Privacy Policy

Effective Date: February 1, 2026
Last Updated: February 1, 2026


TABLE OF CONTENTS

  1. Introduction
  2. Information We Collect
  3. How We Use Your Information
  4. How We Share Your Information
  5. International Data Transfers
  6. Data Retention
  7. Your Privacy Rights
  8. Security
  9. Cookies and Tracking Technologies
  10. Third-Party Services
  11. Children’s Privacy
  12. Data Retention Policy
  13. Changes to This Policy
  14. Contact Us
  15. Region-Specific Information
  16. Consent Acknowledgment

1. INTRODUCTION

1.1 Who We Are

Kumello Inc. (“Kumello,” “we,” “us,” or “our”) consolidates and organizes global medtech data and provides an AI-powered partnership matching platform for medtech professionals to identify and connect with strategic business partners. We are headquartered in Ontario, Canada.

1.2 Our Commitment to Privacy

We take your privacy seriously. This Privacy Policy explains how we collect, use, disclose, and protect your personal information when you use our Services.

1.3 Scope

This Privacy Policy applies to:

By using our Services, you consent to the collection, use, and disclosure of your personal information as described in this Privacy Policy and our Terms of Service (kumello.com/terms).

1.5 Updates to This Policy

We may update this Privacy Policy from time to time. When we make material changes, we will notify you as described in Section 13.

1.6 Global Scope

This policy applies worldwide; region-specific details in Section 15. We comply with PIPEDA (Canada), GDPR/UK GDPR (EU/UK), CCPA/CPRA (California/US), and other applicable laws. We process data lawfully (contractual necessity, legitimate interests, legal obligations, consent where required).


2. INFORMATION WE COLLECT

2.1 Information You Provide Directly

2.1.1 Account Registration

When you create an account, we collect:

2.1.2 Profile Information

As you use the Services, you may provide:

2.1.3 Communications

We collect information when you:

2.1.4 Payment Information

For paid subscriptions, we collect:

2.2 Information We Collect Automatically

2.2.1 Usage Data

When you use the Services, we automatically collect:

2.2.2 Device and Technical Information

2.2.3 Cookies and Similar Technologies

We use cookies, web beacons, and similar technologies to:

For more details, see Section 9 (Cookies).

2.3 Information From Third Parties

2.3.1 Authentication Services

If you use third-party authentication (e.g., Google Sign-In):

2.3.2 Data Enrichment

We may enhance our database with information from:

2.3.3 Integration Partners

If you connect third-party services to your account:

2.4 Information We Do NOT Collect

To clarify what we do not collect:

2.5 Categories of Personal Information (CCPA/CPRA Notice at Collection)

We collect identifiers (name/email), commercial info (company/product details), internet/electronic activity (usage/search patterns), geolocation (coarse), inferences (preferences/matching). Full list in Privacy Notice if separate. We do not collect sensitive personal information (e.g., health data, precise geolocation) unless explicitly provided and necessary.


3. HOW WE USE YOUR INFORMATION

3.1 Providing and Improving Services

We use your information to:

3.2 AI and Machine Learning

Your information is used to:

Important Notes About AI Usage:

3.3 Communications

We use your contact information to:

3.4 Security and Fraud Prevention

We use information to:

We use and retain information as necessary to:

3.6 Analytics and Research

We use aggregated and anonymized data to:

3.7 Business Transfers

In the event of a merger, acquisition, or sale of assets, your information may be transferred to the acquiring entity.

3.8 AI Model Training and Improvement

We use anonymized and aggregated forms of usage data, interaction patterns, search trends, and other non-identifiable information to train, fine-tune, and improve our AI features (e.g., partnership matching, recommendations, bias reduction). Identifiable personal data is excluded from training unless you provide explicit consent. We use anonymized/aggregated data which is retained indefinitely — even after account closure or deletion request — as it is no longer personal information under PIPEDA, GDPR/UK GDPR, and CCPA/CPRA.


4. HOW WE SHARE YOUR INFORMATION

4.1 Service Providers

We share information with third-party service providers who help us operate the Services:

4.1.1 AI Technology Partners

4.1.2 Infrastructure and Hosting

4.1.3 Payment Processing

4.1.4 Communication Services

4.1.5 Analytics Providers

4.2 Business Partners

When you use the Services to connect with potential partners:

We may disclose information when required by law or when we believe disclosure is necessary to:

4.4 Business Transfers

In the event of a merger, acquisition, bankruptcy, or sale of assets:

We may share information for other purposes with your explicit consent.

4.6 Anonymized and Aggregated Data

We may share anonymized and aggregated data that does not identify you personally:

4.7 What We Do NOT Share

We do NOT:


5. INTERNATIONAL DATA TRANSFERS

5.1 International Data Transfers

Kumello is based in Canada; data may be stored/processed in Canada, the US, EU/EEA, or other countries by us or providers. We ensure adequate protection for transfers:

5.2 Transfer Mechanisms

When we transfer data internationally, we implement appropriate safeguards:

5.3 Countries Involved

Your data may be transferred to and processed in:

5.4 Data Protection Standards

Regardless of location, we ensure:

By using the Services, you consent to international data transfers as described in this section. If you do not consent, please do not use the Services.


6. DATA RETENTION

We retain personal information only as long as necessary (detailed in our separate Data Retention Policy at kumello.com/data-retention-policy). Anonymized/aggregated data retained indefinitely for AI improvement/business purposes (no longer personal information).


7. YOUR PRIVACY RIGHTS

7.1 Rights for All Users

7.1.1 Access

Right: Request access to your personal information

How:

We’ll provide:

7.1.2 Correction

Right: Request correction of inaccurate or incomplete information

How:

7.1.3 Deletion (Right to Be Forgotten)

Right: Request deletion of your personal information

How:

Exceptions: We may retain data for:

7.1.4 Objection

Right: Object to certain processing of your information

How: Contact privacy@kumello.com

Examples:

7.1.5 Data Portability

Right: Receive your data in a portable, machine-readable format

How:

Format: CSV, JSON, or other commonly used formats

Includes:

Right: Withdraw consent for processing based on consent

How:

Effect:

7.1.7 Restrict Processing

Right: Request restriction of processing in certain circumstances

How: Contact privacy@kumello.com

When:

7.2 How to Exercise Your Rights

7.2.1 Verification

To protect your privacy, we must verify your identity before fulfilling requests:

7.2.2 Response Timeline

7.2.3 No Fee

Exercising your rights is free, except:

7.3 Complaints and Concerns

If you have concerns about our privacy practices:

7.3.1 Contact Us First

7.3.2 Supervisory Authorities

You have the right to lodge a complaint with:


8. SECURITY

8.1 Our Security Measures

We implement appropriate technical and organizational measures to protect your information:

8.1.1 Technical Measures

8.1.2 Organizational Measures

8.1.3 Application Security

8.2 Data Breach Response

In the event of a data breach:

What we’ll tell you:

8.3 Your Security Responsibilities

You play a critical role in protecting your information:

8.4 Security Limitations

Despite our efforts:

8.5 Third-Party Security

Our service providers maintain security measures including:


9. COOKIES AND TRACKING TECHNOLOGIES

9.1 What Are Cookies

Cookies are small text files stored on your device that help websites function properly and provide analytics.

9.2 Types of Cookies We Use

9.2.1 Essential Cookies

Purpose: Enable core functionality

Duration: Session or persistent (up to 1 year)
Can you opt out?: No — required for the Services to function

9.2.2 Functional Cookies

Purpose: Remember your preferences

Duration: Persistent (up to 1 year)
Can you opt out?: Yes — but may affect user experience

9.2.3 Analytics Cookies

Purpose: Understand how you use the Services

Duration: Persistent (up to 2 years)
Can you opt out?: Yes — through cookie settings
Providers: Google Analytics, Mixpanel, or similar

9.2.4 Marketing Cookies

Purpose: Measure marketing effectiveness

Duration: Persistent (up to 1 year)
Can you opt out?: Yes — through cookie settings
Providers: Google Ads, LinkedIn, or similar

9.3 Other Tracking Technologies

9.3.1 Web Beacons (Pixels)

Small transparent images used to:

9.3.2 Local Storage

Browser storage used to:

9.3.3 SDKs and APIs

Third-party code that may collect:

9.4 Managing Cookies

You can manage cookie preferences through:

9.4.2 Browser Controls

Most browsers allow you to:

Instructions:

9.4.3 Opt-Out Tools

9.5 Do Not Track

Some browsers have “Do Not Track” (DNT) features. Currently:

9.6 Mobile Device Identifiers

On mobile devices, we may collect:

How to opt out:


10. THIRD-PARTY SERVICES

The Services may contain links to third-party websites or services. We are not responsible for:

Recommendation: Review the privacy policies of any third-party sites you visit.

10.2 Integrated Third-Party Services

If you connect third-party services to your account:

Examples: CRM integrations, email platforms, calendar services

10.3 Third-Party Service Providers

Our service providers have their own privacy policies:

10.4 Social Media

We may maintain social media profiles. When you interact with us on social media:

10.5 Marketing Partners

We may work with marketing partners for:

These partners have their own privacy policies and may collect information about your interactions with our marketing materials.


11. CHILDREN’S PRIVACY

11.1 Age Requirement

The Services are not intended for use by individuals under 18 years of age (or the age of majority in their jurisdiction, whichever is greater).

11.2 No Knowing Collection

We do not knowingly:

11.3 Parental Rights

If you believe we have collected information from a child:

11.4 COPPA Compliance

While we are a Canadian company, we comply with the U.S. Children’s Online Privacy Protection Act (COPPA) for any U.S. children who may inadvertently access our Services.


12. DATA RETENTION POLICY

12.1 Purpose and Scope

Kumello Inc. (“Kumello,” “we,” “us,” or “our”) is committed to privacy, data minimization, and compliance with applicable laws. This policy explains how long we retain data collected through our Services (e.g., medtech partnership platform). It applies to all personal information and other data we collect, process, or store, including from users in the United States, Canada, European Union/United Kingdom, and other international jurisdictions.

This policy should be read together with our Privacy Policy (kumello.com/privacy-policy) and Terms of Service (kumello.com/terms). We retain data only as long as necessary for the purposes for which it was collected, while balancing user privacy rights, legal obligations, security needs, and legitimate business interests — including ongoing improvement of AI-powered features.

12.2 Data Retention Principles

12.3 Retention Periods by Data Type

Data TypeRetention Period (Active Accounts)Retention After Account ClosurePrimary Purpose & Legal BasisNotes / Legal Requirement
Account InformationDuration of the account relationship90 daysAccount management, authentication — Contractual necessity, legitimate interests
Client Content (business plans, files, saved searches, notes, etc.)Duration of the account relationship30 daysProviding and enabling core Services — Contractual necessityExport recommended before closure
Usage Data (navigation, searches, clicks, interactions, feature usage)24 months from collection24 months from collectionProduct analytics, service optimization, AI improvement — Legitimate interestsAnonymized indefinitely
Communications (support tickets, emails, chats, feedback)36 months from date of communication36 months from date of communicationCustomer support, quality assurance, dispute resolution — Legitimate interestsLonger if legally required
Business Relationship Data (outreach history, connection metadata)36 months after last interaction36 months after last interactionRelationship management, business analytics — Legitimate interestsMetadata only
Payment & Financial Data7 years from transaction date7 years from transaction dateAccounting, tax reporting, dispute resolution — Legal obligationTax / GAAP requirements
Technical & System Logs12 months from creation12 months from creationSecurity monitoring, debugging, operations — Legitimate interestsLonger for active incidents
AI Training Data – Identifiable Personal DataNot used without explicit consent; limited per consentN/A (excluded or consent-based)AI model improvement — Consent or legitimate interestsMostly excluded
AI Training Data – Anonymized / Aggregated Usage & PatternsIndefiniteIndefinite (persists after closure)Improve AI matching, recommendations, reduce bias — Legitimate interestsNo re-identification possible
Legal & Compliance Records7 years or as required by law7 years or as required by lawRegulatory compliance, defending claims — Legal obligationIndefinite under legal hold
Backups / Disaster Recovery Copies90 days after deletion from production90 days after deletion from productionBusiness continuity & recovery — Legitimate interestsEncrypted
Medtech Company Database ContentIndefinite (continuously curated/updated)IndefiniteCore service functionality (search & matching) — Legitimate interestsPublic / commercial sources

Anonymized Data Note: Once data is fully anonymized (all direct and indirect identifiers removed, aggregated with others, and protected with techniques such as k-anonymity or differential privacy), it is no longer considered personal information under PIPEDA, GDPR, CCPA/CPRA, and most privacy laws. Such data may be retained indefinitely — even after account closure — for analytics, AI training, product development, and industry insights.

12.4 AI Training and Model Improvement

We use anonymized and aggregated forms of usage data, search patterns, interaction trends, and other non-identifiable information to train, fine-tune, and continuously improve our AI features (e.g., intelligent matching, recommendations, bias reduction).

12.5 Data Deletion and Destruction

Exceptions: Deletion may be delayed or prevented due to legal holds, active investigations, fraud/security matters, regulatory requirements, or ongoing disputes.

12.6 Exceptions and Extensions

Retention periods may be extended when:

12.7 Your Rights

Depending on your location (U.S., Canada, EU/UK, etc.), you may have rights to:

How to exercise rights: Email privacy@kumello.com with your request details. We will verify identity and respond within 30–60 days. Some limitations apply (e.g., legal retention obligations, anonymized data).

You may also lodge a complaint with:


13. CHANGES TO THIS POLICY

13.1 Right to Modify

We may update this Privacy Policy from time to time to reflect:

13.2 Notice of Changes

13.2.1 Material Changes

For material changes that reduce your rights or significantly change our practices, we will:

13.2.2 Non-Material Changes

For minor changes (clarifications, formatting, non-substantive updates):

13.3 Acceptance of Changes

Your continued use of the Services after changes take effect constitutes acceptance of the updated Privacy Policy.

If you do not agree to changes:

13.4 Version History

Previous versions of this Privacy Policy may be available upon request to privacy@kumello.com.


14. CONTACT US

14.1 Privacy Inquiries

For questions about this Privacy Policy or our privacy practices:

Email: privacy@kumello.com

Mail:
Kumello Inc.
Attention: Privacy Officer
37 Jacob Keffer Parkway, Suite 301
Concord, Ontario L4K 5N8
Canada

14.2 Data Protection Officer

For GDPR-related inquiries (EU users):

Email: privacy@kumello.com

Note: Kumello does not currently require a dedicated Data Protection Officer under GDPR Article 37, as we are not a public authority and our core activities do not involve large-scale systematic monitoring or processing of special categories of data. If you have GDPR-related questions, please contact our Privacy Officer at the address above.

14.3 General Contact

For general inquiries about the Services:

Email: support@kumello.com
Website: https://kumello.com/contact

14.4 Response Time

We aim to respond to all privacy inquiries within:


15. REGION-SPECIFIC INFORMATION

15.1 Canadian Users (PIPEDA Compliance)

We collect and process personal information under PIPEDA (Personal Information Protection and Electronic Documents Act).

15.1.2 Your Rights

Under PIPEDA, you have the right to:

15.1.3 Complaints

File complaints with:

Office of the Privacy Commissioner of Canada
30 Victoria Street
Gatineau, Quebec K1A 1H3
Phone: 1-800-282-1376
Website: www.priv.gc.ca

15.2 European Users (GDPR Compliance)

We process your data based on:

15.2.2 Your Rights Under GDPR

You have the right to:

15.2.3 Data Protection Authority

Lodge complaints with your local supervisory authority:

15.2.4 EU Representative

Note: Kumello does not currently require an EU representative under GDPR Article 27, as we do not have an establishment in the EU and are not required to appoint one based on the nature and scale of our processing activities. If our EU operations expand significantly, we will appoint an EU representative and update this policy accordingly. For all EU inquiries, please contact privacy@kumello.com.

15.2.5 Data Transfers

We transfer data from the EU/EEA using:

15.3 California Users (CCPA/CPRA Compliance)

15.3.1 Categories of Information Collected

15.3.2 Your California Rights

You have the right to:

15.3.3 How to Exercise Rights

Note: CCPA requires at least two designated methods for submitting requests. We provide online account settings and email. Toll-free phone support may be added as our California user base grows.

15.3.4 Verification Process

We will verify your identity before fulfilling requests using:

15.3.5 Response Timeline

15.3.6 Business Purpose

We use information as described in Section 3.

15.3.7 No Sale of Information

We do NOT sell personal information to third parties.

15.3.8 Shine the Light (California Civil Code § 1798.83)

California residents may request information about disclosure of personal information to third parties for their direct marketing purposes. We do not share information for third-party marketing purposes.

15.3.9 Authorized Agents

You may designate an authorized agent to make requests on your behalf. We will require:

15.4 Other Regions

If you are located in other jurisdictions:


BY USING KUMELLO, YOU ACKNOWLEDGE THAT:

IF YOU DO NOT AGREE TO THIS PRIVACY POLICY, DO NOT USE KUMELLO.


We review this policy at least annually or when laws, services, or practices change. Material changes will be notified via email and/or platform notice (30 days in advance where required).

Questions about your privacy?

Email: privacy@kumello.com
Mail: Kumello Inc., Attention: Privacy Officer, 37 Jacob Keffer Parkway, Suite 301, Concord, Ontario L4K 5N8, Canada


This Privacy Policy was last updated on February 1, 2026. Please check kumello.com/privacy-policy for the most current version.

This policy aligns with PIPEDA (Canada), GDPR & UK GDPR (EU/UK), CCPA/CPRA (California/U.S.), and other applicable privacy, tax, and data protection laws. Appropriate safeguards (e.g., Standard Contractual Clauses) are used for international data transfers.