Legal

Privacy Notice

Effective date: 14 June 2026·Responsible party: Incendio Digital Labs (Pty) Ltd·Jurisdiction: South Africa (POPIA)

1. Who we are

Kaion OS is a product of Incendio Digital Labs (Pty) Ltd, a private company registered in South Africa ("IDL", "we", "us", "our"). We are the responsible party for the personal information processed through Kaion OS, as defined in the Protection of Personal Information Act, 4 of 2013 ("POPIA").

Contact us at: kaionos@incendiogroup.co.za

2. Information we collect

We collect the following categories of personal information:

  • Identity information — name, email address, and any profile details you provide during onboarding.
  • Usage data — modules activated, features accessed, interaction timestamps, and session metadata.
  • AI conversation data — messages you send to KAI and the responses generated. These are processed to provide the service and may be retained to improve response quality.
  • Device and technical data — browser type, operating system, IP address, and error logs collected automatically for security and performance purposes.
  • Communication data — emails you send to us, and records of support interactions.

We do not collect South African ID numbers, financial account details, biometric data, or health information through Kaion OS unless a specific module expressly requires it and you have provided explicit consent.

3. Why we collect your information

We process your personal information for the following purposes:

  • Service delivery — to provide, operate, and maintain your Kaion OS workspace.
  • AI orchestration — to enable KAI to respond to your instructions and execute approved actions on your behalf.
  • Communication — to send transactional emails (welcome, action notifications, security alerts).
  • Security and fraud prevention — to protect the platform and your account from unauthorised access.
  • Legal compliance — to fulfil obligations under POPIA, tax law, and other applicable South African legislation.
  • Service improvement — to understand how the platform is used and improve its features (using anonymised and aggregated data where possible).

We will not process your personal information for any purpose incompatible with those listed above without your prior consent.

4. Legal basis for processing

We process your personal information on the following grounds under POPIA:

  • Contract — processing is necessary to perform the service you have signed up for.
  • Consent — where you have explicitly agreed, including consent to KAI executing gated actions on your behalf.
  • Legitimate interest — for security monitoring and platform improvement, where our interest does not override your rights.
  • Legal obligation — where processing is required by South African law.

5. Who we share your information with

We do not sell your personal information. We share it only with the following sub-processors, each bound by appropriate data processing agreements:

  • Anthropic, Inc. (USA) — AI model provider powering KAI. Conversation data is processed on Anthropic's infrastructure. See anthropic.com/privacy.
  • Vercel, Inc. (USA) — hosting and deployment platform. Application data transits Vercel's infrastructure. See vercel.com/legal/privacy-policy.
  • Neon, Inc. (USA) — PostgreSQL database hosting. Your workspace data is stored on Neon's infrastructure. See neon.tech/privacy.
  • Resend, Inc. (USA) — transactional email delivery. Your name and email are shared with Resend solely to deliver emails you have requested. See resend.com/legal/privacy-policy.
  • Microsoft Corporation (USA/Ireland) — where you use Microsoft 365 integrations, relevant data is processed under your own Microsoft agreement.

We may disclose personal information to law enforcement or regulatory authorities where required by South African law, including a valid court order or subpoena.

6. International transfers

Our sub-processors are based in the United States. By using Kaion OS, you acknowledge that your personal information may be transferred to and processed in the United States, which may not provide the same level of protection as South African law. We take steps to ensure appropriate safeguards are in place with each sub-processor.

7. Retention

We retain your personal information for the following periods:

  • Account and profile data — for as long as your account is active, plus 36 months after closure.
  • AI conversation data — 12 months from the date of the conversation, unless you request earlier deletion.
  • Audit log entries — 60 months, required for POPIA compliance and legal defence.
  • Email communication records — 36 months.
  • Anonymised usage analytics — indefinitely (no personal information is retained in anonymised data).

8. Your rights under POPIA

As a data subject, you have the following rights:

  • Right of access — to request a copy of the personal information we hold about you.
  • Right to correction — to request correction of inaccurate or incomplete information.
  • Right to deletion — to request deletion of your personal information, subject to our legal retention obligations.
  • Right to object — to object to processing based on legitimate interest.
  • Right to withdraw consent — where processing is based on consent, you may withdraw it at any time.
  • Right to lodge a complaint — with the Information Regulator of South Africa.

To exercise any of these rights, email kaionos@incendiogroup.co.za with the subject line "POPIA Data Request". We will respond within 30 days.

9. Information Regulator

You have the right to lodge a complaint with the Information Regulator of South Africa if you believe we have processed your personal information unlawfully:

  • Website: inforegulator.org.za
  • Email: inforeg@justice.gov.za
  • Address: JD House, 27 Stiemens Street, Braamfontein, Johannesburg, 2001

10. Security

We implement appropriate technical and organisational measures to protect your personal information against unauthorised access, disclosure, alteration, or destruction. These include encryption in transit (TLS), encryption at rest, role-based access controls, and audit logging of all sensitive AI-assisted actions.

No system is completely secure. If you become aware of a security vulnerability or suspected breach, please notify us immediately at kaionos@incendiogroup.co.za.

11. Changes to this notice

We may update this Privacy Notice from time to time. We will notify you of material changes by email (if you have provided one) and by posting the updated notice at kaion.co.za/privacy with a revised effective date. Continued use of Kaion OS after the effective date constitutes acceptance of the updated notice.