1. Overview
Kanrix Systems Inc ("Kanrix", "we", "us", or "our"), registered at 8 The Green, Ste A, Dover, Kent County, Delaware 19901, United States, provides a B2B strategy deployment and KPI management product, and operates the marketing website at kanrix.com (together, the "Service" where the context requires).
This Privacy Policy explains what personal data we collect, how we use it, who we share it with, and what rights you have. It applies to website visitors, business leads, and business customers/users of the Kanrix platform.
We aim to collect only the personal data needed to respond to enquiries, provide demos, and deliver the B2B product. We are committed to processing personal data in accordance with applicable laws, including the EU GDPR, the UK GDPR, and the California CCPA/CPRA, where they apply.
2. Data We Collect
We do not collect payment card or other payment instrument details on the kanrix.com marketing website. Commercial terms and invoicing for the B2B product are handled separately with the customer organisation.
2.1 Marketing website (kanrix.com)
When you use the public website, we may collect:
- Contact form (required fields): first name, company email, message, and email-consent confirmation.
- Contact form (optional fields): last name, job title, company, phone, inquiry type, and country — only if you choose to provide them.
- Demo booking: business contact and scheduling details you enter when booking via Cal.com.
- Technical data: standard server/log data such as IP address, browser type, and pages requested (via our hosting provider), and similar data if optional analytics is enabled with your consent.
- On-device preferences: theme, language, cookie choice, and free-tool worksheet drafts stored in your browser (localStorage) — not sent to us unless you submit a form or enable optional analytics.
2.2 Kanrix B2B product (when your organisation uses the platform)
If your organisation becomes a customer, we process only what is needed to provide the product, which may include:
- Business account details: work name, work email, company, and role/permissions for authorised users.
- Customer content: strategy, KPI, project, and related operational data your organisation enters or connects to the product.
- Communications: emails or support messages you send us about the product.
- Product usage/technical data: as needed to operate, secure, and support the service (for example login/session and security logs).
We do not use the marketing website to collect passwords or payment cards. Platform authentication and any future billing arrangements are handled in the product or via separate B2B contracting—not via the public contact form.
3. How We Use Your Data
We use personal data only as needed to:
- Respond to business enquiries and demo requests
- Provide, operate, secure, and support the Kanrix B2B product for customer organisations
- If you use AI Chat, send the query context and relevant result data to an LLM provider so the response can be returned in natural language (we do not use your data to train models)
- If you enable the MCP Server connector, allow your connected LLM or AI client to query authorised product data so it can answer in that tool (you control which client you connect)
- Send product or service-related notices relevant to an enquiry or customer relationship
- Send marketing communications to business contacts where you have consented or where permitted by law (you may opt out at any time)
- Analyse aggregate website usage if you accept optional analytics
- Detect, investigate, and prevent abuse and security incidents
- Comply with legal obligations
We do not sell your personal data. We do not use customer operational content (KPIs, strategy data, projects) for advertising. We do not collect payment information on the marketing website.
4. Legal Basis for Processing (GDPR)
For users in the European Economic Area (EEA), United Kingdom, and other jurisdictions where a legal basis is required, we rely on the following:
| Purpose | Legal Basis |
|---|---|
| Providing the contracted B2B Service | Performance of a contract (Art. 6(1)(b)) |
| Responding to business enquiries and demos | Legitimate interests (Art. 6(1)(f)) / steps prior to contract |
| Product updates & administrative notices | Legitimate interests (Art. 6(1)(f)) |
| Marketing communications | Consent (Art. 6(1)(a)) or Legitimate interests |
| Security and fraud prevention | Legitimate interests (Art. 6(1)(f)) |
| Legal compliance | Legal obligation (Art. 6(1)(c)) |
6. Data Retention
We retain personal data for as long as necessary to fulfil the purposes described in this policy, and no longer than:
- Website enquiries / demo leads: for as long as needed to respond and manage the business relationship, then deleted or minimised when no longer needed.
- Customer account data: for the duration of the organisation’s subscription plus up to 90 days after closure, then deleted or anonymised.
- Platform content (KPIs, projects, strategy data): deleted within 30 days of account closure unless a longer period is required by law or the customer agreement.
- Business records related to a customer contract (for example invoices issued offline): retained as required for tax and accounting obligations.
- Marketing communications: until you unsubscribe or object.
- Support communications: up to 3 years from the most recent interaction.
7. Your Rights
Depending on your location, you may have the following rights regarding your personal data:
- Access: request a copy of the personal data we hold about you.
- Rectification: request correction of inaccurate or incomplete data.
- Erasure: request deletion of your data ("right to be forgotten"), subject to legal obligations.
- Restriction: request that we restrict processing of your data in certain circumstances.
- Portability: receive your data in a structured, machine-readable format.
- Objection: object to processing based on legitimate interests, including direct marketing.
- Withdraw consent: where processing is based on consent, withdraw it at any time without affecting prior processing.
To exercise any of these rights, email hello@kanrix.com. We will respond within 30 days. If you are unhappy with our response, you have the right to lodge a complaint with your local data protection authority.
9. Security
We implement industry-standard technical and organisational measures to protect your personal data, including:
- Encryption at rest (AES-256) and in transit (TLS 1.2 or higher)
- Role-based access controls and principle of least privilege
- Regular security assessments and penetration testing
- Access limited to personnel who need it to operate and support the Service
- Incident response procedures and breach notification processes
If a personal data breach occurs, our notification path depends on our role:
- Where we are the controller (for example website leads and marketing contacts): if the breach poses a risk to individuals’ rights and freedoms, we will notify the relevant supervisory authority without undue delay and, where feasible, within 72 hours of becoming aware of it, and notify affected individuals when required by law.
- Where we are the processor (Customer Content in the Kanrix product processed for your organisation): we will notify the customer organisation without undue delay so they can assess risk and notify their supervisory authority and affected individuals as required. Details and timelines are set out in our Data Processing Agreement (DPA).
10. International Data Transfers
Kanrix Systems Inc is incorporated in the United States. If you are in the EEA, UK, or another region with data-transfer rules, your information may be processed in the United States and other countries where we or our service providers operate.
Where required, we rely on appropriate safeguards such as Standard Contractual Clauses (SCCs) approved by the European Commission and/or the EU-U.S. Data Privacy Framework where applicable. Details are available on request at hello@kanrix.com.
11. EU & UK Representative (Article 27)
Kanrix Systems Inc is established in the United States and is not established in the European Economic Area (EEA) or the United Kingdom.
We have not appointed an EU representative under Article 27 of the EU GDPR, and we have not appointed a UK representative under the UK GDPR, at this time. Privacy requests from individuals in the EEA or UK should be sent to hello@kanrix.com. You may also lodge a complaint with your local supervisory authority.
If we appoint an EU or UK representative in the future, we will update this section with their contact details.
12. California Privacy Rights (CCPA/CPRA)
If you are a California resident, you may have additional rights under the CCPA/CPRA, including the right to know what personal information we collect and why, the right to delete personal information (subject to exceptions), the right to correct inaccurate information, and the right to non-discrimination for exercising your rights.
We do not sell personal information and we do not share personal information for cross-context behavioral advertising as those terms are defined under the CCPA/CPRA.
From website visitors and business leads, categories may include identifiers (such as name and work email), commercial information related to an enquiry (such as inquiry type), and internet/technical data (such as IP address and browser type). We do not collect payment card information on the website. We use this information for the purposes described in Section 3.
To submit a California privacy request, email hello@kanrix.com with the subject line “California privacy request.” We will verify your request and respond as required by law.
13. Children
Kanrix is a B2B product and website. It is not directed at consumers or individuals under 16 years of age. We do not knowingly collect personal data from children. If you believe we have inadvertently collected data from a minor, please contact us immediately at hello@kanrix.com.
14. Changes to This Policy
We may update this Privacy Policy from time to time to reflect changes in our practices or applicable law. When we make material changes, we will notify you by email (if you are a registered user) or by posting a notice on our website at least 30 days before the changes take effect. The updated policy will always be available at kanrix.com/privacy.
15. Contact Us
For any questions about this Privacy Policy or to exercise your data rights:
Controller / business: Kanrix Systems Inc
Address: 8 The Green, Ste A, Dover, Kent County, Delaware 19901, United States
Privacy & general enquiries: hello@kanrix.com