Short version: we collect the account and usage data needed to run the product, we treat the material you upload as yours, we do not train models on it, and you can export or delete it.
01
What we collect
Account data: the name, work email and organisation you give us when you create an account, plus authentication records so we can keep you signed in.
Workspace data: the sources you upload, the rubrics you configure, the deliverables produced, and the approvals recorded against them.
Operational data: logs of requests, errors and runs, used to keep the service working and to investigate problems. These include timestamps, IP address and browser details.
We do not collect special category data, and the product is not designed to hold it. If your material contains it, tell us before a pilot begins.
02
Your content
Uploaded sources and produced deliverables belong to you. We process them to run the product on your instruction, and for no other purpose.
Each customer's workspaces, sources and deliverables are separated. A run cannot read material outside the project it belongs to.
Our staff do not read your content as a matter of routine. Access happens only where you ask for support that requires it, or where we are legally compelled, and it is logged.
03
Models and training
We do not train models on your content. We do not permit our model providers to train on it either, and we contract for that explicitly.
Grading runs send the relevant material to a model provider for the duration of the run. That material is not retained by the provider for training and is not used to improve their models.
Where we improve our own rubrics and prompts, we work from aggregate signals and from material we have written ourselves, not from your deliverables.
04
Sub-processors
We use a small number of third parties to run the service. Each is bound by a data processing agreement. This list is current as of the date above and we will update it here before adding to it.
Cloud hosting, for the application, database and file storage.
A model provider, for grading and drafting runs, contracted not to train on your content.
Error monitoring, for diagnostics and uptime, which receives no workspace content.
Email delivery, for sign-in links and service notices.
05
Retention and deletion
We keep workspace content for as long as the workspace exists. You can export and delete a workspace and its contents at any time, and deletion removes the material rather than hiding it.
Deleted material clears from backups within 30 days. Operational logs are kept for 90 days.
Approval records are kept for the life of the workspace, because an audit trail that can be quietly edited is not an audit trail. Deleting the workspace deletes them with it.
06
Your rights
You can ask for a copy of the personal data we hold about you, ask us to correct it, ask us to delete it, or object to how we are processing it. Write to us and we will respond within 30 days.
Where Kryterea processes material on behalf of your organisation, your organisation is the controller and we act on its instructions. If you are an end user of a customer workspace, raise the request with them first and we will support it.
07
Cookies
The product sets a session cookie so you stay signed in, and stores your theme preference locally. Neither is used for advertising.
We use privacy-preserving analytics on the marketing site to count page views. It does not set tracking cookies and does not build a profile of you.
08
Changes and contact
When this policy changes materially we will say what changed and when, rather than only moving the date at the top. Customers on an active agreement will be told directly.
Questions about this policy, or about how your material is handled, go to the contact page.