Kasper AI Privacy Policy and Data Protection Policy
Introduction
Kasper AI needs to collect and use certain information about individuals. These individuals may include our data scientists, clients, and employees. This policy outlines how personal data should be collected, handled, and stored in accordance with the company’s data protection standards and to comply with UK law.
Why this policy exists?
This data protection policy ensures Kasper AI:
• Complies with data protection laws and follows best practices.
• Protects the rights of staff, customers, and partners.
• Is transparent about how it stores and processes individuals’ data.
• Safeguards itself from the risks of a data breach.
Data Protection Law
This policy adheres to the applicable data protection laws in the UK, including the General Data Protection Regulation (GDPR). Personal information must be collected and used fairly, stored securely, and not disclosed unlawfully.
People, Risks, and Responsibilities
Policy Scope
This policy applies to:
• The headquarters of Kasper AI
• All staff and volunteers of Kasper AI
• All contractors, suppliers, and other individuals working on behalf of Kasper AI
It encompasses all data held by the company concerning identifiable individuals, even if such information technically falls outside the GDPR. This includes names, addresses, email addresses, telephone numbers, and any other information related to individuals.
Data Protection Risks
This policy is designed to mitigate data security risks for Kasper AI, including breaches of confidentiality, failure to provide choice, and reputational damage resulting from unauthorized access to sensitive data.
Responsibilities
Everyone associated with Kasper AI has a responsibility to ensure that data is collected, stored, and handled appropriately. Key areas of responsibility include:
• The board of directors, who are ultimately responsible for legal compliance.
• The data protection officer, responsible for keeping the board informed about data protection matters, reviewing procedures, providing training, handling queries, and approving contracts with third parties handling sensitive data.
• The Chief Technology Officer (CTO), responsible for ensuring the security standards of systems, services, and equipment, conducting regular security checks, and evaluating third-party services.
• The Managing Director, responsible for approving data protection statements in communications, addressing queries from the media, and ensuring marketing initiatives adhere to data protection principles.
General Staff Guidelines
• Access to data covered by this policy should be limited to those who need it for their work.
• Confidential information should not be shared informally, and requests for access should be made through appropriate channels.
• All employees should undergo training on their data protection responsibilities.
• Strong passwords must be used and not shared.
• Personal data should not be disclosed to unauthorized individuals, whether within the company or externally.
• Regular review and updates of data are necessary, with deletion and secure disposal of unnecessary data.
Data Storage
This section outlines guidelines for safe data storage, whether in paper or electronic form, emphasizing secure locations, encryption, backup procedures, and adherence to approved security standards.
Data Use
Employees are reminded to ensure that personal data is accessed and used securely, with encrypted transfers and restrictions on data transfer outside the European Economic Area (EEA).
Data Accuracy
Employees working with data are obligated to take steps to keep it accurate and up-to-date, minimizing unnecessary additional data sets and updating information regularly.
Subject Access Requests
Individuals have the right to request information about the personal data held by Kasper AI. The data controller will handle such requests, ensuring verification of identity and providing the requested data within 14 days.
Disclosing Data for Other Reasons
In certain circumstances, personal data may be disclosed to law enforcement agencies without the consent of the data subject. The data controller will ensure that requests are legitimate and seek advice from the board and legal advisers when necessary.
Providing Information
Kasper AI aims to keep individuals informed about how their data is processed, with privacy statements available on request and on the company’s website.
Information Provisions
When providing personal data, individuals are informed about various aspects, including the identity of the organization, contact details, processing purposes, data storage duration, and individuals' rights.
If you have any questions or need further information on Kasper AI’s privacy policy, please email nasir@kasperai.com.
Crafting Success Stories
Showcasing AI Successes
FAQ