kyslan ← Back to kyslan.com
Privacy notice

Short, because we collect little.

LAST UPDATED 28 AUGUST 2026 · KYSLAN IS A NORTHBEAMS INC PRODUCT

What we collect

When you request an audit or the sample report, we collect what you type into the form: your name, work email, which PSA you use, your client count, and the revenue and leak figures you set on the calculator. If you fill in the form but stop before running the scan, we keep the contact details you had already entered (name, email, PSA) so we can send you one reminder to finish. We also receive standard technical data (such as IP address and browser type) as part of operating the site.

Why

To respond to your request, run the audit you asked for, and follow up about it. Follow-up means a handful of emails at most: one reminder if you never ran your scan, and up to four notes about a finished report, spread over two months. Every one of them carries a one-click unsubscribe that stops the lot on the spot, and replying "stop" works too. That's it. We do not sell your details and we do not add you to any list you didn't ask for. There are two exceptions to what we share, our partner programme and our advertising, and both are set out below.

Where it lives

Form submissions are delivered to our business inbox and stored as contacts in Resend, which also delivers our email. The site runs on Vercel. If you subscribe, payment is handled by Stripe, our payment processor: Stripe receives your email and billing details, and we never see your card number. Audit data, meaning your report findings, your email address, and sealed connection details while a scan runs, is stored in Google Cloud Firestore. Page fonts are served by Google Fonts, which receives your IP address when a page loads. We use Google Analytics to count page visits and see which pages get read: it receives your IP address and sets a cookie to do that, and it never receives anything from your report. All of them act as our processors, and none of them uses your data to train AI models.

How long

We keep lead details for 24 months after our last contact with you, then delete them. If you become a customer, your details move to our customer records instead.

Your rights

Email hello@kyslan.com to ask what we hold about you, correct it, or have it deleted. We action deletion requests within 30 days. If you're in the UK or EU, you may also have rights under GDPR, including the right to complain to your supervisory authority.

If a partner referred you

We run a small partner programme. Partners are approved by us one at a time, they agree to these terms, and they earn a share of what a customer they introduced pays us.

If you arrive through a partner's referral link, your browser remembers which partner it was for 90 days, and if you subscribe within that window we record that they introduced you. You can clear it at any time by clearing this site's data in your browser.

That partner is then shown, for you: a partly hidden email address (the first letter and the first letter of your domain, so j***@n***.com), whether your subscription is active, which price band you are on, and the date it started. That is the whole list.

A partner never sees anything from your report. Not your findings, not your clients' names, not your numbers, not your PSA data, and not your full email address. They cannot open your report or sign in to your account. If you would rather we did not record a referral for you at all, email hello@kyslan.com and we will remove it.

If you came from one of our ads

If you clicked a Kyslan ad, your browser remembers which ad it was for 90 days. If you subscribe within that window, we tell the ad platform that the click led to a sale, and what it was worth, so we can tell which ads are worth running.

To let them match it up we send a one way scrambled version of your email address, never the address itself. We also use the advertising cookies set by Google, Meta and LinkedIn on this site.

An ad platform never sees anything from your report. Not your findings, not your clients' names, not your numbers, and not your PSA data. You can clear the record of which ad you came from at any time by clearing this site's data in your browser, and you can stop the cookies with your browser's own settings or an ad blocker.

Audit data is different

If you run a Kyslan audit, we connect to your PSA read-only over an encrypted connection and process the data on our servers to build your report. Your PSA access credentials are stored encrypted (AES-256-GCM) and wiped when the scan finishes. If you subscribe and connect your PSA for weekly scans, your connection details stay sealed with the same encryption for as long as your subscription is active, and are wiped when it ends. Report findings are kept so your report link keeps working. The access key is revocable at any time, we never write anything to your PSA, and we do not train models on your data. If you explicitly enable AI-assisted contract analysis, the text of your client agreements is sent to Anthropic, our AI sub-processor, solely to extract scope and billing terms. That option is off by default, runs only with your written authorisation, and your data is never used to train their models either. Email hello@kyslan.com to have an audit and all its data deleted.