Agent Assurance Guided Demo Privacy Notice
This Privacy Notice explains how Konfer, Inc. (“Konfer,” “we,” “us,” or “our”) handles personal information when you register for, access, or use the Konfer Agent Assurance Guided Demo (the “Demo”). It supplements the Terms of Use and Guided Demo Notice.
1.Information we collect
Registration and contact information
We collect the first name, last name, company, and email address entered on the registration form. We record whether the email is pending verification or verified, submission and verification timestamps, and the versions, URLs, content hashes, and checkbox and disclosure text shown for the accepted document set.
Authentication and security information
We process passwordless sign-in state, provider identity identifiers, session identifiers, roles, and security/audit events needed to authenticate users, prevent misuse, investigate failures, and revoke sessions. Application audit records use minimized identifiers and fingerprints rather than storing one-time sign-in codes or raw session tokens.
Uploaded telemetry and run information
If you choose to upload a JSONL file, we collect that file and its agent, tool, identity, action, policy, network, observability, security, and related telemetry fields. We create run state, validation results, normalized evidence, findings, scores, recommendations, visualizations, storyboards, narration text and audio, reports, videos, manifests, hashes, cache identifiers, provider usage, and estimated cost records.
If you open a Konfer-provided scenario, we record the account and tenant, the canonical scenario or package identifier, first- and last-access timestamps, access count, and notification-delivery state. The canonical seeded content itself is Konfer-managed and reused across users; the user-linked access record is personal activity information.
Technical and communications information
Our infrastructure may process IP address, browser or user-agent information, request path, timestamps, response status, and similar network and security-log data. Authentication routes are configured to suppress access logging, and logs are designed not to contain uploaded telemetry, secrets, one-time codes, or session tokens. If you contact us, we process the message and contact details you provide.
2.How we use information
We use personal information to:
- validate registration, send and complete passwordless authentication, maintain sessions, and enforce tenant- and run-scoped authorization;
- provide seeded scenario playback or validate, analyze, narrate, render, store, and deliver an uploaded run;
- send an immediate pre-verification registration notification to authorized Konfer personnel and contractors or service providers and contact you about Agent Assurance;
- maintain tenant-scoped cache and idempotency controls, prevent duplicate cost, measure OpenAI usage, and enforce quotas and cost ceilings;
- secure, troubleshoot, monitor, audit, maintain, and improve the reliability of the Demo without using user-uploaded telemetry for unrelated product improvement;
- respond to requests, enforce agreements, protect rights and safety, and comply with legal obligations.
Konfer does not use user-uploaded telemetry for model training, unrelated product improvement, marketing content, or cross-tenant reuse. The Demo is not configured to opt OpenAI API content into model training.
3.How we disclose information
We disclose information only as reasonably necessary for the purposes above:
- Cloud and infrastructure providers. Google Cloud Platform hosts shared application processing with run-scoped authorization and storage boundaries, the dedicated PostgreSQL schema/database, and encrypted object storage. Google Identity Platform supports passwordless authentication, and configured Google Workspace email services support notifications.
- Speech provider. OpenAI processes sanitized narration text to return AI-generated audio through configured speech or Realtime API endpoints. The raw uploaded file is not intentionally submitted to OpenAI. OpenAI states that API data is not used to train its models by default unless the API customer opts in. Under standard provider controls, abuse-monitoring logs for the relevant endpoints may be retained for up to 30 days; eligible customers may separately qualify for modified or zero-data-retention controls.
- Konfer personnel and contractors or service providers. Authorized recipients receive the submitted name, company, email address, and pending-verification status by email immediately after form submission. Those email copies may persist in recipient mailboxes under Konfer’s and the recipients’ applicable retention and deletion controls. Authorized personnel may otherwise access information when needed to operate, secure, support, review, or improve the Demo within the use restrictions in this notice.
- Legal and corporate events. We may disclose information when required by law, to protect rights or safety, or in connection with a merger, financing, acquisition, reorganization, or sale, subject to appropriate confidentiality and legal safeguards.
Konfer does not sell personal information, transfer Demo contacts to a CRM, or share personal information for cross-context behavioral advertising through this Demo.
4.Retention
- Uploaded and generated run content: the uploaded file, generated artifact content, live guidance and playback state, and tenant-scoped cached content are retained for 30 days from run creation, after which the configured cleanup process schedules deletion.
- Run operational metadata: non-content records including run and creator identity, source kind and dataset identifier, input and artifact hashes, status and timestamps, job and safe error state, artifact metadata, OpenAI model/request usage and estimated cost, and email-delivery state are retained indefinitely unless Konfer fulfills a valid deletion request, subject to the exceptions below. These records do not retain the uploaded file or generated artifact content after content cleanup.
- Completion links: normally 7 days; signed artifact-download URLs: normally 24 hours.
- Authentication audit events: 30 days under the current configuration.
- Registration, contact, submission, verification, consent evidence, and user-linked seeded-scenario access records: retained indefinitely in the dedicated Demo database unless Konfer fulfills a valid deletion request, or unless a longer or narrower record is reasonably necessary for legal compliance, security, fraud prevention, dispute resolution, suppression, or proof of consent.
- Internal notification email copies: may remain in authorized recipient mailboxes until removed under Konfer’s and the recipients’ applicable retention or deletion procedures. Final public activation requires an approved mailbox-retention and request-propagation procedure.
- Backups: protected database backups normally remain for 35 days and may remain recoverable through the cloud provider's seven-day soft-delete window. They are not restored to active use except for continuity or recovery. Deleted data may remain until the applicable backup expires.
- Infrastructure and security logs: retained only as long as reasonably necessary for security, troubleshooting, abuse prevention, and operational accountability, subject to configured rotation and legal holds.
Changing a material retention setting for new users requires a corresponding update to the versioned notice. Konfer-owned seeded packages and reusable seed cache are not subject to user-upload retention because they do not contain a user’s uploaded telemetry. User-linked records showing which seeded package was opened are subject to the activity-record retention described above.
5.Security and international processing
Konfer uses administrative, technical, and organizational safeguards designed to protect information, including TLS in transit, encryption at rest through configured cloud services, server-side secret handling, tenant- and run-scoped authorization, isolated object namespaces, signed expiring artifact URLs, validation and quotas, redacted logs, and restricted operator access. No system is perfectly secure, and we cannot guarantee absolute security.
The Demo is operated from the United States, and providers may process information in the United States and other places where they operate. The geographic scope, controller and processor roles, and any required international-transfer safeguards must be approved by qualified privacy counsel before public activation.
6.Your choices and privacy requests
You can choose a Konfer-provided scenario and avoid uploading your own telemetry. Before uploading, remove information the Demo does not need. You may stop using the Demo or sign out at any time.
Depending on where you live and subject to exceptions, you may have rights to request access, correction, deletion, or a copy of personal information; object to or restrict certain processing; or appeal a response. To submit a request, email support@konfer.ai. We will verify identity and authority before acting. We will not discriminate against you for exercising an applicable privacy right.
Because this Demo does not sell personal information or share it for cross-context behavioral advertising, it does not provide a separate “Do Not Sell or Share” control. If that practice changes, the notice and controls must be updated before the change.
7.Cookies and similar technologies
The Demo uses essential session and framework storage needed for authentication, security, navigation, and playback. The current application does not intentionally use advertising cookies or third-party behavioral advertising trackers. Browser and infrastructure behavior may change as the Demo evolves; a material change requires an updated notice and, where required, consent.
8.Children
The Demo is intended for adults acting in a business capacity and is not directed to anyone under 18. Do not use the Demo or submit personal information if you are under 18.
9.Changes to this notice
Konfer will ordinarily give at least 30 days’ advance notice of a material change and require acknowledgment or acceptance of the new version at the next sign-in when appropriate. A change may take effect sooner when reasonably necessary for an urgent legal, regulatory, fraud, or security issue; we will provide notice as soon as reasonably practicable.
10.Contact
Privacy questions and requests:
Konfer, Inc.
691 S. Milpitas Blvd., Suite 217
Milpitas, CA 95035
support@konfer.ai
510-396-2337