We are a small company that works with brand and market data. This page explains, in plain language, what personal information we collect, why we collect it, who we share it with, how long we keep it, and how you can get it back or have it deleted.
ktau is an AI visibility company based in Toronto, Canada. We help brands understand and improve how large language models describe and recommend them. We operate the website at ktau.ai and the application at app.ktau.ai.
For the purposes of Canadian privacy law (PIPEDA), the UK and EU GDPR, and comparable regimes, ktau is the controller of the personal information described on this page. Our registered address and contact details are in the panel above, and appear in the footer of every page on this site.
This policy covers personal information we handle through our public website, our contact and newsletter forms, our sales and support conversations, and the ktau application.
It does not cover third-party websites we link to, and it does not cover data our customers upload or connect to the ktau application about their own end users. Where a customer instructs us to process data on their behalf inside the application, we act as a processor (or "service provider") and that customer's own privacy policy governs the relationship with their users. Our handling of that data is set out in the agreement we sign with the customer.
We try to collect as little as we can get away with. Concretely:
| Category | What it includes | Where it comes from |
|---|---|---|
| Contact details | Name, business email address, company name, phone number, and anything you type into the message field. | You, via our contact form or by emailing us. |
| Account data | Name, work email, password credentials, workspace and role, billing contact. | You, when you register for or are invited to the ktau application. |
| Usage data | Pages viewed, features used, approximate location derived from IP address, browser and device type, referring page, timestamps. | Automatically, when you use the site or the application. |
| Technical logs | IP address, request metadata, error and security events. | Automatically, from our hosting and infrastructure providers. |
| Brand and market data | Public information about brands, products, publishers and sources, and the outputs of language models when queried about them. | Public web sources and model APIs. This is normally about organisations, not individuals — but it can incidentally include the names of people who write publicly under their own byline. |
| Correspondence | Emails, meeting notes, and support tickets. | You, when you talk to us. |
We do not knowingly collect special-category data (health, biometrics, religion, political opinion, and similar), and we ask that you do not send it to us.
We do not sell personal information, and we do not share it with third parties for their own advertising purposes.
Where the GDPR or UK GDPR applies to you, we rely on the following bases:
Where PIPEDA applies, we rely on your express or implied consent as appropriate to the sensitivity of the information, and on the exceptions PIPEDA allows for business contact information used strictly for business communication.
Our public website runs on Webflow, which sets a small number of cookies that are strictly necessary to serve the site, keep it secure, and remember your preferences. The ktau application sets a session cookie so that you stay signed in.
Where we use analytics to understand aggregate traffic, we configure it to avoid cross-site tracking and advertising profiles. We do not run advertising pixels on this website.
You can block or delete cookies through your browser settings. Blocking strictly necessary cookies may stop parts of the site or the application from working.
We share personal information only with service providers who help us run the business, and only to the extent they need it. Each is bound by contract to protect it and to use it only on our instructions. The categories are:
We may also disclose information if we are legally required to, if we need to establish or defend legal claims, or in connection with a merger, acquisition, or sale of assets — in which case we will tell affected individuals before their information becomes subject to a different privacy policy.
ktau is Canadian, and some of our service providers are located in the United States and elsewhere. That means your personal information may be stored or processed outside your country of residence, and may be accessible to courts and law-enforcement authorities in those jurisdictions.
Where we transfer personal information out of the UK or the European Economic Area, we rely on the European Commission's adequacy decision for Canada or on Standard Contractual Clauses with the receiving party, together with additional safeguards where they are needed.
| Data | Retention |
|---|---|
| Contact form enquiries | 24 months from the last contact, unless the conversation becomes a customer relationship. |
| Account data | For the life of the account, then 90 days after closure, unless you ask us to delete it sooner. |
| Billing and tax records | 7 years, as Canadian tax law requires. |
| Technical and security logs | Up to 12 months. |
| Marketing subscriptions | Until you unsubscribe, plus a suppression record so we do not email you again. |
When a retention period ends we delete the information or irreversibly anonymise it.
We encrypt data in transit with TLS and at rest in our production databases. Access to production systems is limited to the people who need it, protected by multi-factor authentication, and reviewed periodically. We keep audit logs, patch our dependencies, and require confidentiality commitments from everyone who works with us.
No system is perfectly secure. If a breach affects your personal information and creates a real risk of significant harm, we will notify you and the relevant regulator — including the Office of the Privacy Commissioner of Canada — as the law requires.
Depending on where you live, you have some or all of the following rights over the personal information we hold about you:
To exercise any of these, email hello@ktau.ai with the request and enough detail for us to find your records. We will confirm receipt and respond within 30 days. If we need longer we will tell you why. We may ask you to verify your identity first — we will not use that information for anything else.
An authorised agent may make a request on your behalf with written proof of authority.
ktau is a business tool. It is not directed at children, and we do not knowingly collect personal information from anyone under 16. If you believe a child has given us personal information, email hello@ktau.ai and we will delete it.
Our work involves querying commercial language models to observe how they describe brands, and generating content and analysis on behalf of customers. Two commitments follow from that:
Analysis outputs are generated by statistical models and can be wrong. They are decision support, not a statement of fact about any person or company.
We will update this page when our practices change. The effective date and version number at the top always reflect the current text. If a change materially affects your rights, we will give notice by email or a prominent notice on the site before it takes effect.
Questions, requests, and complaints about privacy all go to the same place:
ktau — Privacy
30 Adelaide St E, Toronto, ON, Canada
hello@ktau.ai
We would rather hear from you first, but you always have the right to go straight to a regulator. In Canada that is the Office of the Privacy Commissioner of Canada. In the EEA or UK it is your national data protection authority, or the Information Commissioner's Office in the UK.