Privacy Policy

A service operated by Kiungor, Inc. · Effective as of July 31, 2026

This Privacy Policy (the “Policy”) describes how Kiungor, Inc., a Delaware corporation with its principal place of business in Austin, Texas (“Kiungor,” “we,” “us,” or “our”) handles information in connection with CIRIS (Case Readiness and Intake Integrity Service), a document-validation and pre-submission integrity service, together with its website, application, and related tools (the “Service”). By using the Service, you agree to the practices described here.

The Service is a business-facing tool used by organizations such as law firms and other regulated-industry professionals (each, a “Customer”) and their authorized users. This Policy should be read together with the CIRIS Terms of Service and, where applicable, a Data Processing Agreement (“DPA”) between Kiungor and the Customer.

1. Our Two Roles: Controller and Service Provider

The Service involves two categories of information, and Kiungor’s role differs for each:

  • Account and business information. For information about Customers and their authorized users — such as names, business contact details, and account and usage data — Kiungor acts as a controller and handles it as described in this Policy.
  • Customer Content. For the documents and data that a Customer uploads to be validated, which may contain personal information about the Customer’s own clients or applicants, Kiungor acts as a service provider or processor. We process that information only to provide the Service and on the Customer’s documented instructions. The Customer is the controller of that information and is responsible for providing any required notices to, and obtaining any required consents from, the individuals it concerns.

If you are an individual whose documents were submitted to CIRIS by an organization (for example, by your attorney), that organization — not Kiungor — is the controller of your information, and you should direct privacy requests about that content to them. We will assist our Customers in responding to such requests as required by law and any DPA.

2. Information We Collect

Account and business contact information

When a Customer registers or uses the Service, we may collect the name, business email address, telephone number, employer or organization, job role, and, where relevant, billing information of the Customer and its authorized users.

Information collected automatically

We may automatically collect technical information such as IP address, browser and device type, access times, log data, and referring addresses. This information is used to operate, secure, and maintain the quality of the Service and to produce general usage statistics.

Customer Content

Customers upload documents and data for validation. This Customer Content may contain personal information about third parties — for example, a Customer’s clients or applicants — and may include information that is sensitive or special-category, such as identity and government-issued documents, immigration status, national origin, financial information, and professional or health-related credentialing information. It may also include information about minors, for example in family-based immigration filings. We process Customer Content only to provide the Service and on the Customer’s instructions, and not for our own independent purposes.

3. Sensitive and Special-Category Information

Because CIRIS is used in regulated industries, Customer Content may include sensitive or special-category personal information. We process such information solely to provide the validation Service on the Customer’s instructions and as permitted by applicable law and any DPA. We do not use sensitive information contained in Customer Content for advertising, and we do not sell it. The Customer, as controller of that information, is responsible for establishing a lawful basis for its processing and for any notices or consents required from the individuals concerned.

4. How We Use Information

We use account and business information to:

  • operate, deliver, secure, and support the Service, and provide the features Customers request;
  • communicate about accounts, including service notices, confirmations, and changes to the Service or this Policy;
  • carry out our obligations and enforce our rights under the Terms, including billing and collection;
  • detect, prevent, and address security incidents, fraud, and misuse;
  • comply with legal obligations; and
  • improve and develop the Service, using aggregated or de-identified information where practicable.

We process Customer Content only to provide the Service on the Customer’s instructions, as described above. We do not use Customer Content to train machine-learning models except as separately agreed in writing with the Customer.

5. Automated Processing

CIRIS performs automated checks to validate and flag potential issues in documents. These results are advisory: they are intended to support, not replace, review by the Customer’s qualified professionals, and CIRIS does not make legal, immigration, or other final decisions about any individual. Where applicable law grants individuals rights concerning automated processing, those rights are generally exercised through the Customer as controller of the relevant Customer Content.

6. How We Share Information

We do not sell, rent, or lease Customer or account lists, and we do not sell Customer Content. We share information only as follows:

  • Service providers and sub-processors. We share information with trusted vendors — such as cloud-hosting, infrastructure, security, and support providers — who process it on our behalf under contract, only to help us provide the Service, and who are required to protect it and not use it for other purposes.
  • Legal and safety. We may disclose information without notice if we believe in good faith that it is required by law or legal process, or is necessary to protect the rights, property, or safety of Kiungor, our Customers, or the public.
  • Business transfers. Information may be transferred in connection with a merger, acquisition, financing, or sale of assets, subject to the confidentiality commitments in this Policy.

For Customer Content, any sharing is on the Customer’s instructions or as required to provide the Service under the Terms and any DPA.

7. Sub-processors and Data Hosting

We store data on servers operated by third-party hosting vendors with whom we have contracts. We engage sub-processors to help deliver the Service and remain responsible for the tasks we assign to them. Where required by a DPA, we will make available a current list of sub-processors and provide a mechanism for notice of changes.

8. Data Retention

We retain account and business information for as long as an account is active and as needed to provide the Service, comply with legal obligations, resolve disputes, and enforce agreements. We retain Customer Content in accordance with the Customer’s instructions and any DPA, and we delete or return it as described below and on termination, subject to any legal-retention requirements.

9. Security

We take measures designed to protect information from unauthorized access, use, alteration, or disclosure, including encryption of data in transit using protocols such as SSL/TLS and, for stored data, appropriate technical and organizational safeguards such as access controls. No method of transmission or storage is completely secure, however, and we cannot guarantee absolute security. You acknowledge that security and privacy limitations inherent to the internet are beyond our control.

10. Your Rights and Choices

Depending on your location and applicable law, you may have rights to access, correct, delete, or restrict the use of personal information about you, to object to certain processing, or to receive a copy of it. To exercise rights concerning account or business information we control, contact us at the address below; we will respond as required by law after verifying your request.

For personal information contained in Customer Content, the Customer is the controller. If you are an individual whose information a Customer submitted to the Service, please direct your request to that Customer; we will assist the Customer in responding as required.

Limits on deletion

We may be unable to delete information where retention is necessary to complete a requested transaction or service, to comply with a legal obligation or existing legal process, to detect or prevent security incidents or fraud, to identify and repair errors, to exercise or protect legal rights, or otherwise to use the information internally in a lawful manner compatible with the context in which it was provided.

11. Children’s Information

The Service is a business tool and is not directed to children, and we do not knowingly permit children to create accounts. Customer Content may, however, contain personal information about minors — for example, in family-based immigration or similar filings. Where it does, we process that information only to provide the Service on the Customer’s instructions, and the Customer, as controller, is responsible for the lawful basis for its processing.

12. International Users and Data Transfers

Kiungor operates and administers the Service from the United States. If you access the Service or provide information from outside the United States, you understand that information may be processed and stored in the United States and other countries, and you are responsible for compliance with your local laws. Where required, we implement appropriate safeguards for cross-border transfers.

13. Cookies and Similar Technologies

The Service may use cookies and similar technologies to keep you signed in, remember preferences, secure the Service, and understand how the Service is used. These are used to operate the Service, not for third-party behavioral advertising. Most browsers let you decline cookies; if you do, some features of the Service may not function properly.

14. Links to Other Sites

The Service may contain links to other websites we do not operate. We are not responsible for the content or privacy practices of those sites, and we encourage you to read the privacy statements of any site you visit.

15. Changes to This Policy

We may update this Policy from time to time — for example, when our Service, data practices, or the law change. When changes are significant, we will provide notice by a reasonable method, such as email to the account’s primary contact, a prominent notice within the Service, or by updating this Policy. Continued use of the Service after changes take effect constitutes acknowledgment of the updated Policy.

Contact

Questions, comments, or concerns about this Policy may be directed to:

Kiungor, Inc. · Austin, Texas, USA · service@kiungor.com