Legal information
Policies, terms of service, and patents we hold.
Privacy policy
Privacy policy
Last updated: [September 7, 2026]
In brief. We collect information you provide, information created when you use our websites and services, and information supplied by your organization. We use it to provide and secure the Services, respond to you, manage our business relationships, improve performance, and communicate with you. We share it only for the purposes explained below. Your rights depend on where you live and how Kore.ai handles the information.
1. About this notice
This Notice explains how Kore.ai, Inc. and the Kore.ai company responsible for a particular interaction (together, "Kore.ai," "we," "us," or "our") collect, use, share, keep, and protect personal information.
It applies when you visit a Kore.ai website or other digital property that links to this Notice; create or use an account; use a Kore.ai product, platform, application, or related service; request information, a demonstration, or support; join an event, survey, or waitlist; communicate with us; or receive marketing from us. We call these websites, products, applications, and services the "Services."
This Notice does not apply to third-party websites or services, even if you reach them through a Kore.ai Service. Their own privacy notices apply. It also does not cover workforce or applicant information when Kore.ai gives the individual a separate notice.
Kore.ai, Inc. is the main contact for this Notice. For website and direct corporate interactions, it is responsible for the information unless a form, contract, event notice, regional section, or other collection notice identifies a different Kore.ai company.
2. When Kore.ai acts for itself and when it acts for a customer
When Kore.ai decides why and how personal information is used, Kore.ai is responsible for that use. Privacy laws may call Kore.ai a controller, business, or data fiduciary. Examples include our websites, direct account administration, business relationships, marketing, events, support, and security work.
Many Kore.ai Services are used by enterprise customers. A customer may submit, connect, generate, or otherwise make information available through the Services. When the customer decides why and how that information is used and Kore.ai follows the customer's instructions, Kore.ai acts as the customer's processor or service provider. The customer's privacy notice applies to that processing. Please send requests about customer-controlled information to the customer first; we will assist the customer where required.
Customers decide what information to place in the Services and are responsible for having the notices, permissions, and other legal grounds needed for their use.
3. Information we collect
3.1 Information you give us
- Contact details, such as your name, email address, telephone number, and profile photo.
- Work and organization details, such as employer, job title, business address, organization name, and business contact details.
- Account details, such as account identifiers, login and authentication information, preferences, and profile settings.
- Billing and transaction details, including billing contacts and payment information where applicable.
- Information in demonstration requests, forms, waitlists, surveys, event registrations, and support requests.
- Messages, files, feedback, and any other information you choose to provide.
3.2 Information collected automatically
- We may collect this information through server logs, cookies, web beacons, and similar technologies.
- Internet Protocol address, browser type, operating system, device type, device identifier, and device settings.
- Pages, features, search terms, links, and advertisements you interact with, together with dates, times, duration, and frequency of use.
- Technical, diagnostic, performance, security, and server-log information.
- Approximate location based on your Internet Protocol address and, where a Service feature requests it and you enable it, location made available by your device settings, GPS, nearby Wi-Fi access points, cell towers, or sensors.
3.3 Information processed through customer use of the Services
Depending on a customer's configuration, customer-controlled information may include messages, files, prompts, responses, connected data sources, recordings, and other content. The customer controls what is submitted and how the Service is configured, subject to its agreement with Kore.ai.
3.4 Where information comes from
- directly from you;
- from your browser, device, and use of the Services;
- from your employer or another organization that gives or manages your access;
- from another user who invites you or communicates with you;
- from applications, integrations, and data sources enabled by you or the customer; and
- from service providers that support our operations.
4. Why we use personal information
- Provide, operate, maintain, and support the Services.
- Create, administer, authenticate, and secure accounts.
- Respond to questions, demonstration requests, support needs, and other communications.
- Manage relationships with customers, partners, suppliers, and other business contacts.
- Process transactions and manage contracts and business records.
- Send product, service, event, research, and other updates where allowed by law.
- Personalize and improve website and Service experiences.
- Understand use, measure performance, and improve reliability.
- Detect, investigate, and prevent fraud, misuse, security incidents, and unlawful or harmful activity.
- Enforce agreements, policies, and terms; comply with law; and establish, exercise, or defend legal claims.
5. Customer Data and AI model training
Kore.ai uses data received through a customer's use of the Kore.ai offering only to provide the Services.
Kore.ai does not use that Customer Data for internal training, knowledge-base updates, internal product enhancements or updates, or to train generalized AI models offered as part of the Services.
If a customer chooses a third-party model, integration, application, or data source, information may be sent to that third party as configured by the customer. The third party's terms and privacy practices apply to its handling of the information.
7. Marketing choices
Where allowed by law, we may use your contact details to send information about Kore.ai products, services, events, research, and other updates. You can opt out of marketing emails at any time by using the unsubscribe link in the message. We may still send necessary service, transaction, administration, and security messages.
9. International transfers
Kore.ai operates internationally. Personal information may be transferred to, stored in, or processed in a country other than the country where it was collected, including the United States and India. Privacy laws and government access rules may differ between countries.
When a law restricts an international transfer, we use a method allowed by that law and take any additional steps required for the transfer. These may include transferring to a country recognized as providing adequate protection, using approved contractual safeguards, or relying on another lawful transfer method. You may ask us for more information about the safeguard used for your information by contacting privacy@kore.ai.
10. How long we keep information
We keep personal information only for as long as reasonably necessary for the purposes described in this Notice. We then delete it or irreversibly anonymise it, unless a longer period is necessary for legal, tax, accounting, contractual, security, fraud-prevention, or dispute-resolution purposes.
If you withdraw consent, we will stop the consent-based processing and, where required by applicable law, erase the relevant personal information and instruct our service providers to do the same, unless we are required or permitted by law to retain it. Protected backup copies may remain isolated until the relevant backup cycle expires and are not used for ordinary business purposes.
11. How we protect information
We use reasonable technical and organizational measures designed to protect personal information from unauthorized access, use, disclosure, change, loss, or misuse. Data processed through the Services is encrypted in transit and at rest. We also use access controls, infrastructure security, monitoring, vulnerability management, and incident-response processes.
No Internet transmission or electronic storage system is completely secure, so we cannot guarantee absolute security.
More information is available through the Kore.ai Trust Center.
12. Your privacy rights and choices
Your rights depend on where you live and how Kore.ai uses the information. Subject to the law that applies, you may be able to:
- ask for access to or a copy of your personal information;
- ask us to correct incomplete or inaccurate information;
- ask us to delete information;
- restrict or object to certain uses;
- withdraw consent for future use when we rely on consent;
- receive certain information in a portable format;
- opt out of marketing and, where applicable, sale, sharing, targeted advertising, or certain profiling;
- appeal a decision on a request where the law provides that right; and
- complain to a privacy regulator or authority.
These rights have conditions and exceptions. We may ask for information needed to verify your identity or authority. We use verification information only to handle the request, prevent fraud, and keep required records.
To make a request, email privacy@kore.ai or use our online privacy request form.
If the information is controlled by a Kore.ai customer, send your request to that customer. We will help the customer where required.
13. Children's privacy
The Services are intended for business use and are not directed to children under 13. Kore.ai does not knowingly collect personal information from children under 13 for its own purposes. If we learn that we collected a child's information in a way prohibited by law, we will take appropriate steps to delete it.
A customer may use a Service in a setting involving children. In that case, the customer decides why and how the information is used and is responsible for the required notice, permission, and safeguards; Kore.ai processes the information on the customer's instructions. Higher age and parental-consent rules may apply, including in Europe and India.
14. Changes to this Notice
We may update this Notice when our practices, Services, technologies, or legal duties change. We will change the "Last updated" date and, when required, give a more prominent or direct notice before a material change takes effect.
15. Contact us
For questions, complaints, or privacy requests, contact:
Kore.ai, Inc.
7380 West Sand Lake Road, Suite 390
Orlando, Florida 32819, United States
Email: privacy@kore.ai
Regional office contacts are listed below. The Kore.ai company responsible for a particular activity may also be identified in a form, contract, event notice, or other collection notice.
EEA: Kore.ai Germany GmbH, Westendstr. 28, 60325 Frankfurt am Main, Germany.
United Kingdom: Kore.ai UK Ltd., 2 Minister Court, London EC3R 7BB, United Kingdom.
India: Kore.ai Software India Pvt. Ltd., 3rd floor, Aurobindo Galaxy Towers, Hi-Tech City Road, Madhapur, Hyderabad 500081, India; +91-40-4252 8888.
United States privacy information
This section applies to residents of U.S. states that give them privacy rights in relation to Kore.ai's processing. It adds to the main Notice. State laws use different terms and may not apply to every person or activity.
Information collected and used during the last 12 months
This section applies to residents of U.S. states that give them privacy rights in relation to Kore.ai's processing. It adds to the main Notice. State laws use different terms and may not apply to every person or activity.
During the same period, we may have disclosed these categories for business purposes to the recipients described in Section 8. The category disclosed depends on the service the recipient provides and the interaction involved.
Sale, sharing, and targeted advertising
Kore.ai does not sell personal information for monetary payment. Our Cookie Policy explains that advertising cookies may collect information about activity on this and other sites to provide targeted advertising. Depending on the state law, disclosure of identifiers and Internet or network activity to advertising partners for this purpose may be called a "sale," "sharing," or "targeted advertising," even when no money is paid.
You can opt out by turning off advertising cookies through our website's cookie controls or by using the online privacy request form. Where a legally recognized browser-based opt-out preference signal applies, we treat it as an opt-out request for that browser or device as required by law.
U.S. state rights
Subject to the law that applies, you may ask to access, correct, delete, or receive a portable copy of personal information; learn about categories, sources, purposes, and disclosures; opt out of sale, sharing, targeted advertising, or qualifying profiling; limit certain uses of sensitive personal information; and appeal a decision on a request. We will not discriminate against you for using an applicable privacy right.
Use the contact methods in Section 12. An authorized agent may submit a request where allowed. We may require proof of authority and may verify your identity directly. If an appeal right applies, our response will explain how to appeal.
We use sensitive personal information described in this Notice only for the service, account, payment, requested feature, security, and legal purposes explained here. If applicable law gives you a right to limit another use, you may submit that request through the same methods.
EEA and United Kingdom privacy information
This section applies when the EU General Data Protection Regulation (GDPR) or United Kingdom GDPR governs Kore.ai's use of personal data. "Personal information" in the main Notice means "personal data" here.
Who is responsible
Kore.ai, Inc. is responsible for the website and direct corporate interactions unless another Kore.ai company is named when the information is collected. A local Kore.ai company may be responsible for a local contract, event, office interaction, or other activity when it decides why and how the data is used. The collection notice or contract will identify that company where needed. You may contact the Privacy Team at privacy@kore.ai or use the Germany or UK office details in Section 15.
Our reasons under data-protection law
Where we rely on legitimate interests, our interests include operating and securing the Services, managing business relationships, improving reliability, preventing misuse, communicating with business contacts, and protecting legal rights. We consider the effect on your rights and reasonable expectations. You may object as explained below.
Information received from other sources
When we receive personal data from someone other than you, the sources may include your organization, another user who invites or communicates with you, a customer-enabled application or data source, and service providers supporting our operations. We provide the required information within the time required by law and, where relevant, at the first communication or disclosure.
Special-category data
Please do not include health, biometric, racial or ethnic origin, religious, political, sexual-orientation, trade-union, or other special-category data in ordinary website, marketing, demo, event, or business-contact forms unless a specific notice asks for it. Customer-controlled content may include this kind of data when a customer chooses and lawfully configures a Service to process it. Kore.ai then processes it for the customer under the customer agreement.
International transfers
Personal data may be processed outside the EEA or United Kingdom, including in the United States and India. When the destination is not recognized as providing adequate protection, we use approved contractual safeguards (SCC) or another transfer method allowed by the applicable law and add further safeguards where required. Contact privacy@kore.ai to ask about the safeguard used for your data and how to obtain more information or a copy, subject to necessary redactions.
Your EEA and UK rights
Subject to legal conditions and exceptions, you may ask for access, correction, deletion, restriction, and portability; object to use based on legitimate interests or direct marketing; and withdraw consent at any time without affecting earlier lawful use. If we use your data for direct marketing, you may object at any time and we will stop that marketing use.
You may complain to the data-protection authority where you live or work or where you believe a violation occurred. In the United Kingdom, this is the Information Commissioner's Office. You may also contact us first so we can try to address the concern.
Automated decisions
If Kore.ai uses personal data for a decision based only on automated processing that has a legal or similarly significant effect on you, we will give you the information and safeguards required by law at or before that processing. This does not describe decisions made by a customer using a customer-configured Service; the customer's notice applies to those decisions.
India privacy information
This section applies to personal information processed in India or otherwise covered by Indian privacy law. It reflects the rules that apply now and identifies rights that will apply as the Digital Personal Data Protection Act, 2023 (DPDP Act) comes into force in phases.
India entity and contact
For an activity carried out by the India company, the responsible company is Kore.ai Software India Pvt. Ltd., 3rd floor, Aurobindo Galaxy Towers, Hi-Tech City Road, Madhapur, Hyderabad 500081, India; telephone +91-40-4252 8888. For privacy questions, rights, or grievances, email privacy@kore.ai and state that your request concerns India.
Information and purposes
The information, sources, purposes, recipients, retention approach, and security measures are explained in Sections 3 to 11. Under India's current sensitive-data rules, information such as passwords, financial information, health information, medical records, sexual orientation, and biometric information may receive additional protection. For Kore.ai's own activities, we collect sensitive information only when it is lawful, needed for a stated purpose, and accompanied by the notice and consent required by law. Customer-controlled content may contain other information selected by the customer.
Notice and consent
When we ask for consent, we explain in clear language what information is requested and the specific reason for using it. We also explain how to withdraw consent, exercise rights, and raise a complaint. When the relevant DPDP Act and Rules provisions apply, the notice for each consent request will be understandable on its own, list the requested data, describe the specific service or use, and provide a direct way to withdraw consent and make a request. Withdrawing consent will be as easy as giving it, subject to steps needed to confirm the request.
A general privacy page does not replace a short notice shown at the form, account screen, cookie tool, or other place where information is requested. Those shorter notices should be read with this Notice.
India rights
Rights depend on the law and its commencement date. They may include asking for a summary of personal data and processing, correction, completion, updating, and erasure; withdrawing consent; using Kore.ai's grievance process; and nominating another person to exercise rights after death or incapacity. Send a request to privacy@kore.ai or use the online privacy request form. We will respond within the period required by the law that applies.
Sharing and transfers
Where India's current sensitive-data rules apply, we share sensitive information with permission, as agreed in a lawful contract, or when required by law. We transfer it only when the recipient provides the level of protection required by law and the transfer is necessary for the lawful contract or is consented to as required. When the DPDP Act's transfer provisions apply, we will also follow any restrictions issued by the Central Government and any other Indian law that provides stronger protection.
Children in India
When the DPDP Act's child provisions apply, a child will generally mean a person under 18 unless an exception applies. Where Kore.ai is responsible for the processing, we will obtain verifiable parental consent when required and will not carry out prohibited tracking, behavioral monitoring, or targeted advertising directed at children. When a customer is responsible and Kore.ai processes data for that customer, the customer must provide the required notice and consent and Kore.ai will follow the customer's lawful instructions.