Kion Assistant

Privacy Policy

How Kion Consulting handles information in Kion Assistant

1. Who we are

Kion Assistant is operated by Kion Consulting (kion.co.za), a company registered in South Africa. For the purposes of the Protection of Personal Information Act, 2013 (POPIA), we are the responsible party for the information described in this policy.

Questions, requests and complaints about this policy go to [kion.assistant@kion.co.za](mailto:kion.assistant@kion.co.za).

2. What this policy covers

This policy covers the Kion Assistant web application, the optional local agent you can install on your own computer, and the messaging channels the product can be reached through, such as Microsoft Teams and WhatsApp.

It does not cover the separate services you choose to connect to Kion Assistant — your Microsoft 365 or Google account, your own databases, your employer's systems. Those remain governed by their own terms and by the agreement between you and their operator.

3. What we collect

Account information. Your email address and a username are required to hold an account. Your name, surname, preferred alias, a short description of yourself, a profile picture, and mobile, WhatsApp or iMessage numbers are all optional, and are stored only if you or your administrator supply them. If you sign in with a password, we store a bcrypt hash of it, never the password.

Sign-in and security records. Every authentication attempt is recorded: the email address attempted, the outcome, the time, the source IP address, the browser or device user agent, and a device name. The same details are kept for active sessions and API keys. These records exist to let us and your administrator investigate account compromise, and they are retained after an account is deleted.

What you create in the product. Your conversations and the assistant's replies, files you upload, documents the product generates for you, knowledge collections you build, notes and the memories the assistant forms about your work, and the record of tools it ran on your behalf, including the inputs and the results.

Data from services you connect. When you connect an account or system, the product holds an access token for it and processes whatever that connection is scoped to reach. Depending on what you authorise, this can include the contents of your mailbox, your calendar, your files, your repositories, or your databases. You choose which connections exist and what each one may do.

Operational records. Approvals you granted or refused, scheduled work, usage and cost figures per model call, and audit events describing what the system did.

4. How we use it

We process the information above in order to:

  • provide the product — answer you, run the tools you ask for, and keep your work available across sessions;
  • keep the assistant useful over time, by retaining conversation history and the memories it forms, which you can review and delete;
  • operate the connections you authorise, and hold the credentials needed to do so;
  • protect the account and the service — detect and investigate unauthorised access, enforce rate limits and approval gates, and maintain an audit trail;
  • meter and report usage and cost to you and to your administrator;
  • send you transactional messages such as email verification and notifications you have asked for.

Google user data. Kion Assistant's use of information received from Google APIs will adhere to the Google API Services User Data Policy, including the Limited Use requirements. Information received from Google Workspace APIs is not used to develop, improve or train generalised or non-personalised artificial-intelligence or machine-learning models.

5. AI model providers

This is the disclosure that matters most, so it has its own section. To answer you, the product sends the relevant part of your conversation — which may include the content of files, emails or records you asked it to work with — to an artificial intelligence model provider, and receives the reply.

Which provider is used depends on the model your administrator has configured and the model you select. The product is able to use the following, and a provider is only reachable if a key for it has been configured:

PurposeProviders the product can use
Conversation and reasoningAnthropic, OpenAI, Azure OpenAI, DeepSeek, Moonshot, xAI, Mistral, Z.ai, and self-hosted models run on infrastructure we control
Search over your own documentsOpenAI, Voyage AI
Image and screen understandingOpenAI, Anthropic, Moonshot
Speech to text and text to speechYour browser, OpenAI, ElevenLabs, Deepgram, Google, Azure

These providers act as operators on our behalf under their own terms. We do not control their infrastructure, and most process data outside South Africa. Retention at the provider varies by provider and by the commercial terms in place: some retain prompts for a limited period for abuse monitoring. If your work is sensitive enough that this matters, speak to your administrator about which models are enabled, before you use the product for that work.

6. Who else we share information with

Services you connect. When the assistant acts on a connected account, it necessarily discloses to that service what the action requires — the recipient and body of an email it sends for you, the query it runs against your database.

Your organisation. If your account belongs to an organisation, the owner of that organisation can see operational records for every member, including sign-in events with IP addresses, approval decisions, and usage and cost. An organisation owner can also delete or modify sessions belonging to members. Private conversation content is not listed in the administrative views, but an administrator with access to the underlying server can reach it.

Infrastructure providers. The product runs on Amazon Web Services. Email we send on our own behalf is delivered through Microsoft 365.

Legal obligations. We may disclose information where the law requires it, or to establish, exercise or defend a legal claim.

7. Information sent outside South Africa

Our servers and database are hosted in South Africa. However, as section 5 explains, prompt content is sent to AI model providers that generally process it outside South Africa, most often in the United States or the European Union. Some connected services you authorise also store data abroad.

We rely on section 72(1)(b) of POPIA for these transfers: they are necessary for the performance of the contract between you and us, in that the product cannot generate a reply without sending the request to a model. Where a provider offers terms that bind it to an adequate level of protection, we prefer those terms.

8. How long we keep it

Different records have different lives. The main ones:

RecordRetained
Your account and profileUntil the account is deleted
Conversations, files, memories and documentsUntil you or your administrator delete them, or the account is deleted
Model usage and cost records365 days
Security audit events180 days, or 365 days if critical
Detailed tool results and working data7 to 30 days
Evidence supporting a memory90 days
Case files and investigations90 days
Downloaded attachments and generated documents24 hours after the run, where cleanup is enabled

Sign-in and security audit records deliberately survive deletion of the account they refer to, because their purpose is to show what happened to an account, including its removal. They are retained for the periods above and then purged.

9. How we protect it

Traffic to the product is encrypted with TLS. Passwords are stored as bcrypt hashes; API keys and session refresh tokens are stored only as SHA-256 digests. Credentials for connected services, private keys, and the payloads of approval requests are encrypted at rest with a key held separately from the database.

Access is controlled by per-organisation isolation, role checks on every endpoint, rate limits, account lockout after repeated failed sign-ins, and an approval gate that requires a human decision before sensitive actions run. When the assistant is given access to a computer you enrol, that access is limited to the folders and capabilities you grant, is time-boxed, and every action is logged.

10. Your rights

Under POPIA, and under comparable law elsewhere if it applies to you, you may:

  • ask what personal information we hold about you, and receive a copy;
  • ask us to correct or complete information that is inaccurate;
  • ask us to delete information that we no longer have grounds to keep;
  • object to processing, on grounds relating to your situation;
  • withdraw consent you gave, without affecting what was lawful before you did;
  • complain to the Information Regulator, as described below.

Much of this you can do yourself in the product: delete a conversation, a memory, a document or a connected account at any time. For anything else, or to delete your account entirely, write to [kion.assistant@kion.co.za](mailto:kion.assistant@kion.co.za) and we will act within 30 days. If your account belongs to an organisation, we may need to refer your request to its administrator, and we will tell you if we do.

Deleting your account removes your profile and the content attached to it. Sign-in and security audit records are kept for the periods in section 8.

11. Cookies and tracking

We set no cookies. The product keeps your sign-in token in your browser's session storage, which the browser clears when you close the tab, and your interface preferences in local storage on your own device. Neither is sent to any third party.

There is no analytics service, no advertising network, no tracking pixel and no third-party script in this product. We do not track you across other websites.

The web server keeps standard access logs (the requesting IP address, the page asked for and the time) for security and capacity planning. They are held for a short period and are never used to profile anyone.

12. Children

This is a workplace product. It is not directed at children, and we do not knowingly collect information from anyone under 18. If you believe a child has given us information, write to us and we will delete it.

13. Changes to this policy

When this policy changes we will update the version and date shown at the foot of this page. If a change materially affects how we handle your information, we will tell you in the product or by email before it takes effect.

14. Complaints

If you are not satisfied with how we have handled your information, tell us first at [kion.assistant@kion.co.za](mailto:kion.assistant@kion.co.za) so that we have the chance to put it right.

You may also complain to the Information Regulator (South Africa), inforegulator.org.za, at complaints.IR@inforegulator.org.za.