Back to Kavrynt
Kavrynt legal

Privacy Policy

This policy explains how personal information is handled across Kavrynt's public website, multi-tenant service-management platform, support operations, AI-assisted features, and related communications.

Effective
24 July 2026
Version
1.0
Plain-language summary. Kavrynt collects only the information needed to operate, secure, support, and improve the service. Tenant data is separated by access controls. AI assistance is human-governed. Kavrynt does not sell personal information, and it does not use ticket or asset content for third-party advertising.

1. Who we are and when this applies

Kavrynt is operated by Tripartite Genesis Development (“Kavrynt”, “we”, “us”, or “our”). SmartGeeks may act as a technology and service-delivery partner under Kavrynt's instructions and applicable confidentiality obligations.

This Privacy Policy applies when you visit kavrynt.cc, request access, a demonstration, an evaluation workspace or a purchase, use a Kavrynt account, submit or work on a support ticket, communicate through the platform, or otherwise interact with Kavrynt.

It does not replace a customer-specific data-processing agreement, Order Form, employment notice, or other written agreement. Where those documents provide stronger protections or more specific instructions, they control for that processing.

2. Our privacy role

For ticket, asset, user-directory, knowledge-base and other workspace data submitted by or for a customer (“Customer Data”), the customer is generally the controller or responsible party and Kavrynt acts as its processor or operator. The customer decides why that data is processed and controls authorised users, roles, integrations, retention instructions and support workflows.

Kavrynt is generally the controller or responsible party for public enquiries, prospective-customer records, account-security data, commercial administration, essential service telemetry, fraud prevention, platform audit evidence, and information required to meet our own legal obligations.

If you use Kavrynt through an employer, client, school, service provider or other organisation, contact that organisation first about its use of your Customer Data. We will assist it with verified requests as required by law and contract.

3. Information we collect

  • Identity and account data: name, work email, organisation, tenant, user identifier, role, account status, invitation and authentication events.
  • Support contact data: department, office or location, telephone number, WhatsApp number, preferred contact method and your operational-support consent. These details are restricted to authorised support and management users.
  • Ticket and service data: ticket titles, descriptions, categories, urgency, impact, priority, status, attachments, requester-visible messages, internal notes, assignments, approvals, resolution details, feedback, SLA events and status history.
  • IT asset data: device, owner, assigned user, location, manufacturer, model, serial or asset tag, lifecycle, operating-system, warranty, maintenance and linked-ticket information supplied by the customer.
  • Remote-support data: TeamViewer session details deliberately shared for an authorised support session and the related support record. Do not submit permanent passwords or credentials for email, banking, Kavrynt or other accounts.
  • Public enquiry and commercial data: company, contact details, team size, requested plan, seat estimate, billing cycle, purchase-order reference, use case and messages submitted through access, demo, workspace or purchase forms.
  • Technical and security data: IP address, browser and device information, timestamps, session and authentication metadata, request identifiers, integration status, error and performance records, audit events and indicators used for rate-limiting or abuse prevention.
  • AI-operation data: the minimum ticket or workflow context needed for an AI request, generated result, provider/model, prompt-template version, confidence, latency, usage, error status, human acceptance or rejection, override reason and final decision.
  • Communication data: email delivery status, notification events, support correspondence, scheduled reports and information you provide when contacting us.

We obtain information from you, your organisation and its authorised users, configured identity or integration providers, support communications, and the service itself. We may also receive inbound email that your organisation deliberately routes to Kavrynt.

4. Why and on what basis we use it

Depending on the relationship and applicable law, we process personal information to perform a contract, take requested pre-contract steps, comply with law, pursue legitimate operational and security interests, act on a customer's documented instructions, protect vital interests, or rely on consent where consent is the appropriate basis.

  • Provide authentication, tenant access, ticketing, IT asset management, notifications, reporting, remote-support coordination and other requested platform functions.
  • Provision and administer tenants, users, roles, subscriptions, evaluations, purchases and customer relationships.
  • Route, prioritise, assign, troubleshoot, resolve, audit and improve service requests.
  • Generate human-governed AI recommendations, summaries, drafts, predictions and low-risk automation where enabled.
  • Secure Kavrynt, enforce permissions and tenant isolation, detect abuse, investigate incidents, maintain audit evidence and meet legal or regulatory requirements.
  • Send transactional and operational communications. Marketing communications, if introduced, will provide the choices required by applicable law.
  • Measure reliability and feature performance using aggregated or de-identified information where practical.

Where we rely on legitimate interests, we balance those interests against the rights and reasonable expectations of affected people. You may object where applicable. Withdrawing consent does not affect processing that occurred lawfully before withdrawal or processing supported by another lawful basis.

5. AI-assisted processing and human governance

Kavrynt may use AI to interpret intake, recommend classification and priority, suggest assignments or knowledge, draft communications, summarise tickets, identify SLA risk and support other documented workflows. AI outputs may be incomplete or wrong and must be reviewed in context.

Kavrynt records available provenance, confidence and human review evidence. Low-confidence results are escalated; medium-confidence results require human confirmation; only low-risk, reversible actions may be automated at high confidence. AI must not independently perform destructive administration, legal approvals, high-risk access changes or other irreversible privileged actions.

The current OpenAI integration requests store: false and uses a privacy-preserving, hashed safety identifier. We minimise the context sent to a configured AI provider. Customers and users must not place account passwords, payment-card data, unnecessary special category data or other unrelated secrets into tickets or AI fields. Core ticketing is designed to continue when the AI provider is unavailable.

Where applicable law gives you a right not to be subject to a significant decision based solely on automated processing, you may request meaningful information and human review using the contact details below.

6. When information is shared

We do not sell personal information. We share it only as needed to provide and secure the service, follow a customer's instructions, complete a requested transaction, protect rights and safety, or comply with law. Recipients may include authorised users in your tenant, approved support personnel, professional advisers, a buyer in a legitimate corporate transaction subject to safeguards, public authorities where legally required, and the service providers below.

ProviderPurposeWhen used
SupabaseDatabase, authentication and storageCore service
RailwayApplication runtime and hostingCore service
CloudflareDNS, TLS, content delivery and network securityCore service
ResendTransactional email delivery and status eventsEmail features
OpenAIConfigured AI-assisted operationsWhen an AI feature is invoked
Google / MicrosoftFederated sign-inWhen selected and configured
TeamViewerCustomer-enabled remote supportWhen authorised for a session
SmartGeeksTechnology and service-delivery supportAs operationally required

Providers process information under applicable contracts, confidentiality terms and security requirements. The provider list may change as the service evolves. We will give notice of material changes where required by law or contract.

7. International data transfers

Kavrynt and its providers may process information in countries other than the country where it was collected. When required, we use contractual protections, recognised transfer mechanisms, risk assessments and supplementary security measures designed to preserve an appropriate level of protection. Customers may request relevant transfer information or a data-processing addendum at [email protected].

8. Retention, deletion and account closure

We keep personal information only for as long as reasonably necessary for the purpose collected, the active customer relationship, documented customer instructions, security and fraud prevention, dispute resolution, backup cycles, audit integrity, and legal, accounting or regulatory obligations.

Workspace content is generally retained for the subscription or evaluation period and any agreed retrieval or transition period. A customer administrator may request export or deletion subject to the applicable agreement. When retention is no longer required, data is deleted or de-identified through operational and backup cycles.

Protected audit and ticket-history records cannot be selectively altered by ordinary users. This preserves accountability, but it does not make them exempt from the customer's retention schedule, contractual deletion duties or applicable law. We may retain a minimal record of a legal request, consent withdrawal, security incident or suppression preference where necessary to prove compliance.

9. Security and incident handling

Kavrynt uses technical and organisational safeguards appropriate to the service, including tenant-scoped database policies, server-side authorisation, least-privilege role controls, encrypted transport, protected session handling, signed webhooks, rate limits, validation, privileged-action reason capture, immutable or protected audit evidence, monitoring and dependency health checks.

No internet service can guarantee absolute security. Customers remain responsible for choosing authorised administrators, configuring integrations safely, reviewing user access, protecting endpoints and credentials, and promptly reporting suspected compromise. We will investigate credible incidents and notify affected customers or authorities as required by applicable law and contract.

Report a suspected privacy or security incident to [email protected] and, for urgent escalation, copy [email protected]. Do not include passwords or sensitive ticket content in the email.

10. Cookies and local browser storage

Kavrynt currently uses only storage that is necessary or functional for the service: authentication/session state, a secure Command Centre session cookie, interface preferences such as theme or sidebar state, and deployment-version checks. These mechanisms support security, sign-in and the interface; they are not used to build third-party advertising profiles.

Google, Microsoft, TeamViewer or other third-party sites may use their own cookies when you choose their services. Their notices govern that activity. If Kavrynt introduces non-essential analytics or advertising technologies, we will update this notice and request consent where required.

11. Your rights and choices

Depending on where you are and the applicable law—including POPIA, the GDPR or UAE data-protection law—you may have rights to be informed, access personal information, correct inaccurate information, request deletion, restrict or object to processing, receive portable data, withdraw consent, request human review of qualifying automated decisions, and complain to a regulator.

Submit a request to [email protected] with the subject “Privacy rights request”. Tell us your name, organisation, tenant and the right you want to exercise. We may verify identity and authority before acting. If Customer Data is controlled by your organisation, we may refer the request to that organisation and support its response. We respond within the period required by applicable law and explain any lawful limitation.

You may also complain to the regulator in your jurisdiction. In South Africa, this is the Information Regulator. EEA/UK residents may contact their local data-protection supervisory authority. UAE residents may use the applicable federal or free-zone data-protection authority. We would appreciate the opportunity to resolve a concern directly first, but this does not limit your right to complain.

12. Workplace and tenant responsibilities

A tenant administrator may manage your account, assign roles, access workspace records, configure notifications and integrations, and export or delete Customer Data as permitted by the agreement and law. Your organisation is responsible for providing its own notices, obtaining any required permissions, and ensuring its use of Kavrynt is lawful. Do not use a personal workspace for another organisation's confidential information without authority.

13. Children

Kavrynt is a business service and is not directed to anyone under 18. Do not create an account for or deliberately submit personal information about a child unless a customer has a lawful, documented business need and has completed all required safeguards and permissions. Contact us if you believe a child supplied information without appropriate authority.

14. Changes to this policy

We may update this policy to reflect service, provider, legal or operational changes. We will publish the updated version and effective date here and provide additional notice for material changes where required. Previous contractual commitments continue to apply unless lawfully amended.

15. Contact and formal notices

Privacy, legal and general enquiries: [email protected].

Escalations: [email protected].

Operator: Tripartite Genesis Development, Kavrynt service. Our formal service address for contractual notices is the address in the applicable Order Form, invoice or signed customer agreement. If you do not have one, request the current formal service address through the primary contact email above.