Privacy Policy

Applies to the Kiluma™ platform, kiluma.ai, and primerosystems.com

Version date: August 10, 2026  ·  v1.0

1. Introduction and Scope

This Privacy Policy explains how Primero Systems Inc. (“Primero,” “we,” “us,” or “our”) collects, uses, and discloses personal information. It applies to: (1) the Kiluma platform and its applications (the “Product”); and (2) our public marketing websites at kiluma.ai and primerosystems.com (the “Marketing Sites”). The Product and the Marketing Sites are together the “Services.” Some parts of this Policy apply only to particular Services: our use of cookies and advertising technologies (Sections 4 and 5) applies to the Marketing Sites, and the authenticated Product uses only strictly necessary and functional cookies and does not use advertising or cross-context behavioral-advertising technologies.

Customer Content in the Product. When a business customer uses the Product, the data that customer creates, uploads, or processes — including personal information about its own users, contacts, and other individuals (“Customer Content”) — is processed by us on that customer’s behalf as a service provider (or processor). Our handling of Customer Content is governed by our agreement with that customer, including the Data Processing Addendum (“DPA”), and not by this Privacy Policy. If you are an individual whose personal information appears in a customer’s account and you wish to exercise privacy rights over that information, please contact that business customer, which controls the information; we will assist the customer as required by law and our agreement.

Geographic scope. The Services are offered to business users globally. This Policy applies to our processing of personal information (also called “personal data”) in the United States and, where applicable, in the European Economic Area (EEA), the United Kingdom (UK), Switzerland, and other regions. Where we process personal data as a processor on a business customer’s behalf (Customer Content in the Product), that processing is governed by our Data Processing Addendum — including its European, UK, and Swiss terms and international-transfer mechanisms — rather than by this Policy.

2. Personal Information We Collect

The categories of personal information we collect depend on how you interact with us. We collect or may collect the following categories (using the categories defined under California law):

  • Identifiers: name, business email address, business contact details, account username, and online identifiers such as IP address and device identifiers.

  • Customer records and commercial information: billing contact details, subscription and plan information, and transaction history. Full payment-card details are collected and processed directly by our payment processor (Stripe) and are not stored by us.

  • Internet or other network activity: log data, pages and features viewed, actions taken, referring pages, and similar usage information collected through cookies and analytics.

  • Geolocation data: approximate location derived from IP address; we do not collect precise geolocation.

  • Professional or employment information: job title and company name for business contacts and account users, and, when you apply for a job with us through our careers page, the information contained in your application (such as your resume, contact details, and work history).

  • Sensitive personal information: account log-in in combination with any required security or access code, password, or credentials allowing access to the account. We use this information only to provide, authenticate, and secure the Services, and not to infer characteristics about you.

  • Inferences: limited inferences drawn from the above, such as product-usage preferences, used to operate and improve the Services.

Sources. We collect this information directly from you (for example, when you register, contact us, or fill out a form); automatically from your use of the Services and your devices (through cookies and similar technologies); from the organization on whose behalf you use the Product; and from our service providers, such as our analytics and payment providers.

Job applicants. If you apply for a position with us through primerosystems.com, we collect and use the information in your application to evaluate your candidacy, communicate with you about the role, and comply with our legal obligations. We retain applicant information in accordance with our data-retention schedule and applicable law, and this use is covered by this Policy.

3. How We Use Personal Information

We use personal information for the following business and commercial purposes:

  • To provide, operate, maintain, secure, and support the Services, and to create and administer accounts.

  • To process transactions, manage subscriptions, and handle billing (through our payment processor).

  • To respond to inquiries and provide customer support.

  • To evaluate and communicate with job applicants and to manage our recruiting and hiring.

  • To communicate with you about the Services, including service and security notices and, where permitted, marketing (from which you may opt out).

  • To analyze and improve the Services and develop new features, including through deidentified and aggregated data.

  • To detect, prevent, and respond to fraud, abuse, security incidents, and other harmful or unlawful activity.

  • To comply with legal obligations and enforce our agreements and policies.

We do not use sensitive personal information for purposes other than those permitted under applicable law, and we do not use it to infer characteristics about you.

Legal bases (EEA, UK, and Switzerland). Where the GDPR, UK GDPR, or Swiss FADP applies to our processing of your personal data, we rely on the following legal bases: performance of a contract with you or your organization; our legitimate interests in operating, securing, supporting, and improving the Services and communicating with business contacts (balanced against your rights and interests); compliance with our legal obligations; and your consent where required (for example, for certain cookies or marketing), which you may withdraw at any time.

4. Cookies and Analytics

This Section applies to our Marketing Sites (kiluma.ai and primerosystems.com), which use cookies and similar technologies to operate the sites, remember your preferences, and understand how the sites are used. The authenticated Product uses only strictly necessary and functional cookies (for sign-in, security, and preferences) and does not use analytics or advertising cookies. We use the following general categories: strictly necessary cookies (required for the site to function); functional cookies (to remember preferences); and analytics or performance cookies (to measure and improve site usage). On our marketing websites (kiluma.ai and primerosystems.com) we use advertising and targeting cookies and similar technologies for cross-context behavioral advertising through Google Analytics 4 and its Google Analytics Advertising Features (which may include Google Signals, remarketing and audiences, demographics and interests reporting, and Google Ads linking and conversion measurement). These tags are managed through a Google-certified consent management platform using Google Consent Mode; for visitors in the EEA, the UK, and Switzerland, analytics and advertising cookies are set only after opt-in consent, and for U.S. visitors you may opt out as described in Section 8 (and we honor the Global Privacy Control). You may also opt out through Google’s Ads Settings, the Google Analytics opt-out browser add-on, or the Network Advertising Initiative opt-out. These features are used only on our marketing websites and are not used within the Kiluma product.

You can control cookies through your browser settings and, where offered, through the cookie controls presented on the Marketing Sites. Disabling some cookies may affect how the sites function. In the EEA, the UK, and Switzerland, we set non-essential cookies (such as analytics cookies) only with your consent, which you can give or withdraw through the cookie banner or controls on the Marketing Sites. We honor opt-out preference signals such as the Global Privacy Control (GPC) as a valid request to opt out of the sale or sharing of personal information for the browser or device from which we receive them. Our sites do not respond to Do Not Track (DNT) signals.

See our Cookie Policy for the specific cookies and providers used on our marketing websites.

5. How We Disclose Personal Information

We disclose personal information in the following ways:

  • Service providers and subprocessors: we share personal information with vendors that perform services on our behalf — including cloud hosting (Amazon Web Services), AI model processing (OpenAI), and email, analytics, and support providers — under contracts that limit their use of the information to providing services to us. Payment processing is handled by Stripe as an independent controller, and the Google Drive connector is a customer-directed Connector that you enable; these, together with the subprocessors that process Customer Content on our behalf, are addressed in our Data Processing Addendum and identified in our subprocessor documentation. Personal information processed through our AI features is used only to provide the Services (real-time inference) and is not used to train or fine-tune general or third-party AI models.

  • Legal and safety: we may disclose information to comply with law or legal process, to respond to lawful requests, or to protect the rights, property, or safety of Primero, our users, or others.

  • Business transfers: we may disclose information in connection with a merger, acquisition, financing, reorganization, or sale of assets, subject to appropriate confidentiality protections.

  • With your direction or consent: we may disclose information at your direction or with your consent.

Sale and sharing of personal information. We do not sell your personal information for monetary consideration. We share personal information for cross-context behavioral advertising through advertising cookies and similar technologies on our marketing websites, using Google Analytics Advertising Features; under the California Consumer Privacy Act, as amended (the “CCPA/CPRA”), this is treated as a “sale” or “share.” For visitors in the EEA, the UK, and Switzerland, Google Ireland Limited acts as our processor for these features and this sharing occurs only with your consent, and personal data transferred to Google in the United States is protected by the European Commission’s Standard Contractual Clauses (with the UK and Swiss addenda). You may opt out at any time using the “Your Privacy Choices” control described in Section 8 and by enabling the Global Privacy Control (GPC). We also do not knowingly sell or share the personal information of individuals under 16.

International data transfers. We are based in the United States and may process personal data in the United States and other countries. Where we transfer personal data from the EEA, the UK, or Switzerland to a country not recognized as providing an adequate level of protection, we rely on appropriate safeguards — principally the European Commission’s Standard Contractual Clauses, as supplemented by the UK International Data Transfer Addendum and the Swiss adaptations, or another lawful transfer mechanism. For personal data we process as a processor (Customer Content), transfer safeguards are addressed in our Data Processing Addendum. You may request information about these safeguards using the contact details below.

Google User Data. When you connect Google Drive, Kiluma accesses only the files you specifically select, using the per-file drive.file OAuth scope. We use this access solely to import the files you choose into your account; we do not scan your Drive in the background, and access is import-only (no write-back). You may revoke access at any time through your Google account settings or within Kiluma. Kiluma’s use and transfer to any other app of information received from Google APIs will adhere to the Google API Services User Data Policy, including the Limited Use requirements. Imported files become Customer Content and are handled under your agreement and the DPA. We do not use Google user data to train or improve general or third-party AI models, and we do not sell or share Google user data or use it for advertising.

6. Data Retention

We retain personal information for as long as necessary to fulfill the purposes described in this Policy, to provide the Services, to comply with our legal obligations, to resolve disputes, and to enforce our agreements. When personal information is no longer needed, we delete or deidentify it. Deidentified and aggregated data, which is not personal information, may be retained and used as permitted by law, applying the deidentification standard in Section 14 of the DPA. We maintain and use such data only in deidentified or aggregated form, do not attempt to reidentify it except as permitted by law to validate our deidentification process, and require any recipient to honor equivalent restrictions.

We determine retention periods based on the type of information and the purpose for which it is held. For example, we retain billing and transaction records for approximately seven (7) years to meet tax and accounting requirements, and we purge personal information from routine encrypted backups within ninety (90) days. Personal information associated with a Product account is retained in accordance with our agreement with the relevant business customer, including the return-and-deletion provisions of the Terms of Service and the DPA. We maintain a more detailed internal data-retention schedule that governs specific categories of information.

7. Security

We maintain reasonable administrative, technical, and physical safeguards designed to protect personal information, including access controls, encryption of data in transit and at rest, and monitoring. No method of transmission or storage is completely secure, and we cannot guarantee absolute security. Our security measures for Customer Content in the Product are described further in the DPA.

8. Your Privacy Rights

California (CCPA/CPRA). If you are a California resident, you have the right to: know and access the categories and specific pieces of personal information we have collected about you, the sources, the purposes, and the categories of recipients; delete personal information we have collected from you; correct inaccurate personal information; opt out of the sale or sharing of personal information, which you can exercise through our “Your Privacy Choices” control and by enabling the Global Privacy Control (GPC); limit the use of sensitive personal information (note: we use sensitive personal information only for purposes permitted under the CCPA/CPRA, and we do not use or disclose it for purposes that would give you a right to limit); and not be discriminated or retaliated against for exercising your rights.

Other U.S. states. If you are a resident of another U.S. state with a comprehensive privacy law (such as Virginia, Colorado, Connecticut, Utah, Texas, Oregon, Montana, and others as they take effect), you have similar rights, to the extent applicable under your state’s law, which may include the rights to access, correct, delete, and obtain a portable copy of your personal information, and to opt out of targeted advertising, the sale of personal information, and certain profiling. Where you have the right to opt out of targeted advertising or the sale of personal information, you may do so through our “Your Privacy Choices” control and by enabling the Global Privacy Control (GPC). Where required, you may appeal a decision we make about your request as described below.

EEA, UK, and Switzerland. If the GDPR, UK GDPR, or Swiss FADP applies to you, you have the rights to access your personal data; to rectify inaccurate data; to erase data; to restrict or object to processing; to data portability; and, where processing is based on consent, to withdraw consent at any time. Where we act as a processor on a business customer’s behalf, we will refer your request to that customer, which is the controller. You also have the right to lodge a complaint with your supervisory authority — in the EEA, your national data protection authority; in the UK, the Information Commissioner’s Office (ICO); and in Switzerland, the Federal Data Protection and Information Commissioner (FDPIC).

How to exercise your rights. You (or an authorized agent acting on your behalf) may submit a request in two ways: (1) by emailing privacy@kiluma.ai; or (2) by submitting the privacy request form available on the applicable website (kiluma.ai or primerosystems.com). To protect your information, we will take reasonable steps to verify your identity before responding, and we may decline or limit a request as permitted by law. We will respond within the timeframes required by applicable law. If we deny your request and your state provides a right to appeal, you may appeal by replying to our decision or contacting privacy@kiluma.ai; if you have concerns about our response, you may contact your state attorney general or, in the EEA, UK, or Switzerland, your supervisory authority.

9. Children’s Privacy

The Services are intended for business use and are not directed to children. We do not knowingly collect personal information from children under 16. If we learn that we have collected personal information from a child under 16 without appropriate consent, we will delete it. In the EEA, the UK, and Switzerland, where processing of a child’s personal data relies on consent, the applicable minimum age (between 13 and 16, depending on the country) applies. Business customers are responsible for not submitting the personal information of children to the Product, as described in our Acceptable Use Policy and Terms.

10. Third-Party Sites and Services

Our Services may link to, or integrate with, third-party websites and services that we do not control. This Policy does not apply to those third parties, and we are not responsible for their privacy practices. We encourage you to review the privacy policies of any third-party site or service you use.

11. Changes to This Policy

We may update this Policy from time to time. We will post the updated Policy with a revised “Last Updated” date and, for material changes, provide additional notice as required by law or as described in the Kiluma Terms of Service. For material changes, we will provide advance notice and the change will take effect prospectively, consistent with Section 1.6 of the Terms and the approach in Section 8 of the Acceptable Use Policy; non-material changes are effective on posting.

12. Contact Us

If you have questions about this Policy or wish to exercise your privacy rights, contact:

Primero Systems Inc.
Attn: Privacy
11440 West Bernardo Court, Suite 300
San Diego, CA 92127
Privacy requests: privacy@kiluma.ai, or the privacy request form on kiluma.ai or primerosystems.com

EU Representative (GDPR Article 27): Instant EU GDPR Representative Ltd. (Attn: Adam Brogden), Office 2, 12A Lower Main Street, Lucan, Co. Dublin X78 X5P8, Ireland. Email: contact@gdprlocal.com. EU data-subject requests: https://primerosystemsinc.gdprlocal.com/eu.

UK Representative (UK GDPR Article 27): GDPRLocal Ltd., 1st Floor, Front Suite, 27-29 North Street, Brighton, England BN1 1EB (Attn: Adam Brogden). Email: contact@gdprlocal.com. UK data-subject requests: https://primerosystemsinc.gdprlocal.com/uk.