Privacy notice

Last updated 10 September 2026

What we hold about you, why we hold it, who else touches it, how long it stays, and how to make us stop. Written to be read, not to be survived.

Who we are

Your Kairos is a trading name of Taybridge Group Limited, a company registered in Scotland, No. SC885181, registered office 87 City Road, Brechin, Angus, DD9 6DL. For anything on this page, write to hello@yourkairos.tech. A person reads it. We have not appointed a data protection officer and are not required to.

Who this notice is for

Three sorts of people, and it covers all three:

It is not for people who receive an outreach email sent through Kairos. If one of our clients has emailed you and you want to know why, the answer is at the foot of that email — where their details came from, what it is for, how long it is kept and how to stop it. The business that wrote to you chose you and decides what is kept about you; we run the software for them, on their instructions, under a written contract. Ask them, or reply to the email and you come off the list permanently. The one thing that is ours rather than theirs is the research file, and that has its own section here.

We also use our own system to contact businesses ourselves. When we do, we are in exactly the same position as any client, and the same information appears at the foot of our own emails.

If you filled in the form on our website

That form does not send anything to us. Pressing the button opens your own email program with your answers already typed in, addressed to Steve at Taybridge Group. Nothing reaches us until you send it yourself, and if you change your mind and close the window, we never see it.

Once you do send it, we hold your email in a business mailbox: your name, your address, your business and whatever you wrote in the box. We use it to answer you and to work out whether we should be working together — that is the legitimate interest we rely on. There is no automatic clear-out of a mailbox, so if you would like your enquiry deleted, ask and we will delete it. You are not obliged to give us any of it, and no law requires you to; give us less and we may simply not be able to answer usefully.

If you have a Kairos sign-in

There is no sign-up form. Nobody can create a Kairos account by typing an address into our website, and nobody can be joined to a business's account except by us — so if you have a sign-in, you are here because we invited you, and nearly everything below came from you or from your business.

There is one way to be in our records without having been invited. Somebody at the business may have given us your address so that we can send notices about the account. In that case your colleague nominated you, not us. We hold that address, we write to it about the account, and nothing else. If that is you and you would rather we did not, say so and we will stop and remove it.

What we hold:

None of it is required by law. It is what the service needs to run: without a connected mailbox and a profile there is nothing for Kairos to do.

The mailbox connection — exactly what we can and cannot see

This is the part people care about most, so it is stated precisely. We ask Microsoft for four things and nothing else: permission to send mail as you; permission to read message headers; a token so the connection keeps working without you signing in again; and enough to know which mailbox connected.

We cannot read your emails. The permission we hold is Microsoft's Mail.ReadBasic. It does not return the body of a message, the preview text or attachments — that is how Microsoft built the permission, not a policy we promise to keep. If Microsoft ever granted us a permission that could reach a message body, our software refuses the connection outright rather than storing it.

What we do look at, and only this: the headers of messages that match something we sent for you, so we can tell that a reply arrived. Anything that does not match is discarded without being read.

The credential is encrypted before it is stored — AES-256-GCM, with the key held outside the database and outside the backups, and tied to the specific connection so it cannot be lifted and used elsewhere.

You can withdraw the permission at any time. There is a Disconnect button on your own page in Kairos: press it and we delete the credential and stop being able to send, straight away. You can also withdraw it from your own Microsoft 365 account, which stops us just the same. Either way, you can connect again whenever you like.

The research file we keep ourselves

Before writing to somebody on a client's behalf, we read what their company's website says publicly. What we find goes into a shared reference file, filed under the company's web address rather than under any one client's list, so that two clients writing to the same company do not cause the same research twice.

Most of it is about the business. Sometimes it names a person — a role, a job title, somebody a business quotes or credits on its own page. That may be you, and it may be true even though no client has ever contacted you or your company. When it happens, keeping that fact is our decision, not the client's: the file has no client's name on it, it is shared across all of them, and it exists whether or not anybody ever writes to that business. For this one file we are responsible in law, not our client.

Why we hold it

Who else handles it

We keep the list short on purpose. Everyone below works to a written contract and can only use your details to do the job we have given them.

WhoWhat they doWhere
SupabaseOur database. Everything above is stored hereIreland
Fly.ioRuns our softwareLondon
CloudflareServes our web pages, our DNS and our mail forwardingRouted locally
ResendSends your sign-in emails and our own internal fault alertsUnited States
AnthropicThe AI that writes the first draft of each email. It receives your business profile and the name the emails send asUnited States

Two of them are outside the UK. Anthropic's data processing agreement incorporates the International Data Transfer Addendum approved by the Information Commissioner, and their terms state that they do not train models on customer content. Resend's does the same, and Resend is also certified under the UK Extension to the EU–US Data Privacy Framework, the arrangement the UK Government has approved for sending personal data to American companies that have signed up to it.

Each of them uses its own suppliers under its own contract — hosting, infrastructure and the like. That is ordinary, and it is why the list above is the companies we chose and pay rather than every company beneath them.

Microsoft is not on that list. Your mailbox is yours and Microsoft is your provider, not our supplier. We hold a permission you granted; we do not hand them your data.

We will also give your details to somebody else if the law makes us, and we will tell you if that happens unless we are forbidden to.

How long we keep it

Different records are kept for different lengths of time, because they are kept for different reasons. One period for everything would be wrong in both directions.

Your rights

You can ask us for a copy of what we hold about you, ask us to correct it, ask us to delete it, ask us to restrict what we do with it, ask for it in a portable form, and object to us relying on legitimate interests. Write to hello@yourkairos.tech and we will answer within one month.

No decision about you is made by a machine on its own, and we do not profile anybody.

If we get it wrong you can complain to the Information Commissioner's Officeico.org.uk, 0303 123 1113 — though we would rather you told us first so we can fix it.

Cookies, and the tracking we do not do

We set no cookies anywhere. Not on our website, not on the desk you sign in to, not on the pages we serve at bot., connect. and unsubscribe.

When you sign in to the desk, your browser keeps your session in its own local storage and remembers which client you last looked at. That never leaves your browser and we cannot read it. Signing out clears it. Opening the desk sends your browser's request to nobody but us — no fonts, no libraries, no images from anywhere else.

Our own web service logs one line per request — the method, the page, the result and how long it took. It does not log your IP address, and it deliberately does not log the address of a one-click unsubscribe link, because that link is a credential. Our database provider records sign-in events in its own logs, including the IP address and browser they came from; we do not use those.

There are no tracking pixels, no open tracking and no click tracking in any email we send — not in outreach and not in our own sign-in emails. Our system cannot record that a message was opened or read: the only things it is able to record about a message are that it was delivered, that it bounced, that a reply arrived, that an out-of-office arrived, or that somebody unsubscribed. There is nowhere for anything else to be written down. Every message is checked immediately before it leaves for any remote image or any link, and refused if one is found. That is a deliberate commitment and it is a lot of the point of us.

No advertising and no analytics, on any page or in any email.

Changes

If we change this notice we will change the date at the top. If the change matters, we will email you.