Effective as of June 1st, 2020

Privacy Policy

 

Your privacy is important to us. At Kairos, we are committed to protecting your personal information with the highest level of integrity. This policy is intended to inform you of our privacy practices in association with the collection and use of your information obtained through our website (www.kairos.com), services, and applications. This Privacy Policy is incorporated into, and subject to the Terms of Service as well as our other security policies. The following comprises the terms of our policy:

Kairos AR, Inc. and its affiliates (collectively “Kairos”, “we” and “us”) respect your privacy. This Privacy Policy describes the types of personal information (“Personal Information”) we collect through our facial recognition products and services (“Kairos Services”) and about our visitors (“Users”) via our online presence, which include our main website at https://www.kairos.com/ , as well as services and websites that we enable Internet users to access, such as the HII (collectively, our “Sites”), which may have their own respective privacy policies, in which case the respective privacy policies shall supersede this. This Privacy Policy also describes how we use Personal Information, with whom we share it, your rights and choices, and how you can contact us for privacy related messages. We may modify or update this Privacy Policy from time to time, and upon its publication on kairos.com/privacy, it shall become effective and your continued use of the Sites indicates your acceptance. It is your responsibility to check the Privacy Policy regularly for modifications or updates to ensure your compliance. This Privacy Policy incorporated by reference into the Kairos Terms of Use.

 
 
 

1. Overview

Kairos obtains Personal Information about you from various sources to provide our Kairos Services and to manage our Sites. “You” may be a visitor to one of our websites, a user of one or more of our Kairos Services (“User” or “Licensee”), or a customer of a User (“Customer”). If you are a Customer, please refer to the privacy policy and terms of use or equivalent to understand how the Licensee implementing our Kairos Services uses your Personal Information. Any capitalized terms not defined herein shall have the same meaning and effect as set forth in the Terms of Use. Kairos collects data through the API for research purposes only. The data collected through the Kairos API includes biometric information such as facial images, which may be considered personal and sensitive information. Kairos will use the collected data only for research purposes. The research may include analyzing trends, identifying patterns, or developing new products and services. Kairos may disclose the collected data to third parties, including research institutions and organizations, only for research purposes. The data will not be disclosed for commercial or marketing purposes. Kairos will retain the collected data only for as long as necessary to fulfill the research purposes. After the research is complete, the data will be securely deleted or anonymized to protect individual privacy. Kairos will take reasonable measures to protect the collected data from unauthorized access, use, or disclosure. This includes implementing appropriate physical, technical, and administrative safeguards.

 

2. Personal Information We Collect

When you visit our Sites, we collect two types of information from you; Personal Information, which you actively provide us, and Information automatically collected from your devices.

(a) Personal Information that we collect about you. Personal Information is any information that relates to an identified or identifiable individual. The Personal Information that you provide directly to us through our Sites will be apparent from the context in which you provide the data. In particular:

- When you register for a Kairos account we collect your full name, email address, and account log-in credentials.

- When you fill-in our online form or contact our sales team, we collect your full name, work email, country, and anything else you submit in the forms.

- When you respond to Kairos emails we collect your email address, name and any other information you choose to include in the body of your email or responses as well as metadata that may automatically be included. If you contact us by phone, we will collect the phone number you use to call Kairos.

If you contact us by phone as a Licensee, we may collect additional information in order to verify your identity such as name, postal address, telephone number, and email address.

If you are a Customer, when you appear in an authorized camera feed of a Licensee or conduct transactions through a Licensee’s application, we will receive your biometric data and any associated transaction information such as facial images, which may be considered personal and sensitive information. Depending on how the Licensee implements our Kairos Services, we may receive this information directly from you, or from the Licensee or third parties. The information that we collect may include biometrics, email address, and other information that is detected or can be derived from an image or other transaction conducted using the Kairos Services.

Different use cases and applications of our Kairos Services require the collection of different categories of information. The Licensee will determine the information it collects.

You may also choose to submit information to us via other methods, including: (i) in response to marketing or other communications, (ii) through social media or online forums, (iii) through participation in an offer, program or promotion, (iv) in connection with an actual or potential business relationship with us, or (v) by giving us your business card or contact details at trade shows or other events.

(b) Information that we collect automatically on our Sites. Our Sites use cookies and other technologies to function effectively. These technologies record information about your use of our Sites, including:

- Browser and device data, such as IP address, device type, operating system and Internet browser type, screen resolution, operating system name and version, device manufacturer and model, language, plug-ins, add-ons and the language version of the Sites you are visiting;

- Usage data, such as time spent on the Sites, pages visited, links clicked, language preferences, and the pages that led or referred you to our Sites.

- We also may collect information about your online activities on websites and connected devices over time and across third-party websites, devices, apps and other online features and services. We use Google Analytics on our Sites to help us analyze Your use of our Sites and diagnose technical issues. We may also use Cookies to enhance your experience.

 

3. How We Use Personal Information

(a) Our products and services. We use Personal Information to facilitate the business relationships we have with our Users, to comply with our financial regulatory and other legal obligations, and to pursue our legitimate business interests. However, we do not warrant that we are in compliance with all applicable law and cannot warrant that our Licensees or Users use the Kairos Software in a manner that is compliant with applicable laws. We also use Personal Information to complete payment transactions and to provide payment-related services to our Users.

(b) Marketing and events-related communications. We may send you email marketing communications about Kairos products and services, invite you to participate in our events or surveys, or otherwise communicate with you for marketing purposes, provided that we do so in accordance with the consent requirements that are imposed by applicable law. When we collect your business contact details through our participation at trade shows or other events, we may use the information to follow-up with you regarding an event, send you information that you have requested on our products and services and, with your permission, include you on our marketing information campaigns.

(c) At Kairos, our vision is to simplify digital identity. To do this, provided we have the permission of our clients and it is not prohibited by applicable law, we use the information we collect to improve and develop our Services. This includes building and improving algorithms and developing and testing new checks, products and services.

As part of this work, we train our computers to recognize specific patterns in information and make predictions about new sets of information based on those patterns. This is known as machine learning. We’ve gathered a substantial and unique set of images and fraud data from around the world, from which we can train our machine learning models to locate and extract the information to detect fraud, and to engage in facial recognition and verification.

Where we are acting as a data controller in using information to further develop our Services, we do so on the basis that the processing is necessary for the legitimate interest of the client and Kairos and, where we use special category data, for reasons of substantial public interest. Such interests include measuring and mitigating algorithmic bias with a view to providing fair and inclusive Services, which effectively detect fraud, and are balanced against the rights and freedoms of users. To safeguard the rights and freedoms of users, Kairos has implemented specific measures, including pseudonymisation, where possible, impact assessments and strict security controls to safeguard the fundamental rights and the interests of the users.

 

4. How We Disclose Personal Information.

Kairos does not sell or rent Personal Information to marketers or unaffiliated third parties. We share your Personal Information with trusted entities, as outlined below.

(a) Service Providers. We share Personal Information with a limited number of our service providers. We have Service Providers that provide services on our behalf, such as identity verification services, website hosting, data analysis, information technology and related infrastructure, customer service, email delivery, and auditing services. These Service Providers may need to access Personal Information to perform their services. We authorize such Service Providers to use or disclose the Personal Information only as necessary to perform services on our behalf or comply with legal requirements. We require such Service Providers to contractually commit to protect the security and confidentiality of Personal Information they process on our behalf. Our Service Providers are predominantly located in the European Union and the United States of America.

(b) Business Partners. We share Personal Information with third party Business Partners when this is necessary to provide our Kairos Services to our Users. Examples of third parties to whom we may disclose Personal Information for this purpose are banks and payment method providers (such as credit card networks) when we provide payment processing services, and the professional services firms that we partner with to deliver the Kairos Software or communication.

(c) Our Licensees and third parties authorized by our Users. We share Personal Information with Users as necessary to maintain a User account and provide the Kairos Services. We share data with parties directly authorized by a User to receive Personal Information. The use of Personal Information by an authorized third party is subject to the third party’s privacy policy.

(d) Corporate transactions. In the event that we enter into, or intend to enter into, a transaction that alters the structure of our business, such as a reorganization, merger, sale, joint venture, assignment, transfer, change of control, or other disposition of all or any portion of our business, assets or stock, we may share Personal Information with third parties for the purpose of facilitating and completing the transaction.

(e) Compliance and harm prevention. We share Personal Information as we believe necessary: (i) to comply with applicable law, or payment method rules; (ii) to enforce our contractual rights; (iii) to protect the rights, privacy, safety and property of Kairos, you or others; and (iv) to respond to requests from courts, law enforcement agencies, regulatory agencies, and other public and government authorities, which may include authorities outside your country of residence.

(f) Kairos may disclose the collected data to third parties, including research institutions and organizations, only for research purposes. The collected data will not be disclosed for commercial or marketing purposes..

 

5. Your Rights and Choices.

You have choices regarding our use and disclosure of your Personal Information:

(a) Opting out of receiving electronic communications from us. If you no longer want to receive marketing-related emails from us, you may opt-out via the unsubscribe link included in such emails. We will try to comply with your request(s) as soon as reasonably practicable. Please note that if you opt-out of receiving marketing-related emails from us, we may still send you important administrative messages that are required to provide you with our Kairos Services.

(b) How you can see or change your account Personal Information. If you would like to review, correct, or update Personal Information that you have previously disclosed to us, You may do so by signing in to your Kairos account or by contacting us.

(c) Your data protection rights. Depending on your location and subject to applicable law, you may have the following rights with regard to the Personal Information we control about you:

- The right to request confirmation of whether Kairos processes Personal Information relating to you, and if so, to request a copy of that Personal Information;

- The right to request that Kairos rectifies or updates your Personal Information that is inaccurate, incomplete or outdated;

- The right to request that Kairos erase your Personal Information in certain circumstances provided by law;

- The right to request that Kairos restrict the use of your Personal Information in certain circumstances, such as while Kairos considers another request that you have submitted (including a request that Kairos make an update to your Personal Information); and

- The right to request that we export to another company, where technically feasible, your Personal Information that we hold in order to provide Kairos Services to you.

Where the processing of your Personal Information is based on your previously given consent, you have the right to withdraw your consent at any time. You may also have the right to object to the processing of your Personal Information on grounds relating to your particular situation.

(d) Process for exercising data protection rights. In order to exercise your data protection rights, you may contact Kairos as described in the Contact Us section below. We take each request seriously. We will comply with your request to the extent required by applicable law. We will not be able to respond to a request if we no longer hold your Personal Information. If you feel that you have not received a satisfactory response from us, you may consult with the data protection authority in your country.

For your protection, we may need to verify your identity before responding to your request, such as verifying that the email address from which you send the request matches your email address that we have on file. If we no longer need to process Personal Information about you in order to provide our Kairos Services or our Sites, we will not maintain, acquire or process additional information in order to identify you for the purpose of responding to your request.

If you are a Customer of a Licensee, please direct your requests directly to the User. For example, if you are making, or have made, a purchase from a merchant using Kairos as a payment processor, and you have a request that is related to the payment information that you provided as part of the purchase transaction, then you should address your request directly to the merchant.

 

6. Security and Retention.

We make reasonable efforts to ensure a level of security appropriate to the risk associated with the processing of Personal Information. We maintain organizational, technical and administrative measures designed to protect Personal Information within our organization against unauthorized access, destruction, loss, alteration or misuse. Your Personal Information is only accessible to a limited number of personnel who need access to the information to perform their duties. Unfortunately, no data transmission or storage system can be guaranteed to be 100% secure. If you have reason to believe that your interaction with us is no longer secure (for example, if you feel that the security of your account has been compromised), please contact us immediately.

If you are licensing the Kairos Software (“Licensee”), we retain your Personal Information as long as we are providing the Kairos Services to you. We may retain Personal Information after we cease providing Kairos Services to you, even if you close your Kairos account, to the extent necessary to comply with our legal and regulatory obligations, and for the purpose of fraud monitoring, detection and prevention. We also retain Personal Information to comply with our tax, accounting, and financial reporting obligations, where we are required to retain the data by our contractual commitments to our financial partners, and where data retention is mandated by the payment methods that we support. Where we retain data, we do so in accordance with any limitation periods and records retention obligations that are imposed by applicable law.

 

7. International Data Transfers.

We are a global business. Personal Information may be stored and processed in any country where we have operations or where we engage service providers. We may transfer Personal Information that we maintain about you to recipients in countries other than the country in which the Personal Information was originally collected, including to the United States. Those countries may have data protection rules that are different from those of your country. However, we will take measures to ensure that any such transfers comply with applicable data protection laws and that your Personal Information remains protected to the standards described in this Privacy Policy. In certain circumstances, courts, law enforcement agencies, regulatory agencies or security authorities in those other countries may be entitled to access your Personal Information.

If you are located in the European Economic Area (“EEA”) or Switzerland, we comply with applicable laws to provide an adequate level of data protection for the transfer of your Personal Information to the US. Kairos Inc. is certified under the EU-U.S. and the Swiss-U.S. Privacy Shield Framework and adheres to the Privacy Shield Principles. In addition, we have implemented intra-group data transfer agreements which you may view upon request.

Where applicable law requires us to ensure that an international data transfer is governed by a data transfer mechanism, we use one or more of the following mechanisms: EU Standard Contractual Clauses with a data recipient outside the EEA, verification that the recipient has implemented Binding Corporate Rules, or verification that the recipient adheres to the EU-US and Swiss-US Privacy Shield Framework.

 

8. Use by Minors.

The Kairos Services are not directed to individuals under the age of thirteen (13), and we request that they not provide Personal Information through the Kairos Services.

 

9. Updates To this Privacy Policy and Notifications.

We may change this Privacy Policy from time to time to reflect new services, changes in our Personal Information practices or relevant laws. The “Last updated” legend at the top of this Privacy Policy indicates when this Privacy Policy was last revised. Any changes are effective when we post the revised Privacy Policy on the Kairos Services. We may provide you with disclosures and alerts regarding the Privacy Policy or Personal Information collected by posting them on our website and, if you are a User, by contacting you through your Kairos Dashboard, email address and/or the physical address listed in your Kairos account.

 

10. Links To Other Websites.

The Kairos Services may provide the ability to connect to other websites. These websites may operate independently from us and may have their own privacy notices or policies, which we strongly suggest you review. If any linked website is not owned or controlled by us, we are not responsible for its content, any use of the website or the privacy practices of the operator of the website.

 

11. Jurisdiction-specific Provisions.

If you live in the European Union and would like to have your Personal Information deleted, please email This email address is being protected from spambots. You need JavaScript enabled to view it. and we will delete any non-anonymized data within 48 hours of the request.

If you have any questions or complaints about this Privacy Policy, please send an email to This email address is being protected from spambots. You need JavaScript enabled to view it. with the subject line “PRIVACY POLICY INQUIRY” or send physical mail to:

Kairos AR, Inc.
1007 North Orange Street 4th Floor #82
Wilmington, DE 19801
United state of America

Attention: Kairos Legal