Kairos Intelligence (Pty) Ltd · Registration number 2026/50194/07 · Version 1.0 · Effective 15 August 2026
This Privacy Policy explains how Kairos Intelligence (Pty) Ltd handles personal information in connection with Kairos CFO. It forms part of, and is Part B of, our Terms and Conditions of Service.
Kairos CFO reads financial records from your accounting system. Financial records contain a great deal of personal information about people who are not our customers — your employees, your directors, your customers, your suppliers and the people they employ. Most of this Policy is about how we handle that information, and about the fact that you, not we, decide what happens to it.
1.Who we are
1.1
Kairos Intelligence (Pty) Ltd (registration number 2026/50194/07), of Atterbury House, Hampton Office Park, 20 Georgian Crescent, Bryanston, 2191, South Africa, is responsible for the processing described in this Policy.
1.2
Our Information Officer is [NAME], contactable at sfourie@kairosintel.co.za and +27 76 545 2494. The Information Officer is registered with the Information Regulator (South Africa).
1.3
Our Promotion of Access to Information Act manual is available at https://kairosintel.app/paia or on request.
1.4
Terms defined in Part A have the same meaning in this Part B.
2.The two roles we play
It matters which role we are in, because it determines who you should approach about your information and who decides what happens to it.
2.1
Operator. For personal information contained in the accounting data we retrieve from your Accounting System or that you upload, you are the responsible party and we are your operator. We process that data only on your documented instructions, to provide Kairos CFO to you. We do not decide what data you connect, what it contains, how long you keep it, or what you do with the output.
2.2
Responsible party. For the information we hold about you and your Users in order to run the account — registration details, credentials, billing records, support correspondence, usage logs and marketing preferences — we decide the purpose and means, and we act as responsible party in our own right.
2.3
If you are an individual whose information appears in a customer's accounting data and you want to exercise a right in respect of it, you should approach that customer. If you approach us, we will refer you to them and assist them in responding. We are not in a position to correct or delete an entry in someone else's ledger.
3.Personal information in your accounting data
We do not choose what is in your ledger. The categories below are what accounting data typically contains, and what we will therefore process on your behalf.
Contact records — names, trading names, contact persons, email addresses, telephone numbers, physical and postal addresses, VAT and tax reference numbers of your customers, suppliers and other counterparties.
Transaction records — invoices, bills, credit notes, expense claims, payments, allocations, journal entries and the narrations and references attached to them, which frequently name individuals.
Banking records — bank transaction lines, payee names, payment references and reconciliation status. We do not retrieve or store your online banking credentials.
Employment-related ledger entries — payroll control accounts, salary and wage journals, director and employee loan accounts, expense reimbursements and related narrations.
Documents you attach — invoices, statements, contracts and supporting documents, where you enable attachment retrieval or upload them.
3.1
Special personal information, as defined in section 26 of POPIA, is not something we ask for and not something Kairos CFO is designed to process. It may nevertheless appear incidentally — for example a medical aid or union deduction in a payroll journal, an identity number on an invoice, or a narration referring to a legal proceeding. Where it does, we apply the same safeguards without distinction and process it only as your operator. You remain responsible for establishing a lawful basis under section 27 for that information being in your records and for it being connected to the Service.
3.2
Children's information is not something the Service is designed to process. It may appear incidentally in a trust or beneficiary ledger. The same position applies.
3.3
You decide what is connected. If you do not want a category of information processed by us, do not connect the Entity or the record set that contains it, or restrict the connection scope. Clause 9 of Part A and Schedule 1 set out what we retrieve.
4.Where you act for your own clients
This section applies if you are an accounting firm, bookkeeping practice or outsourced finance function using Kairos CFO for Entities belonging to your clients.
4.1
In that arrangement your client is the responsible party, you are either that client's operator or a responsible party in your own right depending on your mandate, and we are a further operator or sub-operator in the chain.
4.2
You must ensure that your client agreements permit you to connect their records to a third-party service and to disclose their data to us on these terms. Clause 7 of Part A records the warranty you give us on that point.
4.3
We deal with you, not with your clients. We will not respond directly to a data subject request from a client of yours, and will refer it to you.
4.4
If your mandate for an Entity ends, disconnect it. Continued processing after the mandate ends is processing without authority, and it is yours to prevent, not ours to detect.
5.What we collect as responsible party
Identity and contact details — name, job title, employer, business email address, business telephone number and address.
Account and authentication data — username, hashed credentials, multi-factor authentication settings, role and permission assignments, and Entity access configuration.
Billing and transaction data — billing entity, VAT number, invoices, subscription and payment history, Entity counts, and the payment reference and outcome returned by our payment provider. We do not collect or store full card numbers, card verification values or banking credentials.
Connection metadata — which Accounting Systems you have connected, the scopes granted, connection status, retrieval timestamps and error records.
Usage and technical data — IP address, device and browser type, operating system, features used, timestamps, session and audit logs, and error diagnostics.
Correspondence — support requests, emails and other communications with us.
Marketing preferences — subscriptions, consents and opt-outs.
6.Where we get it
Directly from you — when you register, request a demonstration, correspond with us or make a payment.
From the customer that authorised your access, where you are a User under a corporate subscription.
From your connected Accounting System, where you have authorised the connection.
From a marketplace operator or reseller, where you subscribed through one.
Automatically — through cookies on our website and through platform logging.
From public and third-party sources — company registries and business information providers, for the purpose of verifying a business counterparty or making a business-to-business approach.
7.Why we process it, and on what basis
We rely on the justifications in section 11 of POPIA indicated against each purpose.
To provide, operate, secure and support Kairos CFO, and to perform our contract with you — necessary for the conclusion or performance of a contract (s11(1)(b)).
To retrieve, store and analyse accounting data on your instruction and produce Derived Insights — performance of a contract, on your authority as responsible party (s11(1)(b) read with s20).
To authenticate Users, manage Entity access and maintain audit trails — contract performance and legitimate interest (s11(1)(b) and (f)).
To invoice, meter Entity counts, collect payment and manage credit — contract performance and legal obligation (s11(1)(b) and (c)).
To detect, prevent and investigate fraud, abuse and security incidents — legitimate interest and legal obligation (s11(1)(f) and (c)).
To correct defects, improve the Service and produce aggregated, de-identified analysis and benchmarks — legitimate interest (s11(1)(f)), on the terms and with the controls in clause 14 of Part A.
To comply with law, including tax, company and record-keeping obligations, and to respond to regulators and lawful requests — legal obligation (s11(1)(c)).
To establish, exercise or defend legal claims — legitimate interest (s11(1)(f)).
To send service communications about changes, incidents, maintenance and billing — contract performance (s11(1)(b)).
To send direct marketing about our services — consent, or the existing-customer basis permitted by section 69(3) of POPIA, with an opt-out in every message.
7.1
If we intend to process personal information for a purpose materially different from those listed, we will notify you and, where the law requires it, obtain consent.
8.Connecting your accounting system
8.1
When you connect Xero, Sage or Zoho Books, that provider issues us an access token. We store tokens encrypted, use them only to retrieve the data described in Schedule 1, and refresh them as the provider requires.
8.2
We request read access only, except where you expressly enable a feature requiring write access. We do not use a connection to retrieve data beyond the scopes granted.
8.3
Your accounting provider is a separate responsible party in respect of the data it holds and its own processing. Its privacy notice governs that processing, not this Policy.
8.4
You may revoke a connection at any time, through the Service or through your accounting provider. Revocation stops further retrieval immediately. Data already retrieved is dealt with under clause 26 of Part A and clause 13 of this Part B.
9.Artificial intelligence
9.1
The Service uses machine learning and large language model technology to produce analysis and narrative commentary. Accounting data, including personal information it contains, may be processed by a third-party model provider acting as our sub-operator.
9.2
Those providers are bound in writing not to use your content to train their general-purpose models, and to process it only on our instruction.
9.3
We do not make any decision about you or any individual that has legal consequences, or that affects an individual to a substantial degree, solely by automated means. A score, flag or exception produced by the Service is a prompt for human review, not a determination. This gives effect to section 71 of POPIA.
9.4
A current list of the model providers we use is maintained at https://kairosintel.app/subprocessors.
10.Who we share it with
We do not sell personal information. We share it only as follows:
Sub-operators — cloud hosting and infrastructure, our deployment and hosting partner, artificial intelligence model providers, email and communications providers, and error monitoring and analytics providers. Each is bound in writing to confidentiality, security and use limited to our instructions.
Our payment provider — Payfast (Pty) Ltd, which processes card and electronic payments and is a responsible party in its own right in respect of payment data it collects. We do not receive your full card details.
A marketplace operator or reseller, where you subscribed through one, and only in relation to your subscription, entitlement and support.
Professional advisers — auditors, attorneys, accountants and insurers, under professional duties of confidence.
Regulators, courts and law enforcement — where required by law or where necessary to establish, exercise or defend a legal claim. We assess each request and disclose only what is lawfully required.
An acquirer — in connection with a merger, restructuring, financing or sale of our business, subject to confidentiality undertakings and to this Policy continuing to apply.
10.1
A current list of our sub-operators and the countries in which they process personal information is maintained at https://kairosintel.app/subprocessors. You may subscribe to notifications of changes to that list, and clause 19.5 of Part A gives you 30 days' notice of a new sub-operator and a right to object on reasonable data protection grounds.
11.Where your information is processed
11.1
Our primary hosting region is the Africa (Cape Town) cloud region, in South Africa.
11.2
Some processing, including certain artificial intelligence inference, error monitoring and communications services, may take place outside South Africa.
Where personal information is transferred across a border, we do so only where at least one of the conditions in section 72 of POPIA is met, namely that:
the recipient is subject to a law, binding corporate rules or binding agreement providing an adequate level of protection substantially similar to POPIA and including comparable onward-transfer restrictions;
the data subject consents;
the transfer is necessary for the performance of a contract with the data subject, or for a contract concluded in the data subject's interest; or
the transfer is for the data subject's benefit and consent is not reasonably practicable to obtain.
11.3
We maintain a documented transfer impact assessment for cross-border artificial intelligence processing and will make it available to you on request.
12.How we protect it
12.1
We maintain appropriate, reasonable technical and organisational measures as required by section 19 of POPIA, having regard to generally accepted information security practices.
Encryption of personal information in transit and at rest, including encryption of accounting system access tokens.
Logical separation of each customer's data, and of each Entity within a customer's account, with controls preventing cross-tenant access.
Role-based access control, least-privilege administrative access and multi-factor authentication for administrative accounts.
Infrastructure-level administration that does not require routine access to the content of your accounting data, with any content access being time-bound, logged and reportable.
Logging, monitoring and retention of audit trails.
Confidentiality undertakings and security awareness training for personnel.
Written security and confidentiality obligations imposed on every sub-operator.
Encrypted backups, restoration testing and a documented incident response procedure.
12.2
You are responsible for security within your own environment, including the permissions you grant on the accounting system connection, credential hygiene, and the Entity and User access you configure within the Service.
12.3
No system is perfectly secure. Transmission of information over the internet is at your own risk.
13.How long we keep it
13.1
We keep personal information only for as long as it is necessary for the purpose it was collected for, or for as long as a law requires or permits, in accordance with section 14 of POPIA.
Accounting data retrieved from a connected Entity — for the duration of the subscription and while the Entity remains connected, then for the 30-day export window, then deleted or de-identified within a further 60 days, subject to backup cycles.
Account and billing records — for the duration of the subscription and thereafter as required by the Tax Administration Act 28 of 2011 (five years from the end of the relevant tax period) and the Companies Act 71 of 2008 (seven years where applicable).
Security and audit logs — up to 12 months, unless a longer period is needed for an investigation.
Support correspondence — three years from the date of the last exchange.
Marketing and prospect data — until you opt out, or three years after our last meaningful interaction, whichever comes first.
Records needed to establish, exercise or defend a legal claim — until the claim is resolved and any applicable prescription period has run.
13.2
Deleting data from Kairos CFO does not delete it from your Accounting System. Your accounting records remain with your accounting provider and remain your responsibility to retain for the periods the law requires.
13.3
Aggregated and de-identified data that cannot be linked to an identifiable person is not personal information and may be retained indefinitely, on the terms in clause 14 of Part A.
14.Direct marketing, and cookies
14.1
We send electronic direct marketing only to persons who have consented, or to existing customers in respect of similar services, in accordance with section 69 of POPIA and Chapter 7 of the Consumer Protection Act. Every message contains a means of opting out at no cost. You may also opt out at any time by emailing sfourie@kairosintel.co.za.
14.2
Opting out of marketing does not stop service, security and billing communications, which are necessary for the performance of our contract.
14.3
Our website uses strictly necessary cookies for session management, security and load balancing. Analytics and preference cookies are set only where you have consented through our cookie banner, and you may withdraw consent at any time. We do not use cookies for cross-site behavioural advertising.
15.If something goes wrong
15.1
Where we are the responsible party and there are reasonable grounds to believe personal information has been accessed or acquired by an unauthorised person, we will notify the Information Regulator and the affected data subjects as soon as reasonably possible after discovering the compromise, in accordance with section 22 of POPIA, unless a public body directs a delay for investigative reasons.
15.2
Where we are your operator, we will notify you without undue delay after becoming aware of a compromise affecting your data, and will provide the information you reasonably need to make your own notifications. The obligation to notify the Regulator and affected data subjects in that case is yours, as responsible party.
15.3
Our notification will describe what happened, the possible consequences, the measures taken or intended, and what can be done to mitigate harm.
16.Your rights
Subject to the requirements and exemptions in POPIA and the Promotion of Access to Information Act 2 of 2000, you have the right to:
be told whether we hold personal information about you, and to request a record or description of it, together with the identity of any third party who has had access (s23);
request correction, destruction or deletion of personal information that is inaccurate, irrelevant, excessive, out of date, incomplete, misleading or unlawfully obtained (s24);
object, on reasonable grounds relating to your particular situation, to processing based on legitimate interest (s11(3));
object at any time to processing for direct marketing purposes (s11(3) and s69);
not have a decision with legal or substantially affecting consequences made about you solely by automated processing (s71);
withdraw consent, where processing is based on consent, without affecting the lawfulness of processing before withdrawal; and
complain to the Information Regulator, and to institute civil proceedings in a court.
16.1
To exercise a right, contact sfourie@kairosintel.co.za. A request for access or correction must be made on the prescribed form under the Promotion of Access to Information Act, which is available in our PAIA manual. We may need to verify your identity before acting on a request, and a prescribed fee may apply to an access request.
16.2
We will respond within the period prescribed by law, ordinarily 30 days, and will tell you if we need an extension and why. If we refuse a request we will give reasons and explain how to challenge the refusal.
16.3
Where the information relates to a customer's accounting data rather than to our own records, we will refer the request to that customer, as explained in clause 2.3.
17.Complaints, and changes to this Policy
17.1
If you are not satisfied with how we have handled personal information, please contact our Information Officer first. We would prefer the opportunity to resolve the matter.
17.2
You may also complain to the Information Regulator (South Africa), JD House, 27 Stiemens Street, Braamfontein, Johannesburg, 2001, using the forms and contact details published at https://inforegulator.org.za.
17.3
We may update this Policy. The current version is published at https://kairosintel.app/cfo/privacy with its version number and effective date. Where a change materially affects how we use personal information, we will notify you by email or through the Service before it takes effect.
17.4
Superseded versions are retained and available on request.