KIVEX Privacy Policy
This policy explains how KIVEX processes personal data when operating the KIVEX websites, customer accounts, the KIVEX Hub, orders and support. It also explains the difference between situations in which KIVEX acts as a controller of personal data and situations in which it processes website visitors' data solely on behalf of its Customer.
This is an English translation provided for convenience. In the event of any discrepancy between the Czech and English versions, the Czech version prevails.
Contents
- 1. Controller and contact details
- 2. When KIVEX is a controller and when a processor
- 3. What personal data we process as a controller
- 4. Sources of data
- 5. Purposes and legal bases
- 6. Widget visitor analytics
- 7. AI, voice and training
- 8. Recipients and categories of providers
- 9. Transfers outside the EEA
- 10. Retention periods
- 11. Cookies and similar technologies
- 12. Automated decision-making
- 13. Whether providing data is mandatory or voluntary
- 14. Your rights
- 15. Business communications
- 16. Children
- 17. Complaints
- 18. Changes to this policy
1. Controller and contact details
The controller of personal data for KIVEX's own activities is:
Jakub Macura
Company ID (IČO): 24359939
Drahanovice 143, 783 44, Czech Republic
a natural person doing business under the Trade Licensing Act, registered in the Trade Register
e-mail: [email protected]
(“KIVEX”).
Questions and requests relating to privacy may be sent to the e-mail address above.
2. When KIVEX is a controller and when a processor
2.1. KIVEX as a controller
KIVEX determines the purposes and means of processing, in particular for:
- visitors to KIVEX's own websites;
- persons who create or use a KIVEX account;
- Customers, Consumers and Users of the Hub;
- orders, invoicing and subscription management;
- communication with prospects, and support;
- protection of accounts and infrastructure, prevention of misuse and handling of security incidents;
- its own product analytics for the websites and the Hub, to the extent corresponding to the privacy settings chosen;
- records of legal claims, consents and contractual acts.
2.2. KIVEX as the Customer's processor
When an End User communicates with an Agent deployed on a Customer's website, the controller of the content of the communication and of the related customer purposes is usually that Customer. In that case, KIVEX processes personal data on the Customer's behalf in accordance with its documented instructions and the DPA.
This applies in particular to:
- the text of conversations and text transcripts of voice interactions;
- contact details provided through lead capture;
- requests for hand-off to staff;
- the content of the Customer's knowledge sources;
- conversation topics, summaries and other outputs created for the Customer;
- customer analytics on Agent usage, if the Customer enables it.
Information about the purpose, legal basis and specific duration of such processing should also be provided to the End User by the operator of the website concerned.
2.3. KIVEX's own operational and security purposes
KIVEX may, as an independent controller, process limited technical and security data necessary to protect its own infrastructure, prevent misuse, carry out diagnostics, invoice, exercise its rights or comply with legal obligations. KIVEX does not use this data to build a long-term behavioural profile of a visitor to a Customer's website without an appropriate legal basis.
3. What personal data we process as a controller
Depending on the specific relationship and the features used, we may process, in particular:
- Identification and contact data — name, e-mail, telephone number, organisation, job title, billing details and, where relevant, Company ID (IČO) or other business details. A Company ID is not a condition for concluding a consumer contract.
- Account and access — e-mail, account identifier, Workspace membership, role, sign-in method, verification status, security and audit events.
- Contract and payment data — Order, plan, add-ons, price, billing period, usage, payment status, transaction identifiers, information on acceptance of contractual documents and requests for immediate commencement of the service. KIVEX does not store full payment card numbers in its application database.
- Support and communication — messages, attachments, request history, complaints, withdrawal requests and feedback.
- Technical and security data — IP address, time, user agent, network and sign-in events, error records, rate-limit and anti-abuse events and technical information about the device or session.
- Use of the websites and the Hub — sections visited, features enabled and technical events; optional analytics is enabled only in accordance with the applicable consent status.
- Business contacts and prospects — work contact details, communication history and information relevant to the business relationship, where there is a legal basis for processing them.
Where KIVEX operates its own demonstration Agent as a controller, it may also process the data listed in Article 2.2 to the extent necessary for that demo or for its own customer communication.
4. Sources of data
We obtain data, in particular:
- directly from the person using the account, website, form or Agent;
- from the organisation that gave the User access to the account;
- from the sign-in provider, if the User chooses external sign-in;
- from the payment provider, to the extent necessary to record the transaction;
- from technical use of KIVEX;
- for reasonable B2B communication, also from publicly available professional or company sources, where such processing is lawful.
5. Purposes and legal bases
| Purpose | Legal basis |
|---|---|
| creating an account, concluding and performing the Contract, providing the Service and customer support | performance of a contract or steps taken prior to entering into it |
| recording express requests for immediate commencement of the service, withdrawals, complaints and contract versions | performance of a contract, legal obligation and legitimate interest in proving legal acts |
| invoicing, accounting, tax and statutory records | compliance with a legal obligation |
| security of accounts and infrastructure, prevention of misuse, incident handling | legitimate interest in providing the Service securely and reliably; where applicable, legal obligation |
| necessary technical diagnostics and operational measurement without a long-term visitor profile | legitimate interest in the operation, security and reliability of the Service, to a minimised extent |
| optional product and visitor analytics using a persistent identifier or similar technology | consent where required by the rules on storing or accessing information on a device; subsequent processing depending on the nature of the purpose, typically consent or legitimate interest |
| the “remember conversation” feature expressly enabled by the End User | provision of an expressly requested feature; any other use requires a separate legal basis |
| protection and enforcement of legal claims | legitimate interest or legal obligation |
| our own business communications | legitimate interest or consent depending on the nature of the relationship; sending electronic commercial communications is also governed by Act No. 480/2004 Coll., on Certain Information Society Services |
Where processing is based on legitimate interest, we assess its purpose, necessity, the reasonable expectations of the individuals and the impact on their rights.
6. Widget visitor analytics
6.1. Without analytics consent
Before analytics consent is given, the widget must not create a stable analytics identifier for linking visits of the same anonymous browser across sessions and must not use fingerprinting as a substitute for refused consent.
For necessary operation, security and diagnostics, minimised technical data may be processed on a one-off or short-term basis, for example the Agent identifier, the page path without sensitive query parameters, time, general device category, technical performance and errors. The IP address may be technically available during a network request; it is not used as a substitute identifier for long-term analytics without an appropriate legal basis.
Customer reports without a stable identity may contain only aggregated or modelled metrics and must not be presented as accurate recognition of the same person across visits.
6.2. After analytics consent
After appropriate consent, a pseudonymous, tenant-separated visitor identifier may be created, enabling more accurate measurement of unique and returning visitors. Such an identifier must not, without more, be used to track the same person across unrelated websites of different Customers.
Extended attribution, long-term visitor journeys or Session Replay are used only where they are actually made available, transparently described and covered by an appropriate legal regime.
6.3. Active conversations and remembering history
Once a chat is started, KIVEX may create a temporary identifier necessary to keep messages connected within the active conversation. This identifier is not used for long-term analytics profiling without a separate reason.
If the End User expressly chooses the “remember conversation” feature, an identifier needed to restore the history may be stored on the device. This choice is separate from analytics consent.
7. AI, voice and training
7.1. To generate a response, KIVEX may, to the extent necessary, pass the text of the query, the relevant part of the history, the Agent's instructions and selected parts of knowledge sources to the AI provider involved.
7.2. In voice mode, the audio stream is technically processed on an ongoing basis for speech-to-text conversion, and the response text for voice synthesis. By default, KIVEX stores only the text transcript, not a playable audio recording.
7.3. The standard provision of KIVEX does not rely on using Customer Content or conversation content to train general models of KIVEX or general models of the providers involved. If KIVEX wished in the future to use personal data for a new training purpose, it would first have to establish an appropriate legal basis for such processing, fulfil the duty to inform and, where applicable, obtain the necessary consent; general consent to the use of KIVEX does not in itself permit such use.
8. Recipients and categories of providers
Personal data may be received, to the extent necessary, by:
- authorised KIVEX personnel;
- authorised administrators and Users of the organisation concerned;
- cloud infrastructure and storage providers;
- AI inference providers;
- speech-to-text and voice synthesis providers;
- network protection, CDN, anti-abuse and authentication providers;
- payment and invoicing service providers;
- e-mail and communication infrastructure providers;
- analytics tool providers, only where enabled for the purpose concerned;
- accounting, tax, legal and security advisers bound by appropriate obligations;
- public authorities, where the transfer is required by law;
- a legal successor or acquirer of the business, subject to maintaining appropriate protection.
Some recipients may act as independent controllers for part of their statutory or independently determined purposes, typically, for example, a payment provider or an external sign-in service.
Where KIVEX processes data as the Customer's processor, it makes the specific identities of the relevant sub-processors available to Customers through the Sub-processor Register in the Hub or on request at [email protected]. This public Privacy Policy uses categories of recipients and need not list KIVEX's complete technology stack.
9. Transfers outside the EEA
KIVEX prefers processing within the European Economic Area; however, some of the services involved may include processing in, or remote access from, third countries, in particular the United States of America.
Where personal data is transferred outside the EEA, KIVEX uses a mechanism permitted by Chapter V GDPR, depending on the specific situation, in particular:
- an adequacy decision of the European Commission, including the EU–US Data Privacy Framework for recipients covered by it;
- standard contractual clauses approved by the European Commission;
- another valid mechanism and, where necessary, supplementary technical or organisational measures.
Information on the mechanism used for a specific category of transfer, and a copy of the relevant safeguards, may be requested at [email protected], provided this does not affect the rights of others, trade secrets or system security.
10. Retention periods
We retain data only for as long as necessary for the purpose of processing, performance of the contract, a legal obligation or the protection of rights. Typically:
| Category | Period or criterion |
|---|---|
| account and membership | for as long as the account exists and thereafter for as long as necessary to close the account, handle claims, ensure security and comply with legal obligations |
| orders, records of acceptance of contractual documents and payment metadata | for the term of the Contract and thereafter for as long as necessary for accounting, tax, complaint-handling and legal obligations |
| accounting and tax documents | for the period set by applicable law |
| support, complaints and legal communications | until resolved and thereafter for a period appropriate to the nature of the relationship and possible legal claims |
| routine technical and security logs | by default no more than 30 days; a record relating to a specific incident, misuse or legal claim may be retained separately for as long as necessary |
| customer conversations, text transcripts, leads, topics and summaries processed on behalf of the Customer | standard maximum retention by plan: Free 7 days, One 30 days, Pro 90 days, Advanced 365 days, Scale 730 days; Custom under the Order; earlier erasure may result from the Customer's instruction or the law |
| analytics visitor identifier | only for the duration of valid consent, by default no longer than 12 months from when it was given or renewed, unless withdrawn or deleted earlier |
| record of privacy choice | for as long as necessary to respect and demonstrate the choice; by default we ask for consent again after no more than 12 months, and we do not ask again for at least 6 months after a refusal unless the processing changes significantly |
Technical backups, if made, are used for recovery after an incident and are not used for new purposes. This public Privacy Policy does not promise a specific fixed interval or maximum retention period for backups.
11. Cookies and similar technologies
Information about cookies, localStorage, sessionStorage and similar technologies, their categories, purposes and consent management is set out in KIVEX Cookies and Similar Technologies.
We use necessary technologies without consent only to the extent necessary to transmit a communication or provide a feature expressly requested by the user. We enable optional analytics technologies only after appropriate consent.
12. Automated decision-making
As a controller, KIVEX does not by default use personal data for decisions based solely on automated processing that would in themselves produce legal effects concerning the individual or similarly significantly affect them.
The Customer may use the Agent within its own processes. The Customer, as controller, is responsible for determining the purpose and legal basis of, and for assessing any automated decision-making in, such a customer process; KIVEX provides it with cooperation to the extent set out in the DPA.
13. Whether providing data is mandatory or voluntary
We need data marked as mandatory in particular to create and secure an account, to conclude and perform the Contract, to invoice or to handle a statutory request. Without it, it may not be possible to create the account or provide the requested service.
You do not have to provide optional data. Refusing optional analytics does not prevent you from using the basic features of KIVEX.
14. Your rights
Subject to the conditions of the GDPR, you have, in particular, the right to:
- obtain confirmation as to whether we process your personal data, and request access and a copy;
- request rectification of inaccurate data or completion of incomplete data;
- request erasure, where the statutory conditions are met;
- request restriction of processing;
- receive data in a portable format where the right to data portability applies;
- object to processing based on legitimate interest;
- withdraw consent at any time with effect for the future, without affecting the lawfulness of processing before its withdrawal;
- obtain information about the applicable safeguards for international transfers;
- lodge a complaint with a supervisory authority.
Requests may be sent to [email protected]. KIVEX may reasonably verify the identity and authority of the requester. It will handle the request without undue delay and within the time limits set by the GDPR.
If your request concerns communication with an Agent on a Customer's website, please contact the operator of that website first. KIVEX, as processor, will provide it with the necessary cooperation.
15. Business communications
KIVEX may process the contact details of customers and relevant business contacts for reasonable communication about KIVEX, where there is a legal basis for doing so. The mere public availability of an e-mail address, or the fact that it is a business address, does not automatically mean that unlimited commercial communications may be sent to it.
Electronic commercial communications must be sent in accordance with applicable law, identify the sender and allow an easy way to opt out of further communications. A record of the opt-out may be kept to the minimum extent necessary to respect that choice.
16. Children
Under the Terms of Service, a paid KIVEX account may be created only by a person over 18 years of age. The Service is not intended for the targeted collection of children's personal data through KIVEX's own accounts.
If a Customer deploys an Agent on a service intended for children or other specially protected groups, it is responsible for assessing the legal regime of its processing and must inform KIVEX in advance if such use requires special measures.
17. Complaints
A complaint may be lodged with:
Office for Personal Data Protection (Úřad pro ochranu osobních údajů)
Pplk. Sochora 27
170 00 Prague 7
Czech Republic
uoou.gov.cz
This does not affect the right to contact another competent supervisory authority or a court.
18. Changes to this policy
We publish the current version and its effective date on this page. If a change significantly affects people's expectations or rights, we will inform them of it in an appropriate manner before the new processing begins, where the nature of the change so requires.
Operator: Jakub Macura, Company ID (IČO) 24359939, Drahanovice 143, 783 44, Czech Republic. Contact: [email protected].
All documents are listed in the legal documents overview.

