§ 01 — Identity of the controller
The data controller for kvendra.com, kvendra.ai and Kvendra Cloud is Chronum LLC, a limited liability company incorporated in Wyoming, USA, operating the Kvendra brand. Registered address: 111 NE 1st St, 8th Floor, Miami, FL 33132, Miami-Dade County, United States. EIN 37-2070923. Contact for any privacy matter: security@kvendra.ai.
§ 02 — Scope
This policy covers the websites kvendra.com and
kvendra.ai and the hosted Kvendra Cloud
service at app.kvendra.cloud and
api.kvendra.cloud (account, billing, the hosted
knowledge base and its MCP server). Self-hosted software you run on
your own infrastructure (the Kvendra Platform engine, the CLI and
the Skills plugin used against your own server) sends no data to
Kvendra and is outside this policy.
Kvendra Cloud. To provide the hosted service we process: your account data (email address, username and, if you sign in with GitHub, your GitHub identity); billing data, which is handled by Stripe — Kvendra does not store your card details; the content you and your workspace put in the knowledge base, including files ("Customer Data"), which we store and process to provide the service, including generating search embeddings; and operational logs (such as request metadata and IP addresses) used for security and troubleshooting. The service is hosted on Amazon Web Services in the United States (including Amazon Bedrock for embeddings). We do not sell Customer Data or use it to train AI models. Retention after a subscription ends and deletion are described in the Terms of Service. The Kvendra CLI vault is end-to-end encrypted on your machine: we cannot read its secrets, including in encrypted cloud backups.
§ 03 — Legal bases
We process personal data under these legal bases:
- Contract (GDPR Art. 6.1.b) — for Kvendra Cloud: creating and running your account, billing, and storing and processing the Customer Data you put in the service, as set out in the Terms of Service.
- Consent (GDPR Art. 6.1.a) — for the analytics cookies described in §05. No analytics script is loaded until you click "Accept analytics" in the banner.
- Legitimate interest (GDPR Art. 6.1.f) — for
the lead-dialog form on
/pricing. When you submit this form, the data you typed is sent to our lead-intake service atforms.kvendra.comso we can respond to your B2B inquiry. Processing the inquiry rests on our legitimate interest in answering prospective customers. - Legitimate interest (GDPR Art. 6.1.f) — for the first-party campaign attribution described in §06, with the additional rule for the European Economic Area, the United Kingdom and Switzerland set out there.
- Consent (GDPR Art. 6.1.a) — separately, and only if you tick the optional marketing checkbox, for sending you product updates. This uses a double opt-in: you receive a confirmation email and are only added to the list once you click the confirmation link. You can withdraw at any time via the one-click unsubscribe link in every message.
§ 04 — Purposes of processing
- Measure aggregate site usage (sessions, pages, geography at country level) to improve content priorities.
- Measure conversion of paid campaigns (Google Ads → lead-form submissions) to validate marketing spend.
- Measure which campaigns bring sign-ups and paying customers, per campaign and country, with our own first-party attribution (§06).
- Receive and respond to B2B inquiries submitted through the lead dialogs (purpose
b2b_inquiry, GDPR Art. 6.1.f). - Where you explicitly opt in, send you product updates and news (purpose
marketing, GDPR Art. 6.1.a, double opt-in).
§ 05 — Categories of data
When you opt in to analytics, Google Analytics 4 and Google Ads may process:
- IP address (anonymised — we configure
anonymize_ip: true). - Device and browser information (user-agent, screen size, language).
- Page navigation events (pages viewed, time on page, referrer).
- Conversion events when a lead dialog is submitted — the event name is
lead_submitwith a single parameterlead_type(value:enterprise; earlier submissions also usedteamandsupport-business). No form field contents (name, email, message, etc.) are sent to Google. - Sign-up clicks — when you follow a sign-up link to
app.kvendra.cloud, the eventsignup_clickis sent with two parameters:plan(pro-monthly,pro-yearly,teamorgeneric) andlocation(where on the page the link was). It contains no personal data and is only sent if you accepted analytics.
When you submit a lead dialog, the data you typed (name, email,
company, and the type-specific fields such as role, headcount,
team size, preferred SLA or free-text message) is sent over HTTPS
to our lead-intake service at forms.kvendra.com. That
service runs on Amazon Web Services in the United States: an
API Gateway HTTP endpoint receives the request, a
Lambda function validates it and stores the lead
in a DynamoDB table (system of record), publishes
a notification to Amazon SNS to alert our team,
and — only if you opted in to marketing — sends a double-opt-in
confirmation email via Amazon SES. Alongside the
fields you submit, the service records the consent metadata
(whether you opted in to marketing, the version of this policy you
accepted, the page you submitted from, a server timestamp and the
source IP address) so we can evidence the lawful basis for
processing.
A hidden anti-spam field (a "honeypot") is included in each form;
legitimate browsers leave it empty. We do not send any form field
contents to Google or any advertising network — only the aggregate
lead_submit conversion event described above.
Independently of analytics consent (subject to the rule for the EEA, the UK and Switzerland in §06), we also process:
- Campaign attribution data (campaign parameters, landing path, referring domain, visit time, sign-up country). See § 06.
§ 06 — Campaign attribution (first-party)
When you arrive at kvendra.com from an advertisement or a link that carries campaign parameters, we record which campaign brought you so that we can measure whether our advertising works. This measurement is done by us only: it uses no third-party trackers, and the data is not sent to Google or any other company.
What we record. The campaign parameters in the
address you arrived at: gclid, gbraid and
wbraid (click identifiers added by Google Ads),
utm_source, utm_medium,
utm_campaign, utm_id, utm_term
and utm_content. We also record the page you landed on
(its path only, without any query string), the domain of the site
that referred you (the domain only, never the full address) and the
time of the visit. We keep your first visit and your most recent
visit that came from a campaign or another website.
Where it is stored. In your browser's local storage
on kvendra.com, under the key kvd-attr-v1, for at most
90 days. If you follow a sign-up link, these values are added to
that link so that app.kvendra.cloud can read them.
There they are kept in local storage
(kvd-attr-pending-v1) for at most 24 hours, until you
finish signing up.
What happens when you create an account. Once you have signed up, the values are sent once to our internal reporting system and stored together with your account identifier and the country your sign-up request came from. We work out that country from your IP address at our content-delivery network, and we do not store the IP address itself. We use this record only to calculate aggregate figures per campaign and country, such as sign-ups, paying customers, acquisition cost and return on ad spend. We never show it per person, and we never sell or share it.
Legal basis. Our legitimate interest in measuring
and improving the effectiveness of our own marketing (GDPR Art.
6(1)(f)). If you are in the European Economic Area, the
United Kingdom or Switzerland, or if we cannot tell where you
are, we do not store anything in your browser for this
purpose unless you have accepted analytics in our consent banner.
Without that consent, only the campaign parameters of the page you
are currently viewing are passed along when you click a sign-up
link, and click identifiers (gclid,
gbraid, wbraid) are never passed.
Country cookie. To apply the rule above, our
content-delivery network sets a cookie named kvd-geo
that contains only a two-letter country code. It expires after 24
hours and is strictly necessary for this purpose.
Retention. Browser storage: 90 days (kvendra.com) and 24 hours (app.kvendra.cloud). Our internal record: 25 months from sign-up. It is deleted earlier if you delete your account.
Your choices. You can clear kvd-attr-v1
at any time by clearing this site's data in your browser. You can
object to this processing, or ask us to delete the record linked to
your account, by writing to the contact address in § 13. Objecting
does not affect your account or your subscription.
§ 07 — Third parties
- Google LLC — Google Analytics 4 (measurement) and Google Ads (conversion tracking). Acts as a joint controller / processor for the events described in §05. See policies.google.com/privacy.
- Amazon Web Services, Inc. — hosts the static
site (S3 + CloudFront) and processes server logs (access
timestamps and IPs) for delivery and abuse protection. AWS also
operates the lead-intake service at
forms.kvendra.com(API Gateway + Lambda + DynamoDB + SNS + SES), which stores and routes the contact-form submissions described in §05 and §09. Acts as a processor on our behalf. - Gravatar (Automattic Inc.) — the Kvendra Cloud web application loads your profile image from Gravatar. To do so, your browser sends Gravatar a hash of your email address (not the address itself). If you have no Gravatar profile, a default image is shown. See automattic.com/privacy.
§ 08 — International transfers
Both Google and AWS may process data outside the EEA, in particular in the United States. Transfers rely on the EU-US Data Privacy Framework (DPF) and Google's / AWS's published Standard Contractual Clauses. You can request a copy of the relevant SCC text by writing to security@kvendra.ai.
§ 09 — Retention
- Google Analytics — default 14-month retention on user-level data; configured to the shortest available value (14 months).
- Google Ads — conversion records retained per Google's published policy.
- AWS CloudFront access logs — 90 days, then deleted.
- Lead submissions — stored in DynamoDB with a time-to-live (TTL) of 24 months from submission, after which the record is automatically deleted. Marketing subscribers who confirm double opt-in are held in the SES contact list until they unsubscribe.
- Campaign attribution — browser: 90 days / 24 hours; internal record: 25 months or until account deletion.
§ 10 — Your rights
Under GDPR you have the right to:
- Access the data we hold about you.
- Rectify inaccurate data.
- Erase your data ("right to be forgotten").
- Restrict or object to processing.
- Port your data in a machine-readable format.
- Lodge a complaint with the supervisory authority of your country of residence (in Spain: AEPD).
Send any rights request to security@kvendra.ai. We respond within one month per GDPR Art. 12.3.
§ 11 — Withdraw or change your consent
You can withdraw analytics consent at any time. Click the button below to clear your stored decision; the banner will reappear so you can choose again.
You can also clear the kvd-consent-v1 entry in your
browser's localStorage or refuse cookies in your browser
settings entirely.
If you opted in to marketing updates, you can withdraw that consent independently at any time using the one-click unsubscribe link in any email we send, or by writing to security@kvendra.ai. Withdrawing marketing consent does not affect our handling of a B2B inquiry you submitted.
§ 12 — California residents (CCPA / CPRA)
We do not sell personal information for monetary consideration. Sharing for cross-context behavioural advertising (CCPA's "share" definition) only happens with Google Ads after you opt in. California residents may exercise their CCPA / CPRA rights (know, delete, correct, opt-out of sharing) by writing to security@kvendra.ai. We respond within 45 days.
Campaign attribution data is used only for our own measurement and is not sold or shared for cross-context behavioural advertising. If this changes, we will update this policy beforehand and provide a "Do Not Sell or Share" choice that also honours the Global Privacy Control signal.
§ 13 — Data Protection Officer / contact
Kvendra is below the headcount + processing thresholds that would mandate a formal DPO appointment under GDPR Art. 37. The contact point for all privacy matters is: security@kvendra.ai.
§ 14 — Last updated
Last updated: 2026-10-01. Policy version: v0.10.0.
We will publish a notice at the top of this page when the policy changes materially. Earlier versions are available on request at security@kvendra.ai.