konfer.

Version 2026-09-10-approved-v2 · Last updated September 10, 2026 · Effective September 10, 2026

Agent Assurance Guided Demo Privacy Notice

This Privacy Notice explains how Konfer, Inc. (“Konfer,” “we,” “us,” or “our”) handles personal information when you register for, access, or use the Konfer Agent Assurance Guided Demo (the “Demo”). It supplements the Terms of Use and Guided Demo Notice.

1.Information we collect

Registration and contact information

We collect the first name, last name, company, and email address entered on the registration form. We record whether the email is pending verification or verified, submission and verification timestamps, and the versions, URLs, content hashes, and checkbox and disclosure text shown for the accepted document set.

Authentication and security information

We process passwordless sign-in state, provider identity identifiers, session identifiers, roles, and security/audit events needed to authenticate users, prevent misuse, investigate failures, and revoke sessions. Application audit records use minimized identifiers and fingerprints rather than storing one-time sign-in codes or raw session tokens.

Uploaded telemetry and run information

If you choose to upload a JSONL file, we collect that file and its agent, tool, identity, action, policy, network, observability, security, and related telemetry fields. We create run state, validation results, normalized evidence, findings, scores, recommendations, visualizations, storyboards, narration text and audio, reports, videos, manifests, hashes, cache identifiers, provider usage, and estimated cost records.

If you open a Konfer-provided scenario, we record the account and tenant, the canonical scenario or package identifier, first- and last-access timestamps, access count, and notification-delivery state. The canonical seeded content itself is Konfer-managed and reused across users; the user-linked access record is personal activity information.

Technical and communications information

Our infrastructure may process IP address, browser or user-agent information, request path, timestamps, response status, and similar network and security-log data. Authentication routes are configured to suppress access logging, and logs are designed not to contain uploaded telemetry, secrets, one-time codes, or session tokens. If you contact us, we process the message and contact details you provide.

2.How we use information

We use personal information to:

Konfer does not use user-uploaded telemetry for model training, unrelated product improvement, marketing content, or cross-tenant reuse. The Demo is not configured to opt OpenAI API content into model training.

3.How we disclose information

We disclose information only as reasonably necessary for the purposes above:

Konfer does not sell personal information, transfer Demo contacts to a CRM, or share personal information for cross-context behavioral advertising through this Demo.

4.Retention

Changing a material retention setting for new users requires a corresponding update to the versioned notice. Konfer-owned seeded packages and reusable seed cache are not subject to user-upload retention because they do not contain a user’s uploaded telemetry. User-linked records showing which seeded package was opened are subject to the activity-record retention described above.

5.Security and international processing

Konfer uses administrative, technical, and organizational safeguards designed to protect information, including TLS in transit, encryption at rest through configured cloud services, server-side secret handling, tenant- and run-scoped authorization, isolated object namespaces, signed expiring artifact URLs, validation and quotas, redacted logs, and restricted operator access. No system is perfectly secure, and we cannot guarantee absolute security.

The Demo is operated from the United States, and providers may process information in the United States and other places where they operate. The geographic scope, controller and processor roles, and any required international-transfer safeguards must be approved by qualified privacy counsel before public activation.

6.Your choices and privacy requests

You can choose a Konfer-provided scenario and avoid uploading your own telemetry. Before uploading, remove information the Demo does not need. You may stop using the Demo or sign out at any time.

Depending on where you live and subject to exceptions, you may have rights to request access, correction, deletion, or a copy of personal information; object to or restrict certain processing; or appeal a response. To submit a request, email support@konfer.ai. We will verify identity and authority before acting. We will not discriminate against you for exercising an applicable privacy right.

Because this Demo does not sell personal information or share it for cross-context behavioral advertising, it does not provide a separate “Do Not Sell or Share” control. If that practice changes, the notice and controls must be updated before the change.

7.Cookies and similar technologies

The Demo uses essential session and framework storage needed for authentication, security, navigation, and playback. The current application does not intentionally use advertising cookies or third-party behavioral advertising trackers. Browser and infrastructure behavior may change as the Demo evolves; a material change requires an updated notice and, where required, consent.

8.Children

The Demo is intended for adults acting in a business capacity and is not directed to anyone under 18. Do not use the Demo or submit personal information if you are under 18.

9.Changes to this notice

Konfer will ordinarily give at least 30 days’ advance notice of a material change and require acknowledgment or acceptance of the new version at the next sign-in when appropriate. A change may take effect sooner when reasonably necessary for an urgent legal, regulatory, fraud, or security issue; we will provide notice as soon as reasonably practicable.