1. Who this policy covers
This notice covers website visitors, people contacting Korenact, and organization account users. It also explains the types of information the platform processes when an organization uses it to serve its patients, customers, clients or other contacts.
The service operator’s legal identity and full privacy contact details are being finalized for commercial launch. If you are contacting an organization that uses Korenact, that organization determines its workflow and should provide its own privacy notice. Ask that organization about its use of your information.
2. Information you provide
Website inquiries and pilot requests may include your name, work email, phone, organization, job title, organization type, locations, approximate communication volume, selected channels, current systems, requested languages, workflow need, timing and notes. A pilot request also records its source page, supplied campaign identifiers, contact consent and submission time. We use this information to manage and respond to your request. Submitting an inquiry does not sign you up for a marketing list or a paid subscription. Please do not include patient records or sensitive personal information in a sales inquiry or pilot request.
Organization accounts can contain names, email addresses, roles, organization details, and authentication records. Configured workflows can contain contact details, conversation messages and summaries, appointment information, submitted knowledge, action requests and results, approval records, and support or audit information.
3. Technical and usage information
The service processes operational details such as request and event timestamps, conversation duration, usage measurements, errors, and security events. Website inquiries include a reference, request identifier, timestamps, a hashed request fingerprint, and a hashed abuse-prevention identifier to handle duplicate submissions and limit misuse. The inquiry record does not store the raw IP address. Hosting and network services may separately process IP addresses and request logs. The website currently requests typefaces from Google Fonts; Google’s font-hosting services receive network request information, including the visitor’s IP address, when the fonts are loaded. The console uses browser storage for sign-in and a chosen appearance preference, as described in the Cookies & storage policy.
4. Optional website usage counts
Only if you choose to allow them, the website sends first-party conversion counts containing an event name, public page, selected capability category and submission time. A hashed abuse-prevention identifier helps limit misuse. These events do not include form details, patient information, full URLs or campaign query values. No third-party analytics service is used. Optional counts are off until you choose otherwise, and you can withdraw permission through the website privacy preferences in the footer. Withdrawal stops future optional counts; existing records follow the operator’s retention schedule.
5. Why information is processed
Information is used to respond to requested contact, administer accounts, understand an organization’s service requests, perform authorized workflow steps, support staff review, maintain operational records, protect the service, and investigate errors or misuse. The organization must determine the lawful basis, required disclosures, and data requirements for its customer-facing workflow. Where additional legal grounds are needed for Korenact’s own processing, these must be documented in the final deployment notice.
6. Automated workflow steps
Conversation content and relevant context may be sent to the connected services your organization authorizes for understanding, responses or summaries. Korenact applies checks for action permissions, identity requirements and approvals. Verification answers are excluded from optional language processing and masked in saved messages. Other information fields and connected-service records may still contain personal information. Do not assume transcript redaction removes every sensitive detail.
7. Who may receive information
Authorized organization users can access information within their permitted workflow. Depending on the deployment, connected services may process information for hosting, storage, calls and messages, language processing, scheduling and support. Only the services configured for a workflow receive its applicable requests.
The final deployment must identify the actual services, processing locations and contractual safeguards. Retention and permitted uses of submitted information depend on the authorized account and its terms; this notice does not promise a universal restriction on every service’s processing. Information may also need to be disclosed where legally required or to investigate service abuse, subject to applicable law.
8. International processing
Processing locations depend on the hosting environment and connected services. Do not assume information remains in a particular country. The operator and organization must identify relevant cross-border transfers and any required safeguards before activating workflows that require them. No particular data-residency commitment is made by this website.
9. Retention and deletion
Account, inquiry, conversation, action, and operational records need different retention decisions. Inquiry records are kept for request handling and abuse prevention pending the operator’s finalized retention schedule. The platform can record a conversation retention target, but automated deletion is not implemented for all records. A configured number of days is therefore not a guarantee of deletion. The deployment operator must set and enforce a schedule covering active data, audit records, connected-service copies, and backups, and document it in the final notice and customer agreement.
10. Security and recording
The platform includes organization access checks, action permissions, verification controls, and operational records. Infrastructure protection and credential management also depend on the deployment. These controls do not eliminate all risk. Recording support or a consent field does not establish that a legally valid recording-notice and consent process is active; the organization must validate any recording workflow before use.
11. Your choices and requests
Depending on your location and the applicable law, you may have rights to request access, correction, deletion, restriction, portability, or to object to particular processing, withdraw consent where it is relied on, or complain to a relevant privacy regulator. These rights can have conditions and exceptions.
For an organization-managed conversation, contact the organization you were speaking with first. For your Korenact account or website inquiry, request a private follow-up through our contact page. Include enough context to identify the request, but do not send passwords or unnecessary sensitive records. Identity or authority may need to be verified before a request is fulfilled.
12. Children and sensitive information
The public website and organization administration console are intended for adult business users. Do not submit children’s information, health records, financial account credentials, or confidential case details in a demonstration or sales inquiry. Any workflow involving minors or sensitive information requires a specific review and appropriate protections before activation.
13. Policy updates
This notice must be reviewed as the service, operators, connected services and uses of information change. Material changes need appropriate notice before new processing begins. The date and status above identify this version; an approved customer agreement may provide additional detail for your deployment.