---
title: "Data Privacy & Protection Policy — KrosAI"
description: "How KrosAI collects, uses, stores and protects personal data across its platform and operations."
url: "https://krosai.com/data-privacy"
updated_at: "2026-09-21"
---

# Data Privacy & Protection Policy — KrosAI

> How KrosAI collects, uses, stores and protects personal data across its platform and operations.

_Last updated: Monday, 7th September 2026_

## 1. Purpose

This policy describes how KrosWeb Enterprise Inc., doing business as KrosAI ("the Company," "we," "us"), collects, uses, stores, and protects personal data belonging to its business customers, their end users, and its own employees and advisors, in connection with the KrosAI platform.

## 2. Scope

This policy applies to personal data processed by KrosAI in the course of providing its telephony, number-provisioning, and AI voice agent infrastructure services, across all jurisdictions in which KrosAI operates, including Nigeria, Kenya, Ghana, the United States, and the United Kingdom.

## 3. Data We Collect

- **Business customer data:** business registration details, beneficial ownership information, and contact information, collected as part of onboarding and AML/KYC verification (see AML/KYC Policy).
- **End-user data:** identity and contact information collected during phone number provisioning and KYC verification, and call/SMS metadata generated through use of the platform.
- **Employee and advisor data:** standard employment-related personal data (contact details, compensation, tax information) for the Company's own team.

## 4. How We Use Data

Personal data is used solely for legitimate business purposes, including: verifying customer and end-user identity, provisioning and maintaining telephony services, fraud and AML monitoring, regulatory compliance in each operating jurisdiction, and internal business operations (e.g., payroll for employees).

KrosAI does not sell personal data to third parties.

## 5. Third-Party Processors

KrosAI relies on the following categories of third-party providers to deliver its services, each of which processes data on KrosAI's behalf under their own applicable data protection terms:

- **Infrastructure providers:** Cloudflare, Supabase, Google Cloud
- **Telecom/carrier partners:** our telco partners across the different markets in which we operate
- **Identity verification:** Didit (didit.me)

KrosAI selects third-party processors with regard to their own data protection and security practices, and works toward formal data processing agreements (DPAs) with key providers as commercial relationships are finalized.

## 6. Data Security

- **Authentication:** KrosAI employs modern authentication security, including TOTP-based two-factor authentication (via the Web Crypto API) and WebAuthn/passkey support (via SimpleWebAuthn), alongside login-alert notifications.
- **Access control:** access to customer and end-user data is limited to what is necessary for KrosAI personnel to perform their roles.
- **Ongoing certification:** KrosAI is actively working toward ISO 27001, SOC 2 Type II, and GDPR-aligned compliance, monitored through an independent compliance partner (Oneleet), reflecting the Company's commitment to formalized, independently verified data security practices as it scales.

## 7. International Data Transfers

Given KrosAI's multi-jurisdiction operations, personal data may be transferred and processed across the countries in which KrosAI and its infrastructure providers operate. KrosAI works to ensure appropriate safeguards are applied to such transfers consistent with applicable data protection law in each relevant jurisdiction, including GDPR requirements where applicable to UK/EU-connected data.

## 8. Data Retention

Personal data is retained only for as long as necessary to fulfill the purposes described in this policy, meet regulatory and recordkeeping obligations (including those described in the AML/KYC Policy), and support legitimate business needs. Data is deleted or anonymized when no longer required, subject to applicable legal retention requirements.

## 9. Individual Rights

Where applicable law provides individuals with rights over their personal data (including access, correction, deletion, or objection to processing), KrosAI will respond to verified requests in accordance with the applicable regulatory framework in the relevant jurisdiction.

## 10. Data Breach Response

In the event of a data breach affecting personal data, KrosAI will investigate promptly and provide notification to affected parties and relevant regulators as required under applicable law in the relevant jurisdiction.

## 11. Policy Review

This policy is reviewed periodically and updated as KrosAI's operations, infrastructure, and applicable regulatory requirements evolve, including as ISO 27001, SOC 2, and GDPR-aligned certification work progresses.

## 12. Contact

Questions regarding this policy, or requests relating to personal data, may be directed to team@krosai.com.
