Compliance

DPIA support pack

Last updated: 22 August 2026

How to use this: using AI to process staff and support data can be “high-risk” processing, so as the controller you (the MSP) may need to complete a Data Protection Impact Assessment (DPIA) before rolling KYRA out. KYRA is your processor, so we don’t complete your DPIA for you — but this pack gives you the facts about our processing to drop into your assessment. It is informational, not legal advice; confirm it against your own circumstances.

1 Nature, scope, context & purpose

What the processing is: KYRA is an AI IT-support assistant that answers end-user questions across Microsoft Teams, Slack, a web widget, phone and SMS; retrieves relevant knowledge; can raise/read PSA tickets; and can perform gated Microsoft 365 actions after human approval. Scope: your staff and your clients’ staff/end-users. Context: a B2B service you deploy to your customers; you control which channels, integrations and AI provider are enabled.

2 Personal data & data subjects

3 Recipients, sub-processors & transfers

Recipients are KYRA and the sub-processors on our sub-processor list (including the AI provider, and the telephony/voice providers when the phone channel is used). Some are US-based; those transfers are safeguarded by the UK IDTA and/or EU SCCs. Hosting and storage are in the UK (Azure UK South).

4 Retention

Conversation history is retained for a limited period (currently purged at 90 days) and other records (audit logs, ticket events, failed chats, notifications) per our schedule; on termination we delete or return data per the DPA. Confirm the periods that apply to you as part of your assessment.

5 Necessity & proportionality

KYRA processes only what is needed to answer a request, ground it in your knowledge base, and (where you enable it) raise a ticket or perform an approved action. Data minimisation, tenant isolation and access control limit exposure; the AI provider is controllable per tenant.

6 AI-specific considerations

7 Risks & mitigations

RiskKYRA mitigation
Inaccurate AI answer acted uponAnswers framed as suggestions; privileged actions gated behind human approval; no solely-automated decisions
Excessive data exposure to the AI providerPer-tenant provider control; data minimisation; no special-category data required
Unauthorised cross-tenant accessTenant isolation; role-based access control; audit logging
International transfer risk (US providers)UK IDTA / EU SCCs; UK-South hosting for storage
Credential / secret exposureSecrets encrypted at rest (AES-GCM); users instructed never to share passwords/OTPs; logs record lengths/counts, not secrets
Prompt injection via untrusted contentKB/tickets/messages handled as data, not instructions; schema-validated actions

8 What you still need to do

As the controller you should: confirm your lawful basis; complete your own risk assessment against your context; inform data subjects (privacy notice); and, if a high residual risk remains that you can’t mitigate, consult your supervisory authority (the ICO in the UK) before proceeding. We’re happy to answer reasonable questions to support your DPIA.

Contact

Kyra.bot Ltd — company number 17408470 (registered in England & Wales)

66 Paul Street, London, EC2A 4NA, United Kingdom

Data-protection contact: [email protected]