Skip to content

Legal

Privacy Policy

Last updated: June 2026

This privacy policy explains how KYZON Pty Ltd collects, uses, shares and protects personal information when you use kyzon.com and engage with us about our products. We handle personal information in accordance with the Australian Privacy Act 1988 (Cth) and the Australian Privacy Principles. Where the EU or UK GDPR applies to you, this policy also supports those obligations.

1. Who this policy applies to

This policy applies to visitors to kyzon.com and to people who contact us about our products and services.

  • Website visitors: people browsing our public pages, including product, company and documentation content.
  • Enquirers: people who contact us through our forms or by email to request a demo, request early access, or make a general enquiry.

Use of our products, KYZON Gateway and KYZON Router, by customers is governed by separate service agreements and a Data Processing Agreement, described under Our products and data processing below.

2. What information we collect

Depending on how you use kyzon.com, we may collect:

  • Visitor information, such as IP address, browser and device metadata, pages viewed, timestamps and cookie preferences.
  • Contact information you provide, such as your name, work email, company and the content of your message when you submit an enquiry.
  • Correspondence, such as emails and other messages you send us.

We do not operate self-serve accounts or process payments on kyzon.com. Information processed by our products on behalf of customers is handled under separate agreements.

3. How we use your information

We use personal information to:

  • Respond to your enquiries and provide the demos, early access or information you request.
  • Operate, secure and improve our website.
  • Understand website performance and the quality of our content.
  • Comply with our legal, accounting and security obligations.

We do not sell your personal information, and we do not use your contact details for unrelated marketing without your consent.

4. Legal bases for processing

We handle personal information under the Australian Privacy Principles. Where the GDPR applies to you, we rely on one or more lawful bases under Article 6:

  • Performance of a contract or steps taken at your request, such as responding to an enquiry.
  • Legal obligations, for mandatory compliance and record keeping.
  • Legitimate interests, for website security, reliability and analytics that do not require consent.
  • Consent, for optional analytics cookies and similar technologies.

5. Cookies and analytics

We use strictly necessary cookies for core website functionality. We do not currently use third-party analytics on kyzon.com.

If we introduce optional analytics in future, we will ask for your consent before enabling them.

6. Sharing and service providers

We share personal information with trusted service providers only where needed to operate kyzon.com.

  • Vercel, for website hosting and delivery.
  • Resend, to deliver enquiry messages to our team.

We maintain a register of service providers and review it on a regular schedule. We do not share personal information with others except as described in this policy or with your consent.

7. Our products and data processing

KYZON Gateway and KYZON Router process data on behalf of customers under separate service agreements and a Data Processing Agreement. Under those agreements, customer data is processed on Australian infrastructure, and our sub-processors, including our cloud provider and the AI model providers we route to, are disclosed to customers.

A standard Data Processing Agreement and current sub-processor list are available to customers and prospective customers on request.

Read the Gateway compliance brief

8. Data residency and international transfers

Our products are built to keep customer data in Australia. KYZON Gateway routes inference through AWS in Sydney (ap-southeast-2), and product data is stored in Australian regions.

Website hosting through Vercel may involve processing of limited technical data outside Australia, including in the United States. Where the GDPR applies and data is transferred outside the EEA or UK, we use appropriate safeguards such as standard contractual clauses or another valid transfer mechanism.

9. Retention and security

We retain personal information only for as long as necessary for the purposes described in this policy, and to meet legal, accounting and security requirements. Enquiry correspondence is kept for as long as needed to handle your request and our ongoing relationship.

We use technical and organisational safeguards designed to protect personal information against unauthorised access, loss, misuse and alteration. Product security is described in the Gateway compliance brief.

10. Your privacy rights

Under the Australian Privacy Principles you may request access to the personal information we hold about you and ask us to correct it.

Where the GDPR applies, you may also have rights to erasure, restriction, objection and portability, and where processing is based on consent you can withdraw consent at any time without affecting earlier processing.

We aim to respond to privacy requests within a reasonable time, and within one month where GDPR timelines apply.

11. How to contact us

If you have questions about this policy, or want to exercise your privacy rights, contact us:

Email: privacy@kyzon.com

Post: KYZON Pty Ltd, Suite 305, 275 Alfred Street North, North Sydney NSW 2060, Australia.

12. Complaints

If you wish to make a complaint, or you feel we have not addressed your concern satisfactorily, you may contact the Office of the Australian Information Commissioner at www.oaic.gov.au.

13. Changes to this policy

We review this privacy policy regularly and publish updates on this page. Last updated: June 2026.

Reviewing KYZON for your organisation?

Our compliance brief sets out our security posture, certifications and audit rights, and a Data Processing Agreement is available on request. Or get in touch with any questions.