1. Who we are
Kion Assistant is operated by Kion Consulting (kion.co.za), a company registered in South Africa. For the purposes of the Protection of Personal Information Act, 2013 (POPIA), we are the responsible party for the information described in this policy.
Questions, requests and complaints about this policy go to [kion.assistant@kion.co.za](mailto:kion.assistant@kion.co.za).
2. What this policy covers
This policy covers the Kion Assistant web application, the optional local agent you can install on your own computer, and the messaging channels the product can be reached through, such as Microsoft Teams and WhatsApp.
It does not cover the separate services you choose to connect to Kion Assistant — your Microsoft 365 or Google account, your own databases, your employer's systems. Those remain governed by their own terms and by the agreement between you and their operator.
3. What we collect
Account information. Your email address and a username are required to hold an account. Your name, surname, preferred alias, a short description of yourself, a profile picture, and mobile, WhatsApp or iMessage numbers are all optional, and are stored only if you or your administrator supply them. If you sign in with a password, we store a bcrypt hash of it, never the password.
Sign-in and security records. Every authentication attempt is recorded: the email address attempted, the outcome, the time, the source IP address, the browser or device user agent, and a device name. The same details are kept for active sessions and API keys. These records exist to let us and your administrator investigate account compromise, and they are retained after an account is deleted.
What you create in the product. Your conversations and the assistant's replies, files you upload, documents the product generates for you, knowledge collections you build, notes and the memories the assistant forms about your work, and the record of tools it ran on your behalf, including the inputs and the results.
Data from services you connect. When you connect an account or system, the product holds an access token for it and processes whatever that connection is scoped to reach. Depending on what you authorise, this can include the contents of your mailbox, your calendar, your files, your repositories, or your databases. You choose which connections exist and what each one may do.
Operational records. Approvals you granted or refused, scheduled work, usage and cost figures per model call, and audit events describing what the system did.
4. How we use it
We process the information above in order to:
- provide the product — answer you, run the tools you ask for, and keep your work available across sessions;
- keep the assistant useful over time, by retaining conversation history and the memories it forms, which you can review and delete;
- operate the connections you authorise, and hold the credentials needed to do so;
- protect the account and the service — detect and investigate unauthorised access, enforce rate limits and approval gates, and maintain an audit trail;
- meter and report usage and cost to you and to your administrator;
- send you transactional messages such as email verification and notifications you have asked for.
Google user data. Kion Assistant's use of information received from Google APIs will adhere to the Google API Services User Data Policy, including the Limited Use requirements. Information received from Google Workspace APIs is not used to develop, improve or train generalised or non-personalised artificial-intelligence or machine-learning models.
5. AI model providers
This is the disclosure that matters most, so it has its own section. To answer you, the product sends the relevant part of your conversation — which may include the content of files, emails or records you asked it to work with — to an artificial intelligence model provider, and receives the reply.
Which provider is used depends on the model your administrator has configured and the model you select. The product is able to use the following, and a provider is only reachable if a key for it has been configured:
| Purpose | Providers the product can use |
|---|---|
| Conversation and reasoning | Anthropic, OpenAI, Azure OpenAI, DeepSeek, Moonshot, xAI, Mistral, Z.ai, and self-hosted models run on infrastructure we control |
| Search over your own documents | OpenAI, Voyage AI |
| Image and screen understanding | OpenAI, Anthropic, Moonshot |
| Speech to text and text to speech | Your browser, OpenAI, ElevenLabs, Deepgram, Google, Azure |
These providers act as operators on our behalf under their own terms. We do not control their infrastructure, and most process data outside South Africa. Retention at the provider varies by provider and by the commercial terms in place: some retain prompts for a limited period for abuse monitoring. If your work is sensitive enough that this matters, speak to your administrator about which models are enabled, before you use the product for that work.
7. Information sent outside South Africa
Our servers and database are hosted in South Africa. However, as section 5 explains, prompt content is sent to AI model providers that generally process it outside South Africa, most often in the United States or the European Union. Some connected services you authorise also store data abroad.
We rely on section 72(1)(b) of POPIA for these transfers: they are necessary for the performance of the contract between you and us, in that the product cannot generate a reply without sending the request to a model. Where a provider offers terms that bind it to an adequate level of protection, we prefer those terms.
8. How long we keep it
Different records have different lives. The main ones:
| Record | Retained |
|---|---|
| Your account and profile | Until the account is deleted |
| Conversations, files, memories and documents | Until you or your administrator delete them, or the account is deleted |
| Model usage and cost records | 365 days |
| Security audit events | 180 days, or 365 days if critical |
| Detailed tool results and working data | 7 to 30 days |
| Evidence supporting a memory | 90 days |
| Case files and investigations | 90 days |
| Downloaded attachments and generated documents | 24 hours after the run, where cleanup is enabled |
Sign-in and security audit records deliberately survive deletion of the account they refer to, because their purpose is to show what happened to an account, including its removal. They are retained for the periods above and then purged.
9. How we protect it
Traffic to the product is encrypted with TLS. Passwords are stored as bcrypt hashes; API keys and session refresh tokens are stored only as SHA-256 digests. Credentials for connected services, private keys, and the payloads of approval requests are encrypted at rest with a key held separately from the database.
Access is controlled by per-organisation isolation, role checks on every endpoint, rate limits, account lockout after repeated failed sign-ins, and an approval gate that requires a human decision before sensitive actions run. When the assistant is given access to a computer you enrol, that access is limited to the folders and capabilities you grant, is time-boxed, and every action is logged.
10. Your rights
Under POPIA, and under comparable law elsewhere if it applies to you, you may:
- ask what personal information we hold about you, and receive a copy;
- ask us to correct or complete information that is inaccurate;
- ask us to delete information that we no longer have grounds to keep;
- object to processing, on grounds relating to your situation;
- withdraw consent you gave, without affecting what was lawful before you did;
- complain to the Information Regulator, as described below.
Much of this you can do yourself in the product: delete a conversation, a memory, a document or a connected account at any time. For anything else, or to delete your account entirely, write to [kion.assistant@kion.co.za](mailto:kion.assistant@kion.co.za) and we will act within 30 days. If your account belongs to an organisation, we may need to refer your request to its administrator, and we will tell you if we do.
Deleting your account removes your profile and the content attached to it. Sign-in and security audit records are kept for the periods in section 8.
12. Children
This is a workplace product. It is not directed at children, and we do not knowingly collect information from anyone under 18. If you believe a child has given us information, write to us and we will delete it.
13. Changes to this policy
When this policy changes we will update the version and date shown at the foot of this page. If a change materially affects how we handle your information, we will tell you in the product or by email before it takes effect.
14. Complaints
If you are not satisfied with how we have handled your information, tell us first at [kion.assistant@kion.co.za](mailto:kion.assistant@kion.co.za) so that we have the chance to put it right.
You may also complain to the Information Regulator (South Africa), inforegulator.org.za, at complaints.IR@inforegulator.org.za.