Skip to content
Kyria
Privacy policy

Privacy Policy

Last updated September 2026

This policy describes Kyria's actual current data practices and is kept up to date as the platform evolves. It has not yet been through a formal external legal review; if you have a specific compliance question, please contact us directly.

1. Who this policy covers

This policy covers anyone who visits the Kyria site, and all users of the platform - both businesses and non-business users. It does not cover data a business or user chooses to share directly with another business through the platform's messaging features; that exchange is between the parties involved.

2. What we collect

  • Account and business information: name, email address, business name, Legal Entity Identifier (LEI), and registration details you provide.
  • Verification data: the LEI record data used to verify your business, and the outcome of that verification.
  • Messages and files: content you send to connected businesses through the platform, including uploaded attachments.
  • Security and activity data: sign-in history, device/session information, and an audit log of security-relevant actions on your account.
  • Sensitive business data: where applicable, business bank details, which are encrypted at rest and subject to double-approval controls before any change takes effect.

3. How we use it

We use this data to:

  • Verify business identity and maintain the integrity of the network;
  • Provide messaging, notifications, and account functionality;
  • Secure accounts, detect abuse, and investigate reports of misconduct;
  • Maintain the audit trail required for account accountability;
  • Communicate with you about your account or the service.

We do not sell personal data, and we do not use business or message data for advertising.

4. Who we share it with

We do not share your data with any third parties unless required to do so by law. We use infrastructure and hosting providers to operate the platform, under obligations to protect the data they process on our behalf - this is not third-party sharing of your data, it is how the platform is run.

5. Data retention

Our default is to retain account and message data so you keep a full record of your own history. A business can lower its own retention period from account settings. Audit logs recording security-relevant activity are retained independently of this setting to preserve accountability.

6. Your rights

Depending on where you are located, you may have rights to access, correct, or request deletion of your personal data. To exercise any of these rights, contact us at privacy@kyria.work and we will respond directly.

7. Security

We protect data with enforced two-factor authentication, encryption of sensitive fields at rest, HTTPS in transit, and role-based access control. See our security page for details.

8. International use

Kyria is used by businesses in multiple regions, and data may be processed in a different country than where you are located. We take reasonable steps to protect data regardless of where it is processed.

9. Children's privacy

Kyria is intended for use by working professionals and adults. It is not directed at, and should not be used by, individuals under 18.

10. Changes to this policy

We may update this policy as the platform evolves. Material changes will be reflected by updating the date at the top of this page.

11. Contact

Questions about this policy: privacy@kyria.work.