Legal

Privacy Notice

Version 2.0  ·  Effective date: 23 August 2026  ·  Last updated: 23 August 2026

Plain-English summary: KYRA is a B2B IT-support platform sold to Managed Service Providers (MSPs). We collect only what we need to run the service, we never sell your data, and you can exercise your data-protection rights at any time. This Notice explains when KYRA acts as controller, and describes for transparency the processing KYRA performs as processor for MSPs and their End Customers.
Contents
  1. Who we are
  2. Our roles
  3. Data we process
  4. Purposes & legal bases
  5. AI processing & automation
  6. Recipients & sharing
  7. International transfers
  8. Retention
  9. Security
  10. Personal data breaches
  11. Your rights
  12. Marketing choices
  13. Children
  14. EU representation
  15. Changes
  16. Contact

1 Who we are

KYRA is operated by Kyra.bot Ltd, company number 17408470, registered at 66 Paul Street, London, EC2A 4NA, United Kingdom (referred to here as “we”, “us” or “KYRA”).

For data-protection questions, contact [email protected].

This Notice explains when KYRA acts as controller. It also describes, for transparency, processing KYRA performs as processor for MSPs and their End Customers.

2 Our roles

We are controller for:

For End-User support conversations, customer knowledge, connected PSA data and Microsoft 365 data processed under an MSP or End Customer’s instructions, the relevant MSP or End Customer is controller and KYRA is processor or sub-processor. End Users should first direct rights questions about that data to their employer or IT provider.

3 Data we process

MSP account and commercial data

Security, audit and usage data

End-User and Customer data processed on instruction

Free-text support content may incidentally contain sensitive or special-category information. End Users should submit only information necessary for IT support. Customers should configure access, notices, redaction and retention appropriate to their workforce and use case.

Website, marketing and prospect data

4 Purposes and legal bases where KYRA is controller

PurposeTypical UK GDPR basis
Create and administer MSP Accounts and provide the contracted ServiceContract; legitimate interests for business-user administration
Billing, payment and subscription managementContract; legal obligation for required financial and tax records
Authentication, fraud prevention, security monitoring and incident responseLegitimate interests; legal obligation where applicable
Customer support and service communicationsContract; legitimate interests
Product reliability, capacity and de-identified analyticsLegitimate interests; consent where required for browser analytics
Direct marketing to business contactsLegitimate interests or consent, subject to PECR and opt-out rights
Establish, exercise or defend legal claimsLegitimate interests; legal obligation
Comply with regulators, courts and law enforcementLegal obligation

Where KYRA is processor, the relevant Customer or controller determines the legal basis and purposes.

5 AI processing and automation

KYRA uses AI to retrieve relevant knowledge, generate support answers, summarise and classify content, enrich tickets, review ticket quality and propose actions. End Users are informed that they are interacting with AI unless it is already obvious in context.

AI Outputs can be wrong and should be reviewed according to risk. Privileged Microsoft 365 actions are controlled by configured capability, scope and approval rules. KYRA is not intended to make solely automated decisions producing legal or similarly significant effects on individuals.

Further details are in the AI Transparency and Acceptable Automation Notice.

6 Recipients and sharing

We disclose personal data only where necessary to:

We do not sell personal data or share it for third-party behavioural advertising.

7 International transfers

KYRA’s application, data storage, AI inference and embeddings (Azure OpenAI), and telephony (Azure Communication Services) are hosted in Microsoft Azure UK South. Real-time voice (Azure AI Voice Live) is processed in the EU (Sweden Central). Support content is not routed to US-based AI providers by default. Certain ancillary Subprocessors — for example payment processing (Stripe), transactional email (Brevo, EU) and CDN/DNS (Cloudflare) — may process limited operational data in the United States, European Union or globally.

For Restricted Transfers, we use an applicable adequacy decision or regulation, or appropriate safeguards such as the UK IDTA, UK Addendum or EU SCCs, together with a required transfer assessment and supplementary measures. The current provider and region position is in the Subprocessor Notice.

Support and AI processing of your content takes place in the UK; real-time voice takes place in the EU. This does not extend to the ancillary operational data handled by the payment, email and CDN Subprocessors above, nor to any provider or region a Customer elects to configure under their own contract.

8 Retention

Our retention periods are:

DataDefault retention
MSP account or profile while activeAgreement term
Contract, acceptance and essential financial and tax recordsRequired statutory or business period, ordinarily up to 7 years
Security and administrative audit events6 years where justified by security or compliance needs; shorter where configured and lawful
Login anomaly and failed-auth telemetry12 months
Support conversations and transcripts90 days by default, subject to Customer configuration
Voice audio recordingsNot retained unless recording is explicitly enabled; enabled retention shown at configuration and disclosure
Attachments and screenshotsConversation retention or a shorter configured period
Usage and cost records24 months for operational analytics; billing evidence retained with financial records where necessary
Failed-chat content shared with KYRA180 days unless deleted sooner
Ticket-QA detail12 months unless Customer configures shorter
Deleted operational Customer or End-Customer dataExport window plus deletion within 30 days
Protected backupsBeyond ordinary use and expired within a targeted maximum 90-day backup cycle
Marketing prospects24 months after last meaningful engagement, unless suppressed or required longer for opt-out evidence

Legal holds, disputes and law may require limited longer retention. We retain only what is necessary for that purpose and restrict access. A suppression record may be retained to honour an opt-out.

9 Security

We use technical and organisational measures described in the Security Measures Schedule, including access control, tenant isolation, encryption, secrets management, audit and monitoring, secure development, backup and recovery, and incident response appropriate to risk. A trust-center summary is published at our Security & Trust Center.

No system is completely secure. Customers must use available authentication, role, approval and integration controls.

10 Personal data breaches

Where KYRA is processor, it notifies the relevant Customer or controller without undue delay after becoming aware of a confirmed breach affecting Customer Personal Data. The controller determines whether regulator or individual notification is required.

Where KYRA is controller, we assess risk, notify the ICO or other authority within the legally required time where reportable, and inform affected individuals without undue delay where the applicable high-risk threshold is met.

11 Your rights

Depending on applicable law and KYRA’s role, individuals may have rights to access, rectify, erase, restrict or port personal data, object to certain processing, withdraw consent, and complain to a supervisory authority.

For End-User support and M365 data, contact the employer, End Customer or MSP that controls the deployment. KYRA will assist that controller.

For KYRA-controlled data, contact [email protected]. We may verify identity and will respond within the applicable statutory period, ordinarily one month under UK GDPR, subject to permitted extension.

You may complain to the UK Information Commissioner’s Office at ico.org.uk or to another competent authority.

12 Marketing choices

Business contacts can opt out of marketing at any time using the message link or by contacting us. Opting out does not stop contractual, billing, security or service communications.

13 Children

KYRA is a business IT-support service, not a consumer service directed to children. A Customer wishing to deploy it in a school or another environment involving children must obtain KYRA’s prior written agreement and complete appropriate privacy, safeguarding and DPIA steps.

14 EU representation

If KYRA becomes required to appoint an EU representative under Article 27 EU GDPR, the representative’s details will be inserted here before the affected offering begins. Until then, the operator must not claim unrestricted EU availability where that requirement would apply.

15 Changes

We may update this Notice to reflect law, providers or processing. We will publish the effective date and give reasonable advance notice of material changes where required. A Privacy Notice describes processing; continued use is not treated as consent where consent is legally required.

16 Contact

Kyra.bot Ltd (company number 17408470)

66 Paul Street, London, EC2A 4NA, United Kingdom


Privacy and data-protection enquiries: [email protected]

General enquiries: getaria.tech

We aim to respond to data requests within one month under UK GDPR. For complex requests we may extend this by a further two months, in which case we will inform you of the extension and the reason within the first month.