Draft — not yet reviewed by a lawyer, and not in force.
This wording was prepared to describe what the product actually does, so that a solicitor has something concrete to work from. It is not legal advice and it does not bind anybody. Do not rely on it, publish it, or send it to a client until it has been reviewed and this banner has gone.
Privacy notice
This notice describes what KVAi does with personal data. Most of what passes through the product is not personal data at all — it is an agency's material about its client's medicines — and that material is covered by the data processing agreement instead.
Two different roles
For the accounts of the people who use KVAi, we are the controller: we decide what to collect in order to run the service.
For everything an agency puts into a workspace — briefs, uploaded client documents, outputs and their approval trails — the agency is the controller and we are the processor. We act on their instructions and do not decide what goes in.
What we hold about you, and why
- Your name, work email address, role and initials. To give you an account, put your name against work you approve, and let colleagues see who did what.
- Your password, kept only as a hash, and two-factor details if you enable them. To let you sign in and to protect the account.
- Session records, including IP address and browser. To keep you signed in and to let an administrator end your sessions when your access is removed.
- Your name against approvals and credit ledger entries. Recorded at the moment you act, and retained — see below, because this is the one place we do not delete.
- Billing contact details. Held by Stripe rather than by us; we keep the billing email and, for invoiced accounts, the billing entity, VAT number and purchase order.
Why we are allowed to
For running your account and the service: performance of the contract with your agency. For keeping the service secure and preventing abuse: our legitimate interests. For retaining the approval record: our legitimate interests and, where it applies, a legal obligation — see below.
Your rights, and the one limit on erasure
You can ask for a copy of your data, ask us to correct it, or ask us to erase it. Erasure in KVAi empties your account: your name, email address, password and two-factor details are removed and the account can no longer be used or restored.
What we do not remove is your name where it appears on an approval or a credit ledger entry. An approval is the record that a named human signed off promotional material for a medicine, and a ledger entry is part of the financial record of what an agency owes. Removing the name would not anonymise those records; it would destroy them. We therefore retain the name as it stood at the time of the decision, and nothing else.
For review: this position — that the approver's name is retained under a legal obligation and a legitimate interest rather than erased on request — is the most important thing on this page for a solicitor to confirm or correct. The product is built around it.
You can also complain to the Information Commissioner's Office. We would rather you told us first.
How long we keep things
Account records are kept while your account exists. Approval and credit records are kept under the retention policy published with these documents. Everything in a workspace is removed when an owner deletes the workspace and the grace period ends.
Who else sees it
The organisations listed on the subprocessors page, and nobody else. Several of them are outside the UK, and each transfer is named there.
Automated decisions
KVAi drafts and checks material automatically, but it makes no decision about a person, and nothing it produces takes effect until a person approves it.
Not drafted here, and needed:
The controller's legal identity and registered address, a contact point for data protection enquiries, whether a representative or DPO is required, the transfer mechanism relied on for each non-UK subprocessor, and confirmation of the erasure position above.