Kortexio — Privacy Policy
Effective Date: 12 July 2026 Last Updated: 13 July 2026
This Privacy Policy explains how Kortexio ("Kortexio", "we", "us"), operator of the platform at kortexio.io (the "Service") and our websites, processes personal data. Contact: hello@kortexio.io. Registered legal entity details will be published on this page when confirmed.
Controller vs. Processor. This Policy covers personal data for which we act as controller — chiefly account, billing, website, and support data. Where you use the Service to process personal data contained in your own content (prompts, memory/wiki data, documents), you are the controller and we act as your processor under our Data Processing Agreement (DPA). For that data, your own privacy notices apply.
1. Data We Collect
| Category | Examples | Source |
|---|---|---|
| Account data | Name, business email, company name, role, password hash, authentication identifiers | You (registration via our identity provider) |
| Billing data | Billing address, VAT number, subscription plan, invoices, payment status. Payment card/IBAN details are collected directly by Mollie; we receive only payment confirmation and masked references | You / Mollie |
| Usage and telemetry | Feature usage, API request metadata (timestamps, endpoints, status codes, token counts), log data, IP address, device/browser information | Automatic |
| Support data | Content of support tickets and correspondence | You |
| Website data | Cookie identifiers, analytics events (see Section 7) | Automatic |
| Marketing data | Newsletter subscription status, communication preferences | You |
We do not intentionally collect special categories of personal data as controller. Do not include such data in support tickets.
2. Purposes and Legal Bases (GDPR Art. 6)
| Purpose | Legal basis |
|---|---|
| Creating and administering your account; providing the Service | Contract (Art. 6(1)(b)) |
| Billing, invoicing, payment processing | Contract (Art. 6(1)(b)); Legal obligation (Art. 6(1)(c)) — tax/accounting law |
| Security, fraud prevention, abuse detection, tenant isolation monitoring | Legitimate interests (Art. 6(1)(f)) — protecting the Service and customers |
| Service improvement based on aggregated usage analytics | Legitimate interests (Art. 6(1)(f)) |
| Support and communications about the Service | Contract (Art. 6(1)(b)) |
| Product news and marketing to existing customers | Legitimate interests (Art. 6(1)(f)), with opt-out; otherwise Consent (Art. 6(1)(a)) |
| Compliance with legal obligations and requests from authorities | Legal obligation (Art. 6(1)(c)) |
Where we rely on legitimate interests, we have balanced them against your rights and interests. You may object at any time (Section 6).
3. Sharing and Recipients
We share personal data only with:
- Payment provider: Mollie B.V. (Netherlands) — payment processing (independent controller/processor for payment data under its own terms).
- Hosting provider: Hostinger International Ltd — infrastructure hosting in the European Union (Germany datacenter).
- Analytics provider: Plausible Insights OÜ — aggregated, cookieless website analytics.
- Professional advisors and authorities where required by law or to establish, exercise, or defend legal claims.
A current list of sub-processors used to deliver the Service (processor role) is maintained in the DPA, Annex III, and at https://kortexio.io/dpa#annex-iii.
We do not sell personal data. We do not use customer content or personal data to train AI models.
4. International Transfers
Personal data is stored and processed within the European Economic Area. If a transfer outside the EEA ever becomes necessary (e.g., a support tool), we will implement appropriate safeguards under GDPR Chapter V — an adequacy decision or the European Commission's Standard Contractual Clauses, with supplementary measures where needed — and update this Policy.
5. Retention
| Data | Retention |
|---|---|
| Account data | Life of the account + 30 days after deletion request, unless longer retention is legally required |
| Billing/invoicing records | 10 years (Portuguese tax law) |
| Usage logs and telemetry | 12 months, then deleted or irreversibly aggregated |
| Support tickets | 24 months after closure |
| Marketing preferences | Until you withdraw consent or object |
Customer Content processed on your behalf is retained and deleted per the DPA (deletion or return within 30 days of contract end).
6. Your Rights
Under the GDPR you have the right to: access your data; rectify inaccurate data; erase data; restrict processing; data portability; object to processing based on legitimate interests, including direct marketing; and withdraw consent at any time (without affecting prior processing).
To exercise your rights, contact hello@kortexio.io. We respond within one month (extendable by two further months for complex requests, with notice). We may need to verify your identity.
You also have the right to lodge a complaint with a supervisory authority, in particular the Portuguese authority:
Comissão Nacional de Proteção de Dados (CNPD) Av. D. Carlos I, 134 – 1.º, 1200-651 Lisboa, Portugal · www.cnpd.pt
If we process data on behalf of your organization (processor role), we will refer your request to that organization as controller and assist it as required by the DPA.
7. Cookies and Analytics
Our websites use:
- Strictly necessary cookies — session management, authentication, security (no consent required).
- Analytics — Plausible Analytics (Plausible Insights OÜ), used to understand aggregate site usage without cookies or cross-site tracking. No consent banner is required for this cookieless configuration.
We do not use third-party advertising cookies.
8. Security
We apply technical and organizational measures appropriate to the risk, including: encryption in transit (TLS) and at rest; tenant isolation in our multi-tenant architecture; role-based access control and single sign-on via our identity provider; sandboxed tool execution; administrative access restricted to VPN with strong authentication; logging and monitoring; least-privilege access for personnel; and regular backups. Details of the measures applicable to Customer Content are set out in the DPA, Annex II.
No system is perfectly secure. If a personal data breach occurs that is likely to result in a risk to your rights and freedoms, we will notify the competent authority and, where required, affected individuals in accordance with GDPR Arts. 33–34.
9. Automated Decision-Making
We do not make decisions producing legal or similarly significant effects concerning you based solely on automated processing. The Service provides AI-powered functionality operated under your instructions and control; any decisions based on its outputs are made by you.
10. Children
The Service is intended for business users and is not directed to children under 18. We do not knowingly collect personal data from children.
11. Changes to This Policy
We may update this Policy. Material changes will be announced by email or in-app notice at least 15 days before taking effect. The "Last Updated" date reflects the latest revision.
12. Contact
Kortexio Contact: hello@kortexio.io