Kendri
Home
[COMPANY NUMBER] and [REGISTERED ADDRESS] below still require the Company's real registration details before this document is used live — everything else has been completed.

Kendri — Privacy Notice

Version: 1.0 · Effective date: [EFFECTIVE DATE — to be set at publication]

1. Who we are

Kendri is an AI-powered institutional knowledge and support assistant that helps universities and students' unions answer website visitors' questions using institution-approved information, and route unanswered or potentially sensitive queries to designated staff.

Kendri is a product and trading name of Techytal Ltd, a company incorporated in England and Wales, company number [COMPANY NUMBER], registered office [REGISTERED ADDRESS] ("Techytal", "we", "us"). For any privacy query, contact us at privacy@kendri.co.uk.

2. Two kinds of data, two different roles

This notice covers two distinct situations, because Kendri acts in different legal capacities depending on what data is involved.

A. Data Kendri controls directly

This includes information about our own customers' administrators and our own business operations: institution administrator names and email addresses, subscription and billing data, invoices, support correspondence, security logs, and account records. For this data, Kendri is the data controller.

B. Data Kendri processes on behalf of an institution

Where Kendri processes personal data submitted by a website visitor through the Ask Kendri widget on an institution's own website — such as the text of a question, or an email address voluntarily provided for follow-up — the institution is generally the data controller and Kendri is the data processor, acting only on that institution's instructions. If you are a website visitor with a question about how your data was handled, please contact the institution whose website you used directly; Kendri will also assist in forwarding any request we receive to the relevant institution.

3. What we collect and why

Depending on how you interact with Kendri, we may process: the text of questions asked through the Ask Kendri widget; an email address, only if voluntarily provided when a question is escalated to institution staff; a session identifier used to maintain context within a single conversation; technical information such as IP address or request metadata present in ordinary technical logs; the institution's own website content and page URLs; and, for institution administrators, name and email address and administrative activity records.

We use this information to: provide and operate the Services; generate and retrieve relevant answers; maintain conversation context; route unanswered or sensitive questions to the relevant institution's staff; process any contact details voluntarily supplied for follow-up; maintain security and service integrity; handle billing and subscriptions; and comply with our legal obligations.

4. AI processing

Answering a question may involve sending the question text and relevant website content to third-party AI service providers (see Section 6) so that a response can be generated. Responses are produced from the institution's own authorised content and may occasionally contain errors — Kendri is not an authoritative decision-maker for the institution. We do not use customer or end-user content to train general-purpose AI models unless separately and expressly agreed.

5. The Ask Kendri widget notice

The widget itself displays the following notice to every visitor before they rely on a response:

"Kendri uses AI to answer questions using information provided by [Institution Name]. Responses may occasionally be inaccurate. Please verify important information with the institution. Please do not share passwords, payment card details, or unnecessary sensitive personal information."

6. A note on safety and welfare messages

Ask Kendri includes an automated, best-efforts feature intended to identify messages that may indicate a welfare, safety, or safeguarding concern, and route them to designated institution staff for human follow-up. This is disclosed to visitors as:

"If your message suggests you may need urgent help, it may be shared with designated staff at [Institution Name]. Kendri is not an emergency service."

This feature is probabilistic and best-efforts only: it may miss a genuine concern, or flag an ordinary message unnecessarily, and does not guarantee any particular response time. It is not a substitute for an institution's own safeguarding or emergency procedures, and Kendri is not an emergency, medical, counselling, or safeguarding service.

7. Sub-processors

We use the following categories of third-party service provider to deliver the Services. We will keep this list current and notify institutional customers of material changes as required by our Data Processing Agreement with them.

The full, current list is also maintained on its own page at kendri.co.uk/subprocessors.

8. International transfers

Some of the providers listed above may process information outside the United Kingdom. Where this occurs, we use appropriate legal safeguards recognised under UK data protection law, which may include an applicable adequacy decision, the UK International Data Transfer Agreement, or the UK Addendum to the EU Standard Contractual Clauses.

9. How long we keep information

We retain personal data only for as long as reasonably necessary for the purposes described in this notice, applying the following default periods (subject to legal, security, or dispute-related exceptions):

  • Session conversation context: session-based, target maximum 24 hours
  • Answered visitor questions: 30 days
  • Unanswered or escalated questions, and any email address collected for follow-up: 90 days following resolution or last relevant activity
  • Visitor ratings/feedback: 90 days
  • Usage and cost records, and security/audit logs: 12 months
  • Institution administrator account data: duration of the account plus 30 days
  • Data following contract termination: a 30-day export window, then deletion from active systems (backups roll off within a further 90 days)

10. Your rights

If an institution is the controller of your data (see Section 2), your rights are generally exercised against that institution directly, and we will help forward any request we receive to them. Where Kendri is the controller (for example, if you are one of our own customer's administrators), you may have rights to access, correct, delete, restrict, or object to our processing of your information, and to receive a portable copy of it, subject to applicable law. Contact us at privacy@kendri.co.uk to exercise these rights, or to lodge a concern with the UK Information Commissioner's Office.

11. Security

We maintain technical and organisational measures appropriate to the risk of our processing, including logical separation between different institutions' data, encryption in transit, access controls, administrative audit logging, and regular security review of our systems and vendors.

12. Changes to this notice

We may update this notice from time to time. Material changes will be notified to institutional customers in accordance with our contractual arrangements with them.

13. Contact us

Questions about this notice, or about how Kendri handles personal data, can be sent to privacy@kendri.co.uk.