Privacy Policy
Kinobi builds a graph of companies and the people who make buying decisions at them, from public sources. That means we process personal data about people who never signed up with us. This page explains exactly what we hold, why we believe we are allowed to, and how you get it removed.
- Who we are
- The short version
- Data about visitors and customers
- Data about business contacts in the Kinobi graph
- Where graph data comes from
- Why we are allowed to process it
- Who we share data with
- How long we keep it
- Your rights, and how to use them
- International transfers
- Security
- Changes to this policy
- Contact
1. Who we are
Kinobi is a B2B sales-intelligence product operated by Kinobi, Inc., a Delaware corporation (“Kinobi”, “we”, “us”), with its principal place of business at 11 Franklin St, San Francisco, CA 94102, United States.
For people in the UK, EU, or Switzerland, Kinobi is the data controller for the business-contact data in our graph, and a processor for data our customers upload or ask us to enrich on their behalf.
2. The short version
| Question | Answer |
|---|---|
| Do you track me on this website? | No. This site loads no analytics, no advertising pixels, and no third-party cookies. Our Content-Security-Policy blocks third-party scripts outright, so this is enforced, not just promised. |
| Do you set cookies? | The marketing site sets none. The signed-in product uses strictly necessary cookies for authentication only. |
| Do you hold data about me even if I never signed up? | Possibly, if you are named publicly in a work context — see section 4. |
| Do you sell personal data? | We do not sell data to advertisers or data brokers. But we do make business-contact records available to our customers, and under California law that can count as a “sale” or “sharing”. We treat it as such and honour opt-outs — see section 9. |
| How do I get removed? | Submit a removal request. We action verified requests within 30 days and suppress your identifiers so you are not re-added. |
| Do you use my data to train AI models? | We use third-party language models to read and structure public web pages. We do not sell or license data for third-party model training, and our providers are contractually barred from training on our API inputs. |
3. Data about visitors and customers
What we collect
- Campaign-planning and early-access requests — the contact details and business context you send by email or provide when booking a meeting.
- Account data (early-access users only) — name, work email, and authentication identifiers, handled by our auth provider.
- Support correspondence — anything you send us by email.
- Server logs — our hosting and API providers record IP address, user agent, and timestamps for security and abuse prevention, kept for a rolling 30 days.
What we do with it
We use it to respond to your request, plan the engagement, give you access, keep the service secure, and — if you asked for it — send product updates. Every marketing email has a one-click unsubscribe. We do not add customer contact details to the company graph.
Legal basis (UK/EU): performance of a contract for account and support data; legitimate interests for security and service communications; consent for marketing email, withdrawable at any time.
4. Data about business contacts in the Kinobi graph
This is the part that matters most, and the part most companies in our category bury. Kinobi maintains a graph of organisations and the people associated with them in a professional capacity. If you are publicly identified as working somewhere — on a company team page, a conference speaker list, a regulatory filing, or a public professional profile — you may be in it.
Categories of personal data we may hold
| Category | Examples |
|---|---|
| Professional identity | Name; current job title, function, level, and department; employer; work location |
| Business contact details | Work email address; work phone number, where published |
| Public professional links | Professional network profile URL, public code-hosting username, personal or professional website |
| Career history | Previous employers and titles, role start dates, publicly listed education |
| Role changes | Title changes and departures, where publicly announced |
| Derived data | A short profile summary and a numeric vector (“embedding”) generated from the above, used for search; an assessment of whether the role is likely to be a decision-making one |
| Provenance | The source URL and timestamp for every fact, so any record can be traced back and checked |
We do not collect special-category data (health, race, religion, political opinions, sexual orientation, trade-union membership, biometrics) and we do not want it. We do not collect personal email addresses, home addresses, or personal phone numbers. We do not scrape content behind a login, paywall, or CAPTCHA, and we do not buy contact lists from data brokers. We do not build profiles of private individuals acting outside a professional context.
If you find any of the above in a Kinobi record, that is a defect as well as a rights issue — please tell us and we will remove it and fix the source.
5. Where graph data comes from
Every fact in the graph carries the URL it came from and the date it was read. Our sources are:
- Public company websites — team, about, careers, customer, and newsroom pages
- Public job postings, including company careers pages and applicant-tracking systems
- Public regulatory and corporate filings, including US SEC filings and UK Companies House records
- Public DNS records and HTTP response headers, used to infer which technologies a company runs
- Public advertising transparency libraries operated by the major ad platforms
- News, press releases, and public funding announcements
We collect only from publicly accessible pages. If you are responsible for a site and would rather we did not collect from it at all, email the domain to ankit@kinobi.so and we will stop and delete what we hold — see how to opt out.
6. Why we are allowed to process it
UK/EU (UK GDPR and GDPR): we rely on legitimate interests under Article 6(1)(f) — our interest, and our customers’, in identifying relevant business counterparties, balanced against your rights. We have assessed that balance: the data is professional rather than private, it is already public, it is limited to what a business context requires, we hold no special-category data, we publish exactly what we hold, and we make objection easy and unconditional. We will share our legitimate-interests assessment on request.
Because we obtain this data from sources other than you, Article 14 requires that we tell you. This page, our removal page, and the notice we include when a record is first surfaced are how we do that. If you would rather we did not process your data at all, you have an absolute right to object where it is used for direct marketing, and we will honour it without asking why.
California (CCPA/CPRA): we collect the categories of personal information described in section 4 for the business purposes described in this policy. Making business-contact records available to our customers may constitute a “sale” or “sharing” as those terms are defined by the CPRA. You may opt out at any time via Do Not Sell or Share My Personal Information. We do not knowingly collect information about anyone under 16, and therefore do not sell or share it.
7. Who we share data with
We do not sell data to advertisers or data brokers. We share personal data with:
- Customers, who query the graph under a licence that forbids re-sale, forbids use for consumer marketing, and requires them to honour opt-outs.
- Service providers (subprocessors) who host our infrastructure, send our email, authenticate our users, and provide the language models that structure public pages. The current list, with what each one receives, is published on our Trust page.
- Advertising platforms, only where a customer approves a managed campaign. The audience, platforms, identifiers and customer account used for activation are agreed before launch; we do not place Kinobi graph data into an advertising platform outside that approved scope.
- Authorities, where we are legally compelled. We will tell you unless we are legally barred from doing so.
- An acquirer, if we are ever bought or merged — under the same commitments made here.
8. How long we keep it
| Data | Retention |
|---|---|
| Sales and early-access contact | Until you unsubscribe or ask us to delete it, or 24 months after the last contact |
| Account data | For the life of the account, then 90 days |
| Server logs | 30 days |
| Graph contact records | While the underlying source remains public and the record stays current; re-verified periodically and removed when the source disappears |
| Suppression list | Indefinitely — a one-way hash of your identifiers, kept for the sole purpose of never re-adding you |
9. Your rights, and how to use them
Wherever you live, and whether or not you are our customer, you can ask us to:
- Show you everything we hold about you, and where each fact came from (access / know)
- Correct anything wrong (rectification)
- Delete it (erasure)
- Stop processing it, including an unconditional objection to direct-marketing use (objection / restriction)
- Opt out of any “sale” or “sharing” under California law
- Export it in a machine-readable format (portability)
- Not be discriminated against for exercising any of the above
Use the data request form, or email ankit@kinobi.so with “Data request” in the subject. We respond within 30 days (extendable once by 60 days for complex requests, with notice). We do not charge for this. We may ask for enough information to confirm the request really is about you — we will ask for the minimum needed, and we delete verification material afterwards.
You can also authorise someone to act for you. If we cannot verify an authorised agent, we will tell you why.
If we get it wrong, you can complain to your data-protection regulator — in the UK the ICO, in the EU your national supervisory authority. We would rather you told us first: ankit@kinobi.so.
10. International transfers
We are based in the United States and our infrastructure is hosted there. If you are in the UK, EU, or Switzerland, your personal data is transferred to the US. We rely on the UK and EU Standard Contractual Clauses (with the UK International Data Transfer Addendum where applicable) with each of our subprocessors, plus the supplementary measures described on our Trust page.
11. Security
Data is encrypted in transit (TLS 1.2+) and at rest. Access to production data is limited to those who need it, requires multi-factor authentication, and is logged. Secrets are held in a managed secret store, never in source control. We run automated dependency and vulnerability scanning on every change.
We are an early-stage company and we will not pretend to certifications we do not hold — see the Trust page for exactly where we are on SOC 2 and what compensating controls we run today. To report a vulnerability, see security.txt.
12. Changes to this policy
We version this page and keep the date at the top current. For any change that materially affects your rights, we will announce it here at least 14 days before it takes effect, and email registered users.
13. Contact
Privacy contact: ankit@kinobi.so
Post: Kinobi, Inc., 11 Franklin St, San Francisco, CA 94102, United States
Fastest route for removal: kinobi.so/data-request