Privacy, Security and Compliance

Built on Trust. Prepared for Scale.

Kyntlo protects business workflows with a practical security program, privacy-first policies, customer controls, and transparent compliance status for subscribers and partners.

Current trust posture

Clear Security Signals for Kyntlo Customers

This page summarizes the controls, policies, and operational practices that support Kyntlo. It is written for customers who need to understand how account access, privacy requests, data handling, and security responsibilities are managed.

Active

Security Program

Kyntlo maintains a documented security posture covering account access, customer responsibilities, incident reporting, vendor usage, and data protection expectations.

Published

Privacy and Legal Pages

Privacy Policy, Terms of Use, Refund Policy, Cookie Policy, Accessibility, and Contact pages are available publicly from the website footer.

Integration Required

App Login and Demo Requests

Website login actions point to the Kyntlo Hub, free trial requests use a Kyntlo-styled Forminit form, and demo requests route visitors to the Calendly booking calendar.

Data handling

Data Hosting, Privacy, and Regional Handling

Kyntlo customers may need to understand where business and contact data is stored, processed, and transferred. Data hosting can depend on the connected platform, infrastructure providers, communications providers, payment providers, enabled integrations, and account configuration. Region-specific commitments should be confirmed in writing before launch.

Account-specific

Data Hosting and Residency

Customer data is stored and processed inside the platform and infrastructure provider environments used to operate each Kyntlo account. If a customer needs a specific hosting region or residency position, that requirement should be reviewed and confirmed before onboarding.

Important for Europe

EU and UK Customers

European customers should request available hosting-region details, subprocessors, data transfer safeguards, retention terms, and Data Processing Agreement requirements before onboarding or during due diligence.

Program ready

GDPR, Sensitive Data, and Privacy Rights

GDPR privacy rights may include access, correction, deletion, restriction, objection, portability, and consent withdrawal. Health-related data can be treated as special category personal data under GDPR, so customers should not collect sensitive data unless they have a lawful basis, required consent, and appropriate account controls.

Customer responsibility

CCPA/CPRA and Marketing Rules

Kyntlo customers remain responsible for lawful lists, consent, messaging practices, opt-outs, and honoring applicable consumer privacy requests.

Integration-dependent

Third-Party Processors

Messaging, calendar, payment, analytics, AI, and integration services may process limited data needed to deliver the selected feature or workflow.

Requires written agreement

PHI and Regulated Health Workflows

PHI/HIPAA support is not enabled by default. Kyntlo should not be used for HIPAA-regulated Protected Health Information or regulated health workflows unless a written agreement, eligible provider support, compliance review, and appropriate account configuration are in place.

Security pillars

How Kyntlo Thinks About Protection

The controls below define the standard Kyntlo security model. Final technical behavior may depend on the connected platform, hosting environment, payment provider, communications providers, and customer configuration.

Infrastructure Security

Secure hosting, HTTPS transport, provider access controls, firewall protections, and vendor safeguards are expected for production services.

Product Security

Customer accounts should use role-based permissions, strong authentication, limited user access, and careful workspace administration.

Operational Security

Support access, account changes, billing requests, and security issues should be handled through controlled support channels.

Application Security

Customer-facing forms, automations, AI workflows, and integrations should be reviewed before launch to reduce abuse and data exposure.

Shared responsibility

What Customers Must Control

Kyntlo can provide the workspace, controls, and support path, but each customer controls their users, contact lists, consent records, campaign content, workflow logic, and data handling practices.

  • User access: invite only the users who need access and remove inactive users promptly.
  • Data permission: upload only contacts and data you are authorized to process.
  • Messaging compliance: maintain opt-ins, opt-outs, and lawful marketing practices.
  • Workflow review: test automations, AI responses, and customer-facing messages before launch.
  • Incident reporting: report suspected unauthorized access, account misuse, or billing abuse quickly.

Request Security or Compliance Information

For security questions, privacy concerns, customer due diligence, or account-risk reviews, contact Kyntlo with your company name, account email, request type, and any required deadline.

Contact contact@kyntlo.ai