Kendri — Privacy Notice

Version: 1.0 · Effective date: 27 August 2026

1. Who we are

Kendri is an AI-powered institutional knowledge and support assistant that helps universities and students' unions answer website visitors' questions using institution-approved information, and route unanswered or potentially sensitive queries to designated staff.

Kendri is a product and trading name of Techytal Ltd, a private limited company incorporated in England and Wales, company number 17421712, registered office 17, St Luke's Crescent, Leeds, LS11 8LA ("Techytal", "we", "us"). For any privacy query, contact us at privacy@kendri.co.uk.

2. Two kinds of data, two different roles

This notice covers two distinct situations, because Kendri acts in different legal capacities depending on what data is involved.

A. Data Kendri controls directly

This includes information about our own customers' administrators and our own business operations: institution administrator names and email addresses, subscription and billing data, invoices, support correspondence, security logs, and account records. For this data, Kendri is the data controller.

B. Data Kendri processes on behalf of an institution

Where Kendri processes personal data submitted by a website visitor through the Ask Kendri widget on an institution's own website — such as the text of a question, or an email address voluntarily provided for follow-up — the institution is generally the data controller and Kendri is the data processor, acting only on that institution's instructions. If you are a website visitor with a question about how your data was handled, please contact the institution whose website you used directly; Kendri will also assist in forwarding any request we receive to the relevant institution.

3. What we collect and why

Depending on how you interact with Kendri, we may process: the text of questions asked through the Ask Kendri widget; an email address, only if voluntarily provided when a question is escalated to institution staff; a session identifier used to maintain context within a single conversation; technical information such as IP address or request metadata present in ordinary technical logs; short, automatically generated summaries and topic keywords of each conversation, together with whether its questions were answered (the conversation text itself is kept only until that summary is produced); the institution's own website content and page URLs; the extracted text of documents an institution administrator chooses to upload to enrich the institution's knowledge base; and, for institution administrators, name and email address and administrative activity records.

If an institution connects its own WhatsApp Business number to Kendri, messages sent to that number are handled in the same way as questions asked in the widget. Meta delivers them to Kendri through the institution's own WhatsApp Business account. We use the sender's WhatsApp number to send the reply; it is stored only when a question is passed to institution staff, so they can follow up, and is otherwise represented in our records by a pseudonymous identifier.

When an administrator uploads a document (for example, a policy or handbook), we extract its text and generate the searchable, indexed content used to answer questions from it. The uploaded file itself is not stored — not in a database, a storage bucket, or on disk, even temporarily — only the extracted content is retained.

We use this information to: provide and operate the Services; generate and retrieve relevant answers; maintain conversation context; give the institution's administrators aggregated activity, resolution and topic-trend insights; route unanswered or sensitive questions to the relevant institution's staff; process any contact details voluntarily supplied for follow-up; maintain security and service integrity; handle billing and subscriptions; and comply with our legal obligations.

4. AI processing

Answering a question may involve sending the question text and relevant website content to third-party AI service providers (see Section 6) so that a response can be generated. Responses are produced from the institution's own authorised content and may occasionally contain errors — Kendri is not an authoritative decision-maker for the institution. We do not use customer or end-user content to train general-purpose AI models unless separately and expressly agreed.

5. The Ask Kendri widget notice

The widget itself displays the following notice to every visitor, beneath the institution's welcome message, before they rely on a response:

"Kendri uses AI, so answers may occasionally be inaccurate. Please check important information with [Institution Name], and don't share passwords, payment card details or unnecessary sensitive personal information."

6. A note on safety and welfare messages

Ask Kendri includes an automated, best-efforts feature intended to identify messages that may indicate a welfare, safety, or safeguarding concern, and route them to designated institution staff for human follow-up. This is disclosed to visitors as:

"If your message suggests you may need urgent help, it may be shared with designated staff at [Institution Name]. Kendri is not an emergency service."

This feature is probabilistic and best-efforts only: it may miss a genuine concern, or flag an ordinary message unnecessarily, and does not guarantee any particular response time. It is not a substitute for an institution's own safeguarding or emergency procedures, and Kendri is not an emergency, medical, counselling, or safeguarding service.

7. Sub-processors

We use the following categories of third-party service provider to deliver the Services. We will keep this list current and notify institutional customers of material changes as required by our Data Processing Agreement with them.

The full, current list is also maintained on its own page at kendri.co.uk/subprocessors.

8. International transfers

Some of the providers listed above may process information outside the United Kingdom. Where this occurs, we use appropriate legal safeguards recognised under UK data protection law, which may include an applicable adequacy decision, the UK International Data Transfer Agreement, or the UK Addendum to the EU Standard Contractual Clauses.

9. How long we keep information

We retain personal data only for as long as reasonably necessary for the purposes described in this notice, applying the following default periods (subject to legal, security, or dispute-related exceptions):

  • Session conversation context, including the conversation text held only until an automatic summary is produced: target maximum 24 hours
  • Conversation summaries, topic keywords and answered/unanswered outcome labels, and the topic groupings and weekly topic briefs derived from them: 12 months
  • Answered visitor questions: not kept as text beyond the summary window above
  • Unanswered or escalated questions, and any email address or WhatsApp number collected for follow-up: 90 days following resolution or last relevant activity
  • Visitor ratings/feedback: 90 days
  • Usage and cost records, and security/audit logs: 12 months
  • Institution administrator account data: duration of the account plus 30 days
  • Data following contract termination: a 30-day export window, then deletion from active systems (backups roll off within a further 90 days)

10. Your rights

If an institution is the controller of your data (see Section 2), your rights are generally exercised against that institution directly, and we will help forward any request we receive to them. Where Kendri is the controller (for example, if you are one of our own customer's administrators), you may have rights to access, correct, delete, restrict, or object to our processing of your information, and to receive a portable copy of it, subject to applicable law. Contact us at privacy@kendri.co.uk to exercise these rights, or to lodge a concern with the UK Information Commissioner's Office.

11. Security

We maintain technical and organisational measures appropriate to the risk of our processing, including logical separation between different institutions' data, encryption in transit, access controls, administrative audit logging, and regular security review of our systems and vendors.

12. Cookies and similar technologies

On our own website (www.kendri.co.uk) we use a small number of strictly necessary technologies and, only with your consent, optional analytics.

  • Strictly necessary (always active, no consent required under the Privacy and Electronic Communications Regulations): a sign-in session and one-time-passcode verification state for administrators (stored in your browser's local storage, not sent to us as a cookie); anti-bot and security checks provided by Cloudflare (__cf_bm, cf_clearance and the Cloudflare Turnstile challenge); and a record of your cookie choice itself (kendri_cookie_consent, kept for 12 months).
  • Analytics / performance (optional, off unless you opt in): we use Google Analytics 4, provided by Google, to understand how this website is used — which pages are visited, how visitors arrive, and where they leave. It sets cookies in your browser (_ga and _ga_<id>) that distinguish one visitor from another. Nothing is loaded and no cookie is set unless you accept analytics cookies on the banner; if you decline, no request is made to Google at all. You can change your choice at any time using the "Cookie Preferences" link in the footer. IP addresses are truncated before storage, and we do not use this data to identify you personally or for advertising.
  • Measurement across our other websites: the same Google Analytics property covers techytal.com and scpase.co.uk, which are operated by the same company. If you move between those sites and this one, your visit is counted as one continuous session rather than several. This only happens after you have accepted analytics cookies, and only across those three domains.

The Ask Kendri widget embedded on an institution's own website does not set advertising or cross-site tracking cookies. So that a chat can continue after the page is reloaded, it keeps a session identifier and the visitor's recent conversation in the visitor's own browser (local storage) for up to 7 days; this is not sent to us as a cookie, and clearing the site's data in the browser removes it (see Section 3).

13. Changes to this notice

We may update this notice from time to time. Material changes will be notified to institutional customers in accordance with our contractual arrangements with them.

14. Contact us

Questions about this notice, or about how Kendri handles personal data, can be sent to privacy@kendri.co.uk.