Legal

Privacy Policy

What personal data Kayvrn collects, why we process it, who we share it with, how long we keep it, and your rights.

Effective 9 September 2026

1. Who we are

Conso4s Ltd, a company registered in England and Wales with company number 11083797, registered office Suite 3, Middlesex House, Rutherford Close, Stevenage, SG1 2EF, United Kingdom ("Conso4s", "we", "us", "our") is the data controller for personal data processed through Kayvrn (kayvrn.com and app.kayvrn.com), except where this policy says we act as your processor.

We do not sell personal data. We do not use your scan results or your monitored email addresses to train models, our own or anyone else's. Questions about this policy: [email protected].

2. What we collect

Account and contact information

  • Your name, work email address, and hashed passphrase.
  • Your organisation name, the members you invite, and their roles.
  • Multi-factor authentication settings, session and device metadata, and API keys you create (stored hashed).
  • Messages you send us through the contact form, email, or WhatsApp, and our replies.
  • Notification preferences and unsubscribe state.

Domains you submit and verification records

  • The domains and subdomains you add for monitoring.
  • Verification evidence: the DNS TXT token we issued and observed, the verification file or meta tag we fetched, or the email challenge sent to an administrative address on the domain, plus timestamps and outcomes.
  • Where you connect a DNS provider to automate verification, the OAuth tokens needed for that connection.

Scan results

  • What our probes observed from outside your domain: hostnames and subdomains, IP addresses, open services and banners, TLS certificates and configuration, DNS and email authentication records (SPF, DKIM, DMARC), HTTP security headers, exposed paths and files, and detected software and versions.
  • Derived data: findings, severities, grades, the asset graph, attack paths, and the historical record of how these changed between scans.
  • Reports generated from the above, including PDFs.
  • Scan results are about infrastructure, but they can contain personal data where public records include it, for example an administrative contact in WHOIS or a name in a certificate or exposed file.

Monitored employee email addresses and breach checks

  • Email addresses you add to a domain watchlist, up to a per-domain limit shown in the app.
  • The result of checking each address against known breach corpora: which breaches an address appears in, when they were disclosed, and what categories of data were exposed.
  • We check the addresses you give us. We do not enumerate your staff, and we do not receive breach passwords.

Payment information

  • Subscription tier, billing status, invoices, and the Stripe customer and subscription identifiers.
  • Billing name, address, and tax details where you provide them.
  • Card details go directly to Stripe. We never receive or store your full card number.

Technical logs

  • Server and application logs: IP address, user agent, request path and method, response status, timestamps, and correlation identifiers.
  • Security and audit events: sign-ins and failures, passphrase and MFA changes, domain added or removed, watchlist changes, billing changes, and who did them.
  • Email delivery events for messages we send you: sent, delivered, bounced, complained.

Website analytics

  • On kayvrn.com we use Google Analytics to understand which pages people read. It sets cookies and processes an abbreviated IP address and page interaction data.
  • Analytics cookies are set only where we have your consent or, where local rules allow, on a legitimate interest basis. You can block them in your browser at any time.
  • The application at app.kayvrn.com uses only the cookies and local storage needed to keep you signed in and to remember your interface preferences.

3. Why we process it, and our legal bases

  • To provide the Service: create and run your account, verify your domains, run scans, generate reports, and send you results. Legal basis: performance of our contract with you.
  • To bill you and collect payment, including fraud prevention on payments. Legal basis: contract, and our legitimate interest in being paid and preventing fraud.
  • To keep the Service secure and available: rate limiting, abuse detection, audit logging, incident investigation, and backups. Legal basis: our legitimate interest in protecting the Service and our customers, and our legal obligation to keep personal data secure.
  • To support you and answer messages. Legal basis: contract, and our legitimate interest in responding to enquiries.
  • To improve the Service using aggregated, de-identified usage statistics. Legal basis: our legitimate interest in improving what we sell.
  • To send service emails you cannot opt out of while you hold an account, such as verification, scan completion, domain re-verification warnings, and billing notices. Legal basis: contract.
  • To send marketing email. Legal basis: your consent, or the soft opt-in for existing customers. Every marketing email has an unsubscribe link.
  • To meet legal obligations, such as keeping accounting records and responding to lawful requests. Legal basis: legal obligation.
  • Where we rely on legitimate interests, we have considered your rights and concluded the processing does not override them. Ask us and we will explain the assessment.

4. Monitored email addresses: who controls what

When you add colleagues' email addresses to a breach watchlist, you are the controller for those addresses and we act as your processor. You decide whose addresses are monitored and you are responsible for having a lawful basis and for telling the people concerned, as their employer or as the operator of that domain.

We process those addresses only to run breach checks and show you the results, and we delete them when you remove them from the watchlist or close the account. A Data Processing Addendum is available on request.

5. Who we share data with

We do not sell or rent personal data. We share it with the following processors and providers, each under a contract that limits them to our instructions:

  • Hosting: Contabo GmbH, Germany. Our servers, databases, and backups are in the European Union.
  • Network, CDN, and DDoS protection: Cloudflare, Inc.
  • Payments: Stripe, Inc. and its group companies, who act as their own controller for payment data.
  • Transactional email: our email delivery provider, currently Postmark (Active Campaign, LLC).
  • Breach intelligence: Have I Been Pwned (Superlative Enterprises Pty Ltd, Australia), which receives the email addresses you put on a watchlist in order to return breach matches.
  • Public vulnerability and exploitation intelligence sources, which receive only software and version identifiers, never your personal data.
  • Website analytics: Google Ireland Limited (Google Analytics), on kayvrn.com only.
  • Contact form delivery: Formspree, Inc., for messages sent through the form on our contact page.
  • Professional advisers, and authorities where we are legally required to disclose.
  • A buyer or successor if we sell or restructure the business, under the same protections.

6. International transfers

Your account, scan, and billing data is stored in the European Union. Some of the providers listed above are outside the UK and EEA, mainly in the United States and Australia. Where data leaves the UK or EEA we rely on an adequacy decision where one exists, or otherwise on Standard Contractual Clauses together with the UK International Data Transfer Addendum, plus technical measures such as encryption in transit. Ask us at [email protected] for details of the safeguards for a specific provider.

7. How long we keep it

  • Account and organisation data: for as long as your account is open.
  • After you delete your account, a short grace period applies before the account is irreversibly removed, so that an accidental or fraudulent deletion can be reversed. The current grace period is 7 days for a user and 30 days for an organisation.
  • Detailed scan data (asset inventory, asset relationships, attack paths) is swept on a rolling 90-day window. Older detail is deleted automatically.
  • Reports and finding history are kept while your account is open so you can see trends, and are deleted with the account.
  • Watchlist email addresses and breach results: until you remove the address or close the account.
  • Unclaimed preview reports generated before signup: 30 days, after which the lead record and its findings are deleted.
  • Data export files we generate for you: 7 days, then deleted.
  • Technical and security logs: kept for a limited operational window and then deleted, except where a log is needed for an ongoing security or abuse investigation.
  • Invoices and accounting records: at least six years after the end of the relevant financial year, as UK tax law requires.
  • Marketing suppression records: kept indefinitely, because we have to remember not to email you.

8. How we protect it

  • Passphrases and API keys are stored hashed with Argon2. They are never stored or logged in the clear.
  • All traffic to our sites and API is encrypted in transit with TLS.
  • Optional multi-factor authentication on accounts.
  • Data is isolated per organisation, and every internal service call is authenticated and additionally gated behind an internal secret.
  • Least-privilege access for our staff, with administrative actions written to an audit log.
  • Encrypted backups held in the same EU region as the live data.
  • No security is perfect. If a breach affects your personal data and is likely to be a risk to you, we will tell you and the relevant supervisory authority within the time limits the law sets.

9. Your rights

Under UK and EU data protection law you can ask us to:

  • Give you a copy of the personal data we hold about you, and information about how we process it.
  • Correct data that is wrong or incomplete.
  • Delete your data, where we have no overriding reason to keep it.
  • Restrict or object to processing, including processing based on legitimate interests.
  • Receive your data in a portable, machine-readable format, or have it sent to another provider where technically feasible.
  • Withdraw consent at any time where we rely on consent. This does not affect processing already carried out.

Account export and account deletion are available directly in the app. For anything else, email [email protected]. We respond within one month and may ask for proof of identity first. We do not make decisions with legal or similarly significant effects about you by automated means.

If a domain we scan is yours and you want the data about it deleted, contact us and we will verify control of the domain before acting, using the same proof-of-control methods we use for monitoring.

You can complain to the UK Information Commissioner's Office at ico.org.uk, or to the supervisory authority where you live or work. We would rather you came to us first so we can put it right.

10. Children

Kayvrn is a business service and is not directed at children. We do not knowingly collect data about anyone under 18. Tell us if you think we have, and we will delete it.

11. Changes to this policy

We update this policy when what we do changes. The effective date at the top of the page shows the current version. For material changes we will tell you by email or in the app before they take effect.

12. Contact

  • Email: [email protected]
  • WhatsApp: +44 1438 893080
  • Post: Conso4s Ltd, a company registered in England and Wales with company number 11083797, registered office Suite 3, Middlesex House, Rutherford Close, Stevenage, SG1 2EF, United Kingdom
  • Company number: 11083797. We are registered with the UK Information Commissioner's Office; our registration number is available on request.