Legal

Privacy Policy

This is an early version published ahead of launch and will be refined with counsel. Last updated 20 September 2026.

1. Who we are

Kybex operates a portable business-data platform at kybex.io. A business stores its own company documents and structured registration data with us, and decides when to share that information with an institution such as a bank, payment provider, insurer, landlord or vendor.

This policy explains what we collect, why, how long we keep it, and the choices you have. It applies to businesses using a vault, institutions receiving shares, and visitors to our website.

2. Information we collect

Account information: the email address used to sign in, your name, your account type (business or institution), and the name of the organisation you represent.

Business data you provide: structured fields such as legal name, incorporation number and date, tax identification number, registered address, directors and beneficial owners, along with the documents you upload to support them.

Documents: the files themselves, their file names and types, their sizes, a SHA-256 hash of each file, version numbers, and any expiry date you record.

Activity data: an append-only record of uploads, edits, shares, views and internal support access, each with a timestamp and the actor responsible. This log is central to the service and cannot be edited or deleted.

Technical data: standard server logs, including IP address and browser information, needed to operate and secure the platform.

3. Personal data inside business records

Company records routinely name individuals — directors, beneficial owners, signatories. Where you enter or upload such information, you are responsible for having a lawful basis to do so and for the accuracy of what you submit. Kybex processes that information on your instruction, as part of delivering the vault and share functions you use.

4. How we use information

To operate your vault: storing, hashing, versioning and displaying your documents and structured fields.

To assist with extraction: when you upload a document, we may send it to an AI processing provider to propose matching field values. Proposed values are always marked unconfirmed until you confirm them. We do not use your documents to train third-party models.

To deliver shares: sending the notification email from Kybex, hosting the share page, and recording when it was opened and how the requester responded.

To keep you informed: renewal and expiry reminders, and service notices.

To support and improve the service: aggregate usage measurement, troubleshooting and fraud prevention.

5. When information is shared

With institutions you choose: only the documents and fields you select for a given share, and only through that share.

With service providers: cloud hosting, database and file storage, email delivery, and AI extraction providers, each acting under contract and only to provide the service.

For legal reasons: where we are required to disclose information by law, or to protect our rights, users or the public.

Kybex does not sell your data, and does not share it with institutions you have not shared with.

6. What Kybex does not do

Kybex does not verify that your data or documents are true, and does not check them against any registry. Institutions continue to run their own review. What we can attest to is provenance: that a specific file came from a specific business and has not been altered since a specific date.

7. Retention

We keep vault contents while your account is active. When you delete a document, the record of the deletion stays in the chain-of-custody log even though the file is removed from active storage. Where a document was already shared, the institution's copy of the record persists in its inbox. Chain-of-custody events are retained for as long as we operate the platform, because they are the basis of the provenance guarantee.

You may ask us to close your account and remove your vault contents at any time by writing to privacy@kybex.io.

8. Security

Documents are held in private storage and are not publicly addressable. Access to a vault is limited to the account that owns it and, for support purposes, to authorised Kybex team members whose access is itself logged. Share recipients receive short-lived, per-file download links. Data is encrypted in transit and at rest by our infrastructure providers.

9. International transfers

Kybex is built to be jurisdiction-agnostic. Data may be processed in countries other than the one you operate from, in which case we rely on appropriate safeguards offered by our providers. If you have specific data-residency requirements, contact us before onboarding.

10. Your rights

Depending on where you are, you may have the right to access, correct, export, restrict or delete personal data we hold, and to object to certain processing. Because most content in Kybex is submitted by a business about itself, the fastest route is usually to edit it directly in your vault. For anything else, write to privacy@kybex.io and we will respond within a reasonable period.

11. Cookies

We use only the cookies and local storage needed to keep you signed in and to keep the service secure. We do not run third-party advertising trackers.

12. Changes and contact

We will post any material change to this policy on this page and, where appropriate, notify account holders by email. Questions: privacy@kybex.io.