Kyroco, LLC (“Kyroco,” “we,” “us,” or “our”) provides Korium, a hosted graph-memory service for AI agents and applications (the “Service”). This Privacy Policy explains what personal information we collect, how we use and share it, and the choices and rights you have.
This Policy covers our websites, the Korium sign-up and pricing pages, the customer dashboard and console, and our sales, support, and marketing activities (together, the “Sites and Services”). Capitalized terms not defined here have the meanings given in our Terms of Service.
When you use Korium, you submit data to your memory store (“Customer Content”) that may contain personal information about you or about third parties. We process Customer Content on behalf of our customers, as a service provider / data processor, under our Terms of Service and Data Processing Addendum - not under this Privacy Policy. For that data, the customer (your organization) is the controller and decides how it is used; this Policy does not govern it, and if you are an end user or data subject with a request about Customer Content, you should contact the relevant customer directly. We do not use Customer Content to train, fine-tune, or improve general-purpose or foundation AI models.
This Privacy Policy governs the personal information for which Kyroco is the controller - for example, account, billing, usage, support, and marketing information about the individuals and organizations that visit our Sites or administer the Service.
We do not intentionally collect special-category or highly sensitive personal information about you through our Sites and Services, and you should not submit it to us except through channels designed for it.
We use the personal information we control to:
AI model training. We do not use Customer Content to train, fine-tune, or improve general-purpose or foundation AI models. We may use Usage Data and aggregated or de-identified data to analyze and improve the Service, as described in the Terms of Service.
Where the EU or UK GDPR applies, we rely on the following legal bases: performance of a contract (to provide the Sites and Services you request and administer your Account and billing); legitimate interests (to secure, analyze, and improve our products, prevent fraud and abuse, and conduct direct marketing to business contacts, balanced against your rights); consent (for certain marketing, cookies, or optional features, which you may withdraw at any time); and legal obligation (to comply with applicable law). Where we rely on legitimate interests, you may object as described in Section 8.
We do not sell your personal information, and we do not share it for cross-context behavioral (targeted) advertising, as those terms are defined under U.S. state privacy laws. We disclose personal information only as follows:
We are based in the United States, and by default the Service operates in the United States (additional regions and data-residency options are available to enterprise customers). If you access the Sites and Services from outside the United States, your personal information may be transferred to, stored in, and processed in the United States or other countries where privacy laws may differ from those in your location. Where required, we use appropriate safeguards for international transfers. Our primary safeguard is the European Commission’s Standard Contractual Clauses (with the UK Addendum and Swiss adjustments as applicable), incorporated into our Data Processing Addendum. In addition, several of our subprocessors are certified under the EU-US Data Privacy Framework (and its UK extension), which we may also rely on for transfers to those providers; the Standard Contractual Clauses remain in place regardless. You may request a copy of the relevant safeguards using the contact details in Section 12.
Our websites use cookies and similar technologies to keep you signed in, remember preferences, secure the Service, and measure and improve site performance. We use strictly necessary cookies to operate the Sites, and, where you consent (where required), analytics or preference cookies. You can control cookies through your browser settings and, where offered, our cookie banner or preference center. Details are in our Cookie Notice. We do not currently respond to browser “Do Not Track” signals; where required by law, we treat recognized opt-out preference signals (such as Global Privacy Control) as a valid opt-out of “sale”/“sharing.”
We retain personal information for as long as needed to provide the Sites and Services, maintain your Account, comply with our legal obligations, resolve disputes, and enforce our agreements. Account and billing records are generally retained for the life of the Account and for a reasonable period afterward as required for tax, accounting, and legal purposes. Customer Content is retained and deleted as described in the Terms of Service (including the post-termination retrieval period and deletion), not under this Policy. When personal information is no longer needed, we delete or de-identify it, subject to residual copies in routine backups that are deleted on our standard cycle.
Depending on where you live and the applicable law, you may have some or all of the following rights regarding personal information we control:
How to exercise your rights. Contact us at reports@kyroco.ai. We will verify your request and respond within the time required by applicable law. You may use an authorized agent where the law permits. If you are an end user or data subject and your request concerns Customer Content held by one of our customers, please contact that customer, who is the controller of that data; we will assist them as their processor.
EEA/UK complaints. If you are in the EEA or UK, you may lodge a complaint with your local supervisory authority, though we encourage you to contact us first.
U.S. state privacy laws. If you are a resident of California or another U.S. state with a comprehensive privacy law, you have the rights described above to the extent that law provides. We do not sell personal information or share it for cross-context behavioral advertising, and we do not use or disclose sensitive personal information for purposes that require an opt-out right under those laws.
We maintain administrative, technical, and organizational measures designed to protect personal information, as described in our Terms of Service and at kyroco.ai/legal/security. No method of transmission or storage is completely secure, and we cannot guarantee absolute security. Please protect your credentials and notify us promptly of any suspected compromise.
The Sites and Services are intended for business and professional use by individuals who are at least 18 years old. We do not knowingly collect personal information from children. If you believe a child has provided us personal information, please contact us and we will take appropriate steps to delete it.
The Sites and Services may link to, or interoperate with, third-party websites, agents, tools, and model providers that we do not control. Their privacy practices are governed by their own policies, and we are not responsible for them. Please review the privacy policies of any third party before providing your information.
We may update this Privacy Policy from time to time. If we make a material change, we will update the “Last Updated” date and, where required, provide additional notice. Your continued use of the Sites and Services after an update takes effect constitutes acceptance of the updated Policy.
Contact us:
Kyroco, LLC
Attn: Privacy
5772 Bridgeboro Way, Peachtree Corners, GA 30092
Email: reports@kyroco.ai
Kyroco offers the Service to individuals in the EEA and UK. Our Article 27 EU/UK Representative will be identified here upon appointment. Kyroco has not designated a Data Protection Officer, as one is not required for its current processing.
This section supplements the Policy for California residents and describes how we handle personal information under the California Consumer Privacy Act, as amended by the CPRA. It applies to personal information we collect as a business; it does not apply to Customer Content we process as a service provider on behalf of our customers.
In the preceding 12 months we have collected the following categories of personal information about individuals who visit our Sites or administer the Service, for the business and commercial purposes in Section 2 and from the sources in Section 1:
We disclose these categories to service providers / subprocessors for business purposes (see Section 4 and our Subprocessors list), and we retain them as described in Section 7. We do not knowingly collect sensitive personal information for purposes that would trigger the right to limit its use, and we do not use or disclose it for such purposes.
We do not sell personal information and do not share it for cross-context behavioral advertising, as those terms are defined under the CCPA, and we have not done so in the preceding 12 months. We honor a recognized Global Privacy Control (GPC) signal as a valid opt-out of any “sale” or “sharing.”
How to exercise. Submit a request using the contact details in Section 12 or the request method in Section 8. We will verify your request (and an authorized agent’s authority, where one is used) and respond within the timeframes required by law.