Privacy

Privacy Policy

Your data, on your terms. Here's how HYKLA handles it.

Effective May 25, 2026

← Back to home

HYKLA is built on the principle that enterprises can adopt AI without giving up control or transparency. This Privacy Policy explains what we collect, why, who we share it with, and the rights you have. For privacy questions, write to privacy@hykla.ai.

1. Who We Are

HYKLA Technologies ("HYKLA", "we", "us") provides the HYKLA Enterprise Knowledge OS. This Privacy Policy explains how we collect, use, share, and protect personal data when you visit our websites, sign up for an account, or use the HYKLA platform.

For data you upload as a customer ("Customer Data"), HYKLA acts as a processor on behalf of your organization. For account, billing, and website data, HYKLA acts as a controller.

2. Information We Collect

We collect the following categories of personal data:

  • Account data — name, work email, organization, role, password hash, language and theme preferences.
  • Customer Data — processes, KPIs, events, documents, and messages you submit to the platform.
  • Usage data — pages visited, features used, IP address, browser, device, timestamps, performance metrics.
  • Billing data — billing contact, plan, invoice history. Card details are handled by our payment processor; we do not store full card numbers.
  • Support data — messages you send to our support team and related metadata.
  • AI interaction data — prompts and responses exchanged with the AI COO, used to deliver and improve the feature.

3. How We Use Personal Data

We use personal data to:

  • provide, secure, and improve the Service;
  • authenticate users and enforce role-based access controls;
  • operate billing and customer support;
  • send service notifications and (where permitted) marketing emails;
  • detect abuse, fraud, and security incidents and to comply with legal obligations;
  • generate aggregated, de-identified analytics that do not identify any individual or organization.

We do not sell personal data, and we do not use Customer Data to train foundation models for other customers.

4. Legal Bases for Processing (EEA / UK)

If you are in the European Economic Area or the United Kingdom, we process personal data on one or more of the following legal bases:

  • Contract — to provide the Service you signed up for;
  • Legitimate interests — to secure and improve our products, balanced against your rights;
  • Consent — where required, e.g. for certain cookies or marketing communications;
  • Legal obligation — to comply with applicable laws.

5. How We Share Information

We share personal data only as described below:

  • Sub-processors — vetted cloud, database, email, AI inference, payment, and observability providers that help us run the Service under contract.
  • Within your organization — administrators may have access to your activity inside their workspace.
  • Legal & safety — when required to comply with law or to protect the rights, property, or safety of HYKLA, our customers, or others.
  • Business transfers — in connection with a merger, acquisition, or sale of assets, subject to confidentiality.

6. International Transfers

HYKLA operates globally. Personal data may be processed in countries other than your own. Where required, we rely on appropriate safeguards such as the European Commission's Standard Contractual Clauses, the UK International Data Transfer Addendum, and equivalent mechanisms.

7. Data Retention

We retain personal data for as long as needed to provide the Service, comply with legal obligations, resolve disputes, and enforce our agreements. Customer Data is retained per your subscription and exportable for at least 30 days after termination. Backups follow a rolling deletion schedule.

8. Security

We protect data with encryption in transit (TLS 1.2+) and at rest (AES-256), tenant isolation, role-based access controls, audit logs, secure software development practices, and continuous monitoring. No system is perfectly secure; please report vulnerabilities responsibly to security@hykla.ai.

9. Your Privacy Rights

Subject to applicable law (including GDPR, UK GDPR, and CCPA), you may have the right to:

  • access the personal data we hold about you;
  • correct inaccurate data;
  • delete data ("right to be forgotten");
  • restrict or object to processing;
  • port your data in a structured, machine-readable format;
  • withdraw consent at any time;
  • lodge a complaint with your local data protection authority.

If you are an end user of a HYKLA customer, please direct your request to that customer first. To exercise rights against HYKLA, contact privacy@hykla.ai. We respond within the timeframes required by law.

10. Cookies & Similar Technologies

We use cookies and similar technologies for:

  • Strictly necessary — authentication, session, security, language and theme preference;
  • Analytics — understanding how the Service is used so we can improve it;
  • Functional — remembering settings such as sidebar state.

You can control cookies through your browser settings. Disabling strictly necessary cookies may break parts of the Service.

11. Children

The Service is intended for business use and is not directed to children under 16. We do not knowingly collect personal data from children. If you believe a child has provided us with personal data, please contact us and we will delete it.

12. Changes to This Policy

We may update this Privacy Policy from time to time. Material changes will be announced via the Service or by email at least 30 days before they take effect. The "Effective" date at the top of this page reflects the latest version.

13. Contact Us

For privacy questions or to exercise your rights:

Privacy: privacy@hykla.ai

Security: security@hykla.ai

General: hello@hykla.ai

© 2026 HYKLA Technologies. All rights reserved.