Legal
Privacy Policy
Last updated: 06/22/2026
This Privacy Policy describes how MITS GROUP LLC, operator of the KairosLink platform ("MITS GROUP", "we"), collects, uses, stores and protects personal data in connection with KairosLink, a unified remote monitoring and management (RMM) and incident management (ITSM) service with artificial intelligence intended for managed service providers (MSPs) and IT consultants.
KairosLink is intended for professional use by companies. It is not directed at end consumers or minors.
1. Data controller
The controller of account data is MITS GROUP LLC, a company organized in the state of New Mexico, United States. For any privacy inquiry you can write to us at [email protected].
2. Dual role: controller and processor
It is important to distinguish two situations:
- MSP account data. With respect to the registration and billing data of our direct customers (the MSPs and IT consultants who purchase KairosLink), we act as the data controller.
- Managed computer data. With respect to the information the MSP processes about the computers and end users of its own customers through KairosLink, we act as a data processor: we process that data following the MSP's instructions, and the MSP decides the purpose and scope.
In this second case, the MSP is responsible for having the legal basis and the necessary consents from its customers and end users to install the agent, monitor and remotely access the computers.
3. What data we collect
- Account data: name, email address, organization and access credentials.
- Usage data: activity logs within the panel, sessions, actions performed, IP address, approximate location data derived from the IP, and preferences.
- Technical data of managed computers: computer name, operating system, hardware, IP address, connection status and operational metrics reported by the agent.
- Credentials managed by the MSP: the service includes a vault where the MSP can store credentials of its own customers, encrypted with AES-256. Only the MSP accesses its contents and every access is recorded in an audit log.
- Support session content: executed commands, results, and the screen stream during remote control, according to what the technician does.
- Billing data: the data needed to process payment, handled by our payment processor.
4. Purpose and legal basis
We process data to provide and operate the service, authenticate users, provide support, bill, improve the platform and comply with legal obligations. The legal basis is the performance of the contract, the legitimate interest in operating and securing the service, compliance with legal obligations and, where applicable, consent.
5. Artificial intelligence
KairosLink includes AI features (for example, script generation, diagnostics and documentation). For this, certain session information may be sent to an AI model provider (currently Anthropic) acting as a sub-processor, for the sole purpose of generating the requested response. We recommend not including unnecessary sensitive data in AI requests.
6. Who we share data with
We do not sell personal data. We share information only with providers that help us operate the service (sub-processors), under confidentiality obligations, including:
- Infrastructure and hosting providers.
- Network, CDN and perimeter security provider.
- Artificial intelligence model provider, for the AI features.
- Stripe (Stripe, Inc. and its affiliates), our payment services provider, to process subscription charges. Payment data (such as card data) is handled directly by Stripe under its own policies.
We may also disclose information when required by law or by a competent authority.
7. International transfers
We operate internationally and some of our providers may process data in the United States, the European Union or other countries. In those cases we adopt adequate contractual safeguards to protect the information in accordance with applicable regulations.
8. Retention
We keep data while the account is active and for the period needed to fulfill the purposes described and legal obligations. It is then deleted or anonymized.
9. Security
We apply reasonable technical and organizational measures to protect data, including encryption in transit, encryption of stored credentials, access control, two-factor authentication and tenant isolation. No system is completely infallible, but we work to reduce risks continuously.
10. Your rights
In accordance with the data protection legislation applicable in your jurisdiction, you may exercise the rights of access, rectification, update and deletion of your data, as well as object to certain processing. To exercise them, write to us at [email protected].
11. Cookies
We use cookies and similar technologies strictly necessary for the operation of the service, such as keeping your session signed in. You can manage cookies from your browser settings.
12. Changes to this policy
We may update this Privacy Policy. We will publish the current version on this page and indicate the date of the last update.
13. Contact
For any inquiry about this policy or about the processing of your data, write to us at [email protected].
Postal address
MITS GROUP LLC 2201 Menaul Blvd NE Ste A Albuquerque, NM 87107 United StatesGoverning language
This document is a translation provided for convenience only. The Spanish-language version is the legally binding text, and in the event of any discrepancy or conflict between the two versions, the Spanish version shall prevail.