Privacy Policy
Version 2.0 · Last updated: 28 August 2026
Your privacy matters to us. This policy explains, in plain language, how Kuro AI handles your data — where it lives, which AI processes it, who else sees it, and the control you keep over it.
1. Introduction
Kuro Data AI ("Kuro AI", "we", "us" or "our") provides an AI-powered business intelligence platform for small and medium-sized businesses. We take your privacy seriously and are committed to protecting the personal data you share with us.
This policy applies to our website at kurodata.co and to the Kuro AI application at app.kurodata.ai and related services (together, the "Service"). It is written for the UK GDPR and the Data Protection Act 2018, and also covers EU users under the EU GDPR. Please read it together with our Terms of Service and End User Licence Agreement. By using the Service you acknowledge that you have read and understood this policy.
Our data-protection contact is info@kurodata.co. We have not appointed a Data Protection Officer, as our processing does not require one; our Data Protection Impact Assessment records the reasoning.
2. Our Role: Controller or Processor
For your account data, your use of the platform, billing, support and security logs, we are the data controller.
For business data you bring into Kuro — files you upload, and data pulled from services you connect (email, calendar, cloud drive, CRM, accounting, point-of-sale, WhatsApp) — you or your business are the controller and we are your processor. We process that data only to provide the Service to you, on your instructions, and we never use it to train AI models.
If you are a customer, contact or correspondent of a business that uses Kuro and want to exercise your rights over data they hold in Kuro, please contact that business; we will help them respond.
3. Information We Collect
We collect the following categories of information:
- Account information — your name, email address, password (stored hashed), company name, timezone and language, and an optional two-factor authentication secret (stored encrypted).
- Legal records — your acceptance of the End User Licence Agreement (version, date and IP address), your consent choices (type, version, date, IP address and browser), and your email-verification status.
- Content you create — chat messages and conversation history, voice sessions (audio while you speak, and transcripts), files you upload (CSV, XLSX, DOC/DOCX, PDF, TXT, images) together with the text and search embeddings we derive from them, dashboards, automations and reports.
- Connected-service data — the business data described in section 5, from services you choose to connect.
- Usage and security data — IP address, browser and device details, login attempts, session records, an audit log of actions taken, feature usage and quota counters, and AI model usage and cost records.
- Support and complaints — messages you send us through our contact and waitlist forms (handled by our form provider), by email, or through the in-app complaint form.
- Payment information — when paid plans are enabled, subscriptions are processed by our payment provider, Stripe. We never store your full card details on our systems.
We do not ask for special-category data (such as health, ethnicity or religion). If your business data contains it, you are responsible for having a lawful basis to process it, and it is covered by the processor terms in section 2.
4. How We Use Your Information
We use your information to:
- Provide, operate and maintain the Service, including our AI assistant that answers questions and produces insights from your connected data.
- Sync the services you connect and, where you ask, send emails, create calendar events or update CRM records on your behalf.
- Verify your email address, keep your account secure, and send service notices such as password resets and security alerts.
- Process transactions and manage your subscription (when paid plans are enabled).
- Provide customer support, handle complaints, and respond to your enquiries.
- Monitor, secure and improve the performance and reliability of the Service, using aggregated, non-identifying statistics where possible.
- Comply with our legal obligations, including keeping an audit trail of consent changes and data-rights requests.
We rely on a lawful basis for each use: performance of our contract with you (running your account and the features you use); your consent (each optional sync — email, calendar, drive — and any profiling has its own switch in Privacy & Data Rights and can be withdrawn at any time); our legitimate interests (keeping the Service secure, preventing abuse, improving the Service); and compliance with legal obligations (record-keeping, complaints handling, tax records). Where we rely on legitimate interests we have balanced them against your rights, and you can object at any time.
We do not send marketing emails. If we ever introduce them, they will be opt-in only.
5. Connected Services (Integrations)
Every integration is switched on by you and can be disconnected by you at any time from Settings → Integrations. Unless stated otherwise, you authorise access through the provider’s own sign-in screen, which shows you the exact permissions. Data flows from the provider to Kuro’s UK infrastructure; we send data back only where a "write" is listed.
- Google (Sign-in, Gmail, Calendar, Drive) — we read your profile, Gmail messages (including sender, recipients, subject, body and labels), calendar events and attendees, and the metadata and content of Drive files you select for sync. We write only when you ask Kuro to send an email, create or update a calendar event, or create a file on your behalf.
- Microsoft (Sign-in, Outlook, Calendar, OneDrive) — we read your profile, Outlook mail, calendar and OneDrive files. We write only when you ask Kuro to send an email, update a calendar event or save a file. We register change notifications with Microsoft so your sync stays current.
- HubSpot CRM — we read contacts, companies and deals, and Kuro can create, update and delete them when you ask it to. This is a read-and-write integration.
- Xero (accounting) — read-only: invoices, bank transactions, profit and loss, balance sheet, contacts and organisation settings.
- QuickBooks Online (accounting) — read-only when available: invoices, expenses, profit and loss, balance sheet, cash flow and customer list. Kuro has no functions that write to QuickBooks.
- Square, SumUp, Zettle by PayPal (point-of-sale) — read-only: transactions, orders, products and, where the provider exposes them, customer records.
- Epos Now (point-of-sale) — read-only: transactions, products and customer records. Epos Now does not use a sign-in screen; you paste your Epos Now API key and secret into Kuro and we store them encrypted.
- WhatsApp (via the Meta Cloud API) — messages your customers send to your WhatsApp Business number, which Kuro answers as a chat channel, and the replies Kuro sends on your behalf.
We never receive or store card numbers from any point-of-sale provider — only the payment-method type and card brand.
Disconnecting a service removes the stored credentials immediately and stops all further syncing. Data already synced into Kuro stays in your account until you delete it — by the per-service retention setting, by deleting individual items, or by erasing your account (section 10).
6. AI and Your Data
You are interacting with an AI system. Kuro’s chat, voice assistant, document analysis, dashboards, automations and integrations use large language models and other machine-learning models. AI-generated responses are labelled as such in the product.
Your business data is never used to train our AI models or those of any third party. All models we use are hosted for us by Amazon Web Services on Amazon Bedrock, whose terms prohibit the use of customer content for model training; the model vendors do not receive your data.
- Chat and analysis: NVIDIA Nemotron models, running in the UK (AWS London, eu-west-2).
- Document search: Amazon Titan Text Embeddings, running in the UK (eu-west-2).
- Search re-ranking: Cohere Rerank, running in Germany (eu-central-1) — see section 8.
- Voice assistant: Amazon Nova Sonic, running in Sweden (eu-north-1) — see section 8.
AI outputs are generated from your data and may be wrong, incomplete or out of date. They are business analytics, not financial, investment, tax or legal advice, and our system will decline to give regulated advice. Where a Kuro action fails, you will see an error rather than a claim that it succeeded.
Kuro does not make decisions about you that have legal or similarly significant effects. The one form of profiling — optional usage-based engagement scoring — is off by default and consent-based. You can view, stop or delete it in Settings → My Profile, and see, get an explanation of, or contest any scoring decision in Settings → My Decisions, where a human will review it. Nothing in the Service is withheld from you for declining profiling.
To debug and improve the assistant we record model inputs and outputs — your prompts, the context retrieved, and the response — in an LLM-observability tool operated by Langfuse in the EU (Frankfurt), linked to your internal user ID. This is listed as a sub-processor in section 9.
7. Data Storage and Security
All of your data at rest — database, files, cache and backups — is stored in the United Kingdom (AWS London region, eu-west-2), encrypted. Chat, analysis and document embeddings also run in London.
We protect your data with encryption at rest (AWS KMS) and in transit (TLS), row-level security in our database so that every query is scoped to your business, a restricted database role for the application, signed session tokens, hashed passwords, optional two-factor authentication, rate limits on registration and sign-in, encrypted storage of integration credentials, and an audit trail of administrative access. Our release process requires this policy, our record of processing and our impact assessment to be updated before any change that moves data to a new location.
8. International Data Transfers
Two features involve transient processing in the European Economic Area, because the model we use is not available in London:
- Voice assistant — while a voice session is open, your audio stream and the text of the conversation are processed by Amazon Nova Sonic in AWS Stockholm, Sweden (eu-north-1), over a private AWS network path (never the public internet). Nothing is stored in Sweden and the model does not retain your data.
- Search re-ranking — your question and short excerpts of your documents that matched it are sent to Cohere Rerank in AWS Frankfurt, Germany (eu-central-1) to order the results by relevance. Nothing is stored in Germany and the model does not retain your data.
Transfers from the UK to EEA countries are permitted under the UK GDPR without further safeguards because the UK’s adequacy regulations cover the EEA. Any change to these flows will be published here before it takes effect.
Transfers outside the UK and EEA occur only when you connect a service based elsewhere or ask Kuro to use one (sections 5 and 9). Where a provider is in the United States we rely on the UK Extension to the EU–US Data Privacy Framework (the "UK–US Data Bridge") where the provider is certified, and otherwise on the ICO’s International Data Transfer Agreement or Addendum, together with the provider’s own data-processing terms.
9. Who We Share Information With
We do not sell your personal data. We share it only with the providers below, under contracts that restrict them to processing on our instructions, or where the law requires it.
- Amazon Web Services — hosting, database, storage, AI inference (Amazon Bedrock) and email delivery (Amazon SES). United Kingdom (London), with the two transient EEA flows described in section 8.
- Langfuse GmbH — LLM observability (prompts, retrieved context, responses and your internal user ID). European Union (Frankfurt).
- Tavily — web search. When Kuro searches the web for you, the text of your question is sent to Tavily; results are cached in our UK infrastructure.
- Stripe — payments and subscriptions, when paid plans are enabled. Your name, email, plan and internal user ID; card details go directly to Stripe.
- Meta Platforms (WhatsApp Cloud API) — if you use the WhatsApp channel: your customers’ phone numbers and messages, and Kuro’s replies.
- Our website form provider — messages you send through the contact and waitlist forms on kurodata.co.
- The services you connect (Google, Microsoft, HubSpot, Xero, Intuit QuickBooks, Square, SumUp, PayPal Zettle, Epos Now) — these are independent controllers governed by your own agreement with each of them; we retrieve data from them and, for Google, Microsoft and HubSpot, send what you ask us to.
- Legal and safety — where required by law, regulation, legal process or enforceable governmental request, or to protect the rights, property or safety of Kuro AI, our users or others.
- Business transfers — in connection with a merger, acquisition or sale of assets, subject to the protections in this policy.
Kuro staff with administrative access can access account data for support and security under an audited control; they do not routinely read your content.
10. Data Retention
We retain your personal data for as long as your account is active or as needed to provide the Service. In more detail:
- Account and profile — for the life of the account, then deleted on an erasure request.
- Chat history, voice transcripts, uploaded files, embeddings, dashboards and automations — until you delete them or erase your account. We do not currently expire this data automatically.
- Synced email and calendar data — your choice per service (7, 30, 90 or 365 days, or keep until deleted); expired items are removed by a daily job.
- Synced files, CRM, accounting and point-of-sale data — until you delete them or erase your account.
- Consent and EULA records — for the life of the account plus six years, as evidence of consent.
- Audit log, security events and login records (which include IP address and browser details) — retained after account erasure with the user reference removed, for security and accountability.
- Billing and invoices, when enabled — six years after the tax year, as required by HMRC.
- Database backups — automated snapshots with a 35-day retention; erased data disappears from backups as they age out.
- Email-verification and password-reset tokens — 72 hours, or until used.
When you ask us to delete your data, we remove it from our systems immediately, subject to any legal obligation to retain certain records.
11. Your Rights
Under the UK GDPR and EU GDPR you have the right to:
- Access the personal data we hold about you and receive it in a portable format — Privacy & Data Rights → Export My Data downloads everything linked to your account, instantly.
- Request erasure of your data — Privacy & Data Rights → Delete My Data permanently deletes your account, files and all linked records immediately. This cannot be undone.
- Request rectification of inaccurate or incomplete data — edit your profile in Settings, or ask us.
- Restrict or object to processing, including profiling — available in the app and by email.
- Withdraw consent at any time — toggle any consent in Privacy & Data Rights; syncing stops at the next run. Withdrawal does not affect processing that already happened.
- Not be subject to automated decisions with legal or similarly significant effects, and to have any scoring explained, contested and reviewed by a human — Settings → My Decisions.
Requests by email to info@kurodata.co are answered within one month (extendable by two months for complex requests; we will tell you if so). We may ask you to verify your identity. Rights requests are free unless manifestly excessive.
12. Cookies
Kuro uses strictly necessary cookies and browser storage for sign-in, session security and your preferences. The cookie banner in the application offers "analytics" and "marketing" categories so that we can ask for consent before any such cookies are introduced — none are set today, and we use no third-party analytics, advertising or tracking tools. Our website uses a limited number of cookies to operate the site and remember your preferences; you can control cookies through your browser settings.
13. Complaints
If you are unhappy with how we have handled your personal data, or with an AI decision about you, please tell us first: email info@kurodata.co with the subject "Data protection complaint", or use Privacy & Data Rights → Submit a Complaint in the application. We acknowledge complaints within 5 business days and respond in full within 30 days; complex cases may take up to two further months, and we will tell you why. You can ask for an internal review of our response.
You may complain to the Information Commissioner’s Office at any time: Wycliffe House, Water Lane, Wilmslow, Cheshire SK9 5AF · 0303 123 1113 · ico.org.uk/make-a-complaint. EU residents may contact their national data-protection authority. You also have the right to a judicial remedy and, where you have suffered damage, to compensation.
If your data is in Kuro because a business you deal with uses our Service, we will pass your complaint to that business and help them respond.
14. Children’s Privacy
The Service is a business service for adults and is not directed at children. We do not knowingly collect personal data from anyone under the age of 18. If you believe a child has provided us with personal data, please contact us and we will delete it.
15. Changes to This Policy
We may update this Privacy Policy from time to time. We post changes here with a new version number and "Last updated" date. For material changes — especially any new place your data is processed, any new sub-processor, or any new use of AI — we will notify you in the application or by email before the change takes effect.
16. Contact Us
If you have any questions about this Privacy Policy, how we handle your data, or wish to exercise your rights, contact us at info@kurodata.co.