INSTITUTION-GRADE PRIVACY GOVERNANCE.
KINETIQ is committed to maintaining institution-grade standards for privacy governance, information security, data stewardship, transparency, and operational accountability.
Document Information
Effective Date: August 3, 2026
Version: 1.0
Document Owner: KINETIQ Operations
Next Scheduled Review: August 3, 2027
1. Introduction & Scope
KINETIQ ("KINETIQ," "we," "us," or "our") is committed to maintaining institution-grade standards for privacy governance, information security, data stewardship, transparency, and operational accountability.
This Privacy Policy describes how KINETIQ collects, uses, stores, discloses, protects, and governs information in connection with:
- KINETIQ mobile applications
- KINETIQ websites
- Digital Governance Operating System ("DGOS")
- governance participation systems
- APIs
- member communications
- support channels
- community governance tools
- partner-enabled integrations
- analytics environments
- operational monitoring systems
2. Platform Role, Regulatory Boundaries & Financial Services Disclaimer
KINETIQ is a governance technology platform.
KINETIQ is not:
- a bank
- a depository institution
- a broker-dealer
- an investment adviser
- a securities issuer
- a money transmitter
- a custodial institution
- a payment processor
- a regulated financial institution
KINETIQ does not directly:
- accept deposits
- hold customer funds
- custody assets
- transmit money
- process regulated payments
- perform KYC or CIP
- perform AML monitoring
- conduct OFAC screening
Where regulated financial services exist, those services are performed exclusively by properly regulated third parties.
3. Important Financial Data Display Disclosure
KINETIQ may, where contractually authorized, display limited financial information supplied directly by regulated financial partners.
Such information may include:
- account status indicators
- aggregated financial balances
- community-level financial summaries
- funding eligibility indicators
- financial standing signals relevant to governance participation
4. Definitions
Personal Information
Information that identifies, relates to, describes, or can reasonably be linked to an identifiable individual.
Sensitive Personal Information
Information requiring heightened legal protection, including Social Security numbers, passport numbers, driver's license numbers, government-issued identification numbers, financial account credentials, payment card credentials, biometric identifiers, and tax identifiers.
Governance Data
Information related to participation in governance systems, including voting activity, governance standing, proposal participation, committee activity, and accountability scoring.
DGOS
KINETIQ's Digital Governance Operating System.
5. Information We Collect
KINETIQ collects only information reasonably necessary for governance operations, platform administration, security, operational resilience, communications, and lawful business purposes.
Account Registration Information
- full name
- email address
- mobile number
- username
- authentication credentials
- account identifiers
Governance Participation Information
- voting participation
- proposal activity
- governance standing
- committee interactions
- governance acknowledgments
Device / Technical Information
- IP address
- browser type
- operating system
- device identifiers
- session timestamps
- access metadata
- API usage records
Security Monitoring Information
- failed authentication attempts
- suspicious access behavior
- approximate geolocation indicators
- anomaly detection signals
- anti-collusion telemetry
- abuse-prevention signals
6. Information KINETIQ Does Not Directly Collect
Unless expressly disclosed otherwise, KINETIQ does not directly collect, store, or process regulated financial identity information such as:
- Social Security numbers
- government-issued identity verification documents
- KYC/CIP verification records
- AML screening records
- OFAC screening records
- bank account credentials
- payment card credentials
- brokerage account credentials
Where such information is required, collection occurs exclusively through regulated partners or approved vendors.
7. How We Use Information
KINETIQ uses information for legitimate operational purposes only.
Platform Operations
- account administration
- authentication
- access control
- service delivery
- feature enablement
Governance Operations
- governance administration
- voting systems
- dispute workflows
- committee administration
Security & Abuse Prevention
- fraud prevention
- anomaly detection
- abuse prevention
- authentication security
- anti-collusion monitoring
8. Data Sharing & Disclosure
KINETIQ does not sell personal information in the conventional commercial sense unless expressly disclosed.
Information may be disclosed only where reasonably necessary to:
- Service Providers: Contractually bound processors providing hosting, authentication, communications, and infrastructure
- Financial / Regulated Partners: Where necessary for integrated services
- Legal Authorities: Where required by subpoena, court order, or regulatory process
- Protection of Rights: To protect KINETIQ, members, governance integrity, or platform security
- Corporate Transactions: Including merger, acquisition, or asset transfer
9. Data Retention & Information Lifecycle Management
KINETIQ maintains formal data retention, archival, preservation, anonymization, and destruction controls consistent with operational necessity, governance integrity, security obligations, contractual commitments, and applicable law.
Retention Periods
Account Registration Information: Active account lifecycle + seven (7) years after closure
Governance Records: Seven (7) to ten (10) years or longer where governance integrity requires
Security Logs: Twelve (12) months to seven (7) years depending on risk classification
Support / Dispute Records: Seven (7) years or longer where dispute exposure exists
Analytics Data: Twelve (12) to thirty-six (36) months unless otherwise required
10. Data Retention Schedule
KINETIQ retains personal information only as long as necessary for the purpose for which it was collected, to fulfill legal obligations, or to resolve disputes. The following schedule governs retention of specific data categories:
| Data Category | Retention Period | Basis |
|---|---|---|
| Account registration data (name, email, UID) | Duration of active account + 3 years after closure | Legal obligation, dispute resolution |
| Identity verification records (KYC/Persona) | 5 years from verification date | BSA/AML regulatory standard (held by Persona, not KINETIQ) |
| Governance participation records (votes, proposals) | Duration of active account + 7 years | Institutional integrity, audit obligation |
| Audit log entries | 7 years | Legal obligation, fraud prevention |
| Communication records (support tickets, emails) | 3 years from last interaction | Dispute resolution |
| Device identifiers and session tokens | 90 days from session end | Security |
| Payment routing instructions | Not retained by KINETIQ - held by regulated financial partner | Platform boundary |
| Financial transaction records | Not retained by KINETIQ - held by regulated financial partner | Platform boundary |
| Error and diagnostic logs (Sentry) | 90 days | Operational necessity |
Upon expiration of the applicable retention period, data is deleted or anonymized. Anonymized data (from which no individual can be identified) is not subject to this schedule and may be retained indefinitely for aggregate analytics.
11. Individual Privacy Rights & Request Handling
Subject to applicable law, eligible individuals may request exercise of privacy rights.
- Right of Access: Request categories of information KINETIQ maintains
- Right to Correction: Request correction of materially inaccurate information
- Right to Deletion: Request deletion of eligible information, subject to lawful exceptions
- Right to Data Portability: Where legally applicable
- Right to Restrict Processing: Where legally available
- Right to Object: Where permitted by law
- Right to Appeal: Where required under applicable privacy laws
12. How to Exercise Your Rights - Response Timelines
To submit a data subject request (access, deletion, correction, portability, or opt-out), contact: [INSERT LEGAL EMAIL ADDRESS] with subject line "Privacy Rights Request - [Type of Request]."
KINETIQ will:
- Acknowledge receipt of your request within 10 business days
- Verify your identity before processing (to protect against unauthorized requests)
- Respond substantively within 45 calendar days of receipt
- If additional time is required, notify you within the initial 45-day period and complete processing within 90 calendar days total
KINETIQ will not discriminate against you for exercising any privacy right. Exercising a privacy right does not affect your access to Platform governance functions.
Requests may be denied where fulfillment would: violate a legal obligation, prevent KINETIQ from completing a transaction you requested, impair security or fraud prevention, or interfere with another person's rights.
13. U.S. State Privacy Rights
Residents of certain U.S. jurisdictions may possess enhanced privacy rights, including California, Virginia, Colorado, Connecticut, and Utah. Where applicable, individuals may possess rights to access, correction, deletion, portability, and appeal.
WE DO NOT SELL YOUR PERSONAL INFORMATION
KINETIQ does not sell, rent, or trade personal information to third parties for monetary consideration.
KINETIQ does not share personal information with third parties for cross-context behavioral advertising.
California residents therefore have no opt-out right to exercise under Cal. Civ. Code ยง 1798.120 because no sale occurs. This does not affect your other California privacy rights described below.
14. AI Governance, Automated Decision Support & Explainability
KINETIQ may use rules-based automation, algorithmic systems, and AI-assisted governance support tools to promote governance integrity, security, fairness, and operational resilience.
KINETIQ does not use automated systems to independently:
- provide investment recommendations
- make regulated financial determinations
- determine creditworthiness
- deny regulated financial access
- replace legally required human review
Material governance decisions require meaningful human oversight.
15. Automated Processing and Profiling
KINETIQ uses automated processing to calculate:
- Governance standing status - based on participation history, recusal compliance, and anti-collusion monitoring
- Network influence indicators - based on invitation lineage and participation depth
These calculations affect your governance participation status within the Platform. They do not affect your eligibility for financial services, credit, employment, housing, or any regulated determination.
No automated processing by KINETIQ produces legally significant decisions about your rights outside the Platform. All governance determinations may be reviewed by contacting KINETIQ at [INSERT LEGAL EMAIL ADDRESS].
KINETIQ does not use personal information for external credit scoring, insurance underwriting, employment screening, or any other high-stakes automated decision-making.
16. Incident Response & Breach Notification
KINETIQ maintains formal incident response procedures. Where legally required, notification will be provided consistent with applicable law. If incidents involve regulated financial systems controlled by banking or investment partners, notification responsibilities may be governed by those entities.
17. Children's Privacy
The KINETIQ Platform is intended for users 18 years of age and older. KINETIQ does not knowingly collect personal information from individuals under 18.
If KINETIQ learns that personal information has been collected from a person under 18 without verifiable parental consent, KINETIQ will delete that information as promptly as practicable.
If you believe a minor has submitted personal information to the Platform, contact: [INSERT LEGAL EMAIL ADDRESS].
18. Third-Party Links, APIs & External Services
KINETIQ may connect with third-party services including financial institutions, identity vendors, cloud providers, and analytics vendors. Third-party services operate independently, and KINETIQ does not control their privacy practices unless expressly contracted. Users interacting with external services become subject to those providers' terms and privacy policies.
19. International Data Transfers
KINETIQ is based in the United States. If you access the Platform from outside the United States, your information is transferred to and processed in the United States, where privacy laws may differ from those in your jurisdiction.
By using the Platform, you consent to this transfer. KINETIQ implements appropriate safeguards, including contractual data processing agreements with service providers, to protect transferred data.
KINETIQ does not intentionally direct services to residents of the European Economic Area. If you are an EEA resident and believe your rights under GDPR apply, contact [INSERT LEGAL EMAIL ADDRESS].
20. Privacy by Design
Privacy is built into KINETIQ's Platform architecture, not added afterward. Specific design choices include: separation of governance data from regulated financial data at the infrastructure level; field-level encryption for sensitive records; role-based access controls limiting internal data access to authorized personnel only; and automatic data expiration enforced at the database layer. KINETIQ does not collect personal information it does not need.
21. No Financial Advice & No Fiduciary Relationship
KINETIQ does not provide financial advice, investment advice, tax advice, securities advice, portfolio management, brokerage services, or fiduciary financial services. Governance participation does not create a financial advisory or fiduciary relationship between KINETIQ and any user.
22. Policy Updates & Change Management
KINETIQ may update this Privacy Policy periodically due to legal developments, regulatory changes, platform evolution, or security enhancements. Material changes may be communicated through platform notices, website publication, or account communications. Continued use following updates may constitute acknowledgment where legally permissible.
23. Privacy Contact & Governance Escalation
Privacy inquiries, complaints, or requests may be directed to KINETIQ's Privacy Office. Requests may include privacy rights requests, complaints, correction requests, or data governance concerns.
Outside Legal Counsel: Foley & Lardner LLP - Clyde Tinnen, Partner, 777 East Wisconsin Avenue, Milwaukee, WI 53202-5306, Phone: 414.297.5026. Disclosure of counsel does not designate such counsel as a registered agent, legal notice recipient, service-of-process agent, or arbitration notice recipient unless expressly agreed in writing.
24. Disclaimers & Limitation of Privacy Representations
KINETIQ implements institution-grade safeguards but cannot guarantee absolute security. No digital platform is immune from cyberattacks, unauthorized access, infrastructure failures, or third-party failures. Users share responsibility for maintaining account security.