Privacy Policy

Last updated: 16 July 2026 — Effective date: 16 July 2026

1. Introduction

Welcome to kōdlo (“Platform”, “we”, “us”, or “our”). kōdlo is an agent-native sales workspace built for high-ticket B2B deals, combining a multi-tenant CRM with an always-on AI agent. This Privacy Policy explains what personal data we collect, why we collect it, how we use it, who we share it with, and what rights you have. By accessing or using kōdlo (our website at kodlo.ai and the application at app.kodlo.ai, together with related integrations), you agree to the practices described in this Policy.

Our core commitments:

  • We do not sell or “share” your personal data (including within the meaning of the CCPA/CPRA), and we do not use it for cross-context behavioural advertising.
  • We do not share it with anyone other than the sub-processors listed in Section 6.
  • We do not use your Client Workspace Data, prompts, or AI-generated content to train our or any third party’s AI models.
  • Your core workspace data is hosted in the European Union. The kōdlo application, our databases, and the vector stores that hold your Knowledge Hub and long-term-memory data run on EU-based infrastructure (Hetzner, Germany/Finland). Only specific processing operations — managed AI inference, web search, and object storage — involve non-EU sub-processors, each governed by appropriate transfer safeguards (Section 7).

Each commitment is explained below.

2. Who We Are

kōdlo is operated by REINODE SOFTWARE SPÓŁKA Z OGRANICZONĄ ODPOWIEDZIALNOŚCIĄ, NIP 1133173579 (“Company”).

Contact e-mail: info@kodlo.ai

Registered address: ul. GROCHOWSKA nr. 42 lok. 31, 04-282 Warsaw, Poland.

For GDPR purposes, Reinode Software acts as the Data Controller for account and billing data submitted by users directly. Where users upload third-party contact data or process CRM histories, the Client acts as the Data Controller, and kōdlo acts solely as the Data Processor.

As Reinode Software is established within the EU (Poland), we are not required to appoint an Article 27 EU representative.

Business customers acting as Data Controllers may enter into our Data Processing Agreement (DPA), which sets out our Article 28 GDPR processor obligations, the current sub-processor list, and the Standard Contractual Clauses we rely on.

3. Data We Collect

3.1 Account & Identity Data

When you register for kōdlo via Google SSO (OAuth/PKCE) or email/password, we collect:

  • Full name and work e-mail address.
  • Password (secured using Argon2 hashing; we never store plain text).
  • Billing information (handled by our merchant of record, Paddle).

3.2 Client Workspace Data (User-Submitted)

Data you import or generate inside kōdlo (also referred to as “User Data” in our Terms of Use), including:

  • Prospect records, campaigns, timeline events, and file attachments.
  • Knowledge Hub documents you upload (PDF, DOCX, XLSX, CSV, TXT, MD, PPTX) and the text extracted from them.
  • Custom event taxonomies and personal tone-of-voice settings.
  • AI-generated deep-research briefs and outreach drafts.

Important: You are responsible for ensuring you have a lawful basis to process any third-party personal data you import (e.g., via CSV or LinkedIn export).

3.3 Integration & OAuth Data

If you connect third-party channels (e.g., Google SSO, Telegram, Google Chat), we collect the OAuth tokens and metadata needed to route the AI agent’s responses to your authorized devices.

Where you use Google Sign-In or Google Chat, we access only the Google user data needed to deliver those features (your basic Google profile and the messages you exchange with the agent in Google Chat). Our use of this data is described in Section 5 (Google API Services — Limited Use).

3.4 AI Interaction Data

Your prompts, chat sessions, and the AI agent’s tool calls are logged to provide session memory and workspace continuity. Where you enable Long-Term Memory, chat content and artifacts are also converted into numeric vector embeddings stored in your workspace’s private vector collection to support recall across sessions.

Personal memory-profile opt-out: You can disable your personal Long-Term Memory profile in your settings. Doing so stops the building of your personal memory profile and its use in the agent’s responses. Please note, however, that chat content is still converted into vector embeddings within your workspace’s shared memory collection, where it remains searchable to workspace members through the agent.

3.5 Website Visitor Data

When you visit our public website (kodlo.ai), we and our analytics providers — Google Analytics (Google LLC) and Microsoft Clarity (Microsoft Corporation) — collect standard technical information such as your IP address, browser and device type, pages viewed, and referring URLs, and, via Microsoft Clarity, aggregated (masked) session-replay and interaction data, using cookies and similar technologies (see the Cookies section). These analytics cookies are set only after you consent via the website’s cookie banner. We use this data solely for analytics purposes — to operate, secure, and improve the site. Both providers are US-based; transfers are safeguarded by Standard Contractual Clauses and, where applicable, the EU-US Data Privacy Framework. These analytics run on our website only — the application (app.kodlo.ai) uses strictly-necessary cookies and no analytics.

4. Personal Data of Third Parties & AI Research Profiling

A core function of kōdlo is researching prospects. When you or the AI agent build a prospect record or a research brief, the Platform may compile personal data about identifiable third parties, including: name, job title and employer, professional-network activity, publicly reported news and events, and AI-inferred “signals” or contact-readiness assessments. To do this, the agent may use our web-search sub-processor (Exa) to query publicly available web sources and to discover company and person entities — including public person profiles with professional details such as work and education history — as a default capability of the research agent.

For this third-party data, the Client is the Data Controller and is responsible for: having a lawful basis to process it (typically legitimate interest under Article 6(1)(f) GDPR), providing any notice required under Article 14 GDPR, and honouring data-subject requests, including the right to object. kōdlo processes this data solely as a Data Processor on the Client’s instructions.

Automated decision-making & AI transparency: Contact-readiness scores and “next-best-action” suggestions are decision-support outputs intended to be reviewed by a human user. They are not solely automated decisions producing legal or similarly significant effects within the meaning of Article 22 GDPR. kōdlo is an AI-powered system: when you interact with the agent you are interacting with artificial intelligence, and research summaries, drafted messages, and analyses are AI-generated content that you are responsible for reviewing before use. We maintain these transparency practices in line with the transparency obligations under Article 50 of the EU AI Act.

5. Artificial Intelligence and Strict Data Isolation

We understand that your sales strategies are highly confidential. kōdlo operates on a Zero Training Policy:

  • No Model Training: kōdlo does not use your Client Workspace Data, prompts, or generated artifacts to train, retrain, or improve any AI models. Our managed AI providers are contractually bound to the same standard: Google (Gemini API) does not use prompts or responses from its paid API to train or improve its models and processes them as a data processor under its Data Processing Addendum; Mistral (used for document OCR) is an EU provider that processes data within the EU and does not use paid-API content for model training. Where optional providers (OpenAI, Anthropic) are enabled, their business/developer-API terms likewise exclude your content from model training by default.
  • Architectural Isolation: Every database query is automatically scoped to your specific workspace. Cross-tenant access is restricted at the repository layer, returning a “not found” response to prevent information leakage. Knowledge Hub and Long-Term Memory vector collections are provisioned per workspace.
  • Encrypted Secrets: Where you supply your own provider API keys (LLM, Google/Gemini, Mistral, Exa), they are encrypted at rest using Fernet symmetric encryption.

Google API Services — Limited Use

kōdlo’s use of information received from Google APIs (including via Google Sign-In and Google Chat) adheres to the Google API Services User Data Policy, including the Limited Use requirements. Specifically: (a) we use Google user data only to provide and improve user-facing features of the Platform; (b) we do not use it for advertising; (c) we do not allow humans to read it except with your affirmative consent, for security purposes such as investigating abuse, or where required by law; and (d) we do not transfer it to others except as necessary to provide the Platform, to comply with applicable law, or as part of a merger or acquisition.

6. How We Share Your Data (Sub-processors)

We act as a conduit, using trusted sub-processors to operate the Platform securely. We disclose the categories of personal data below to these service providers solely for the business purposes described, and never for their own independent commercial use. The authoritative, dated list — including how we notify you of changes — is also published at kodlo.ai/sub-processors/. Our current sub-processors are:

Sub-processorRoleDataPurposeHosting / regionTransfer mechanism
Hetzner Online GmbHInfrastructure / hostingAll workspace data, databases, vector stores, backupsApplication hosting; PostgreSQL; Qdrant (Knowledge Hub & Long-Term Memory vectors); RedisEU (Germany / Finland)None — processed within the EU (Art. 28 GDPR DPA)
Google (Gemini API)Managed AI (LLM) & embeddingsPrompts, chat content, document textAI reasoning and agent responses; Knowledge Hub & Long-Term Memory embeddingsUS (Google global infrastructure)SCCs / EU-US DPF; paid-tier no-training
Mistral AIOCRKnowledge Hub document contentOptical character recognition of uploaded documentsEU (France)None — processed within the EU; DPA
Google Cloud StorageObject storageFile attachments, OCR’d documents, AI artifactsSecure storage (signed, expiring URLs)EU / USSCCs / EU-US DPF
Google (Sign-In, Chat)Authentication & integrationsIdentity, messagesSSO, agent channelEU / USSCCs / EU-US DPF
ExaWeb search & entity discoverySearch queries derived from prompts; URLs of pages retrievedReal-time web search, company/person entity discovery, and page-content retrieval for market intelligenceUSSCCs
PaddleMerchant of RecordBilling & contact dataCheckout, tax, invoicingEU / USSCCs / EU-US DPF
Gmail SMTP (Google)Email deliveryEmail address, message contentTransactional email (verification, invites, billing)EU / USSCCs / EU-US DPF
TelegramOptional integrationMessages routed to/from the agentAgent channel — only if you connect itInternationalGoverned by Telegram’s terms
OpenAI / AnthropicOptional / on-demand AI (LLM)Prompts, chat contentAlternative AI reasoning — used only when explicitly enabled by operator configuration or under Enterprise/Gold BYOK; not part of the default managed stackUSSCCs / EU-US DPF

Optional and on-demand AI providers: By default, managed AI processing runs on Google Gemini (reasoning and embeddings) and Mistral (OCR). OpenAI and Anthropic are optional large-language-model providers that are not used in the default managed configuration. Your prompts are sent to OpenAI or Anthropic only if the operator switches the platform’s default provider, or if you (as an Enterprise/Gold customer) configure them under Bring-Your-Own-Key. Mistral is also available as an optional chat provider in addition to its managed OCR role.

Own-fetch first: When the agent needs the content of a specific web page, it first attempts to retrieve it directly from kōdlo’s own EU-based infrastructure (no sub-processor involved); Exa’s content-retrieval API is used only as a fallback.

Enterprise Bring-Your-Own-Key (BYOK): kōdlo offers Enterprise and Gold customers the ability to supply their own API keys for the LLM provider (Google Gemini, OpenAI, Anthropic, or Mistral), web search (Exa), and OCR/embeddings (Mistral / Google). When using BYOK, data processing for those AI operations is governed entirely by your direct agreements with the relevant providers.

7. International Data Transfers

kōdlo is hosted in the European Union. The Platform, its databases, and the vector stores holding your Knowledge Hub and Long-Term Memory data run on EU-based infrastructure (Hetzner, Germany/Finland), and document OCR is performed within the EU (Mistral, France). These operations involve no transfer of personal data outside the EEA.

Certain processing operations rely on US-based sub-processors — notably managed AI inference (Google Gemini), object storage (Google Cloud Storage), web search (Exa), email delivery, billing (Paddle), Google Sign-In/Chat, and — on our public website only — website analytics (Google Analytics, Microsoft Clarity). Where data is transferred to countries outside the EEA, we rely on the European Commission’s Standard Contractual Clauses (SCCs) as our primary safeguard, supplemented by appropriate technical and organisational measures.

Where our US-based sub-processors (such as Google and Paddle) are certified under the EU-US Data Privacy Framework (DPF), we additionally rely on that Framework for the relevant transfers. The DPF’s adequacy decision was upheld by the General Court of the European Union on 3 September 2025; because its long-term status remains subject to further appeal, we maintain SCCs as an independent fallback so that transfers remain lawful regardless of the Framework’s status.

8. Data Retention & Workspace Lifecycle

You control the lifespan of your data:

  • Active Subscriptions: Data is retained for the duration of your active workspace.
  • Workspace Closure: Owners can close their workspace via the UI. Data is retained for a grace period (currently 7 days), during which you will receive pre-deletion warnings and can restore the workspace with one click.
  • Suspension & retention after the grace period: Once the grace period elapses, the workspace is suspended: it can no longer be restored or accessed, and it is queued for permanent deletion. We retain the suspended workspace’s data for up to 24 months from the end of the grace period, based on our legitimate interest (Article 6(1)(f) GDPR) in fraud and abuse prevention (for example, preventing repeated free-trial registrations) and in the establishment, exercise, or defence of legal claims. During this retention period, the e-mail addresses associated with the closed workspace remain reserved and cannot be used to register a new workspace. You may request earlier deletion of your personal data at any time via info@kodlo.ai (Section 10).
  • Permanent Hard Delete: Final deletion is executed as part of our periodic data-cleanup operations, at the latest once the retention period above has elapsed (or earlier upon a verified deletion request). The workspace and all its data undergo a permanent database-level cascade deletion, including the deletion of your per-workspace Knowledge Hub and Long-Term Memory vector collections and your stored file attachments. Backups are purged within 30 days and operational logs within 90 days of deletion.
  • Billing & tax records: retained for 5 years as required by Polish tax and accounting law, even after workspace deletion.
  • Contract Performance (Article 6(1)(b) GDPR): Providing the kōdlo workspace, CRM tools, and AI generation.
  • Legitimate Interest (Article 6(1)(f) GDPR): Maintaining platform security, verifying webhook signatures via HMAC, enforcing rate limits, and retaining suspended-workspace data for fraud and abuse prevention (Section 8).
  • Legal Obligation (Article 6(1)(c) GDPR): Retaining billing records as required by tax authorities.
  • Consent (Article 6(1)(a) GDPR and the ePrivacy rules): Setting analytics cookies on our public website — collected via the website’s cookie banner and withdrawable at any time (Section 12) — and optional marketing communications, which you can opt out of at any time (Section 10).

10. Your Rights (EEA)

Under the GDPR, you have the right to access, rectify, erase (“right to be forgotten”), restrict, or export your personal data, and to object to certain processing. You may also withdraw consent for marketing communications at any time. To exercise these rights, contact info@kodlo.ai. We will respond within one month, as required by the GDPR. You also have the right to lodge a complaint with the Polish supervisory authority (UODO) or your local data protection authority.

11. California Privacy Rights (CCPA / CPRA)

If you are a California resident, the California Consumer Privacy Act, as amended by the CPRA, provides you with additional rights. This section supplements the rest of this Policy.

  • Categories of personal information we collect: identifiers (name, email), professional/employment information, commercial information (subscription/billing records), internet/network activity (usage and technical data), and the content you submit to the Platform. We collect these for the business purposes described in Sections 3–5.
  • Disclosure to service providers: In the preceding 12 months, we have disclosed the categories above to the service providers/contractors listed in Section 6, each for the limited business purposes stated, under contracts that prohibit them from retaining, using, or disclosing the information for any other purpose.
  • No sale / no sharing: We do not sell your personal information and do not “share” it for cross-context behavioural advertising, as those terms are defined under the CCPA/CPRA. Because we do not sell or share personal information, we do not offer a “Do Not Sell or Share My Personal Information” mechanism; we nonetheless honour browser-based opt-out preference signals (such as Global Privacy Control) consistent with our practices.
  • Your rights: to know/access, delete, and correct your personal information; to opt out of sale/sharing (not applicable, as we do neither); to limit the use of sensitive personal information (we do not use sensitive personal information for purposes requiring such a limit); and to be free from discrimination for exercising these rights.
  • Automated decision-making technology (ADMT): The Platform’s contact-readiness scores and suggestions are decision-support outputs subject to human review and are not used to make legal or similarly significant decisions about California consumers without human involvement.

To exercise these rights, contact info@kodlo.ai. We will verify your request and respond within the timeframes required by law (acknowledging within 10 business days and substantively responding within 45 calendar days, extendable by a further 45 days where reasonably necessary). You may use an authorized agent to submit a request on your behalf.

12. Cookies

We use cookies and similar technologies on the application (app.kodlo.ai) and on our public website (kodlo.ai). Cookies are small files stored on your device. The two properties differ: the application uses only strictly-necessary cookies (no analytics, no advertising), so no cookie banner is shown there; the public website additionally uses analytics cookies, which are set only after you consent via the website’s cookie banner. Strictly-necessary cookies do not require consent.

Cookies on the application (app.kodlo.ai):

CookieProviderCategoryPurposeDuration
access_tokenkōdloStrictly necessaryKeeps you signed in — HttpOnly JWT, not readable by JavaScript~15 minutes
refresh_tokenkōdloStrictly necessaryRenews your session without re-login — HttpOnlyUp to 30 days
oauth_statekōdloStrictly necessaryProtects the Google sign-in flow (CSRF / PKCE state)5 minutes

Cookies on our public website (kodlo.ai):

CookieProviderCategoryPurposeDuration
Consent preferencekōdlo (consent manager)Strictly necessaryStores your cookie choices6–12 months
_ga, _ga_*Google Analytics (Google LLC)Analytics (consent required)Measures and improves website usageup to 13 months
_clck, _clsk, CLIDMicrosoft Clarity (Microsoft Corp.)Analytics & session replay (consent required)Understands how visitors use the site (aggregate metrics + masked session replay)up to 1 year
MUID, ANONCHK, SMMicrosoftAnalytics (consent required)Distinguishes visitors / measurementup to 13 months

The website cookie table is representative; the current, auto-updated list is available in the website’s cookie preference centre. You can withdraw or change your consent at any time through the website cookie banner, and you can block or delete cookies through your browser settings. Disabling strictly-necessary cookies may prevent the application from working properly. We keep these tables up to date as our cookies change.

13. Data Breach Notification

In the event of a personal data breach, we will notify the competent supervisory authority without undue delay and, where feasible, within 72 hours of becoming aware of it. Where the breach is likely to result in a high risk to your rights and freedoms, we will also inform affected users without undue delay.

14. Children

The Platform is intended for business and professional users aged 18 and over and is not directed to minors. We do not knowingly collect personal data from children. If we learn that we have collected such data, we will delete it.

15. Security Measures

  • Hosting: Core data is hosted on ISO/IEC 27001-certified EU infrastructure (Hetzner).
  • Encryption: Sensitive secrets are encrypted at rest (Fernet); transport is secured via TLS.
  • Authentication: Short-lived JWT access tokens + refresh-token rotation; tokens are stored as HttpOnly cookies (XSS-resistant).
  • Isolation: Strict per-workspace tenant scoping at the repository layer.
  • Rate Limiting: Per-endpoint rate limiting to prevent abuse.

16. Changes to This Policy

We may update this Policy periodically. We will update the “Last updated” date above, and where changes are material we will provide additional notice. Continued use of the Platform after the effective date constitutes acceptance of the revised Privacy Policy.

17. Contact

kōdlo is operated by REINODE SOFTWARE SPÓŁKA Z OGRANICZONĄ ODPOWIEDZIALNOŚCIĄ. Contact e-mail: info@kodlo.ai

Registered address: ul. GROCHOWSKA nr. 42 lok. 31, 04-282 Warsaw, Poland.

EU/GDPR ✓ Sign in