legal

Privacy Policy

Kaidn is built to see fraud without hoarding personal data. We collect the minimum needed to run the Service, we hash rather than store raw identifiers wherever we can, and we never ask your end users for things we do not need — there is deliberately no phone-number requirement. This policy explains what we process, why, and your rights.

Last updated: 10 July 2026

1. Who this policy covers

This policy applies to the Kaidn website and the Kaidn API and dashboard (the “Service”). It describes how we handle two different kinds of data:

  • Account & website data — information about you, our business customer and site visitors. For this data, Kaidn is the controller.
  • Event data — information you send us about your own end users so we can score it. For this data you are the controller and Kaidn is a processor acting on your instructions (see section 6 and our Terms).

2. What we collect

Account & billing. When you register we collect a name, work email, company name and a hashed password, plus records of your plan and usage. We store only a hash of each API key, never the key itself. Payments are handled by Paddle (see section 5); we receive limited billing metadata such as country, plan and the last four digits or card type — we never receive or store your full card number.

Event data you submit. To score an event you may send us signals such as an IP address, email address, device identifier, event type, timestamp and optional custom fields about one of your end users. Wherever a signal is used only to detect reuse or velocity, we store a hashed or derived value rather than the raw identifier, together with the resulting score and reason codes. Raw email addresses are not retained.

Technical & usage data. Like most services we process log data (such as request metadata and IP) for security, abuse-prevention and debugging. We use Cloudflare Turnstile to tell humans from bots on sign-up and demo forms.

Cookies, storage and fingerprinting on this website. Google Analytics sets cookies on every page; an icon font is requested from Google, which receives your IP address; and the live demo on our home page runs our own fingerprinting library in your browser and keeps an identifier for it in local storage. An earlier version of this policy said we used “browser local storage (not tracking cookies)” and named only an API key and a theme preference. That was wrong. Every cookie, storage key and third-party request is now itemised, with instructions for refusing each one, on our cookies and tracking page.

3. Why we process it, and our legal bases

Where UK/EU data-protection law applies, we rely on these bases:

  • Performance of a contract — to create your account, provide the Service and take payment.
  • Legitimate interests— to secure the Service, prevent fraud and abuse (fraud prevention is expressly recognised as a legitimate interest under GDPR Recital 47), and to improve and develop the Service, balanced against individuals’ rights.
  • Legal obligation — to comply with law, tax and lawful requests.
  • Consent — where we ask for it, for example certain marketing; you can withdraw it at any time.

For event data, you (the controller) are responsible for establishing the lawful basis and providing any notice to your end users for the processing you instruct us to perform.

4. AI-generated explanations

Kaidn can turn raw signals into plain-language “reasons”. By default this is done with our own templates. Where AI narration is enabled, a minimal, signal-level summary (such as reason codes and derived risk factors — not raw personal identifiers) may be sent to a third-party model provider (for example Anthropic or OpenAI) solely to generate the text. These providers act as our sub-processors, do not use the content to train their models under our configuration, and the outputs never make the scoring decision.

5. Who we share data with (sub-processors)

We do not sell personal data. We share data only with service providers who help us run the Service, under contracts that require them to protect it. The complete, current list is on our sub-processor page, which also names what each recipient actually receives and gives 30 days’ notice before the list changes. In outline:

  • Contabo — hosting; our servers are a dedicated VPS in Germany, and it holds the account and event data.
  • Paddle — Merchant of Record; payment processing, invoicing and tax.
  • Cloudflare— DNS, network security, and Turnstile bot protection on sign-up and demo forms, which sends the visitor’s IP address and challenge token to Cloudflare for verification.
  • Google Analytics — website analytics on kaidn.io only. It is never applied to the API or to your event data.
  • AI model providers — only where AI narration is enabled (see section 4), and only signal-level evidence: no address, IP, phone number or device identifier is included.
  • Enrichment services — disposable-domain, domain-age and phone-carrier lookups. These receive a domain or a number range, never the address or the full number. They are itemised on the sub-processor page.
  • Authorities — where required by law, or to establish, exercise or defend legal claims.

Some services we rely on receive nothing at all: our IP geolocation, Tor exit list and abuse blocklists are downloaded as files and matched on our own servers, so no IP address is ever sent to those providers.

6. Processing on your behalf (data processing terms)

Our Data Processing Agreement governs this processing. It is incorporated into the Terms and applies automatically to every customer — there is nothing to request or sign, and it is in force before any event data reaches us.

In summary, when we process event data as your processor we: (a) process it only on your documented instructions and as permitted by law; (b) require our personnel and sub-processors to keep it confidential and secure; (c) help you answer your end users, with endpoints rather than a support queue — one returns everything we hold about a person, another erases them from every record; and (d) delete or return Customer Data within 30 days of termination, subject to any retention required by law.

Event records are also deleted automatically once they pass your plan’s retention window. That is enforced by a scheduled process rather than on request, and each run is logged so the enforcement can be evidenced.

7. International transfers

We and our sub-processors may process data in countries other than yours. Where we transfer personal data internationally, we rely on appropriate safeguards such as the UK/EU Standard Contractual Clauses or an adequacy decision.

8. How long we keep data

We keep account data while your account is active and for a reasonable period afterwards to meet legal, tax and accounting obligations and to resolve disputes.

Event records are deleted once they pass your plan’s retention window — 30 days on Free, 60 on Basic, 90 on Starter and 180 on Growth, with Enterprise agreed in your contract and capped rather than open-ended. This is enforced by a scheduled process rather than on request, each run is logged so we can evidence it, and deletion reclaims the underlying storage so removed records leave the database rather than only disappearing from queries. Some data is held far more briefly: the per-device observation timeline is capped at 72 hours, because the signal it serves is an address changing within a visit.

The fraud graph holds pseudonymised data, not anonymous data.An earlier version of this policy said those signals were de-identified and “no longer identify an individual”. That was wrong, and we would rather correct it than quietly reword it. What the graph stores is a keyed one-way hash of an identifier, and its whole purpose is to match the same person again across operators — which is the definition of singling someone out, not of anonymising them. We therefore treat those hashes as personal data, with the full protection that carries. Their risk score decays on a 90-day half-life, so a stale flag fades rather than following someone indefinitely.

9. Security

We use technical and organisational measures appropriate to the risk, including encryption in transit (HTTPS), hashing of API keys and sensitive identifiers, access controls, and a minimise-by-default approach to personal data. No system is perfectly secure; we cannot guarantee absolute security, and you are responsible for safeguarding your API keys and account credentials.

10. Your rights

Depending on where you live, you may have rights to access, correct, delete, port, or restrict processing of your personal data, to object to processing based on legitimate interests, and to withdraw consent. To exercise a right relating to account or website data, email support@kaidn.io. If your request relates to event data we process for one of our customers, please contact that customer (the controller); we will assist them as their processor. You also have the right to complain to your local data-protection authority.

11. Children

The Service is for business use and is not directed at children. We do not knowingly collect personal data from anyone under 18. If you believe a child has provided us data, contact us and we will delete it.

12. Changes and contact

We may update this policy from time to time and will change the “last updated” date above; material changes will be notified where required. For any privacy question or request, contact support@kaidn.io.

Questions about this document? Email support@kaidn.io. See also our Terms, Privacy Policy, and Refund Policy.