Privacy Policy
Last updated: April 2026
1. Data Controller
KISMO SASU, represented by Guillaume Sanchez, is the data controller for personal data collected on Kismo.ai. DPO contact: dpo@kismo.ai
2. Data Collected
We collect the following data: name, email address, phone number (during registration), browsing data (cookies), voice recordings (when using the Kismo service), billing data (for paid subscriptions).
3. Purpose of Processing
Your data is processed for: providing the Kismo service (transcription, analysis, synthesis), managing your user account, billing and subscription management, sending commercial communications (with your consent), improving our services and usage analysis, complying with our legal obligations.
4. Legal Basis
The processing of your data is based on: contract execution (service provision), your consent (newsletter, non-essential cookies), our legitimate interest (service improvement, security), our legal obligations (billing, legal retention).
5. Data Retention
Account data: duration of subscription + 3 years. Voice recordings: deleted immediately after processing (non-retention option available). Transcriptions and notes: duration of subscription. Billing data: 10 years (legal obligation). Cookies: 13 months maximum.
6. Data Recipients
Your data may be shared with: our technical subcontractors (hosting, AI transcription), our payment providers, competent authorities upon legal request. We never sell your data to third parties.
7. Transfers Outside the EU
Your data is hosted in the European Union. In case of transfer outside the EU (technical subcontractors), we ensure appropriate safeguards are in place (standard contractual clauses, adequacy decision).
8. Your Rights
Under the GDPR, you have the following rights: right of access, right of rectification, right to erasure ("right to be forgotten"), right to restriction of processing, right to data portability, right to object, right to withdraw consent. To exercise your rights: dpo@kismo.ai. You may also file a complaint with the CNIL (www.cnil.fr).
9. Security
We implement appropriate technical and organizational measures to protect your data: encryption at rest and in transit (TLS 1.3), enhanced authentication (SSO, 2FA), limited data access on a need-to-know basis, regular security audits, non-retention policy for recordings (optional).
10. Changes
We reserve the right to modify this privacy policy at any time. Changes take effect upon publication on the site. We will inform you of any significant changes by email.
