Kimara.ai
Privacy Policy
Last Updated: June 25th, 2025
This Privacy Policy explains how Pantheon Software Ltd ("Kimara," "we," "us," or "our") collects, uses, shares, and protects personal information when you visit our website at https://kimara.ai, express interest in our Services, or interact with us in other ways.
1. Introduction
1.1 About This Policy
This Privacy Policy explains how we handle your personal information. By using our website or providing us with your personal information, you acknowledge that you have read and understood this Privacy Policy. If you do not agree with our practices, please do not use our Services or provide us with your information.
1.2 Data Controller
- Pantheon Software Ltd
- Business ID: FI36050587
- Email: privacy@kimara.ai
- Website: https://kimara.ai
1.3 Scope and Consent
By using our website or providing us with your personal information, you acknowledge that you have read and understood this Privacy Policy. If you do not agree with our practices, please do not use our Services or provide us with your information.
2. Information We Collect
2.1 Information You Provide Directly
Early Access Registration:
- Name
- Email address
- Company/Organization name (if applicable)
- Professional role or title (optional)
- Areas of interest in AI tools
- Any additional information you choose to provide in forms or communications
Communications:
- Content of emails or messages you send us
- Feedback, inquiries, or support requests
2.2 Information Collected Automatically
Website Usage Data:
- IP address
- Browser type and version
- Device information (type, operating system)
- Pages visited and time spent
- Referring website
- Date and time of visits
- Geographic location (country/region level)
Session Storage:
We use browser session storage to temporarily store affiliate referral codes when you arrive through a partner link. This is strictly necessary to ensure the service functions correctly and proper attribution occurs. This data is automatically deleted when you close your browser.
2.3 Information from Third Parties
We may receive information about you from:
- Analytics providers (e.g., Google Analytics)
- Marketing partners (with your consent)
- Public databases or social media platforms (where legally permitted)
3. How We Use Your Information
3.1 Legal Basis for Processing
We process your personal data based on the following legal grounds under GDPR:
- Performance of Contract / Strictly Necessary:
- Processing required to provide the Services you've requested
- Ensuring proper functionality including partner attribution
- Legitimate Interests:
- Managing early access registrations
- Improving our website and future Services
- Conducting market research and analysis
- Protecting against fraud and security threats
- Consent:
- Sending marketing communications about our Services
- Sharing your information with selected partners
- Legal Obligations:
- Complying with applicable laws and regulations
- Responding to legal requests from authorities
3.2 Purposes of Processing
- Process and manage early access registrations
- Ensure proper service functionality, including partner attribution
- Send updates about our platform development and launch
- Respond to inquiries and provide support
- Analyze website usage to improve user experience
- Develop and refine our AI Services based on user interest
- Send marketing communications (with your consent)
- Comply with legal obligations
- Protect our rights and prevent misuse of our Services
4. Sharing Your Information
4.1 Service Providers
We may share your information with trusted third-party service providers who assist us in:
- Website hosting and maintenance
- Email delivery services
- Analytics and performance monitoring
- Customer support tools
- Payment processing (when Services launch)
All service providers are contractually required to protect your information and use it only for the purposes we specify.
4.2 Legal Requirements
We may disclose your information when required by law or when we believe disclosure is necessary to comply with legal obligations or court orders, protect our rights, property, or safety, prevent fraud or security threats, or protect the rights and safety of others.
4.3 Business Transfers
In the event of a merger, acquisition, or sale of assets, your information may be transferred to the acquiring entity, subject to the same privacy protections outlined in this policy.
4.4 Aggregated Data
We may share aggregated, anonymized data that cannot identify you personally for research, marketing, or other business purposes.
5. International Data Transfers
Your information may be transferred to and processed in countries outside the European Economic Area (EEA). When we transfer data outside the EEA, we ensure appropriate safeguards are in place, such as:
- Standard Contractual Clauses approved by the European Commission
- Adequacy decisions by the European Commission
- Other legally approved transfer mechanisms
6. Data Retention
We retain your personal information for as long as necessary to fulfill the purposes outlined in this policy, unless a longer retention period is required by law.
- Early access registration data: Until Service launch + 2 years or until you request deletion
- Marketing communications data: Until you unsubscribe + 6 months
- Website analytics data: 26 months
- Session storage data: Automatically deleted when you close your browser
- Legal and financial records: As required by Finnish law (typically 6-10 years)
7. Your Rights Under GDPR
As an EU data subject, you have the following rights. To exercise any of these rights, please contact us at privacy@kimara.ai. We will respond within 30 days.
- Access: Request a copy of the personal data we hold about you.
- Rectification: Request correction of inaccurate or incomplete personal data.
- Erasure ("Right to be Forgotten"): Request deletion of your personal data in certain circumstances.
- Restriction: Request that we limit the processing of your personal data.
- Data Portability: Request your data in a structured, commonly used, machine-readable format.
- Objection: Object to processing based on legitimate interests or for direct marketing purposes.
- Withdraw Consent: Withdraw consent at any time without affecting the lawfulness of prior processing.
- Lodge a Complaint: You have the right to lodge a complaint with the Finnish Data Protection Ombudsman (Tietosuojavaltuutettu) or your local supervisory authority.
8. Data Security
We implement appropriate technical and organizational measures to protect your personal data against unauthorized access, alteration, disclosure, or destruction, including:
- Encryption of data in transit and at rest
- Regular security assessments and updates
- Access controls and authentication measures
- Employee training on data protection
- Incident response procedures
- Regular backups and recovery procedures
However, no method of transmission over the internet is 100% secure. While we strive to protect your personal data, we cannot guarantee absolute security.
9. Children's Privacy
Our Services are not intended for children under 16. We do not knowingly collect personal data from children under 16. If we become aware that we have collected such data, we will promptly delete it.
10. Third-Party Links
Our website may contain links to third-party websites. We are not responsible for the privacy practices of these external sites. We encourage you to review their privacy policies.
11. Changes to This Policy
We may update this Privacy Policy periodically. We will notify you of material changes by posting the updated policy on our website, updating the "Last Updated" date, and sending email notifications for significant changes (if you've provided your email).
12. Contact Information
For questions, concerns, or requests regarding this Privacy Policy or our data practices:
Data Protection Contact:
Pantheon Software Ltd
Email: privacy@kimara.ai
General inquiries: info@kimara.ai