Privacy Notice
1 Who we are
KYRA is operated by Kyra.bot Ltd, company number 17408470, registered at 66 Paul Street, London, EC2A 4NA, United Kingdom (referred to here as “we”, “us” or “KYRA”).
For data-protection questions, contact [email protected].
This Notice explains when KYRA acts as controller. It also describes, for transparency, processing KYRA performs as processor for MSPs and their End Customers.
2 Our roles
We are controller for:
- MSP account registration and administration;
- our direct customer relationship, contracts and communications;
- billing, tax and payment metadata;
- fraud prevention, security monitoring and incident management;
- our websites, marketing, enquiries and product analytics;
- legal claims and compliance.
For End-User support conversations, customer knowledge, connected PSA data and Microsoft 365 data processed under an MSP or End Customer’s instructions, the relevant MSP or End Customer is controller and KYRA is processor or sub-processor. End Users should first direct rights questions about that data to their employer or IT provider.
3 Data we process
MSP account and commercial data
- Name, work email, job role, company, phone and contact preferences.
- Account roles, customer scope and authentication records.
- Password hashes where password login is used; Microsoft SSO identifiers where SSO is used.
- Billing contact, subscription, invoices, credits, payment status and Stripe customer and payment metadata. KYRA does not receive complete card details.
- Contract, Order Form, document version and acceptance records.
- Support requests and communications with KYRA.
Security, audit and usage data
- Login time, IP address, user agent, approximate network or location indicators and success or failure telemetry.
- Session, revocation, role, support-access and impersonation records.
- Configuration, integration, approval, billing and administrative audit events.
- Message, ticket, call and feature usage counts.
- Error logs, diagnostic data and failed-chat records where sharing is enabled.
End-User and Customer data processed on instruction
- Teams, Slack, SMS, phone and widget messages and associated channel identifiers.
- Names, work email addresses, phone numbers and organisation or customer identifiers.
- Voice audio during a call, transcripts, call direction, timing and duration, transfer events and recording state.
- Attachments, screenshots and extracted text.
- Knowledge-base articles, documents, links, embeddings and provenance.
- Microsoft 365 directory, group, licence, device, mailbox, MFA and sign-in information, according to permissions and configuration.
- Requested, approved and completed account, group, licence and session actions.
- PSA tickets, comments, classifications, priorities, status, time and resolution information and technician identifiers.
- Ticket-QA scores, flags and coaching suggestions where that feature is enabled.
- Approver identity, decision and notification records.
Free-text support content may incidentally contain sensitive or special-category information. End Users should submit only information necessary for IT support. Customers should configure access, notices, redaction and retention appropriate to their workforce and use case.
Website, marketing and prospect data
- Website request data, IP address, device and browser information and cookie or storage preferences.
- Optional analytics events where consent is required and given.
- Enquiry, demo, campaign and prospect contact information.
- Publicly available business information used to understand a prospective MSP, where lawful.
- Website-assistant conversations.
4 Purposes and legal bases where KYRA is controller
| Purpose | Typical UK GDPR basis |
|---|---|
| Create and administer MSP Accounts and provide the contracted Service | Contract; legitimate interests for business-user administration |
| Billing, payment and subscription management | Contract; legal obligation for required financial and tax records |
| Authentication, fraud prevention, security monitoring and incident response | Legitimate interests; legal obligation where applicable |
| Customer support and service communications | Contract; legitimate interests |
| Product reliability, capacity and de-identified analytics | Legitimate interests; consent where required for browser analytics |
| Direct marketing to business contacts | Legitimate interests or consent, subject to PECR and opt-out rights |
| Establish, exercise or defend legal claims | Legitimate interests; legal obligation |
| Comply with regulators, courts and law enforcement | Legal obligation |
Where KYRA is processor, the relevant Customer or controller determines the legal basis and purposes.
5 AI processing and automation
KYRA uses AI to retrieve relevant knowledge, generate support answers, summarise and classify content, enrich tickets, review ticket quality and propose actions. End Users are informed that they are interacting with AI unless it is already obvious in context.
AI Outputs can be wrong and should be reviewed according to risk. Privileged Microsoft 365 actions are controlled by configured capability, scope and approval rules. KYRA is not intended to make solely automated decisions producing legal or similarly significant effects on individuals.
Further details are in the AI Transparency and Acceptable Automation Notice.
6 Recipients and sharing
We disclose personal data only where necessary to:
- Subprocessors listed in the Subprocessor Notice;
- customer-selected Microsoft tenants, Slack workspaces, PSAs, documentation systems and other integrations on instruction;
- professional advisers, insurers, auditors and corporate transaction parties under confidentiality;
- authorities, courts or others where legally required or necessary to protect legal rights and safety.
We do not sell personal data or share it for third-party behavioural advertising.
7 International transfers
KYRA’s application, data storage, AI inference and embeddings (Azure OpenAI), and telephony (Azure Communication Services) are hosted in Microsoft Azure UK South. Real-time voice (Azure AI Voice Live) is processed in the EU (Sweden Central). Support content is not routed to US-based AI providers by default. Certain ancillary Subprocessors — for example payment processing (Stripe), transactional email (Brevo, EU) and CDN/DNS (Cloudflare) — may process limited operational data in the United States, European Union or globally.
For Restricted Transfers, we use an applicable adequacy decision or regulation, or appropriate safeguards such as the UK IDTA, UK Addendum or EU SCCs, together with a required transfer assessment and supplementary measures. The current provider and region position is in the Subprocessor Notice.
Support and AI processing of your content takes place in the UK; real-time voice takes place in the EU. This does not extend to the ancillary operational data handled by the payment, email and CDN Subprocessors above, nor to any provider or region a Customer elects to configure under their own contract.
8 Retention
Our retention periods are:
| Data | Default retention |
|---|---|
| MSP account or profile while active | Agreement term |
| Contract, acceptance and essential financial and tax records | Required statutory or business period, ordinarily up to 7 years |
| Security and administrative audit events | 6 years where justified by security or compliance needs; shorter where configured and lawful |
| Login anomaly and failed-auth telemetry | 12 months |
| Support conversations and transcripts | 90 days by default, subject to Customer configuration |
| Voice audio recordings | Not retained unless recording is explicitly enabled; enabled retention shown at configuration and disclosure |
| Attachments and screenshots | Conversation retention or a shorter configured period |
| Usage and cost records | 24 months for operational analytics; billing evidence retained with financial records where necessary |
| Failed-chat content shared with KYRA | 180 days unless deleted sooner |
| Ticket-QA detail | 12 months unless Customer configures shorter |
| Deleted operational Customer or End-Customer data | Export window plus deletion within 30 days |
| Protected backups | Beyond ordinary use and expired within a targeted maximum 90-day backup cycle |
| Marketing prospects | 24 months after last meaningful engagement, unless suppressed or required longer for opt-out evidence |
Legal holds, disputes and law may require limited longer retention. We retain only what is necessary for that purpose and restrict access. A suppression record may be retained to honour an opt-out.
9 Security
We use technical and organisational measures described in the Security Measures Schedule, including access control, tenant isolation, encryption, secrets management, audit and monitoring, secure development, backup and recovery, and incident response appropriate to risk. A trust-center summary is published at our Security & Trust Center.
No system is completely secure. Customers must use available authentication, role, approval and integration controls.
10 Personal data breaches
Where KYRA is processor, it notifies the relevant Customer or controller without undue delay after becoming aware of a confirmed breach affecting Customer Personal Data. The controller determines whether regulator or individual notification is required.
Where KYRA is controller, we assess risk, notify the ICO or other authority within the legally required time where reportable, and inform affected individuals without undue delay where the applicable high-risk threshold is met.
11 Your rights
Depending on applicable law and KYRA’s role, individuals may have rights to access, rectify, erase, restrict or port personal data, object to certain processing, withdraw consent, and complain to a supervisory authority.
For End-User support and M365 data, contact the employer, End Customer or MSP that controls the deployment. KYRA will assist that controller.
For KYRA-controlled data, contact [email protected]. We may verify identity and will respond within the applicable statutory period, ordinarily one month under UK GDPR, subject to permitted extension.
You may complain to the UK Information Commissioner’s Office at ico.org.uk or to another competent authority.
12 Marketing choices
Business contacts can opt out of marketing at any time using the message link or by contacting us. Opting out does not stop contractual, billing, security or service communications.
13 Children
KYRA is a business IT-support service, not a consumer service directed to children. A Customer wishing to deploy it in a school or another environment involving children must obtain KYRA’s prior written agreement and complete appropriate privacy, safeguarding and DPIA steps.
14 EU representation
If KYRA becomes required to appoint an EU representative under Article 27 EU GDPR, the representative’s details will be inserted here before the affected offering begins. Until then, the operator must not claim unrestricted EU availability where that requirement would apply.
15 Changes
We may update this Notice to reflect law, providers or processing. We will publish the effective date and give reasonable advance notice of material changes where required. A Privacy Notice describes processing; continued use is not treated as consent where consent is legally required.
16 Contact
Kyra.bot Ltd (company number 17408470)
66 Paul Street, London, EC2A 4NA, United Kingdom
Privacy and data-protection enquiries: [email protected]
General enquiries: getaria.tech
We aim to respond to data requests within one month under UK GDPR. For complex requests we may extend this by a further two months, in which case we will inform you of the extension and the reason within the first month.