Privacy Policy

Effective August 22, 2026 17 min read

1. Introduction

Kronisys Inc. ("Kronisys," "we," "us," or "our") operates Strata, an AI-powered enterprise intelligence platform that serves as a general AI assistant with optional enterprise extensions. This Privacy Policy explains how we collect, use, disclose, and protect your personal data when you access or use the Strata platform, our website, and related services (collectively, the "Services").

By using our Services, you acknowledge that you have read and understood this Privacy Policy. If you do not agree with this Privacy Policy, please do not use our Services.

Enterprise customers: If your organization has provisioned your Strata account, your organization's Data Processing Addendum governs the handling of data submitted through your account. This Privacy Policy applies to data Kronisys controls directly.

2. Data We Collect

Data you provide directly

  • Account Information: Name, email address, organization name, and role when you create a Strata account, including identifiers generated by Microsoft SSO authentication.
  • Inputs and Outputs: Natural language prompts ("Inputs") you submit to Strata and the responses, SQL queries, charts, exports, and other content generated by Strata ("Outputs").
  • Database Connection Credentials: SQL Server connection strings, server addresses, and authentication credentials you provide to connect your databases. These are encrypted at rest and in transit.
  • Memory: Facts and preferences you choose to save (or that the AI saves with your permission) for cross-conversation context. Memory entries are scoped to your individual user account, are user-controlled (enable or disable in Settings), and are individually viewable and deletable.
  • Feedback: Ratings, comments, bug reports, and suggestions you submit about the Services.
  • Communications: Information you provide when contacting our support team.

Data collected automatically

  • Device & Connection Data: Device type, operating system, browser type, IP address, timezone, and general location derived from your IP address.
  • Usage Data: Dates and times of access, features used, prompts submitted, models selected, integrations activated, and interaction patterns with the Services.
  • Log Data: Server logs, error reports, performance data, and diagnostic information generated during your use of the Services.
  • Audit Logs: Administrative actions taken in your organization (user invitations, role changes, permission updates, session revocations) are logged with actor identity, timestamp, target, and action details. Visible only to organization administrators.
  • Activity Logs: Per-conversation metadata including model selected, token counts, response time, and SQL queries executed (when the database extension is connected) is logged for cost tracking, rate limiting, and quality monitoring.
  • Cookies: Strata sets the cookies required to operate the Services, and — only if you accept via our cookie banner — Google Analytics 4 cookies to measure aggregate site usage. We do not set advertising cookies, and no analytics cookies are set unless you opt in; you can decline at any time from the banner.
    • strata_session — HTTP-only, Secure, SameSite=None authentication session token. Required for sign-in; SameSite=None is what lets it reach the Strata for Outlook task pane, which loads inside Outlook's own frame. Lifetime: a rolling 12-hour window that slides forward each time you use Strata, so an idle session expires after 12 hours and an active one keeps renewing — up to a hard cap of 7 days from the original sign-in.
    • strata_csrf — Non-HTTP-only CSRF token (double-submit pattern) used to protect state-changing requests. Lifetime: 24 hours.
    • _ga / _ga_G-R3YBNQJZF0 — Google Analytics 4 cookies that measure aggregate site usage. Set only after you accept cookies via the banner; not set if you decline. Lifetime: up to 2 years.

Data from third-party integrations

  • Microsoft SSO: When you sign in with Microsoft, we receive your name, email, and organization identifier from Microsoft Entra ID.
  • OneDrive: File metadata and content you choose to access or save through the OneDrive integration.
  • SharePoint: Site and document-library files and metadata indexed for your organization's knowledge base. Requires OneDrive to be enabled.
  • Outlook: Email addresses, subjects, and message content you interact with through the Outlook integration.
  • Microsoft Teams: Channel information, message content, and user identifiers when you interact with the Strata Teams bot.
  • Atlassian (Jira and Confluence): Jira issue and request content, comments, project and queue metadata, and the identity of reporters and assignees; and Confluence page content, space and page metadata, and comments — retrieved from your Atlassian Cloud site when the Atlassian extensions are connected. Jira and Confluence share a single Atlassian connection but are enabled separately by your administrator.

3. How We Use Your Data

We use your personal data for the following purposes:

  • Providing the Services: To operate Strata, process your prompts, generate outputs, execute SQL against your databases, and deliver exports and reports.
  • Agent Execution: To run the scheduled and on-demand agents you create, which process your prompts and connected data on your behalf and deliver results by email or to connected services.
  • Account Management: To create, maintain, and secure your Strata account.
  • Integration Functionality: To facilitate connections between Strata and your connected services (SQL Server, OneDrive, SharePoint, Outlook, Teams, Jira, and Confluence), including operating the Strata bot within your Microsoft Teams channels.
  • Programmatic & API Access: When your organization issues API keys, to authenticate and process requests made to the Strata API on your behalf, deliver API responses, and send event notifications to the webhook endpoints your administrators configure.
  • AI Model Routing: To route your prompts to the AI model you select from your organization's curated catalog — spanning providers such as OpenAI, Anthropic, xAI, DeepSeek, Mistral AI, Cohere, and Microsoft — through Microsoft Azure AI Foundry.
  • Web Search: When web search is enabled for a conversation, to send a search query derived from your prompt to our web search provider (Brave Search) and incorporate the results into the AI's response.
  • Memory Storage: To remember user preferences, project context, and facts across separate conversations when memory is enabled. Memory is scoped to your individual user account and is never shared across users or organizations.
  • Service Improvement: To analyze usage patterns, debug errors, and improve the quality, performance, and reliability of the Services.
  • Safety & Compliance: To prevent fraud, abuse, and violations of our Usage Policy, and to comply with legal obligations.
  • Communications: To send you service announcements, security alerts, and administrative messages.

4. AI Model Training & Third-Party Models

Strata routes your prompts to third-party AI models — from providers including OpenAI, Anthropic, xAI, DeepSeek, Mistral AI, Cohere, and Microsoft — through Microsoft Azure AI Foundry. The specific models available to you are the curated catalog your organization enables. When processing your prompts:

  • We do not use your Inputs or Outputs to train any AI models. Your prompts and their results are not used for model training by Kronisys or, pursuant to our Microsoft Azure AI Foundry agreements, by our AI providers.
  • Your Inputs are transmitted to the selected AI provider via Microsoft Azure AI Foundry to generate Outputs. This transmission is governed by our Foundry agreements with Microsoft, which prohibit the use of customer data for model training.
  • Inference-time processing: AI providers may temporarily log Inputs and Outputs for abuse detection, safety monitoring, billing reconciliation, and operational reasons. This processing occurs on the selected provider's inference infrastructure accessed via Microsoft Azure AI Foundry. Logs retained for these purposes are subject to the providers' enterprise retention policies and are not used for training.
  • The in-product help assistant is the one exception, and Kronisys operates it. Every AI feature that touches your data — chat, scheduled agents, documents, voice and the API — runs in your organization’s own Azure AI Foundry. The help assistant in the corner of the app does not: Kronisys hosts it, pays for it, and routes it to a small model through our own Microsoft Azure AI Foundry, so you can ask for help before your Foundry is connected or while it is unavailable. What reaches us is the question you type, your display name, which page of Strata you are on, and up to 30 previous turns of that same support conversation. Your chat history, documents, database results and mailbox are not sent, and the page context is restricted to a page identifier and three status flags so it cannot carry content. Support conversations are not used to train any model.
  • Third-party content awareness: Inputs you submit may contain personal data of third parties (such as recipients, names, addresses, or contract terms in emails or documents). By submitting such content, you confirm under our Usage Policy that you have the legal right to share it with our AI providers for processing.
  • We may use aggregated, de-identified usage analytics to improve Strata's prompt routing, schema matching, and semantic embedding systems. This data cannot be used to identify individual users or reconstruct specific prompts.

Your data is never used for AI training. Strata accesses AI models through Microsoft Azure AI Foundry, which prohibits the use of your data for training models.

5. Data Sharing & Disclosure

We disclose personal data only in the following circumstances:

  • AI Model Providers: Your Inputs are transmitted to the AI provider behind the model you select (such as OpenAI, Anthropic, xAI, DeepSeek, Mistral AI, Cohere, or Microsoft) via Microsoft Azure AI Foundry to generate Outputs. These providers process data under Microsoft Azure AI Foundry agreements that restrict their use of your data.
  • Web Search Provider: When web search is enabled for a conversation, a search query derived from your prompt is sent to Brave Search to retrieve live results. Only the generated query is sent — not your database contents or the rest of your conversation.
  • Microsoft Services: When you use Microsoft integrations, data is exchanged between Strata and Microsoft's APIs in accordance with Microsoft's privacy practices and your organization's Microsoft agreements.
  • Atlassian (Jira and Confluence): When your organization enables the Jira or Confluence extension, Strata exchanges data directly with your organization's Atlassian Cloud site rather than through Microsoft. Reads retrieve issue and request fields, comments, Confluence pages, and the associated project, queue, and space metadata; where an administrator has enabled writes, the issues, pages, and comments Strata creates are sent to that site. This processing is governed by your organization's agreement with Atlassian.
  • Transactional Email: User invitations, security alerts, and administrative notifications are sent via Azure Communication Services. Recipient email addresses, subject lines, and message bodies are processed by Microsoft Azure Communication Services under Microsoft's enterprise data processing terms.
  • Geographic Location: When you sign in, your IP address is sent to a third-party geolocation service (ipapi.co) to display approximate session location (city, region, country) on the Sessions page in your account settings. Only the IP address is shared with this service; no other personal data is sent. Geographic data is stored only with the session record and is not used for any other purpose.
  • Service Providers: We engage third-party service providers for hosting (Microsoft Azure), analytics, and customer support. These providers are contractually bound to protect your data.
  • Legal Requirements: We may disclose data to comply with applicable law, legal process, or governmental requests, or to protect the rights, property, or safety of Kronisys, our users, or the public.
  • Corporate Transactions: In connection with a merger, acquisition, or sale of assets, your data may be transferred as part of the transaction.

Kronisys does not sell your personal data. We do not share your personal data for targeted advertising purposes.

6. Integrations

Strata integrates with the following services. Each integration handles data as follows:

IntegrationData AccessedHow Data is Used
SQL ServerDatabase schemas, table structures, query resultsSchema discovery, SQL generation and execution, result display and export
OneDriveFile names, metadata, file contentsSearching files, reading documents, saving generated exports and reports
SharePointSite and document-library files, metadata, contentsIndexing curated documents for the organization knowledge base and reading them to ground AI answers (requires OneDrive)
OutlookEmail addresses, subjects, message body, attachmentsSearching inbox, drafting and sending emails with report attachments
TeamsChannel info, message content, user identifiersProcessing prompts via the Teams bot, sharing results in channels
JiraIssue and request fields, comments, project and queue metadata, reporter and assignee identitySearching and reading Jira Software issues and Jira Service Management requests; where an admin enables writes, creating issues and posting internal comments
ConfluencePage content, space and page metadata, commentsSearching spaces and reading pages to ground answers; where an admin enables writes, creating pages and posting comments

All integration data is transmitted via encrypted connections using OAuth 2.0 authentication. Strata accesses only the data necessary to fulfill your specific requests and does not persistently store integration data beyond the active session unless explicitly saving exports to OneDrive at your direction.

Jira and Confluence are provided by Atlassian rather than Microsoft, and reach Strata over a single Atlassian connection; your administrator enables each product separately, and either may be allowed without the other. Atlassian Cloud pins your Jira and Confluence data to the region selected when your Atlassian site was created, and Strata’s platform database and your organization’s Azure AI Foundry deployment are separate infrastructure in their own regions — an Atlassian request therefore crosses regions by design, and connecting Atlassian does not move your Jira or Confluence data out of Atlassian. Comments Strata posts on a Jira Service Management request are always internal notes, never visible to the customer who raised the request. Strata never indexes Jira or Confluence content into the knowledge base; issues, service requests, comments, and pages are read live to answer the request in front of you and are not embedded or retained as knowledge base content. See the Atlassian extensions page for the full permission and write-approval model.

7. Subprocessors

Strata uses the following subprocessors to deliver the Services. The authoritative, current list — including change-notice and objection terms — is maintained at Sub-processors page; the table below is a copy of it. Each is bound by data processing agreements that restrict use of customer data; Atlassian, which is engaged only where your organization enables the Jira or Confluence extension, processes that content under your organization’s own agreement with Atlassian for the site you connect. Enterprise customers may execute Kronisys's Data Processing Addendum to govern this processing.

SubprocessorPurposeData ProcessedLocation
Microsoft Azure (App Service, SQL Database, Blob Storage, Communication Services)Hosting, database, file storage, transactional emailAll customer dataUnited States (Azure region varies by deployment)
Microsoft Azure AI FoundryAI model routing and inference. Models from OpenAI, Anthropic, xAI, DeepSeek, Mistral AI, Cohere, and Microsoft are provisioned and reached through Foundry; these providers are bound by Microsoft's enterprise terms, which prohibit training on customer data.Prompts and responsesUnited States
Brave Search (Brave Software, Inc.)Returning live web results for conversations where web search is enabledSearch queries derived from promptsUnited States
Stripe, Inc.Payment processing, invoicing, and subscription billing (ACH debit, card, and hosted invoices)Billing contact details, billing address, and tax ID; payment-method metadata such as card brand and last four digits or bank last four. Full card and bank account numbers are entered on Stripe-hosted surfaces and are not received or stored by Kronisys.United States
Atlassian (Jira and Confluence Cloud)Reading from, and — where an administrator has enabled writes — creating content in, your organization's Atlassian Cloud site. Engaged only where your organization enables the Jira or Confluence extension.Jira issue and request fields and comments; Confluence page and space content and comments; the project, queue, space, and participant metadata returned with themThe region of your organization's Atlassian Cloud site, as set when that site was created
Mapbox, Inc.Rendering interactive maps, converting addresses into coordinates (geocoding), and looking up named places when Strata answers a location question. Engaged only where your organization allows geocoding.Address, place-name and search text drawn from prompts, query results, or connected data, and the coordinates returned for it. Map styles and tiles load directly in the browser, so the viewing device's IP address and the map area being viewed also reach Mapbox.United States
Google LLC (Google Places API)Retrieving a photograph of a named venue for a place card, and only where a place lookup was run with venue detail requested.The venue name, address and coordinate already resolved through Mapbox. Photographs are relayed through Kronisys, so no browser IP address reaches Google.United States
ipapi.coIP geolocation lookup, so an administrator can see the approximate location of a sign-in. First provider tried. Engaged only where remote geolocation is enabled for the deployment.A truncated IP address only — the final octet of an IPv4 address is zeroed, and an IPv6 address is cut to its first three segments. No account or content data is sent.United States
ip-api.comIP geolocation lookup. Fallback, used only when the provider above fails or times out.A truncated IP address only, as above. This provider is reached over plain HTTP rather than TLS — see Security.Not disclosed by the provider
ipwho.isIP geolocation lookup. Fallback, used only when both providers above fail or time out.A truncated IP address only, as above.Not disclosed by the provider
CARTO (Carto Inc.) and unpkgServing the fallback map. When Mapbox is unavailable — no token, no WebGL, or its tiles are blocked — Strata draws the map with the Leaflet library (loaded from unpkg) over CARTO basemap tiles, so a map still renders.The viewing device’s IP address and the map area being viewed, because tiles and the library load directly in the browser. No address text, prompt content, or account data is sent — the coordinates were already resolved before the map is drawn.United States

The three IP geolocation providers form a single fallback chain and are tried in the order listed; the first one to answer ends the request. Kronisys does not send a full IP address to any of them.

Microsoft 365 services (Outlook, OneDrive, SharePoint, and Teams) are data sources you connect at your own direction, not Kronisys subprocessors; data in those systems remains governed by your agreements with Microsoft. Atlassian is listed above because Jira and Confluence content does not stay inside the Microsoft boundary — Strata sends it to, and receives it from, Atlassian Cloud directly rather than through Microsoft Graph. Your Atlassian site itself remains yours and remains governed by your organization’s own agreement with Atlassian, and Atlassian Cloud pins the data in it to the region set for that site — separate from Strata’s platform database and from your organization’s Azure AI Foundry deployment, each of which has its own region.

Kronisys will provide 30 days' notice before adding new subprocessors to enterprise customers via email to designated administrators.

Objection right. Enterprise customers may object in writing to a new subprocessor within 30 days of notice by emailing legal@kronisys.com. If we cannot reasonably accommodate the objection, the affected enterprise customer may terminate the affected portion of the Services without penalty by giving written notice within 30 days of our response.

8. Data Retention

  • Account Data: Retained for the duration of your account plus 30 days after deletion.
  • Inputs & Outputs: Conversation history is retained indefinitely by default for as long as your organization’s subscription is active. Removing a conversation from your view hides it but does not erase it: organizations commonly rely on complete chat history for supervision, recordkeeping, and regulatory obligations, so Strata does not silently destroy it. Your administrator may set an organization-wide retention period, after which conversations you have removed are permanently deleted by an automated job; until such a period is set, none are. Administrators can also request erasure of a specific conversation or of the entire organization’s data at any time (see Your Rights). If the subscription is cancelled, a 30-day deadline applies — see After cancellation below.
  • After cancellation: When an organization’s subscription is cancelled, Kronisys records a retention deadline 30 days later. Nothing is deleted during those 30 days: administrators keep access to the administrative surfaces and can export conversation history, memory entries and account data in JSON, or request erasure sooner. Reactivating the subscription clears the deadline. Once it passes, the organization is scheduled for permanent deletion and every record belonging to it is destroyed — conversations, artifacts, files, memory entries, audit logs and activity logs. Deletion is carried out by a job that runs once a day, so it takes effect on the first run after the deadline passes — at least 30 days after cancellation, and never sooner. We do not send a reminder beforehand.
  • Database Credentials: Encrypted connection strings are retained while your database connection is active. You may disconnect and delete credentials at any time.
  • Memory Entries: Retained until you delete them individually or disable the memory feature. Deletion takes effect immediately; entries are removed from the platform database rather than held for a further period.
  • Audit Logs: Retained per organization configuration, default 365 days, then automatically deleted by a nightly cleanup job.
  • Activity Logs: On the same nightly schedule as audit logs, and following your organization’s configured retention period, the free-text and IP address columns of an activity log entry are stripped. The de-identified usage and cost row itself is kept rather than deleted, because it is what billing and usage reporting are built from, and is then covered by Usage Analytics below. A global 365-day backstop strips any entry your organization’s own policy does not reach sooner.
  • Usage Analytics: Aggregated, de-identified analytics may be retained indefinitely for service improvement.
  • Safety & Compliance: Data flagged for safety review or required by law may be retained for up to 3 years.

9. Security

We implement appropriate technical and organizational measures to protect your data:

  • Encryption: Data is encrypted in transit (TLS 1.2+) and at rest (AES-256). One narrow exception, disclosed rather than glossed: where remote IP geolocation is enabled for the deployment, the second provider in the fallback chain (ip-api.com) is reached over plain HTTP. Only a truncated IP address is sent — the final IPv4 octet zeroed, or an IPv6 address cut to its first three segments — and only after the primary HTTPS provider has already failed or timed out. No account data, credentials, prompts, files, or any other customer content is ever transmitted unencrypted.
  • Database Credential Storage: AES-256-GCM application-layer encryption with a key stored as an Azure App Service environment variable, separate from the database itself.
  • Authentication: Microsoft Entra ID (Azure AD) Single Sign-On exclusively. No passwords are stored or managed by Strata. Multi-factor authentication, conditional access, and session timeout policies are inherited from your organization's Microsoft tenant.
  • Network: Hosted in Azure App Service with HTTPS-only enforced (TLS 1.2 minimum). The platform database is restricted to the App Service via Azure firewall rules and is not exposed to the public internet.
  • Threat Detection: Microsoft Defender for SQL is enabled on the platform database with vulnerability assessments and anomalous activity alerts.
  • Multi-Tenant Isolation: Strata is a multi-tenant SaaS platform. Customer data is logically isolated by organization identifier. Conversation history, audit logs, files, database connections, and user settings from one organization are never accessible to users of another organization. Tenant isolation is enforced at every API endpoint via authenticated session checks against the organization identifier derived from the user's Microsoft SSO domain.
  • Access Controls: Employee access to production systems follows the principle of least privilege. All access is logged and audited.
  • Incident Response: We maintain an incident response plan and will notify affected customers within 72 hours of confirming a personal data breach, in accordance with GDPR Article 33 and other applicable laws.

10. Your Rights & Choices

Depending on your jurisdiction, you may have the following rights regarding your personal data:

  • Access: Request a copy of the personal data we hold about you.
  • Correction: Request correction of inaccurate or incomplete personal data.
  • Deletion: Request deletion of your personal data, subject to legal retention obligations and to your organization’s own recordkeeping requirements. Note that removing a conversation from your own view in Strata hides it from you but does not by itself erase it from the platform — see Data Retention. To have conversation content permanently erased, contact your organization’s administrator or email privacy@kronisys.com.
  • Memory Control: You can view, edit, or delete individual memory entries from your account Settings at any time, and you can disable the memory feature entirely. Disabling memory does not delete previously saved entries; you may delete them individually.
  • Data Portability: Request a copy of your data in a structured, machine-readable format.
  • Objection: Object to processing of your personal data for certain purposes.
  • Restriction: Request restriction of processing in certain circumstances.
  • Withdraw Consent: Where processing is based on consent, you may withdraw consent at any time without affecting the lawfulness of prior processing.

To exercise any of these rights, please contact us at privacy@kronisys.com. We will respond within 30 days of receiving your request.

11. International Data Transfers

Your data may be processed in the United States and other countries where Kronisys, its affiliates, or service providers operate. When transferring data outside the European Economic Area (EEA) or the United Kingdom, we ensure appropriate safeguards are in place, including:

  • Adequacy decisions by the European Commission
  • Standard Contractual Clauses approved by the European Commission
  • Other legally recognized transfer mechanisms

12. Children

Strata is an enterprise product not intended for use by individuals under the age of 18. We do not knowingly collect personal data from children. If you believe a child under 18 has provided personal data to us, please contact us at privacy@kronisys.com and we will take steps to delete such information.

13. Changes to This Policy

We may update this Privacy Policy from time to time. When we make material changes, we will notify you by updating the "Effective" date at the top of this page and, where required, by providing additional notice (such as via email or an in-product notification). We encourage you to review this page periodically.

14. Contact Information

If you have questions about this Privacy Policy, or wish to exercise your privacy rights, you can reach us at: