may be sent to AI infrastructure providers solely to produce the requested output and operate the Service.

AI outputs can be incomplete or inaccurate and are designed for human review. KoComply keeps substantive approvals manual and does not intend its agents to make legally binding decisions about individuals. Customers must validate outputs before relying on, publishing or submitting them to auditors, regulators, customers or other third parties.

06

Integrations, OAuth and MCP connections

When an administrator connects a third-party service, KoComply receives the permissions and data authorised through that service's consent screen, API key, service account or similar method. This may include account identifiers, configuration, users and groups, assets, repositories, tickets, device posture, logs, evidence and security findings. We use connection tokens and credentials to maintain the integration and perform requested checks; customers should grant the least privilege necessary and may revoke access from KoComply or the provider.

KoComply also offers a protected Model Context Protocol (MCP) endpoint. If you authorise an AI client to connect, that client may invoke the KoComply tools and access results within the authorised account scope. The external AI client has its own privacy practices. Review its permissions before approval and disconnect it when no longer needed.

Third-party integrations are governed by both this Policy and the provider's terms. Removal of a connection stops future collection but does not automatically delete information previously imported or required for an audit trail.

07

Cookies and analytics

We use necessary browser storage for authentication, security, consent choices, session controls and interface state. With your consent, Google Analytics measures page views and product usage. Advertising storage and ad personalisation are denied by default. You can accept or decline analytics in our cookie banner and clear site data in your browser to reset your choice.

Browser "Do Not Track" signals are not consistently standardised. We honour the consent controls described above and applicable opt-out requirements.

08

How we disclose information

We may disclose information to:

  • authorised users, administrators and collaborators in your workspace;
  • hosting, database, authentication, AI, analytics, email, communications, security, support and payment providers acting for us;
  • third-party integration providers at your direction;
  • independent audit partners or professional advisers when you request or authorise their involvement;
  • government authorities or other parties when required by law or reasonably necessary to protect rights, safety and platform integrity; and
  • a buyer, investor or successor in connection with a merger, financing, reorganisation or sale, subject to appropriate confidentiality protections.

We do not sell personal data or share it for cross-context behavioural advertising. We may use aggregated or de-identified information that cannot reasonably identify you.

09

International transfers

KoComply and its providers may process information in India, the United States and other countries where they operate. Those countries may have different data-protection laws. Where required, we use recognised safeguards such as contractual protections and transfer assessments. Customers with specific residency requirements should address them in their order form or data processing addendum before connecting data.

10

Retention and deletion

We retain information for as long as needed to provide the Service, maintain security and audit trails, meet contractual and legal obligations, resolve disputes and enforce agreements. Retention varies by data type, workspace settings and legal requirements. After account closure or a valid deletion request, we delete or de-identify data within a commercially reasonable period, subject to backups, legal holds, security records and records we must retain. Disconnected integrations no longer supply new data, but existing evidence may remain until deleted under the workspace's retention process.

11

Security

We use administrative, technical and organisational safeguards designed to protect information, including access controls, authentication, encryption where appropriate, logging and provider oversight. No internet service is completely secure. Customers are responsible for protecting credentials, managing workspace access, reviewing agent actions and promptly notifying us of suspected unauthorised use.

12

Your choices and privacy rights

Subject to applicable law, you may request access, correction, deletion, restriction, objection, portability or withdrawal of consent, and may complain to an appropriate data-protection authority. We may need to verify your identity. If KoComply processes your data for a customer, submit your request to that customer first; we will assist it as required.

You may opt out of non-essential marketing using the unsubscribe method in a message or by contacting us. You will still receive necessary security, account and transactional communications.

13

Children

KoComply is a business service and is not directed to children under 18. We do not knowingly collect personal data from children. Contact us if you believe a child has provided data to the Service.

14

Changes and contact

We may update this Policy as the Service, integrations or law changes. We will post the revised version here, update the date above and provide additional notice where required. Material changes apply prospectively.

For privacy questions or rights requests, email shanti@kocomply.com. The data controller is Kocomply Technologies. Please include enough detail for us to identify the relevant account and request.