Privacy Policy
This Privacy Policy describes how Optima Engineering LLC ("Optima," "we," "us," or "our") collects, uses, and protects personal information when you use the Kraken AI platform (also referred to as "Kraken" or the "Kraken Platform"), our website, and related services (collectively, the "Services"). Kraken AI is an AI Agent Harness Platform that provides tooling for deploying, monitoring, securing, and governing AI agents in production environments.
By accessing or using our Services, you acknowledge that you have read and understood this Privacy Policy. If you are using the Services on behalf of an organization, you represent that you are authorized to accept this policy on behalf of that organization.
1. Information We Collect
Information You Provide
We collect information you provide directly to us, including:
- Account information: name, email address, company name, job title, and password when you create an account or request a demo.
- Billing information: payment method details and billing address, processed through our third-party payment processor. We do not store full payment card numbers.
- Communications: information you provide when you contact us for support, submit feedback, or otherwise communicate with us.
- Customer Data: data you upload, submit, or transmit through the Services, including operational data, workflow configurations, agent configurations, and any data processed by agents operating on the platform.
Information We Collect Automatically
When you access or use our Services, we automatically collect certain information, including:
- Usage data: information about how you interact with our Services, including features used, pages visited, actions taken, timestamps, and session duration.
- Device information: browser type and version, operating system, device type, screen resolution, and unique device identifiers.
- Network information: IP address, internet service provider, and general geographic location derived from your IP address.
- Log data: server logs including access times, pages viewed, referring URLs, and system activity.
- Cookies and similar technologies: we use cookies, web beacons, and similar tracking technologies as described in our Cookie Policy.
Information from Third Parties
We may receive information about you from third parties, including:
- Single sign-on providers: if you authenticate using a third-party identity provider (e.g., Google Workspace, Okta, SAML), we receive your name, email address, and profile information as authorized by that provider.
- Integration partners: when you connect third-party services to Kraken AI through our Connector Marketplace, we may receive data necessary to facilitate those integrations.
- Business partners: we may receive information from referral partners, resellers, or marketplace partners in connection with our business operations.
2. How We Use Your Information
We use the information we collect to:
- Provide, operate, maintain, and improve the Services, including agent orchestration, monitoring, safety controls, and governance features.
- Process transactions, send billing confirmations, and manage your account.
- Send technical notices, security alerts, support messages, and administrative communications.
- Respond to your requests, comments, and questions, and provide customer support.
- Monitor and analyze trends, usage, and activity to improve the Services and user experience.
- Detect, investigate, and prevent security incidents, fraud, and other harmful or unauthorized activity.
- Comply with legal obligations and enforce our terms, policies, and agreements.
- Send marketing communications about products, features, and events that may interest you, subject to your communication preferences.
3. How We Share Your Information
We do not sell your personal information for monetary consideration. We may share your information in the following circumstances:
- Service providers: with third-party vendors who perform services on our behalf, such as cloud hosting, payment processing, analytics, email delivery, and customer support. We require service providers to protect your information and limit use to providing services to us.
- Sub-processors: with sub-processors who process Customer Data on our behalf, as described in our Data Processing Agreement.
- Legal compliance: when required by law, regulation, legal process, or governmental request, or when we believe disclosure is necessary to protect our rights, your safety, or the safety of others.
- Business transfers: in connection with a merger, acquisition, reorganization, or sale of assets, in which case your information may be transferred as part of the transaction.
- With your consent: when you direct us to share information with a third party, such as when enabling integrations through the Connector Marketplace.
4. Data Retention
We retain your personal information for as long as necessary to fulfill the purposes described in this Privacy Policy, unless a longer retention period is required or permitted by law. Specifically:
- Account data: retained for the duration of your account and for a reasonable period afterward to comply with legal obligations and resolve disputes.
- Customer Data: retained for the duration of your subscription. Upon termination, Customer Data is deleted in accordance with our standard processes, unless legal requirements mandate longer retention.
- Usage and log data: retained for a reasonable period for analytics and security purposes, then de-identified or deleted.
- Communications: retained as long as necessary to address your inquiry and for a reasonable period afterward.
5. Data Security
We implement reasonable technical and organizational measures designed to protect your information. No method of transmission or storage is completely secure, and we cannot guarantee absolute security. You assume all risk associated with data transmission and storage. Specific security commitments, if any, are addressed in individually negotiated Enterprise Agreements.
6. International Data Transfers
Optima Engineering LLC is based in the United States. If you access our Services from outside the United States, your information may be transferred to, stored, and processed in the United States or other countries where our service providers operate.
For transfers of personal data from the European Economic Area (EEA), United Kingdom, or Switzerland to countries that have not been deemed to provide an adequate level of data protection, we rely on appropriate safeguards, including the European Commission's Standard Contractual Clauses (SCCs), as detailed in our Data Processing Agreement.
7. Your Rights and Choices
General Rights
Depending on your location, you may have the right to:
- Access the personal information we hold about you.
- Correct inaccurate or incomplete personal information.
- Delete your personal information, subject to legal retention requirements.
- Restrict or object to certain processing of your personal information.
- Receive your personal information in a portable, machine-readable format.
- Withdraw consent at any time, where processing is based on consent.
EEA, UK, and Swiss Residents (GDPR)
If you are located in the European Economic Area, United Kingdom, or Switzerland, you have additional rights under the General Data Protection Regulation (GDPR) or equivalent legislation. Our legal bases for processing your personal data include:
- Performance of a contract: processing necessary to provide the Services you have requested.
- Legitimate interests: processing necessary for our legitimate business interests, such as improving the Services, ensuring security, and communicating with you, provided these interests are not overridden by your data protection rights.
- Legal obligation: processing necessary to comply with applicable laws.
- Consent: where you have given explicit consent to specific processing activities.
You also have the right to lodge a complaint with your local data protection authority. For enterprise customers, we act as a data processor on your behalf, and you remain the data controller. Please refer to our Data Processing Agreement for details.
California Residents (CCPA/CPRA)
If you are a California resident, the California Consumer Privacy Act (CCPA) and California Privacy Rights Act (CPRA) provide you with additional rights:
- Right to know: you may request details about the categories and specific pieces of personal information we have collected, the sources of collection, the purposes for collection, and the categories of third parties with whom we share it.
- Right to delete: you may request deletion of your personal information, subject to certain exceptions.
- Right to correct: you may request correction of inaccurate personal information.
- Right to opt out of sale or sharing: we do not sell your personal information for monetary consideration as defined by the CCPA/CPRA.
- Right to non-discrimination: we will not discriminate against you for exercising your privacy rights, except where permitted by applicable law.
To exercise any of these rights, please contact us at privacy@optima.engineering. We will verify your identity before processing your request and respond within the timeframes required by applicable law.
8. Children's Privacy
The Services are designed for business use and are not directed to individuals under the age of 18. We do not knowingly collect personal information from anyone under 18. If we become aware that we have inadvertently collected personal information from a person under 18, we will take steps to delete it. If you believe such a person has provided us with personal information, please contact us at privacy@optima.engineering.
9. Changes to This Privacy Policy
We may update this Privacy Policy at any time in our sole discretion. Updated versions will be posted on our website. All modifications are immediately binding upon posting. We are not obligated to notify you of changes. It is solely your responsibility to review this policy regularly. Your continued use of the Services constitutes your acceptance of the then-current policy.
10. Contact Us
If you have questions about this Privacy Policy or wish to exercise your data protection rights, please contact us:
- Email: privacy@optima.engineering
- General inquiries: hello@optima.engineering
- Entity: Optima Engineering LLC
For enterprise customers with a Data Processing Agreement, please follow the contact procedures specified in your agreement.