Privacy Policy
1. Who we are
Kitma Studio is operated by Kitma Tech Pte. Ltd. ("Kitma", "we", "us"), a company incorporated in Singapore (UEN 202634861N) with its registered office at 68 Circular Road, #02-01, Singapore 049422.
This policy explains how we collect, use, share and protect personal data when you visit our website, contact us, or use Kitma Studio (the "Service"). It is written to meet the Singapore Personal Data Protection Act 2012 ("PDPA") and, where they apply, the EU and UK GDPR and other local privacy laws.
2. Definitions
- Personal data: information about an identified or identifiable person.
- Customer: the organisation that signs up for Kitma Studio and manages a workspace.
- Customer Content: anything a Customer or its users put into the Service, including chats, files, knowledge, connected app data, and the tools, agents and workflows they build.
- Usage data: information collected automatically when the Service is used, such as log entries and device details.
3. Our role
For website visitors, people who contact us, and account and billing details, we are the data controller (an "organisation" under the PDPA).
For Customer Content, we act as a data processor (a "data intermediary" under the PDPA) on behalf of the Customer. The Customer decides what data goes into its workspace and why. If you are a user in a Customer's workspace, questions about that data should first go to your organisation's administrator.
4. What we collect
- Contact and inquiry details: your name, work email, company, company size, and the message you send us.
- Account details: name, email, role, department and team, profile photo, and sign-in information. Passwords are stored only as secure hashes.
- Billing details: plan, invoices and billing contact. Card details are handled by our payment provider (Stripe). We never see or store full card numbers.
- Customer Content, as defined above.
- Connection credentials: API keys, OAuth tokens and passwords you give us to connect apps, databases and AI model providers. These are encrypted at rest and never shown again after you save them.
- Usage data: IP address, browser and device type, pages and features used, time stamps, error reports, and AI usage such as token counts and cost.
- Cookies: we use essential cookies and local storage to keep you signed in and remember preferences such as light or night mode. If we add analytics cookies, we will ask for consent where the law requires it.
5. How we use personal data
- To provide, run, secure and support the Service.
- To reply to inquiries and arrange walkthroughs.
- To manage accounts, subscriptions, usage limits and billing.
- To send service messages such as sign-in links, approvals, alerts and changes to these terms.
- To detect, prevent and investigate fraud, abuse and security incidents.
- To improve the Service using aggregated or de-identified usage data.
- To send product news, only where you have agreed or the law allows. You can unsubscribe at any time.
- To meet legal obligations.
6. AI processing and your content
- We do not use Customer Content to train AI models, ours or anyone else's.
- To answer a request, the relevant content is sent to the AI model provider chosen for that task. That is either a provider we manage for you, or a provider you connect with your own key ("bring your own key"). When you use your own key, your agreement with that provider also applies.
- Redaction settings let administrators mask sensitive fields before data reaches a model or appears in logs.
- Code the Service generates runs in isolated sandboxes. By default these have no network access.
7. Legal bases (where GDPR applies)
We rely on: performing our contract with you or your organisation; our legitimate interests in running, securing and improving the Service; your consent, for example for marketing emails or optional cookies; and compliance with legal obligations.
8. Who we share data with
- Service providers who help us run the Service, such as cloud hosting (Amazon Web Services), email delivery, payments (Stripe) and customer support. They may only use data to provide their services to us.
- AI model providers selected by Kitma or by the Customer, as described in section 6.
- Apps you connect, when you or your agents act in them.
- Professional advisers and authorities, where the law requires it or to protect rights, safety and security.
- A buyer or successor, if Kitma is involved in a merger, acquisition or sale of assets. We will tell you before your data becomes subject to a different policy.
We do not sell personal data.
9. International transfers
Managed SaaS customers can choose where their workspace data is stored (currently India, EU, US or Singapore). Some processing, such as support or AI model calls, may happen in other countries. Where data leaves its origin country, we use safeguards required by law, such as contractual clauses giving a comparable standard of protection. Self-Hosted customers control where their data is stored.
10. How long we keep data
We keep personal data only as long as needed for the purposes above. Workspace administrators can set how long chat history is kept (30 days to forever) and how long audit logs are kept (90 days to 7 years). When a subscription ends, we delete or return Customer Content within a reasonable period, unless the law requires us to keep it. Inquiries are kept for up to 24 months after our last contact.
11. Security
We use encryption in transit and at rest, an encrypted vault for credentials, role-based access that is closed by default, isolated sandboxes, an append-only audit log, and regular backups. No system is completely secure. If a data breach affects you, we will notify you and the relevant authorities as the law requires.
12. Your rights
Depending on where you live, you may have the right to access, correct, delete or export your personal data, to object to or restrict processing, and to withdraw consent. To make a request, email contact@kitma.ai. We may need to confirm your identity first. If your data is in a Customer's workspace, we will pass your request to that Customer.
You may also complain to a data protection authority, such as Singapore's Personal Data Protection Commission.
13. Children
Kitma Studio is a business service and is not meant for anyone under 18. We do not knowingly collect personal data from children. If you think a child has given us data, contact us and we will delete it.
14. Links to other sites
Our website and the Service may link to other websites and apps. We are not responsible for their privacy practices, so please read their policies.
15. Data Protection Officer
You can reach our Data Protection Officer at contact@kitma.ai (subject: "Data Protection Officer"), or by post at Kitma Tech Pte. Ltd., 68 Circular Road, #02-01, Singapore 049422.
16. Changes to this policy
We may update this policy. We will change the effective date above and, for significant changes, tell you by email or in the Service before they take effect.