Privacy Policy
Last updated: August 4, 2026
1. Introduction
This Privacy Policy explains how Adsero, LLC ("Adsero", "Kraitos", "we", "us", or "our") collects, uses, discloses, and safeguards personal data in connection with Kraitos AIDR, our business-to-business AI-governance and endpoint-security platform available at aidr.kraitos.io (the "Service").
Kraitos AIDR helps organizations discover, monitor, and govern the use of AI coding assistants and other AI tools across their workforce, and provides endpoint-security telemetry such as threat detection, software inventory, and secret-exposure findings. Because the Service is deployed by organizations onto devices used by their own personnel, this Policy distinguishes carefully between the data we handle as a controller and the data we handle as a processor on behalf of our business customers (see Section 3).
This Policy applies to the marketing website, the web dashboard, the APIs, and the endpoint agent software (collectively, the "Service"). It does not apply to third-party products or websites that we do not control.
If you have questions about this Policy or our data practices, contact us at [email protected] or at the address in Section 15.
2. Who We Are and Scope
The Service is operated by Adsero, LLC, a Florida limited liability company, which does business as Kraitos and as Adsero Security, and is the provider of Kraitos AIDR.
- Our business customers are the organizations ("Customers") that subscribe to the Service and deploy the endpoint agent within their environments.
- Authorized users are the individuals a Customer invites to access the dashboard (for example, security administrators).
- Monitored users are the Customer's own personnel (for example, developers and other employees or contractors) whose devices run the endpoint agent and whose AI-tool activity and endpoint telemetry the Service records on the Customer's behalf.
This Policy covers all three groups but, as explained below, our legal role differs depending on the category of data.
3. Controller vs. Processor Roles
Data-protection laws such as the EU/UK General Data Protection Regulation ("GDPR") and the California Consumer Privacy Act as amended by the CPRA ("CCPA/CPRA") assign different responsibilities depending on who decides the purposes and means of processing. Our roles are:
A. Kraitos AIDR as a processor (service provider) — endpoint and AI-tool telemetry. For the AI-tool telemetry, endpoint/device telemetry, and secret findings that the endpoint agent collects from a Customer's devices (see Sections 4.2–4.4), the Customer is the data controller and Kraitos AIDR is the data processor (a "service provider" under CCPA/CPRA). We process this data only on the Customer's documented instructions and in accordance with our Data Processing Addendum ("DPA"). The Customer decides who to monitor, what to collect, and how long to retain it, and the Customer is responsible for having a lawful basis and for informing its personnel (see Section 6).
B. Kraitos AIDR as a controller — account and billing data. For the account, billing, and administrative data of the Customer and its authorized dashboard users (see Section 4.1), and for our own operation of the marketing site and Service, Kraitos AIDR acts as a controller. This Policy governs that processing directly.
Where we act as a processor, the Customer's own privacy notice — not this Policy — governs how monitored users may exercise their rights; we will refer such requests to the relevant Customer.
4. Categories of Data We Collect
4.1 Account, billing, and administrative data (we act as controller)
- Identity and contact data for authorized users: name, email address, and role.
- Authentication data: a hashed password (we never store passwords in plaintext), session identifiers, and multi-factor settings if enabled.
- Organization/tenant data: organization name, tenant identifier, and configuration settings.
- Subscription and payment metadata: plan, subscription status, and billing history. Card payments are processed by Stripe; we do not store full card numbers. We retain only limited payment metadata such as the card brand and last four digits, and a Stripe customer/subscription identifier.
- Support and communications data: messages you send us and related correspondence.
4.2 AI-tool telemetry captured by the endpoint agent (we act as processor)
Where enabled by the Customer, the endpoint agent records the use of AI coding assistants and related AI tooling, which may include:
- AI assistant session content: prompts submitted, responses returned, and tool calls made.
- File paths accessed during a session.
- Token counts and cost estimates.
- MCP (Model Context Protocol) server and tool usage.
- The AI models and tools used.
Note on sensitive content. AI-assistant prompts and responses can contain sensitive information typed or generated by the Customer's personnel — including source code, credentials, or personal data. Customers control what is captured and are responsible for governing this content appropriately.
4.3 Endpoint and device telemetry (we act as processor)
- Device and identity attributes: hostname, logged-in username, operating system, and hardware/device identifier.
- Agent metadata: agent version and configuration.
- Running processes and outbound network connections, in particular connections to large-language-model (LLM) API endpoints.
- Installed AI tools and browser extensions.
- File-integrity events, malware/threat detections, and indicator-of-compromise ("IOC") matches.
- Software and dependency inventory.
4.4 Secret findings (we act as processor)
- Detected credentials or secrets discovered on monitored devices, stored in redacted form for general viewing plus the raw value for the detailed finding view so administrators can investigate.
- Associated metadata such as entropy score and severity.
4.5 Data collected automatically about use of the dashboard (we act as controller)
- Log and technical data: IP address, browser type, device type, and timestamps.
- Strictly necessary cookies and similar technologies used to keep you signed in and to protect against cross-site request forgery. See our Cookie Policy for details.
- Marketing-website analytics. Our public website at www.kraitos.io uses Google Analytics 4 to measure page views and referrals, and Cloudflare Web Analytics, which is cookieless. The dashboard and the endpoint agent do not load either. See our Cookie Policy for the cookies involved and how to opt out.
5. How and Why We Use Data (Lawful Bases)
When we act as a controller (Section 4.1, 4.5), we rely on the following lawful bases under GDPR:
- Performance of a contract (Art. 6(1)(b)): to create and administer accounts, authenticate users, provide the Service, and process subscriptions and billing.
- Legitimate interests (Art. 6(1)(f)): to secure, maintain, monitor, and improve the Service; to prevent fraud and abuse; and to communicate about service-related matters. We balance these interests against your rights.
- Legal obligation (Art. 6(1)(c)): to meet accounting, tax, and other legal requirements.
- Consent (Art. 6(1)(a)): where we ask for it, for example for optional marketing communications. You may withdraw consent at any time.
When we act as a processor (Sections 4.2–4.4), we process data solely on the documented instructions of the Customer, who is responsible for establishing the applicable lawful basis for the monitoring. Typical customer purposes include AI-usage governance, security monitoring, threat detection, incident response, and compliance.
We do not sell personal data, and we do not use AI-tool telemetry, endpoint telemetry, or secret findings to train our own or third parties' machine-learning models except as instructed by the Customer.
6. The Endpoint Agent and Employee-Monitoring Notice and Consent
The endpoint agent is workforce-monitoring software. Because it can record AI-assistant prompts and responses, running processes, network connections, and secret findings from personnel devices, it may capture personal data and sensitive content.
Customer responsibility. The Customer, as controller, is solely responsible for:
- Determining the lawful basis for monitoring under applicable employment, privacy, and surveillance laws.
- Informing its personnel that the endpoint agent is deployed and describing what it collects, consistent with any transparency, notice, works-council, or consent requirements in the relevant jurisdictions.
- Configuring the scope of collection and retention appropriately, and limiting access to the collected data within its organization.
Kraitos AIDR provides the tooling and controls but does not, as processor, undertake the Customer's notice-and-consent obligations toward the Customer's personnel. Monitored users with questions about why they are being monitored should contact their own organization.
7. Sharing and Sub-Processors
We share personal data only as needed to operate the Service:
Sub-processors / service providers. We engage vetted third parties to host and support the Service. Each is bound by contractual obligations consistent with our DPA. A current list — including name, purpose, and location — is maintained in the Annex to our Data Processing Addendum (DPA) and summarized below:
- Stripe — payment processing.
- Mailgun / Anymail — transactional email delivery.
- DigitalOcean — cloud hosting, managed PostgreSQL databases, and Spaces object storage (including data exports).
- Slack — only where a Customer configures alert delivery to its own Slack workspace.
- Sentry — application error monitoring.
- Cloudflare — content delivery network, edge security, and secure tunneling.
- Google — Google Analytics on the marketing website only; not used in the dashboard or the agent.
Professional advisers and authorities. We may disclose data to legal, accounting, and insurance advisers, or to law enforcement or regulators, where required by law or to protect our rights, users, or the public.
Business transfers. If we are involved in a merger, acquisition, financing, or sale of assets, personal data may be transferred as part of that transaction, subject to this Policy or successor terms.
We do not sell personal data or share it for cross-context behavioral advertising.
8. International Data Transfers
We and our sub-processors may process personal data in countries other than the one where it was collected, including the United States. Where we transfer personal data out of the European Economic Area, the United Kingdom, or Switzerland to a country without an adequacy decision, we rely on appropriate safeguards such as the European Commission's Standard Contractual Clauses ("SCCs") (and the UK Addendum, where applicable), together with supplementary measures where needed. You may request more information about these safeguards using the contact details in Section 15.
9. Data Retention
We retain personal data only for as long as necessary for the purposes described in this Policy, unless a longer period is required by law:
- Account and billing data (controller): retained for the life of the account and then for three (3) years to meet legal, tax, and accounting obligations.
- AI-tool telemetry, endpoint telemetry, and secret findings (processor): retained according to the Customer's configured retention settings and instructions. On expiry or on termination of the Customer's subscription, we delete or return this data as described in the DPA.
- Logs and security data: retained for 90 days and then deleted or aggregated.
Where the Customer controls retention, the Customer's settings govern; where we control retention, we apply the periods above and delete or irreversibly anonymize data thereafter.
10. Security
We maintain technical and organizational measures designed to protect personal data, including:
- Encryption in transit (TLS) and encryption at rest for stored data.
- Tenant isolation using row-level security ("RLS") so that each Customer's data is logically segregated.
- Access controls, including role-based access, least-privilege principles, and authentication safeguards for our personnel.
- Network protections, logging and monitoring, and error monitoring.
- Secure software-development and change-management practices.
A fuller description of our technical and organizational measures is provided in the Annex to our DPA. No method of transmission or storage is completely secure, and we cannot guarantee absolute security.
11. Your Privacy Rights
11.1 GDPR / UK GDPR rights
Where we act as a controller and subject to applicable law, you may have the right to:
- Access the personal data we hold about you and receive a copy.
- Rectify inaccurate or incomplete data.
- Erase your data ("right to be forgotten").
- Restrict or object to certain processing, including processing based on legitimate interests.
- Data portability — receive certain data in a structured, machine-readable format.
- Withdraw consent at any time where processing is based on consent.
- Lodge a complaint with the data-protection supervisory authority in your country of residence, place of work, or the place of the alleged infringement.
Self-serve export and deletion. The Service provides self-service GDPR export and delete endpoints so that eligible data can be exported or erased directly. Where you are a monitored user of a Customer, we act as processor and will refer your request to the relevant Customer, who controls the data.
11.2 CCPA / CPRA rights (California)
If you are a California resident, and subject to applicable law, you may have the right to:
- Know / access the categories and specific pieces of personal information we have collected.
- Delete personal information we have collected, subject to exceptions.
- Correct inaccurate personal information.
- Opt out of any "sale" or "sharing" of personal information — note that we do not sell or share personal information as those terms are defined under the CPRA.
- Limit the use of sensitive personal information.
- Non-discrimination for exercising your rights.
Where we handle personal information as a service provider on a Customer's behalf, we will direct your request to that Customer.
11.3 How to exercise your rights
Authorized users can use in-product export and delete tools where available, or contact [email protected]. We will verify your identity before acting and will respond within the timeframes required by applicable law. You may use an authorized agent where the law permits.
12. Children's Data
The Service is a business tool that is not directed to children and is not intended for use by anyone under the age of 16. We do not knowingly collect personal data from children. If you believe a child has provided us personal data, contact us at [email protected] and we will delete it.
13. Automated Decision-Making
We do not use the personal data described in this Policy to make decisions producing legal or similarly significant effects about individuals solely by automated means without human involvement. Detections and findings surfaced by the Service are intended to support, not replace, human review by the Customer.
14. Changes to This Policy
We may update this Policy from time to time. When we make material changes, we will update the "Last updated" date above and, where appropriate, provide additional notice (for example, by email or an in-product notice). Your continued use of the Service after an update constitutes acceptance of the revised Policy.
15. Contact Us
For privacy questions or to exercise your rights, contact:
- Email: [email protected]
- Privacy contact: [email protected] (we have not appointed a formal Data Protection Officer under GDPR Art. 37)
- Controller: Adsero, LLC (d/b/a Kraitos)
- Postal address: 12605 Race Track Rd, Tampa, FL 33626, USA
- Governing law: This Policy is governed by the laws of the State of Florida, United States, without prejudice to mandatory data-protection rights available under your local law.
If you are in the EEA or UK and are not satisfied with our response, you may lodge a complaint with the supervisory authority in your country. We have no establishment in the European Union and have not appointed an Article 27 representative; if that changes, we will update this Policy.