Keydris / Legal
Privacy Policy
Effective August 20, 2026
Contents · 19 sections
Keydris, Inc. (“Keydris,” “we,” “us,” or “our”) provides authorization control-plane infrastructure intended to help organizations and systems establish, issue, manage, verify, and revoke delegated authority for AI agents, applications, services, and other systems.
This Privacy Policy explains how we may collect, use, disclose, retain, and otherwise process personal information when you interact with our websites, accounts, APIs, SDKs, software, integrations, support channels, and other services that reference this Policy (collectively, the “Services”).
We primarily provide the Services to businesses and organizations.
01
Scope
This Privacy Policy applies when you visit one of our websites; create or administer a Keydris account; use the Services on behalf of an organization; interact with a Keydris API, SDK, dashboard, or integration; request a demo, trial, evaluation, or other business interaction; contact us or request support; or otherwise provide personal information to us in connection with the Services.
This Policy describes our own handling of personal information. Organizations using the Services remain responsible for their own privacy practices, systems, agents, users, instructions, and legal obligations.
Where we process personal information on behalf of a customer, the applicable customer agreement and any applicable data-processing terms may govern that processing.
Third-party applications, APIs, platforms, models, websites, and other services connected to the Services maintain their own privacy practices.
03
Personal Information We May Process
The information we process depends on your relationship with us and how the Services are used.
A. Business and Account Information
We may process information such as:
- name and work email address;
- organization, job title, and professional role;
- account identifiers, administrator status, and account preferences;
- authentication-related information;
- trial or evaluation information; and
- commercial relationship information.
B. Communications and Support Information
If you communicate with us, we may process emails, support requests, questions, feedback, correspondence, attachments, and other information you choose to provide.
Do not send passwords, private keys, signing keys, payment credentials, access tokens, or other secrets through general support or communication channels unless we specifically request them through a channel designed for that purpose.
C. Technical, Usage, and Security Information
When you access one of our websites or Services, we and our service providers may process technical and operational information such as:
- IP address and network information;
- browser, device, and operating-system information;
- timestamps, session identifiers, and request identifiers;
- API and integration activity;
- pages or features accessed;
- diagnostic and error information; and
- security-related events.
D. Authorization-Related Information
When an organization uses the Services, we may process the information necessary to establish, issue, manage, verify, enforce, record, or revoke delegated authority. Depending on the functionality used, this may include:
- agent, system, user, or organization identifiers;
- authority grants, scopes, permissions, and policies;
- operational or transaction limits and conditions;
- approval, expiration, and revocation information;
- verification results and timestamps; and
- authorization configuration and related authorization records.
Authorization information may constitute personal information where it identifies or relates to an individual.
E. Information from Customers and Integrations
We may receive relevant information from organizations that authorize individuals to use the Services, from authorized administrators, from customer-enabled integrations, APIs, and SDKs, from service providers acting on our behalf, and from other sources involved in a legitimate business relationship with us.
04
Information Customers Should Not Submit
Unless a Service is specifically designed and documented to receive it, customers should not submit passwords, private keys, signing keys, payment-card credentials, unnecessary API credentials or other secrets, unnecessary sensitive personal information, or information unrelated to the authorization purpose for which the Services are being used.
Customers are responsible for determining what information is appropriate to provide through their implementations.
05
How We Use Personal Information
We may use personal information to provide and operate the Services: to create and administer accounts, authenticate users and administrators, establish and manage delegated authority, issue, verify, and revoke authorization information, evaluate authorization policies, limits, and conditions, maintain authorization and operational records, and provide APIs, SDKs, and integrations.
We may use personal information to support and communicate with you: to troubleshoot technical issues, respond to support requests and other communications, send operational, security, administrative, and legal communications, and, where permitted by applicable law, send business or product communications.
We may use personal information to keep the Services reliable and secure: to monitor and maintain reliability and performance, secure accounts, systems, and Services, and detect, investigate, and prevent fraud, misuse, abuse, unauthorized access, and security threats.
We may use personal information to run our business: to develop, maintain, and improve the Services and our operations, and to administer trials, evaluations, Orders, billing, and customer relationships.
We may use personal information to meet legal obligations and protect rights: to comply with applicable law, respond to lawful requests, investigate violations of applicable terms, establish, exercise, or defend legal claims, enforce agreements, and protect the rights, safety, and property of Keydris, our customers, users, and others.
Where we process Customer Data on behalf of a customer, we process that information as reasonably necessary to provide, maintain, secure, troubleshoot, and support the Services and otherwise according to the applicable customer relationship.
We may use aggregated or de-identified information that does not reasonably identify an individual or customer for security, analytics, development, and operational purposes.
06
AI Agents and Customer Responsibilities
Customers determine the agents, applications, users, systems, permissions, policies, limits, instructions, and underlying actions associated with their use of the Services.
Customers are responsible for determining whether they may lawfully provide or direct us to process personal information; for providing required privacy notices and obtaining required permissions, consents, or other legal bases; for configuring their implementations appropriately and maintaining appropriate access controls; for limiting the information they submit to what is reasonably necessary; and for ensuring that their agents, applications, and systems do not submit unauthorized or unnecessary information.
We do not independently determine whether an underlying agent action is lawful, appropriate, accurate, safe, or commercially desirable.
Authorization information provided through the Services does not replace a customer’s own governance, security controls, access controls, compliance obligations, legal review, or human oversight.
07
How We May Disclose Personal Information
We may disclose personal information in the following circumstances.
A. Service Providers and Professional Advisers
We may engage service providers and professional advisers that support functions such as cloud infrastructure and hosting, authentication, communications and email delivery, customer support, security, monitoring and diagnostics, analytics, billing, and legal, accounting, and other business operations. These recipients may process information as reasonably necessary to provide their services to us and subject to applicable contractual or legal obligations.
B. Customer Organizations
If you use the Services through an organization, relevant account, configuration, authorization, support, security, administrative, and usage information may be made available to authorized administrators or users of that organization.
C. Customer-Enabled Integrations
If a customer enables an integration or instructs us to interact with a third-party service, information may be exchanged with that service as reasonably necessary to provide the requested functionality. Third parties have their own privacy practices, and their independent processing is governed by their own terms and privacy policies.
D. Legal, Security, and Safety Purposes
We may preserve, use, or disclose information where reasonably necessary to comply with applicable law, respond to valid legal process or enforceable governmental requests, investigate fraud, abuse, unauthorized use, or security incidents, enforce agreements, or protect the Services, our legal rights and property, our customers and users, or others.
E. Corporate Transactions
Information may be disclosed or transferred in connection with a proposed or completed financing, investment, merger, acquisition, corporate restructuring, reorganization, bankruptcy, sale of assets, or similar corporate transaction. Where appropriate, information will remain subject to applicable confidentiality and legal protections.
08
Advertising and Sale of Personal Information
We are a B2B authorization-infrastructure provider. We do not operate an advertising network, and we do not disclose personal information to third parties solely in exchange for monetary consideration.
If our practices materially change in a manner requiring additional disclosures, choices, or consent under applicable law, we will update our practices and this Privacy Policy as appropriate.
09
Controller and Processor Roles
Our privacy role depends on the particular processing activity.
We may determine the purposes and means of processing certain information associated with our own website, account-administration, business-relationship, security, communications, support, product, and legal-compliance operations. For those activities, we may act as a controller, business, or similar role under applicable privacy law.
Where we process Customer Data solely on behalf of a customer to provide the Services according to that customer’s instructions, we may act as a processor, service provider, or similar role.
The applicable customer agreement, any applicable Data Processing Addendum, and the specific processing activity determine the parties’ respective responsibilities.
11
Retention and Deletion
We retain personal information for as long as reasonably necessary for the purposes described in this Privacy Policy. Retention periods vary depending on the type of information, the applicable Service, the duration of the customer relationship, authorization-record, audit, security, and operational requirements, contractual obligations, dispute-resolution and fraud-prevention needs, and applicable legal obligations.
When information is no longer reasonably necessary, we may delete, anonymize, aggregate, or otherwise dispose of it. Information may remain for a limited period in backups or similar systems after deletion from active systems.
We may retain information where reasonably necessary to comply with applicable law or a legal hold, investigate security incidents, prevent fraud or abuse, resolve disputes, enforce agreements, or establish, exercise, or defend legal claims. Closing an account does not necessarily require immediate deletion of every record where continued retention is reasonably necessary for these purposes.
Customers may request account deletion by contacting security@keydris.com.
Certain authorization and audit records are maintained on an append-only basis and cannot be deleted by customers through the Services.
12
Security
We use reasonable administrative, technical, and organizational measures designed to protect information against unauthorized access, loss, misuse, alteration, or disclosure. No internet transmission, software platform, network, or electronic storage system can be guaranteed to be completely secure.
Customers remain responsible for protecting their own systems, agents, applications, accounts, credentials, integrations, endpoints, policies, and configurations.
If you believe you have identified a vulnerability, unauthorized access, an account compromise, misuse of Keydris, or another security concern involving the Services, contact security@keydris.com.
13
International Processing and Transfers
We and the service providers supporting the Services may process information in countries different from the country where you reside or a customer operates. We currently process personal information primarily in the United States.
Privacy and data-protection laws may differ between jurisdictions. Where applicable law requires particular safeguards or mechanisms for international transfers of personal information, we will use measures appropriate to the applicable processing.
14
Privacy Rights and Choices
Depending on your location and applicable law, you may have rights concerning your personal information. These may include rights to request access to, correction of, deletion of, or a copy of certain personal information, and to request restriction of or object to certain processing. Where processing is based on consent, you may have the right to withdraw consent.
These rights are not absolute and may be subject to applicable exceptions, limitations, identity-verification requirements, and other legal requirements. We may request information reasonably necessary to verify your identity, the validity of your request, and your authority to make a request on behalf of another individual.
We will not unlawfully discriminate against you for exercising applicable privacy rights.
Where we process personal information on behalf of a customer, we may direct you to the relevant customer or assist that customer as appropriate.
You may submit privacy requests to security@keydris.com.
15
Marketing Communications
Where permitted by applicable law, we may send communications regarding our products, Services, events, updates, or other business matters. You may unsubscribe from promotional emails using the unsubscribe method included in the communication.
Even after you opt out of promotional communications, we may continue sending communications reasonably necessary for account administration, security, Service operation, transactions, contractual matters, or legal notices.
16
Third-Party Services
The Services may link to, interoperate with, or be used alongside third-party websites, applications, APIs, AI models, protocols, networks, platforms, infrastructure, or other services. We do not control the independent privacy practices of those third parties.
Customers should evaluate third-party services and review their terms and privacy policies before enabling or using integrations.
17
Children’s Privacy
The Services are designed for businesses and organizations and are not directed to children. Individuals under 18 should not create or administer Keydris business accounts.
If we learn that personal information from a child has been provided contrary to this Policy, we may take appropriate steps to remove it.
18
Changes to This Privacy Policy
We may update this Privacy Policy as our Services, technology, business, data practices, security practices, or legal obligations change over time.
When we update this Privacy Policy, we will publish the revised version with an updated effective date. If applicable law requires additional notice or consent for a material change, we will provide it as required.
19
Contact Us
Questions, privacy requests, security reports, or concerns relating to this Privacy Policy or our privacy practices may be submitted to:
Keydris, Inc.
Email: security@keydris.com
When contacting us about a privacy request, please provide sufficient information for us to understand the request and, where reasonably necessary, verify your identity or authority.
If your request relates to personal information we process on behalf of a customer organization, we may direct you to that organization or assist the organization as appropriate.