Privacy Policy
Last updated: July 2026
This Privacy Policy explains how Hannsville Technologies Pte. Ltd. (“HeyKiko”, “we”, “us”) collects, uses, discloses, and safeguards information when you use our website and AI agent platform (the “Service”). We are committed to data minimisation and to handling personal data in line with Singapore's Personal Data Protection Act (PDPA) and comparable regulations.
1. Information we collect
We collect only what we need to provide the Service:
- Account data — name, work email, organisation, and authentication details when you register.
- Content you provide — documents, files, and links you upload to train your agent.
- Conversation data — messages exchanged with your deployed agents, retained according to your configured retention policy.
- Usage and device data — log data, IP address, browser type, and interactions, used for security and to improve the Service.
2. How we use information
- To provide, operate, and maintain the Service.
- To ground agent answers in your uploaded content and generate citations.
- To secure the platform, detect abuse, and prevent fraud.
- To communicate with you about updates, support, and billing.
- To comply with legal obligations.
3. AI processing and your content
Your uploaded content is used solely to power your agents. We do not use your content or end-user conversations to train public or shared AI models. Content is processed by our retrieval pipeline and the configured AI provider strictly to answer questions for your organisation.
4. Sharing and disclosure
We do not sell personal data. We share data only with sub-processors required to run the Service (for example, cloud hosting and AI model providers) under appropriate data-protection terms, or where required by law.
5. Data retention
We retain personal data only as long as necessary for the purposes above or as required by law. Conversation retention is configurable; the platform default is 12 months. You may request earlier deletion.
6. Security
We protect data with encryption in transit (TLS 1.2+) and at rest (AES-256), access controls, and audit logging. No system is perfectly secure, but we apply enterprise-grade safeguards as a baseline.
7. Google user data (Calendar integration)
If you choose to connect a Google Calendar to enable appointment booking, we access your Google data via Google's OAuth consent flow using two scopes:
- calendar.readonly— we read your calendar's free/busy times solely to offer your customers appointment slots when you are actually available and to prevent double-booking.
- calendar.events — we create calendar events for confirmed bookings, and update or cancel those events when a booking changes.
We store only the bookings created through the Service and the OAuth tokens needed to maintain your connection (encrypted at rest). We do not store the contents of your other calendar events; free/busy information is read transiently to compute availability. Google user data is never used for advertising, never sold, and never transferred to third parties except as necessary to provide the booking feature you requested or as required by law. No humans read this data except with your explicit consent, for security purposes, or to comply with applicable law.
Our use and transfer of information received from Google APIs adheres to the Google API Services User Data Policy, including the Limited Use requirements.
You can disconnect Google Calendar at any time from your dashboard (Calendar → Disconnect), which deletes our stored tokens, or revoke access from your Google Account security settings.
8. Your rights
Subject to applicable law, you may request access to, correction of, or deletion of your personal data, and you may withdraw consent. To exercise these rights, contact us at the address below.
9. International transfers
Where data is processed outside your country, we ensure a comparable standard of protection through contractual and technical measures.
10. Changes to this policy
We may update this policy from time to time. Material changes will be posted on this page with a revised “Last updated” date.
Questions about this policy? Email support@hannsville.com.