Privacy Policy
Last Updated: 16 Sep 2026 · Effective: 16 Sep 2026
This Privacy Policy explains how Cievo Pte. Ltd. (“Cievo,” “we,” “us,” or “our”) collects, uses, shares, and protects your personal information when you use the Kadres platform (app.kadres.ai) and related services (the “Service”). By using the Service, you agree to the practices described in this Privacy Policy. If you do not agree, please do not use the Service.
1. Who We Are
Company: Cievo Pte. Ltd.
UEN: 202539592W
Registered Address: 70C Telok Blangah Heights #15-537, Telok Blangah Ridgeview, Singapore 103070
Primary Contact: contact@cievo.sg
Cievo is a Singapore-incorporated company subject to the Personal Data Protection Act 2012 (PDPA) of Singapore. Where our users are located in the European Union / UK, we also comply with the General Data Protection Regulation (GDPR). Where users are in California and other US states, we comply with applicable US state privacy laws including the CCPA/CPRA.
EU/EEA Representative (GDPR Article 27): Cievo Pte. Ltd. is a non-EU company that offers services to EU/EEA residents and is aware of its obligation to designate an EU Representative under Article 27 GDPR. We are actively working to fulfil this obligation. In the interim, EU/EEA residents may direct all privacy inquiries, data subject rights requests, and regulatory communications to contact@cievo.sg. We will update this section with the name and contact details of our appointed EU Representative as soon as the appointment is completed.
UK Representative: Cievo Pte. Ltd. is the data controller for UK residents. All UK privacy inquiries may be directed to contact@cievo.sg in the interim.
2. Information We Collect
2.1 Account & Registration Information
When you create a Kadres account, we collect:
| Data | Purpose |
|---|---|
| Email address | Account creation, authentication, transactional communications |
| Password (hashed, never stored in plain text) | Account authentication |
| Name or display name | Account identification |
| Mobile phone number | Agent deployment, SMS transactional communications, account verification |
| Company name | Account identification, business context, subscription management |
| Job title / role | Service personalisation, understanding use case |
| Industry / sector | Service personalisation and platform improvement |
| Subscription tier and status | Feature access management |
Why we collect your phone number: Your phone number is integral to the AI agent deployment model. Your Agent may communicate status updates, completion alerts, and error notifications to your registered number. We also use it to verify your identity and prevent account abuse.
Why we collect company and professional information: Kadres is a business tool. Company and role information helps us tailor the Service to your use case, manage enterprise or team subscriptions, and communicate relevant product updates. This information is optional at registration but may be required for certain subscription tiers or enterprise agreements.
2.2 Voice Recordings & Voice Models
This is sensitive personal data. We handle it with heightened care.
If you use the AI voice synthesis feature, we collect:
| Data | Purpose |
|---|---|
| Audio recordings of your voice (“Voice Recordings”) | Creating your AI voice model |
| AI Voice Model derived from your recordings | Generating synthetic speech for your videos |
| Metadata (recording length, file format, upload timestamp) | Service operation and quality assurance |
How it is processed: Voice Recordings are transmitted to our designated AI voice synthesis provider for model creation and speech synthesis. The provider processes your recordings under their privacy policy and our Data Processing Agreement with them.
Retention: Voice Recordings and Voice Models are retained while your account is active. Upon account deletion, they are deleted from Cievo's systems within 30 days. We request deletion from our voice synthesis provider; their independent retention practices are governed by their own policies.
Legal basis (GDPR): Explicit consent (Article 9(2)(a)), given at the time of voice data submission. Singapore PDPA: Consent given at the time of submission; purpose notified herein.
Illinois Residents — Biometric Information Privacy Act (BIPA) Notice: If you are an Illinois resident, your voice recording constitutes a “voiceprint” and is classified as biometric data under the Illinois BIPA (740 ILCS 14). Before we collect your Voice Recording, we will inform you in writing of the specific purpose and retention period; obtain your separate written consent prior to collection; and not profit from, sell, lease, trade, or otherwise disclose your biometric data except as required to deliver the Service.
Illinois BIPA Retention & Destruction Schedule: Your voiceprint (Voice Recording and Voice Model) is retained for the duration your account is active. It is permanently destroyed within 30 days of account deletion or within 3 years of your last interaction with the Service, whichever occurs first. This schedule is publicly available in this Privacy Policy in compliance with 740 ILCS 14/15(a).
2.3 Images You Upload
When you upload photographs or image files for video creation:
| Data | Purpose |
|---|---|
| Uploaded image files | AI video generation |
| Image metadata (file name, dimensions, upload timestamp) | Service operation |
How it is processed: Images are transmitted to our designated AI video generation provider for video creation. Images are processed under our Data Processing Agreement with the provider.
Retention: Images are retained while your account is active. Upon account deletion, images are deleted within 30 days.
Note on faces and likenesses: If your images contain identifiable persons (including yourself), this constitutes personal data of those individuals. You are responsible for ensuring you have the right to submit such images. See our Terms of Service, Section 5.
2.4 Text Inputs & Agent Instructions
| Data | Purpose |
|---|---|
| Text prompts and creative briefs | Generating video scripts and directing AI pipelines |
| Agent configuration settings | Personalising your Agent's behaviour |
| Agent instruction history | Delivering the Service and troubleshooting |
Query processing: Your text instructions are transmitted to our designated AI language model provider for processing under our Data Processing Agreement with the provider.
Retention: Active agent logs are retained for 90 days from creation, after which they are deleted or anonymised.
2.5 Video Outputs
| Data | Purpose |
|---|---|
| AI-generated video files | Delivery to you, hosting in your tenant dashboard |
| Video metadata (creation time, parameters used) | Service operation and audit |
| Social media post records (if posting is enabled) | Audit log of actions taken by your Agent |
Retention: Video outputs are retained while your account is active. Upon account deletion, they are deleted within 30 days.
2.6 Social Media Account Data
If you authorise Cievo to post on your social media accounts:
| Data | Purpose |
|---|---|
| OAuth access tokens for connected platforms | Posting content on your behalf |
| Post performance data (if retrieved by the platform API) | Dashboard analytics |
| Connected account identifiers (platform user ID, handle) | Identifying the target account |
Access tokens are stored in encrypted form and are scoped to the specific permissions you grant (e.g., “upload video” only). We do not access your social media messages, contact lists, or follower data.
Retention: Access tokens are retained while the integration is active. You may disconnect integrations at any time in your account settings, which triggers immediate token deletion.
2.7 Device & Technical Information
| Data | Purpose |
|---|---|
| IP address | Security, fraud prevention, approximate location |
| Browser / device type and operating system | Compatibility, support |
| Session identifiers | Authentication |
| Dashboard usage patterns | Service improvement |
Retention: Technical logs are retained for 90 days, then deleted or anonymised.
2.8 Payment Information
We do not store your payment card details. Payment processing is handled by Stripe, Inc. We store:
| Data | Purpose |
|---|---|
| Stripe Customer ID | Linking your account to your Stripe record |
| Subscription status and tier | Feature access |
| Transaction IDs and amount | Billing records (retained 7 years for accounting/tax compliance) |
2.9 Communications
If you contact us:
| Data | Purpose |
|---|---|
| Email address and message content | Responding to support requests |
| Phone number (if provided in support context) | Follow-up communication |
| Attachments and screenshots | Issue diagnosis |
Support communications are retained for 24 months.
3. How We Use Your Information
| Purpose | Data Used | Legal Basis (GDPR) |
|---|---|---|
| Providing the Service (video creation, agent deployment) | All categories | Contract performance |
| Service personalisation based on professional context | Company name, job title, industry | Legitimate interest |
| AI voice synthesis | Voice Recordings, Voice Models | Explicit consent |
| AI video generation | Images, text prompts | Contract performance |
| Agent communication (dashboard, messaging channels, SMS) | Phone number, account data | Contract performance |
| Social media posting on your behalf | OAuth tokens, video outputs | Consent |
| Subscription and billing management | Account data, Stripe data | Contract performance |
| Security and fraud prevention | IP address, usage data | Legitimate interest |
| Service improvement (anonymised/aggregated) | Usage patterns | Legitimate interest |
| Legal compliance | Relevant data as required | Legal obligation |
| Export controls and sanctions screening | Account data, IP address, country of access | Legal obligation / Legitimate interest |
| Marketing communications (opt-in only) | Email, phone number | Consent |
We do not use your Voice Recordings, Images, or identifiable Video Outputs for advertising.
4. How We Share Your Information
4.1 General Principle
WE DO NOT SELL YOUR PERSONAL INFORMATION. We share your information only as described below.
4.2 AI Processing Providers
| Category | Data Shared | Purpose |
|---|---|---|
| AI language model provider | Text prompts, agent instructions | Script generation, language reasoning |
| AI video generation provider | Images, video generation parameters | AI video creation |
| AI voice synthesis provider | Voice Recordings | Voice model creation and speech synthesis |
All providers act as our sub-processors and are bound by Data Processing Agreements restricting them from using your data for any purpose beyond providing the Service to Cievo.
4.3 Infrastructure Providers
| Provider | Data Shared | Purpose |
|---|---|---|
| Stripe, Inc. | Account ID, subscription status | Payment processing |
| Authentication provider | Account credentials, profile data | User authentication and access management |
| Network and storage infrastructure provider | DNS, CDN, traffic data, file storage | Networking, security, content delivery |
| Cloud hosting provider (VPS) | Tenant environment data | Hosting your Agent |
4.4 Legal Requirements
We may disclose your information if required in response to a subpoena, court order, or government request; to comply with our legal obligations; to protect the rights, property, or safety of Cievo, our users, or the public; to enforce our Terms of Service or investigate fraud; or to comply with export control laws and sanctions screening obligations. We will notify you of legal disclosure requests unless prohibited by law or where notification would create a risk of harm.
4.5 Business Transfers
If Cievo is involved in a merger, acquisition, or sale of assets, your information may be transferred. We will notify you via email and/or dashboard notification. You will have the option to delete your account before the transfer completes.
4.6 Aggregated or Anonymised Data
We may share aggregated or anonymised data that cannot identify you (e.g., platform statistics, usage trends) for business or research purposes. This data is not “personal information” under any applicable law.
5. Your Privacy Rights
5.1 Rights Available to All Users
| Right | How to Exercise |
|---|---|
| Access your personal data | Email contact@cievo.sg — “Data Access Request” |
| Correct inaccurate data | Edit in account settings, or email contact@cievo.sg |
| Delete your account and data | Account settings → Delete Account, or email contact@cievo.sg |
| Withdraw consent for voice data | Email contact@cievo.sg — “Voice Training Opt-Out” |
| Disconnect social media integrations | Account settings |
| Opt out of marketing communications | Unsubscribe link in any email or SMS “STOP” reply |
5.2 EU / EEA / UK Users (GDPR)
In addition to Section 5.1, you have the right to:
- Data portability: Request a copy of your data in machine-readable format (JSON/CSV)
- Object to processing: Object to processing based on legitimate interest
- Restrict processing: Limit how we use your data while resolving a dispute
- Lodge a complaint: With your national Data Protection Authority — see edpb.europa.eu
Response time: Within 30 days (extendable to 60 days for complex requests). No fee unless requests are manifestly unfounded or excessive.
Legal bases for processing sensitive data: We rely on explicit consent (Article 9(2)(a) GDPR) for processing voice recordings and images of identifiable persons. You may withdraw this consent at any time; withdrawal will affect our ability to deliver voice-related features.
Automated decision-making: We use AI to generate content based on your inputs. This does not constitute automated decision-making with legal effects on you. You review and control all outputs before publication.
5.3 California Users (CCPA / CPRA)
California residents have the right to:
- Know what personal information we collect, use, and disclose
- Delete your personal information
- Correct inaccurate personal information
- Opt out of sale — we do not sell your personal information
- Limit use of sensitive personal information — contact contact@cievo.sg
Sensitive personal information we collect: Voice recordings (audio data constituting biometric-adjacent data). You may limit our use of this data to providing the Service only. Non-discrimination: We will not discriminate against you for exercising your privacy rights. Response time: Within 45 days (extendable to 90 days).
5.4 Singapore Users (PDPA)
As a Singapore company, we comply with the PDPA. You have the right to access your personal data held by us; correct inaccurate, incomplete, or misleading data; and withdraw consent for any processing (noting this may affect your ability to use the Service).
Do Not Call (DNC) Registry: We comply with the DNC Registry. We will check the registry before sending any marketing SMS. Transactional messages (agent alerts, billing, account security) are exempt.
Complaints: File with the Personal Data Protection Commission (PDPC) at pdpc.gov.sg if we do not resolve your concern.
5.5 US Multi-State Privacy Rights
Residents of the following US states have privacy rights substantially similar to the CCPA rights described in Section 5.3. We honour these rights for all applicable residents:
| State | Law | Rights Available |
|---|---|---|
| Virginia | Consumer Data Protection Act (VCDPA) | Access, correct, delete, portability, opt-out of sale / targeted advertising / profiling |
| Colorado | Colorado Privacy Act (CPA) | Access, correct, delete, portability, opt-out of sale / targeted advertising / profiling |
| Texas | Texas Data Privacy and Security Act (TDPSA) | Access, correct, delete, portability, opt-out of sale / targeted advertising |
| Connecticut | Connecticut Data Privacy Act (CTDPA) | Access, correct, delete, portability, opt-out of sale / targeted advertising / profiling |
| Utah | Utah Consumer Privacy Act (UCPA) | Access, delete, portability, opt-out of sale / targeted advertising |
How to exercise: Email contact@cievo.sg with subject “US State Privacy Rights Request — [Your State]”. We will respond within 45 days. We do not discriminate against users who exercise these rights.
Illinois Residents: See Section 2.2 for our full Illinois BIPA notice, including the publicly available retention and destruction schedule. To submit a BIPA inquiry, contact contact@cievo.sg with subject “Illinois BIPA Request”.
6. Data Security
6.1 Security Measures
| Measure | Details |
|---|---|
| Encryption in transit | TLS 1.2+ on all connections |
| Encryption at rest | AES-256 for data stored in our systems |
| Tenant isolation | Each user's Agent and data run in a dedicated container environment; no cross-tenant data access |
| Access controls | Role-based access for Cievo staff; MFA required for internal systems |
| Third-party DPAs | All AI and infrastructure providers bound by Data Processing Agreements |
| Security monitoring | Automated threat detection and audit logging |
6.2 Tenant Data Isolation
Your Voice Model, Images, Video Outputs, and Agent logs are stored in an isolated tenant environment. Other Cievo users cannot access your tenant data.
6.3 Limitations
No internet transmission or electronic storage is completely secure. We cannot guarantee absolute security. You are responsible for maintaining the confidentiality of your account credentials.
6.4 Data Breach Response
If a data breach affects your personal information: we will notify you within 72 hours (GDPR) or as required by applicable law; notify the PDPC within 3 calendar days of a notifiable breach (Singapore PDPA); and provide details of what data was affected, when, and what steps we are taking.
7. Data Retention Summary
| Data Type | Retention Period |
|---|---|
| Account data (email, name) | Until account deletion |
| Company and professional information | Until account deletion or updated by user |
| Phone number | Until account deletion or number change |
| Voice Recordings | Until account deletion (deleted within 30 days of deletion request) |
| Voice Model | Until account deletion (deleted within 30 days) |
| Uploaded Images | Until account deletion (deleted within 30 days) |
| Agent Logs & Text Inputs | 90 days from creation |
| Video Outputs | Until account deletion (deleted within 30 days) |
| Social media access tokens | Until integration disconnected |
| Payment records (transaction IDs, subscription status) | 7 years (tax/accounting) |
| Support communications | 24 months |
| Technical logs (IP, session) | 90 days |
| Anonymised analytics | Indefinite (not personal data) |
After account deletion, backup systems are purged within 90 days.
Termination without cause: Where Cievo terminates your account without cause, the same 30-day deletion timeline applies to all personal data categories above. You will be notified of termination and your deletion rights by email.
Termination for breach: Where your account is terminated due to a violation of our Terms of Service, we may retain certain records (account identifiers, violation logs, content metadata) for up to 24 months for fraud prevention, legal defence, and protecting the integrity of the Service. This does not include your Voice Recordings, Images, or Video Outputs, which are deleted within 30 days.
8. International Data Transfers
Your data is processed by providers in multiple countries, including but not limited to the United States and other jurisdictions. The countries in which our sub-processors operate may change as our providers change.
8.1 Safeguards
For transfers outside Singapore: all providers are bound by Data Processing Agreements (DPAs) with equivalent PDPA protection obligations and providers operating under Singapore's Third Schedule transfer mechanisms or equivalent adequacy frameworks.
For transfers outside the EU/EEA/UK: Standard Contractual Clauses (SCCs) approved by the European Commission, and Transfer Impact Assessments conducted where required.
8.2 Right to Information
You may request a copy of the safeguards we use for international transfers by emailing contact@cievo.sg.
9. Children's Privacy
Kadres is NOT directed at persons under 18. We do not knowingly collect personal data from anyone under 18. If we learn we have collected data from a person under 18, we will immediately delete their account and all associated data. If you believe a minor has created an account, contact contact@cievo.sg immediately.
10. Cookies and Tracking
10.1 Web Dashboard
The Kadres web dashboard uses:
| Technology | Purpose | Can be disabled? |
|---|---|---|
| Session cookies | Authentication, keeping you logged in | No (required for functionality) |
| Local storage | Dashboard preferences, cached state | Partial (clearing browser data) |
| Security tokens (CSRF) | Preventing cross-site request forgery | No (required for security) |
We do not use third-party advertising cookies. We do not use behavioural tracking tools on the dashboard.
10.2 Marketing Website
The Kadres marketing site (kadres.ai) does not currently use analytics or tracking cookies, so no cookie banner is shown. If we introduce non-essential cookies in the future, we will update our Cookie Policy and present a consent banner as required by law.
11. AI-Specific Privacy Disclosures
11.1 AI Output and Privacy
AI-generated videos may, in some cases, produce outputs that unintentionally resemble real persons or reproduce elements from training data. If you believe an AI output infringes your privacy or intellectual property rights, contact contact@cievo.sg immediately.
11.2 No Sale of Voice or Biometric Data
We will never sell, license, or commercially transfer your Voice Recordings or Voice Model to any third party for their own commercial purposes without your explicit written consent.
11.3 EU AI Act Compliance (Regulation (EU) 2024/1689)
The EU Artificial Intelligence Act applies to Kadres from August 2026. As a deployer of AI systems used to generate synthetic audio, video, and image content, Cievo complies with the following transparency obligations:
- Disclosure of AI-generated content: All video and audio content produced by the Service is AI-generated. We apply technical measures (metadata labelling where supported) to mark outputs as machine-generated in accordance with Article 50 of the EU AI Act.
- Interaction with AI systems: When you interact with your deployed Agent, you are interacting with an automated AI system. This is disclosed at account setup and within your dashboard at all times.
- Synthetic media disclosure: Content generated by the Service that depicts or simulates real or fictional persons, voices, or environments is AI-generated synthetic media. You are required under Article 50(4) of the EU AI Act to disclose this to audiences when distributing such content, except where the content is evidently artistic, creative, or satirical in nature.
- No prohibited AI practices: Cievo does not use AI systems for subliminal manipulation, exploitation of vulnerabilities, social scoring, real-time biometric identification in public spaces, or any practice prohibited under Article 5 of the EU AI Act.
- Risk classification: Kadres's AI systems are classified as limited-risk under the EU AI Act, subject to transparency obligations only.
- Right to explanation: EU users may contact contact@cievo.sg to request information about how the AI systems used in the Service process their personal data and influence outputs delivered to them.
12. Third-Party Services
Kadres integrates with third-party AI, infrastructure, and platform providers, each engaged as a sub-processor under a Data Processing Agreement. We are not responsible for their independent privacy practices. We review our providers periodically and may add, change, or remove them as the Service evolves.
For the messaging platforms you connect to your Agent (such as Discord or Telegram), please also review those platforms' own privacy policies, as your interactions on those platforms are subject to their terms.
13. Changes to This Privacy Policy
We may update this Privacy Policy at any time. We will notify you of material changes by dashboard notification, email to your registered email address, and SMS to your registered phone number (for significant changes). Material changes take effect 30 days after notification. Continued use constitutes acceptance.
Material changes include: new categories of data collected, new third-party providers with data access, changes to retention periods, changes to your rights, changes to international transfer safeguards.
14. Jurisdiction-Specific Notices
14.1 Singapore (PDPA)
Cievo Pte. Ltd. is the data controller. We comply with all ten PDPA obligations (Consent, Purpose Limitation, Notification, Access & Correction, Accuracy, Protection, Retention Limitation, Transfer Limitation, Data Breach Notification, Openness). Data Breach Notification: significant breaches (affecting 500+ individuals or causing significant harm) reported to PDPC within 3 calendar days.
14.2 European Union / EEA / UK (GDPR)
Cievo Pte. Ltd. is the data controller for EU/EEA/UK users. Standard Contractual Clauses (SCCs) govern all international transfers of EU personal data.
EU Representative (Article 27 GDPR): Cievo is actively working to appoint a designated EU Representative as required under Article 27 GDPR. Until that appointment is completed, EU/EEA residents may direct all data subject rights requests and supervisory authority communications to contact@cievo.sg.
Data Processing Agreement (DPA) for Business Customers: If you are using Kadres on behalf of a business and your use involves processing personal data of EU/EEA individuals, you may require a Data Processing Agreement with Cievo as required under GDPR Article 28. Email contact@cievo.sg with subject “DPA Request”. We will provide a standard DPA within 10 business days.
Supervisory authority complaints: You have the right to lodge a complaint with your national Data Protection Authority — see edpb.europa.eu for a full list.
14.3 California (CCPA/CPRA)
Categories of personal information collected: Identifiers (email, phone, device ID); Professional and employment information (company name, job title, industry); Biometric-adjacent data (voice recordings); Commercial information (subscription status); Internet activity (dashboard usage); Inferences (content preferences).
We do not sell personal information. We do not share personal information for cross-context behavioural advertising.
14.4 Illinois (BIPA)
If you are an Illinois resident and use the voice synthesis features of the Service, your voice recording constitutes a biometric identifier under the Illinois Biometric Information Privacy Act (740 ILCS 14). See Section 2.2 for our full Illinois BIPA notice, including the publicly available retention and destruction schedule as required by 740 ILCS 14/15(a). To submit a BIPA-related inquiry or request, contact contact@cievo.sg with subject “Illinois BIPA Request”.
14.5 Other US States (Virginia, Colorado, Texas, Connecticut, Utah)
See Section 5.5 for the full multi-state privacy rights applicable to residents of Virginia, Colorado, Texas, Connecticut, and Utah.
15. Contact Us
Cievo Pte. Ltd.
70C Telok Blangah Heights #15-537, Telok Blangah Ridgeview, Singapore 103070
UEN: 202539592W
| Purpose | Contact |
|---|---|
| General support | contact@cievo.sg |
| Legal / Terms inquiries | contact@cievo.sg |
| Privacy / Data rights | privacy@cievo.sg |
| Cookies inquiries | privacy@cievo.sg |
| Security issues | security@cievo.sg |
| DMCA / IP infringement | contact@cievo.sg |
Response times: Privacy rights requests — within 30 days (GDPR) or 45 days (CCPA); Security issues — within 24 hours.
| Jurisdiction | Regulatory Authority |
|---|---|
| Singapore | Personal Data Protection Commission — pdpc.gov.sg |
| EU/EEA | Your national Data Protection Authority — edpb.europa.eu |
| UK | Information Commissioner's Office — ico.org.uk |
| California | California Privacy Protection Agency — cppa.ca.gov |
BY CREATING AN ACCOUNT OR USING THE SERVICE, YOU ACKNOWLEDGE THAT YOU HAVE READ AND UNDERSTOOD THIS PRIVACY POLICY.
Cievo Pte. Ltd. — Singapore