Privacy Policy
Effective August 15, 2026
1Who we are and what this policy covers
Kairos is software for live-entertainment operators — the people who run concerts, DJ sets, and comedy shows. Venue operators use Kairos to plan events, staff them, and keep track of the vendors and crew who make them happen.
This policy is published by Kairos Events Inc ("Kairos", "we", "us"), a Delaware corporation.
It covers:
- our public website at kairosevents.co;
- the Kairos application;
- the email and WhatsApp channels a workspace can use to send information to Kairos.
We act in two different roles, and the difference matters. Section 2 explains it. If you are a member of the public whose contact details a venue has stored in Kairos, section 4 is written for you.
2Our two roles
We are responsible for account data. When you sign up, we decide how your account information is used — your name, email, and how you use the product. This policy governs that data.
We handle workspace data on our customers' behalf. Everything a venue operator puts inside their workspace — their events, their staff and vendor contacts, the messages sent to their Kairos address — belongs to that operator. They decide what goes in and why. We only handle it on their instructions, we do not use it for our own purposes, and we do not sell it or share it for advertising.
Specifically, for workspace data we:
- process it only to provide the product to that operator;
- keep each workspace isolated from every other;
- do not use it to train or improve any artificial-intelligence model;
- return or remove it when the operator closes their workspace or asks us to.
If you have a question about data held inside a specific venue's workspace, contact that venue first. We will help them respond.
3Data we collect about account holders
When you create a Kairos account or are invited to one, we store:
| What | Why |
|---|---|
| Email address and login credential | To create and secure your account |
| First and last name | To identify you to your colleagues |
| Phone number and job title (optional) | To help your workspace reach you |
| Profile photo (optional) | Shown to your colleagues |
| Workspace membership and role | To decide what you can see and do |
| A record of role changes | So workspace owners can audit who changed access |
| Access tokens you create | To let tools you authorize act on your behalf |
Your profile photo is stored in a private bucket. It is not publicly accessible, and only you can write to your own.
Access tokens are stored as a one-way hash. We never keep the token itself, so we cannot show it to you again after you create it.
We do not currently charge for Kairos and we do not collect payment details. If that changes, we will update this policy and name our payment processor before taking any payment.
4Data that others provide about you
This section is for people who never signed up for Kairos.
A venue operator can enter contact details for the staff and vendors they work with — a sound engineer, a security lead, a lighting supplier. They can also import many contacts at once from a spreadsheet, and they can write free-text notes about a person.
If a venue has entered your details, we may hold:
- your name;
- your phone number and email address;
- the company you work with;
- notes the venue has written about working with you;
- your appearance on the To or Cc line of an email sent to that venue's Kairos address.
We did not obtain this from you, and we have no direct relationship with you. The venue operator that entered your details decides why they hold them and is responsible for having a lawful reason to do so, and for telling you they use Kairos. We publish this section so that you can understand what happens to your information regardless.
Your rights still apply. Section 10 explains how to exercise them. If you contact us, we will route your request to the venue that controls your data and help them act on it.
5Messages sent to a workspace
A workspace can receive information through two channels. Both work the same way: a message arrives, our software reads it, and it proposes an update for a human at the venue to approve or reject.
Email. Each workspace has its own Kairos email address. When someone emails it, we store the sender's address and display name, the subject, the message body, and the addresses on the To and Cc lines. We do not download, open, or store attachments — not the files, and not their file names.
WhatsApp. A workspace administrator can register their own phone number so they can send updates by WhatsApp. If you are a registered user, we store your number, your WhatsApp display name, and the text of the messages you send.
If you are not registered, we handle your number differently. We do not read or store your message. We reply once to tell you the number is not monitored, and to send that single reply we hold your number for up to about 35 days before deleting it. Separately, we keep a one-way cryptographic hash of your number for about 35 days so that we do not reply to you repeatedly. A hash cannot be read back to reveal your number.
We never download or store images, audio, documents, or any other media sent over WhatsApp. We verify that every message genuinely comes from WhatsApp before we process it.
We do not use the content of your messages to train or improve any artificial-intelligence model.
6Automated processing and AI
Kairos uses an AI model to read inbound messages and draft suggested updates — for example, "add this person to Friday's door team."
The AI cannot change anything. This is enforced by the database itself, not only by our software: the account the AI runs under has no permission to write to any business record. It can only file a suggestion. The kinds of suggestion it can make are fixed and limited — creating an event, filling a staffing slot, and adding a person to fill one. It cannot invite anyone, change anyone's access, delete anything, or send email on your behalf.
A person at the venue reviews every suggestion and approves, edits, or rejects it. No suggestion takes effect on its own.
To produce a suggestion, the model receives the message content and relevant context from that workspace's own records. It does not receive data from any other workspace.
Once a person approves a suggestion, the information in it becomes a permanent business record — an event, a staffing assignment, or a contact. From that point it is ordinary workspace data and is no longer subject to the message retention period in section 8.
7How we use data
We use personal information to:
- provide the product and keep your account working;
- keep accounts and workspaces secure, and investigate abuse;
- prevent unwanted or automated traffic on our messaging channels;
- respond to support requests;
- meet our legal obligations.
We do not sell your personal information, and we do not share it for cross-context behavioral advertising. We do not share it with advertising networks, data brokers, or resellers. We do not use it for advertising or profiling. We have not sold or shared personal information in the preceding twelve months.
8How long we keep data
We are precise here because the distinction matters.
| What | How long |
|---|---|
| Message content and sender details (email and WhatsApp) | Permanently erased 90 days after we receive it. The message record itself — its identifier and processing history — is kept indefinitely, but with the content and identifying fields blanked |
| Suggestion contents drafted by the AI | Permanently erased after 90 days |
| A one-way fingerprint used to spot duplicate events | Up to 18 months, then erased |
| Unknown WhatsApp sender's number | About 35 days |
| A registered WhatsApp number | For as long as the registration is active. If it is revoked or never completed, deleted after 90 days of inactivity |
| Approved records — events, contacts, assignments | Kept until the venue operator removes them or closes the workspace |
| Account and membership records | Kept for the life of the account |
| Role-change audit records | Kept indefinitely, so workspace owners retain a reliable access history |
Please read this carefully: when we say message content is erased after 90 days, we mean the content and the sender's details are permanently removed. The record that a message arrived, and any record created after someone approved a suggestion from it, remain. We do not claim that a message record becomes fully anonymous after 90 days.
Two exceptions we would rather name than gloss over:
- Invitations. If someone invites you to a workspace, we keep the invitation record — including your email address — indefinitely. That is true whether you accepted it, ignored it, or it was withdrawn.
- WhatsApp conversation grouping. One internal identifier we use to group a WhatsApp conversation retains the sender's phone number after the 90-day erasure, even though the sender field on the same record is cleared.
Neither is necessary for the product to work, and we intend to change both. Until we do, this policy describes what actually happens rather than what we would prefer to say.
10Your rights and choices
Depending on the state you live in, you may have the right to:
- know what personal information we hold about you and how we use it;
- access a copy of it;
- correct information that is wrong;
- delete it;
- opt out of sale or of sharing for advertising — we do neither, so there is nothing to opt out of;
- not be discriminated against for exercising any of these rights. We will not degrade your service because you asked.
For reference, the categories of personal information we collect are: identifiers (name, email, phone), professional information (job title, company, role at a venue), electronic activity limited to the messages described in section 5, and visual information limited to a profile photo you choose to upload. Section 9 lists who receives them. We do not collect biometric data, precise geolocation, financial account information, or government identifiers.
How to make a request: email hello@kairosevents.co. Tell us what you want and enough detail for us to find your data. We will respond within 45 days, and will tell you if we need longer.
Please read this before you make a request, so you know what to expect:
- We handle every request manually. Kairos does not currently offer a self-service button to download or delete your data. We are being explicit about this rather than implying a capability we do not have.
- If your data sits inside a venue operator's workspace, that operator decides the outcome. We will pass your request to them promptly and help them act on it.
- We may need to verify your identity before we act. You may use an authorized agent.
- Some records survive a deletion request. We keep security and access-audit records, and anything we are legally required to retain. We will tell you what we kept and why.
If we cannot resolve your concern, you may contact your state Attorney General.
11Security
- Every workspace's data is isolated at the database level. A request carrying one workspace's credentials cannot read another's.
- Membership is checked on every request, not cached from a login token.
- The AI's database account has no permission to write to any business record.
- Invitation tokens and access tokens are stored only as one-way hashes.
- Profile photos are stored in a private bucket restricted to their owner.
- Inbound webhooks are cryptographically verified before we process them.
- Traffic is encrypted in transit.
No system is perfectly secure, and we do not claim otherwise. If we discover a breach affecting your data, we will notify you as the law requires.
13Children
Kairos is a business tool and is not directed at children. You must be 18 or older to hold an account. We do not knowingly collect data from anyone under 13. If you believe we have, contact us and we will delete it.
14Changes to this policy
If we make a material change, we will update the date at the top and tell account holders before it takes effect.