Privacy

Privacy Policy

Last updated: June 22, 2026

This policy explains how KayMind handles personal data through our website and during client engagements. KayMind is operated by New Bay Corporation, a United States company.

1. Scope

This policy covers data we collect as a business through our website, inquiries, and project communications. When we build and operate systems for a client, the client is the controller of the data in those systems and we act as a processor under their instructions; that relationship is governed by our Data Processing Addendum.

2. What we collect

Information you provide when you contact us or submit a project brief, including name, email, company, and what you choose to tell us about your project; standard technical data from website visits, such as IP address, browser type, and pages viewed; and communications during an engagement.

3. How we use it

To respond to inquiries, scope and deliver projects, operate and improve our website, and meet legal obligations. We do not sell personal data. We do not use client business data to train models for any purpose outside that client's own project.

4. Legal bases (GDPR)

Where GDPR applies, we process personal data on the basis of legitimate interest, contract, consent where you provide it, and legal obligation.

5. Sharing

We share data only with service providers who help us operate, such as hosting, email, and analytics, under appropriate agreements, and where required by law. A current list of sub-processors used in client engagements is maintained in our Data Processing Addendum.

6. Retention

We keep personal data only as long as needed for the purpose it was collected, or as required by law, and then delete or anonymize it.

7. Your rights

Depending on your location, you may have rights to access, correct, delete, port, or restrict the use of your personal data, and to object to certain processing. To exercise any of these, contact [email protected]. Where GDPR applies, you also have the right to lodge a complaint with your local supervisory authority.

8. International transfers

We are based in the United States and may process data there. Where we transfer personal data out of the EEA or UK, we rely on appropriate safeguards such as Standard Contractual Clauses. Data residency options for client systems are described in our DPA.