Privacy Policy
Last updated: 2 September 2026
This policy explains what personal data Intentric collects, how it's used, who it's shared with, and the choices and rights available to you. It covers both this marketing website and the Intentric product itself — see Scope, just below, for how those two are different.
Intentric is operated by Kanata Florida, LLC, a Florida limited liability company doing business as Intentric, of 2213 NW 1st Pl, Cape Coral, FL 33993, United States. Where this policy says “we” or “us”, it means that company, which is the controller of the personal data described below.
Scope: This Website vs. the Intentric Product
This policy covers two different things, and it's worth separating them clearly up front:
- This website (the marketing pages at this domain, including this one) is a static site. It has no login, no user account system, and no customer database. The only way to give us information through this site is by submitting the contact/request-access form.
- The Intentric product is the separate, authenticated platform that organizations use, once onboarded, to turn infrastructure intent into policy-gated, human-approved, audited cloud changes. It has its own accounts, organizations, and data.
Most of what follows about accounts, infrastructure intent, credentials, and billing applies to the product, not to this marketing site. Where a section below applies to only one of the two, it says so explicitly.
What We Collect
What we collect depends on whether you're browsing this marketing website or using the Intentric product.
| Where | Category | Examples |
|---|---|---|
| This website | Contact & access-request data | Name, work email, company, and whatever you write in the message field, if you submit the contact form |
| This website | Basic site analytics | Pages viewed, referring page, browser/device type, and an approximate location derived from IP address, in aggregate — this site has no accounts, so we cannot and do not build individual visitor profiles |
| Intentric product | Account & identity data | Name, email, organization, hashed authentication credentials, SSO/OIDC identifiers |
| Intentric product | Infrastructure intent & configuration data | Natural-language requests, the plans and resource configurations generated from them, and approval decisions |
| Intentric product | Usage & audit data | API usage, agent run records, and audit trail entries, including the identity of whoever took an action and when |
| Intentric product | Billing data | Billing contact details and subscription tier; payment card details are handled directly by our payment processor and are not stored on our servers |
| Intentric product | Brokered cloud access | Short-lived, scoped cloud session credentials issued per job; we do not store customers' long-lived cloud account credentials |
How We Use It
- To respond to inquiries submitted through the contact/request-access form.
- To provide, operate, and maintain the Intentric product for customers who use it — including generating infrastructure plans, evaluating them against policy gates, routing them for human approval, and executing approved plans.
- To maintain the audit trail that records who did what, and when, so customers (and we) can review and reconstruct activity on their account.
- To secure the service — detecting abuse, enforcing rate limits, and investigating suspected credential compromise.
- To bill for the product, via our payment processor.
- To understand aggregate traffic on this website and improve it.
- To comply with legal obligations and enforce our agreements.
We do not use data collected through this marketing website to make automated decisions about you, and we do not sell it.
Sharing
We do not sell personal data, and we do not share it with third parties for their own marketing purposes. We share data only as needed to operate the service:
- Cloud providers, acting on the customer's behalf. When the Intentric product provisions infrastructure, it does so using short-lived, scoped credentials brokered from the customer's own cloud account (see Security, below) — the cloud provider processes that request as the customer's agent, not as a third party receiving the customer's data from us.
- Service providers who help us run the service — for example, hosting/infrastructure providers, our payment processor for billing, and email delivery for transactional messages. They receive only what's needed to perform their function and are bound by confidentiality and data-protection obligations.
- Legal disclosures. We may disclose data if required by law, subpoena, or other legal process, or to protect the rights, property, or safety of Intentric, our customers, or others.
- A change in business control (merger, acquisition, or asset sale) — we would require any successor to honor the commitments in this policy for data collected under it.
Each customer organization's data is logically isolated from every other customer organization's data; it is not pooled or shared across organizations.
Cookies
This website may use a minimal, functional cookie or local storage to support form behavior (for example, remembering that you've dismissed a notice), and may use basic, aggregate analytics (page views, referrer, browser/device type) to understand traffic and improve the site. This site does not run third-party advertising or cross-site tracking cookies, and — because it has no account system — it cannot tie analytics data to an identified individual.
The Intentric product uses strictly necessary cookies or tokens to keep you signed in and to protect your session; it does not use advertising cookies.
Most browsers let you block or delete cookies through their settings. Doing so shouldn't prevent you from browsing this website, though it may affect sign-in on the product or optional convenience features here.
Retention
- Contact/access-request submissions are kept as long as needed to respond to your inquiry and for a reasonable follow-up period, then deleted or anonymized.
- Aggregate site analytics are retained only in aggregate form; we do not maintain long-lived individual visitor profiles from this website.
- Product account and configuration data is retained for the duration of the customer relationship, plus a limited period afterward for legitimate business, security, and legal purposes.
- Audit trail entries are retained longer than most other data by design — an audit trail that gets pruned casually isn't a meaningful security or compliance control — subject to each customer's contractual and legal retention requirements.
- Brokered cloud session credentials are short-lived by design and expire automatically when the job that requested them ends; we do not retain them past that point.
Your Rights
Depending on where you're located, you may have rights over your personal data under laws such as the EU/UK General Data Protection Regulation (GDPR) or the California Consumer Privacy Act and California Privacy Rights Act (CCPA/CPRA). We aim to honor these rights for anyone they apply to, regardless of location, including the right to:
- Know what personal data we hold about you and how it's used.
- Access a copy of your personal data.
- Correct inaccurate personal data.
- Request deletion of your personal data, subject to legitimate exceptions (for example, audit records we're required, or need, to retain).
- Object to or restrict certain processing, and request portability of data you provided to us.
- Not be discriminated against for exercising any of these rights.
Access and deletion are also available in the product itself: an account holder, or an administrator of their organization, can export the personal data an organization holds about them and request its deletion, without contacting us first. Because each organization is the controller of the data it holds, a request covers one organization at a time — if you belong to more than one, exporting or deleting from one does not affect the others.
Deletion destroys the encryption key your data is held under rather than marking a record as removed. That means it cannot be read again afterwards, including from a backup, and it cannot be undone by us on request.
To exercise any of these rights, or if you would rather we handle it for you, contact us at the address in Contact, below. We'll verify your request and respond within the time required by applicable law. This section describes the rights we aim to honor directly; it isn't a claim of participation in any specific third-party-certified privacy compliance program.
Security
This is a general privacy policy, not our full security documentation — see the Security page for the complete picture. The controls most relevant to your data:
- Policy gates evaluate every infrastructure plan before it can run — region allowlists, spend ceilings, and a rule that any destructive change always requires human approval.
- Mandatory human approval — no automated identity can approve its own work, and approval is recorded against the exact change that will execute, not a summary of it.
- Scoped credential brokering — the product never stores customers' long-lived cloud account credentials. Execution runs under a short-lived, narrowly scoped credential issued per job, which expires when the job ends.
- A tamper-evident record of decisions, approvals, grants of access and results is kept against the identity that acted, and cannot be altered after the fact.
- Hashed credential storage — issued API keys and similar bearer credentials are hashed at rest; the plaintext is shown once, at issuance.
- Per-organization data isolation enforced at the database layer, so one customer's data isn't reachable through another's queries.
No security program can guarantee absolute protection against every possible attack. If you believe you've found a security issue, please use the contact information below (and see the Security page) rather than disclosing it publicly.
Children's Privacy
Neither this website nor the Intentric product is directed at children, and we do not knowingly collect personal data from children under 13 (or the equivalent minimum age where you live, such as 16 in parts of the EU). If you believe a child has provided us with personal data, contact us and we'll delete it.
Changes to This Policy
We may update this policy as the product, this website, or applicable law changes. We'll update the "Last updated" date at the top when we do. For material changes that affect Intentric product customers' data, we'll aim to provide more direct notice (for example, by email) in addition to updating this page. We encourage you to review this policy periodically.
Contact
Questions about this policy, or requests to access, correct, or delete your personal data, can be sent to:
Or by post to Kanata Florida, LLC, 2213 NW 1st Pl, Cape Coral, FL 33993, United States.
For security vulnerability reports specifically, see the Security page.